SocGen TECHNOLOGIES LIMITED DATA PRIVACY STATEMENT

Copyright © 2021
At Socgen Technologies Limited, we are committed to protecting your personal data and
respecting your privacy.
INTRODUCTION
This policy and any additional terms of use incorporated as well as other policies, (together
our Terms of Use) apply to your use of:
• Spotlit version 10008. Mobile application software (App) available on our site (App
Site), once you have downloaded or streamed a copy of the App onto your mobile
telephone or handheld device (Device).
• Any of the services accessible through the App (Services) that are available on the App
Site or other sites of ours (Services Sites), unless the EULA (if provided) states that a
separate privacy policy applies to a particular Service, in which case that privacy policy
only applies. This policy sets out the basis on which any personal data we collect from
you, or that you provide to us, will be processed by us. This App is not intended for
children and we do not knowingly collect data relating to children. Please read the
following carefully to understand our practices regarding your personal data and how
we will treat it.
Alternatively, you can download a pdf version of the policy here.
IMPORTANT INFORMATION AND WHO WE ARE
Socgen Technologies Limited is the controller and is responsible for your personal data
(collectively referred to as “we”, “us” or “our” in this policy).
If you have any questions about this privacy policy, please contact them using the details set
out below.
Contact details
Our full details are:
Socgen Technologies Limited
Data Controller
[email protected]
P.O. BOX 55368- CITY SQUARE
KENYA

Changes to the privacy policy and your duty to inform us of changes
We keep our privacy policy under regular review.
We reserve the right to make changes to this policy at any time. Once any changes are
made, these changes will be posted on this page and, where appropriate, notified to you by
SMS OR by email OR when you next start the App or log onto one of the Services Sites- as
far as technically and legally feasible. The new policy may be displayed on-screen and you
may be required to read and accept the changes to continue your use of the App or the
Services.
It is important that the personal data we hold about you is accurate and current. Please
keep us informed if your personal data changes during our relationship with you.
Third party links
Our Sites may, from time to time, contain links to and from the websites of our partner
networks, advertisers and affiliates. Please note that these websites and any services that
may be accessible through them have their own privacy policies and that we do not accept
any responsibility or liability for these policies or for any personal data that may be collected
through these websites or services, such as Contact and Location Data. Please check these
policies before you submit any personal data to these websites or use these services.
THE DATA WE COLLECT ABOUT YOU
This App collects, by itself or through third parties personal data. We may collect, use, store
and transfer different kinds of personal data about you which may include:
• Identity Data.
• Contact Data.
• Financial Data.
• Transaction Data.
• Device Data.
• Content Data.
• Profile Data.
• Usage Data.
• Marketing and Communications Data.
• Location Data
We explain these categories of data below.

We also collect, use and share Aggregated Data such as statistical or demographic data for
any purpose. Aggregated Data could be derived from your personal data but is not
considered personal data in law as this data will not directly or indirectly reveal your
identity. For example, we may aggregate your Usage Data to calculate the percentage of
users accessing a specific App feature. However, if we combine or connect Aggregated Data
with your personal data so that it can directly or indirectly identify you, we treat the
combined data as personal data which will be used in accordance with this privacy policy.
Personal Data collected may be freely provided by you, or in the case of usage data,
automatically collected when using this App.
Unless otherwise provides, all Data requested is mandatory and failure to provide this Data
may make it impossible for this App to provide its services. In instances where some Data is
not mandatory, you may opt not to provide such data without consequences to the
availability or functioning of the App services.
HOW IS YOUR PERSONAL DATA COLLECTED?
We will collect and process the following data about you:
• Information you give us. This is information (including Identity, Contact, Financial, and
Marketing and Communications Data) you consent to giving us about you by filling in
forms on the App Site and the Services Sites (together Our Sites), or by corresponding
with us (for example, by email or chat). It includes information you provide when you
register to use the App Site, download or register an App, subscribe to any of our
Services, search for an App or Service, make an in-App purchase, share data via an
App’s social media functions, *enter a competition, promotion or survey, or other
activities commonly carried out in connection with an app and when you report a
problem with an App, our Services, or any of Our Sites. If you contact us, we will keep a
record of that correspondence.
• Information we collect about you and your device. Each time you visit one of Our Sites
or use one of our Apps or services we will automatically collect personal data including
Device, Content and Usage Data. We collect this data using cookies and other similar
technologies. Please see our cookie policy for further details.
• Location Data. We also use GPS technology or other technology to determine your
current location. Some of our location-enabled Services require your personal data for
the feature to work. If you wish to use the particular feature, you will be asked to
consent to your data being used for this purpose. You can withdraw your consent at
any time by disabling Location Data in your settings OR through ways stipulated or
referenced as acceptable ways on withdrawal of such consent on this policy.
• Information we receive from other sources including third parties and publicly available
sources. We will receive personal data about you from various third parties and public
sources.

