Privacy Policy
Effective date: March 2, 2026 · Last updated September 23, 2026
Adili is operated by Algolab Limited. This policy explains how we collect, use, disclose, and safeguard personal data when you use Adili, including the Adili mobile app for iOS and Android, and related services available through algolab.africa.
1. Scope
This policy applies to account users, organization administrators, team members, support contacts, SACCO and group members who use the Adili mobile app, and borrower-related information processed in the platform by our customers.
2. Data we collect
Depending on how the service is used, we may process:
- Account and identity data, including name, email address, profile image, and login credentials.
- Session and security data, including session tokens, IP address, and user agent.
- Organization data, including organization profile, branch setup, roles, members, and invitations.
- Borrower and guarantor identity, contact, address, demographic, and employment data entered by customers.
- Loan, disbursement, repayment, portfolio, ledger, document, media, audit, and reliability data.
- In the Adili mobile app: your phone number (you sign in with a code sent by SMS), name, email address, the organizations and branches you belong to, and the financial records your organization keeps (savings, loans, repayments, contributions) that you are allowed to see.
- Your device's push notification token, issued by Firebase Cloud Messaging (Google) if you allow notifications, used only to deliver notifications to that device. We store it with your account, and it is deleted when you sign out of the app or delete your account. You can turn notifications off in your device settings.
3. What we do not collect
The Adili mobile app has no advertising, no third-party analytics or crash reporting tools, does not track you across other apps or websites, and does not read your location, contacts, or photos unless you choose to share them.
4. How we use personal data
- To provide, secure, and maintain the service.
- To authenticate users and manage organization access control.
- To process loan operations, repayment workflows, reporting, documents, and media.
- To send account, operational, and transactional communications.
- To send sign-in codes by SMS and notifications to the mobile app.
- To detect misuse, investigate incidents, and satisfy legal obligations.
5. Legal bases
- Performance of our contract with customers.
- Legitimate business and security interests.
- Compliance with legal and regulatory obligations.
- Consent, where consent is required by applicable law.
6. Data sharing and subprocessors
We do not sell personal data. We share only the data needed with: our SMS provider (phone number and message content, for sign-in codes and messages your organization sends); our mobile money payment provider (phone number and amount, for payments you start); a licensed credit bureau (identity and credit history, when your organization runs a credit check or reports as the law requires); and Google's Firebase Cloud Messaging (push notification token and notification content). We may also share data with authentication, cloud storage, email, ledger, financial infrastructure, hosting, queueing, and observability providers solely to operate the service. We may also disclose data where required by law or to protect rights, safety, and security.
7. International transfers
Your data may be processed in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers.
8. Data retention
We retain data for as long as necessary to provide the service, meet legal obligations, resolve disputes, enforce agreements, and maintain reliable audit history. Retention periods may vary by data type.
9. Deleting your account
You can delete your account at any time in the app: staff open More → Security & sessions → Delete account, and members open Account → Delete account. Without the app, follow the steps at /en/delete-account.
Deleting your account immediately removes your name, phone number, email address, photo, your access to every organization, and all your sign-in methods and sessions. Financial records your organization must keep by law (loans, repayments, savings, audit history) stay with the organization and no longer identify you.
10. Security
We apply technical and organizational controls designed to protect data, including access controls, transport security, logical segregation by organization, and operational monitoring. No method of transmission or storage is fully risk-free.
11. Customer role and borrower data
For borrower and guarantor records entered by a customer organization, the customer is generally the data controller and we act as a processor. Customers are responsible for lawful collection authority and required notices.
12. Your rights
Subject to local law, you may have rights to access, correct, delete, restrict, object to, or port personal data. To make a request, contact support@adili.app.
13. Cookies and local storage
We use essential cookies and local storage for core functionality, including session continuity and interface preferences. See our Cookie Policy for details.
14. Children
The service is intended for business and institutional use and is not directed to children.
15. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by an updated “Last updated” date and, where appropriate, additional notice.
16. Contact
Algolab Limited · algolab.africa · support@adili.app · United Republic of Tanzania