Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your information in compliance with the Tanzania Personal Data Protection Act, 2019.
Last updated: February 27, 2026
Version: 2.1 - PDPA Compliant
Tanzania PDPA Compliance Statement
Mguso Meet is fully committed to complying with the Tanzania Personal Data Protection Act, 2019 (PDPA). We are registered as a data controller with the Personal Data Protection Commission (PDPC) and implement appropriate technical and organizational measures to protect your personal data.
Our PDPA Commitments:
- Lawful basis for all data processing activities
- Purpose limitation and data minimization principles
- Accuracy and storage limitation of personal data
- Security safeguards and breach notification procedures
- Accountability and documentation of compliance
Data Controller Registration Details
Mguso Meet is registered as a data controller under the Tanzania Personal Data Protection Act, 2019.
Controller Name: Mguso Solutions Limited
Registration Number: PDPC-2024-TZ-001234
Registration Date: January 15, 2024
Jurisdiction: Tanzania Mainland
Categories of Data Processed: Personal, Contact, Payment, Meeting Data
Purposes of Processing: Service Provision, Payment Processing, Analytics
Data Subject Categories: Hosts, Participants, Website Visitors
Recipient Categories: Payment Processors, Video Infrastructure Providers
Data Protection Officer (DPO)
Our Data Protection Officer is responsible for overseeing our compliance with the PDPA and is your point of contact for all data protection matters.
For data protection inquiries, rights requests, or breach notifications, please contact our DPO directly at [email protected] or call +255 712 345 678.
1. Introduction
Mguso Meet ("we," "our," or "us") is committed to protecting your privacy in accordance with the Tanzania Personal Data Protection Act, 2019. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website meet.mguso.co.tz and use our virtual meeting platform services.
By using Mguso Meet, you consent to the data practices described in this policy. If you do not agree with the terms of this privacy policy, please do not access or use our website or services.
This policy applies to all users of our services in Tanzania and internationally, ensuring compliance with PDPA and applicable data protection laws.
2. Information We Collect
Personal Information
We may collect personal information that identifies you, including:
- Name, email address, and contact information
- Payment information (processed securely through third-party providers)
- Profile information and preferences
- Company or organization information
- Government identification information where required by law
Meeting Data
To provide our services, we collect and process meeting-related data:
- Meeting schedules and participant lists
- Audio and video recordings (when enabled by hosts)
- Chat messages and transcripts
- Meeting analytics and attendance data
- Screen sharing content and virtual whiteboard data
- Meeting duration and participation metrics
Technical Information
We automatically collect certain technical information:
- IP address and geolocation data
- Browser type, operating system, and device information
- Usage data and interaction patterns
- Cookies and similar tracking technologies
- Device identifiers and network information
3. How We Use Your Information
We use the information we collect on the following lawful bases under the PDPA:
- Contractual Necessity: Provide, maintain, and improve our virtual meeting services
- Legal Obligation: Process payments and comply with regulatory requirements
- Legitimate Interest: Send you important notifications about your meetings and ensure security
- Consent: Respond to your questions, provide customer support, and marketing communications
- Legal Obligation: Analyze usage patterns to optimize our platform and prevent fraud
- Legal Requirement: Comply with legal obligations and regulatory requirements
4. Information Sharing
We Do Not Sell Your Personal Information
We never sell your personal information to third parties.
Third-Party Service Providers
We share information with trusted third-party providers who help us operate our services under data processing agreements:
- Payment Processors: Flutterwave, ClickPesa for payment processing
- Video Infrastructure: Whereby for video meeting functionality
- Email Services: For sending notifications and updates
- Analytics: To understand how our platform is used
Legal Requirements
We may disclose your information if required by law or to protect our rights, property, or safety.
5. Data Security
We implement appropriate technical and organizational measures to protect your information:
- End-to-end encryption for small room meetings
- Secure data transmission using HTTPS/TLS
- Regular security audits and vulnerability assessments
- Access controls and authentication systems
- Compliance with international security standards (ISO 27001)
- Regular staff training on data protection
- Incident response procedures and breach management
While we take reasonable measures to protect your information, no method of transmission over the internet is 100% secure.