COOKIES
We use cookies and/or other tracking technologies to distinguish you from other users of
the App, App Site, the distribution platform (Appstore) or Services Sites and to remember
your preferences. This helps us to provide you with a good experience when you use the
App or browse any of Our Sites and also allows us to improve the App and Our Sites. For
detailed information on the cookies we use, the purposes for which we use them and how
you can exercise your choices regarding our use of your cookies see our website.
HOW WE USE YOUR PERSONAL DATA
Most commonly we will use your personal data in the following circumstances:
• Where you have consented before the processing.
• Where we need to perform a contract we are about to enter or have entered with you.
• Where it is necessary for our legitimate interests (or those of a third party) and your
interests and fundamental rights do not override those interests.
• Where we need to comply with a legal or regulatory obligation.
We will only send you direct marketing communications by email or text if we have your
consent. You have the right to withdraw that consent at any time by contacting us.

DISCLOSURES OF YOUR PERSONAL DATA
When you consent to providing us with your personal data, any disclosure shall be in
accordance with applicable law and regulations. We shall assess and review each application
made for such information and may refuse to grant such access to a requesting party.
Your information may be disclosed to:
 Law-enforcement agencies, courts, public authorities or regulatory authorities in
response and compliance to a lawful mandate within reasonable and lawful
demands
 Subsidiaries, associates, partners or agents who are involved in delivering our
products
Your information will not be disclosed to any individual or entity that is acting beyond its
legal mandate.
INTERNATIONAL TRANSFERS
In certain instances, we may transfer your data outside of Kenya as some of our external
third parties are based outside of Kenya, so their processing of your personal data will
involve a transfer of data outside Kenya.
Where we send your information outside Kenya, we will make sure that your information is
properly protected and transferred in accordance with the relevant data protection laws.
Please contact us if you want further information on the specific mechanism used by us
when transferring your personal data out of Kenya in accordance with data laws.

DATA SECURITY
All information you provide to us is stored on our secure servers. Any payment transactions
carried out by us or our chosen third-party provider of payment processing services will be
encrypted using Secured Sockets Layer technology or alternative encryption technology.
Where we have given you (or where you have chosen) a password that enables you to
access certain parts of Our Sites, you are responsible for keeping this password confidential.
We ask you not to share a password with anyone.
Once we have received your information, we will use strict procedures and security features
to try to prevent your personal data from being accidentally lost, used or accessed in an
unauthorised way.
We will collect and store personal data on your Device using application data caches and
browser web storage (including HTML5) or alternative mechanisms and other technology.
Certain Services include social networking, chat room or forum features. Ensure when using
these features that you do not submit any personal data that you do not want to be seen,
collected or used by other users.
We have put in place procedures to deal with any suspected personal data breach and will
notify you and any applicable regulator when we are legally required to do so.
DATA RETENTION
We will retain your personal data only for as long as may be reasonably necessary to satisfy
the purpose for which it is processed, including for purposes for ensuring compliance with
any legal, regulatory, tax, accounting or reporting requirements.
In some circumstances you can ask us to delete your data: see your legal right below for
further information.
In some circumstances we will anonymise or pseudonymise your personal data (so that it
can no longer be associated with you) for research or statistical purposes, in which case we
may use this information indefinitely without further notice to you.
In the event that you do not use the App for a period of one (1) year then we will treat the
account as expired and your personal data may be deleted.
YOUR LEGAL RIGHTS
Under certain circumstances you have the following rights under data protection laws in
relation to your personal data. These include:
• Request access to your personal data. You have the right to learn or obtain disclosure
on certain aspects where their data is being processed.
• Request correction of your personal data. You have the right to verify and seek

