DidhoPay
Privacy Policy
This Privacy Policy explains how Didho Digital (Pty) Ltd ("DidhoPay", "we", "us", "our") collects, uses, discloses, and protects your information when you use the DidhoPay mobile application, USSD service, and related services (together, the "Service").
DidhoPay is a mobile money and payment service operating in the Kingdom of Eswatini. Because we are a financial service provider, we are required by law to collect and verify certain information about you. By creating an account or using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.
1. Who we are and how to contact us
Data controller: Didho Digital (Pty) Ltd
Email: privacy@didho.co.za
Website: didho.co.za
DidhoPay operates under the regulatory oversight of the Central Bank of Eswatini (CBE) and applicable Eswatini anti-money-laundering and financial-services laws.
2. Information we collect
We only collect information needed to provide the Service, verify your identity, keep your account secure, and meet our legal obligations.
a. Identity and KYC information
- Full name, date of birth, gender, and nationality
- National identity number and a photograph/scan of your identity document (captured with your device camera; some fields are read automatically using optical character recognition)
- A facial image / selfie used to confirm that you are the holder of the identity document (biometric verification and liveness check)
b. Contact and address information
- Mobile phone number
- Email address (if provided)
- Residential or business address (region, inkhundla, chiefdom, town)
c. Financial and transaction information
- Wallet balance and transaction history (deposits, withdrawals, transfers, merchant and agent payments)
- Payment details and references
- Source of funds and, where applicable, expected transaction activity
- Screening results required by law, such as politically-exposed-person (PEP) and sanctions status
d. Account and security information
- Your PIN, stored only in a securely hashed form — we never store it in plain text
- One-time passwords (OTPs) and multi-factor authentication data
- Login, session, and device-security records
e. Device and technical information
- Device identifiers, device model, and operating-system version
- IP address and approximate location derived from it
- App interaction and diagnostic/log data
- A push-notification token, to deliver alerts
f. Communications
- SMS one-time verification codes sent to your number. Where you allow it, the app may read the incoming verification SMS solely to auto-fill the code. We do not read your other messages.
- Records of your interactions with customer support
We do not knowingly collect information from anyone under 18 years of age. The Service is intended for adults only.
3. How we use your information
- Provide the Service — create and operate your wallet, and process deposits, withdrawals, transfers, and payments
- Verify your identity (KYC) — confirm who you are during onboarding, including document scanning and facial matching
- Comply with the law — meet anti-money-laundering (AML) and counter-terrorist-financing (CFT) obligations; screen against sanctions and PEP lists; monitor transactions; and make regulatory reports where required
- Keep your account secure — authenticate you with your PIN and one-time passwords, detect and prevent fraud, and investigate suspicious activity
- Communicate with you — send transaction confirmations, security alerts, verification codes, and service notices by SMS and push notification
- Support you — respond to your questions and resolve issues
- Improve and maintain the Service — diagnose problems and improve reliability and security
We do not sell your personal information, and we do not use it for third-party advertising.
4. Legal basis for processing
We process your information because it is:
- Necessary to provide the Service you have requested (to perform our contract with you);
- Required to comply with legal and regulatory obligations (including AML/CFT and financial-services law); and/or
- Necessary for our legitimate interests in securing the Service and preventing fraud, balanced against your rights.
Where the law requires your consent — for example, to process your biometric/facial data for identity verification, or to read verification SMS for auto-fill — we ask for it, and you may withdraw it, subject to the limits explained below.
5. How we share your information
We share information only as needed to run the Service and meet our obligations:
- Service providers (processors) who act on our instructions, including: Smile Identity (identity verification and facial/biometric matching), our SMS provider (delivery of one-time codes and alerts), Google Firebase (push notifications), and Amazon Web Services (AWS) and MongoDB Atlas (secure cloud hosting and data storage)
- Financial partners — banks, mobile-network operators, and payment networks, strictly to process and settle your transactions
- Regulators and authorities — the Central Bank of Eswatini, the Financial Intelligence Unit, courts, and law-enforcement agencies, where we are legally required or permitted to disclose information
- Professional advisers and auditors — under confidentiality
- In a business transfer — if our business is merged, acquired, or reorganised, subject to this Policy
We require all service providers to protect your information and to use it only for the purposes we specify.
6. Where we store and process your information
DidhoPay is a domestic payment service operating within Eswatini. We do not process cross-border or international money transfers. This section concerns only where your information is stored and processed — not the movement of funds.
Our systems are hosted on cloud infrastructure located in the AWS Africa (Cape Town) region in South Africa, and some information may be processed by our service providers outside Eswatini. Where information is stored or processed outside Eswatini, we take steps to ensure it remains protected in line with this Policy and applicable law.
7. How we protect your information
- Encryption of data in transit (TLS/HTTPS) and protection of data at rest
- Storing PINs only as secure hashes
- Multi-factor authentication and account-lockout controls
- Access controls, so staff only access data they need
- Monitoring, logging, and fraud-detection controls
No method of transmission or storage is completely secure, but we work continuously to safeguard your information. Please keep your PIN and one-time codes confidential and never share them with anyone — including anyone claiming to be from DidhoPay.
8. How long we keep your information
We keep your information for as long as your account is active and for as long afterwards as the law requires. Because we are a financial service provider, we are legally required to retain identity and transaction records for a minimum period — generally at least five (5) years after the end of our relationship or a transaction, as required by Eswatini AML law. After the applicable retention period, we securely delete or anonymise your information.
9. Your rights and choices
Subject to applicable law, you may:
- Access the personal information we hold about you
- Correct information that is inaccurate or out of date
- Request deletion of your information (see "Account and data deletion" below)
- Withdraw consent where we relied on it
- Object to or restrict certain processing
- Complain to us or to the relevant regulator
To exercise any of these rights, contact us at privacy@didho.co.za. We may need to verify your identity before acting on your request. Some rights are limited where we are legally required to keep information (for example, AML records).
10. Account and data deletion
You can request deletion of your DidhoPay account and associated personal data by:
- Using the account-deletion option in the app (Settings → Account → Delete account), or
- Emailing privacy@didho.co.za from your registered details, or
- Visiting didho.co.za/delete-account
When you request deletion, we will close your account and delete or anonymise your personal data, except information we are legally required to retain (such as identity and transaction records kept for AML and financial-regulatory purposes) and any information needed to resolve disputes, prevent fraud, or enforce our terms. Retained records are kept secure and access-restricted, and are deleted once the legal retention period ends. Any outstanding wallet balance must be withdrawn or settled before an account can be closed.
11. Permissions the app uses
- Camera — to capture your identity document and selfie during verification
- SMS (verification codes) — to receive and, with your permission, auto-fill one-time login/verification codes
- Notifications — to send you transaction and security alerts
- Internet / network access — to connect securely to our servers
- Photos / storage (if applicable) — to attach supporting documents
You can manage permissions in your device settings; disabling some permissions may limit parts of the Service.
12. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you in the app or by other means. Your continued use of the Service after changes take effect means you accept the updated Policy.
13. Contact us
If you have any questions, requests, or complaints about this Policy or your information, contact Didho Digital (Pty) Ltd at privacy@didho.co.za.