6. Data Retention Periods
We retain your information only as long as necessary for the purposes outlined in the PDPA:
Specific Retention Periods:
- Account Information: Retained while your account is active plus 7 years for legal compliance
- Meeting Recordings: Retained according to your plan settings (30 days to 1 year)
- Chat Transcripts: Retained for 6 months unless saved by host
- Payment Records: Retained for 7 years for tax and legal compliance
- Access Logs: Retained for 2 years for security purposes
- Consent Records: Retained for 7 years as required by PDPA
- Marketing Communications: Retained until you unsubscribe or consent is withdrawn
- Deleted Account Data: Anonymized and retained for 2 years for legal compliance
You can request deletion of your account and associated data at any time, subject to legal retention requirements.
7. Data Subject Rights Procedures
Under the Tanzania PDPA, you have the following rights regarding your personal data:
Right to be Informed
You have the right to be informed about the collection and use of your personal data. This privacy policy provides this information.
Right of Access
You can request access to your personal data. We will provide a copy within 30 days of your request.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure (Right to be Forgotten)
You can request deletion of your personal data when it's no longer necessary for the purposes it was collected.
Right to Restrict Processing
You can request restriction of processing your personal data under certain circumstances.
Right to Data Portability
You can request transfer of your data to another service in a structured, machine-readable format.
Right to Object
You can object to processing of your personal data for direct marketing or other legitimate interests.
How to Exercise Your Rights:
- Submit your request in writing to [email protected]
- Provide sufficient information to identify yourself and your data
- Specify which right you wish to exercise
- We will acknowledge your request within 5 working days
- We will respond substantively within 30 days
- If we cannot comply, we will explain the reasons
8. International Data Transfer Safeguards
Your information may be transferred to and processed in countries other than Tanzania. We ensure appropriate safeguards are in place for international transfers:
Our Transfer Safeguards Include:
- Standard Contractual Clauses: We use EU-standard contractual clauses for international transfers
- Data Processing Agreements: All third-party processors sign agreements ensuring PDPA-level protection
- Adequacy Assessments: We conduct assessments before transferring to new countries
- Security Measures: Encryption and access controls apply to all international transfers
- Regulatory Compliance: We comply with PDPC requirements for cross-border data transfers
Countries Where Data May Be Processed:
- Tanzania: Primary processing location
- United States: Video infrastructure (Whereby) - protected by SCCs
- European Union: Payment processors - GDPR compliant
- Other Countries: Only with adequate safeguards and PDPC approval
9. Data Breach Notification Procedures
We have established procedures for detecting, investigating, and notifying data breaches in compliance with the PDPA:
Our Breach Response Process:
- Detection (Within 24 hours): Immediate investigation of suspected breaches
- Assessment (Within 48 hours): Evaluate breach impact and affected data subjects
- PDPC Notification (Within 72 hours): Report to Personal Data Protection Commission
- Data Subject Notification: Inform affected individuals if high risk to their rights
- Containment: Immediate measures to prevent further data loss
- Recovery: Restore systems and affected data
- Post-Incident Review: Analyze cause and implement improvements
Breach Notification Content:
When we notify you of a breach, we will include:
- Nature of the personal data breach
- Categories and approximate number of affected individuals
- Likely consequences of the breach
- Measures we have taken or propose to take
- Recommendations for individuals to protect themselves
10. Children's Privacy
Our services are not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected information from a child under 13, we will take steps to delete such information immediately in accordance with PDPA requirements.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law, including PDPA requirements. We will notify you of any changes by:
- Posting the new policy on this page
- Updating the "Last updated" date and version number
- Sending email notifications for significant changes
- Website banners for material changes
Your continued use of our services after any changes constitutes acceptance of the updated policy.
12. Contact Information
If you have any questions about this Privacy Policy or our data practices, or wish to exercise your data subject rights, please contact us:
Data Protection Officer:
Email: [email protected]
Phone: +255 762 144 325
Response Time: Within 7 working days
General Inquiries:
Email: [email protected]
Phone: +255 762 144 325
Postal Address:
Mguso Solutions Limited
Ukonga, Dar es Salaam
Tanzania
Postal: 41064 DSM
Website:
For urgent data breach notifications, please contact our DPO immediately at [email protected] or call +255 712 345 678.
Tanzania PDPA Compliance
This privacy policy has been reviewed and approved by our Data Protection Officer to ensure compliance with the Tanzania Personal Data Protection Act, 2019.
Key PDPA Principles Followed:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
PDPC Registration Details:
Related Policies
Privacy Policy Version 2.1 - PDPA Compliant
Effective Date: February 27, 2026 | Next Review: February 27, 2027
This policy is reviewed annually and as required by law or regulatory changes.