rectification of your data and ask for it to be updated or corrected. To update your
information go here.
• Request erasure of your personal data. You have the right, under certain
circumstances, to request erasure of your personal data.
• Object to processing of your personal data. You have the right, under certain
circumstances to object to the processing of your data if the said processing is carried
out on a legal basis other than consent. Where such personal data is required to be
processed as a consequence of pursuing legitimate interests of the company as a
matter of public interest; you may object by providing a ground related to their
particular situation to justify the objection. However, if your data is utilised for direct
marketing and advertising purposes, you may object at any time without providing any
justification.
• Request restriction of processing your personal data. You have the right, under certain
circumstances, to restrict the processing of your data and in such an instance your data
will not be processed for any other reason other than storing it.
• Request transfer or your personal data. You have a right to receive your data in a
structured, commonly used and machine readable format. You have the right to
transmit the data to another data controller. Where technically feasible, the data can
be transmitted to another controller without any hindrance.
• Right to withdraw consent. You have the right to withdraw consent where you
previously given your consent to the processing of your personal data. Note that the
withdrawal will not affect the lawfulness of any processing carried out before you
withdraw your consent.
You also have the right to ask us not to continue to process your personal data for
marketing purposes.
You can exercise any of these rights at any time by contacting us at [email protected]
GLOSSARY
“includes” means what follows is not necessarily exhaustive and as such the examples
included are not the only items or situations in the meaning or explanation of the said text.
“lawful basis Consent” means processing your personal data where you have signified your
agreement by a statement or clear opt-in to processing for a specific purpose. Consent will
only be valid if it is a freely given, specific, informed and unambiguous indication of what
you want. You can withdraw your consent at any time by contacting us.
“Legitimate Interest” means the interest of our business in conducting and managing our
business to enable us to give you the best service/product and the best and most secure
experience. We make sure we consider and balance any potential impact on you (both
positive and negative) and your rights before we process your personal data for our
legitimate interests. We do not use your personal data for activities where our interests are

overridden by the impact on you (unless we have your consent or are otherwise required or
permitted to by law). You can obtain further information about how we assess our
legitimate interests against any potential impact on you in respect of specific activities by
contacting us.
“Performance of Contract” means processing your data where it is necessary for the
performance of a contract to which you are a party or to take steps at your request before
entering into such a contract.
“Comply with a legal obligation” means processing your personal data where it is necessary
for compliance with a legal obligation that we are subject to
THIRD PARTIES
May include external third parties, Service providers acting as processors or otherwise who
provide IT and system administration services.
Professional advisers acting as processors or joint controllers including lawyers, bankers,
auditors and insurers who provide consultancy, banking, legal, insurance and accounting
services.
Kenya Revenue Authority, regulators and other authorities acting as processors or joint
controllers based who require reporting of processing activities in certain circumstances.

DESCRIPTION OF CATEGORIES OF PERSONAL DATA
• Identity Data: Would include first name, last name, maiden name, username or similar
identifier, marital status, title, date of birth, gender.
• Contact Data: Includes billing address, delivery address, email address and telephone
numbers.
• Financial Data: Includes bank account and payment card details, Mobile Financial
Services identifiers provided by different carriers
• Transaction Data: includes details about payments to and from you and details of inApp purchases.
• Device Data: includes the type of mobile device you use, a unique device identifier [(for
example, your Device’s IMEI number, the MAC address of the Device’s wireless
network interface, or the mobile phone number used by the Device), mobile network
information, your mobile operating system, the type of mobile browser you use, time
zone setting, etc
• Content Data: includes information stored on your Device, including friends’ lists, login
information, photos, videos or other digital content, check-ins, etc.

Profile Data: includes your username and password, in-App purchase history, your
interests, preferences, feedback and survey responses.
• Usage Data: includes details of your use of any of our Apps or your visits to any of Our
Sites including, but not limited to, traffic data and other communication data, whether
this is required for our own billing purposes or otherwise and the resources that you
access.
• Marketing and Communications Data: includes your preferences in receiving marketing
from us and our third parties and your communication preferences.
• Location Data: includes your current location disclosed by GPS technology or any other
technology that may be used to access your location
NON COMPLIANCE WITH THIS STATEMENT
We shall have the right to terminate any agreement with you for non-adherence to
provisions of this policy and reject any application for information contrary to this policy.
FURTHER INFORMATION ABOUT PERSONAL DATA
This application may send push notifications to the user.