PayGo Logo

Privacy Policy

Last Reviewed: June 2026

Table of Contents

1. Introduction

At Digital Shared Services Limited (DSSL), protecting the privacy and security of personal information is a fundamental part of our business operations.

We are committed to processing personal data lawfully, fairly, transparently, and securely in accordance with the Data Protection Act No. 3 of 2021 of the Republic of Zambia and other applicable regulatory requirements.

As a Payment Aggregator and Financial Technology (FinTech) company, we facilitate electronic payment services between customers, merchants, financial institutions, mobile money operators, and other payment ecosystem participants.

2. Our Role as a Data Processor

In most circumstances, DSSL acts as a Data Processor as defined under the Data Protection Act No. 3 of 2021.

This means that we process personal data on behalf of and under the instructions of our clients, who typically include:

  • Banks and Financial Institutions
  • Mobile Money Service Providers
  • Merchants and Businesses
  • Government Institutions
  • Other regulated entities

These organisations determine the purposes and means of processing personal data and therefore act as the Data Controllers.

We only process personal data as necessary to provide payment aggregation, transaction processing, reconciliation, settlement, fraud prevention, compliance, and related technology services.

Where required by law or where we independently determine the purposes and means of processing certain information, we may also act as a Data Controller.

3. Personal Data We May Process

Depending on the services provided, we may process the following categories of personal data:

  • Full names
  • National Registration Card (NRC) numbers
  • Passport numbers
  • Mobile phone numbers
  • Email addresses
  • Physical addresses
  • Date of birth
  • Bank account information
  • Payment card information
  • Transaction records
  • Merchant information
  • Device and technical information
  • IP addresses and system logs
  • Customer identification and verification information

We only process personal data that is necessary for legitimate business, legal, regulatory, and contractual purposes.

4. How We Use Personal Data

Personal data may be processed for the following purposes:

  • Facilitating payment transactions.
  • Merchant onboarding and management.
  • Customer verification and authentication.
  • Fraud detection and prevention.
  • Anti-Money Laundering (AML) and Know Your Customer (KYC) compliance.
  • Transaction monitoring and reconciliation.
  • Regulatory reporting obligations.
  • Customer support and dispute resolution.
  • Information security and system administration.
  • Business continuity and operational resilience.

6. Sharing of Personal Data

We may share personal data with:

  • Licensed financial institutions.
  • Payment service providers.
  • Mobile network operators.
  • Regulatory and supervisory authorities.
  • Law enforcement agencies where legally required.
  • Technology and service providers supporting our operations.
  • Other authorised parties as permitted by law.

All third parties receiving personal data are required to implement appropriate security and confidentiality safeguards.

We do not sell personal information to third parties.

7. Data Security

We maintain appropriate technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, destruction, misuse, alteration, and disclosure.

These measures include:

  • Access controls based on business need.
  • Encryption of sensitive data.
  • Secure network infrastructure.
  • Continuous monitoring and logging.
  • Data loss prevention controls.
  • Security awareness training.
  • Incident response and breach management procedures.

Where payment card data is processed, we maintain controls aligned with applicable PCI DSS requirements.

8. Data Retention

Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal and regulatory requirements, and to meet contractual obligations.

Upon expiry of the applicable retention period, personal data is securely deleted, anonymised, or destroyed in accordance with our records management procedures.

9. International Data Transfers

Where personal data is transferred outside Zambia, such transfers will only occur where:

  • Adequate safeguards are in place.
  • The transfer is permitted under the Data Protection Act No. 3 of 2021.
  • Appropriate contractual protections have been implemented.
  • The Data Protection Commissioner has approved the transfer where required.

10. Your Rights as a Data Subject

Subject to applicable law, you may have the right to:

  • Be informed about how your personal data is processed.
  • Access personal data held about you.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of personal data where legally permissible.
  • Object to certain processing activities.
  • Restrict processing under specific circumstances.
  • Request portability of your personal data where applicable.
  • Withdraw consent where processing is based on consent.

Where we act solely as a Data Processor, requests relating to your personal data may be referred to the relevant Data Controller responsible for determining the purpose of processing.

11. Data Breaches

In the event of a personal data breach, we will respond promptly and take appropriate remedial measures.

Where required by law, notifications will be made to the relevant Data Controller, the Data Protection Commissioner, and affected data subjects in accordance with statutory requirements.

12. Cookies and Website Usage

Our website may use cookies and similar technologies to improve user experience, maintain security, analyse website traffic, and enhance service delivery.

Users may manage cookie preferences through their browser settings.

13. Contact Us

If you have any questions regarding this Privacy Notice or wish to exercise your rights under the Data Protection Act No. 3 of 2021, please contact:

Data Protection Officer / Risk and Compliance Department

Digital Shared Services Limited (PayGo)

Email: info@digitalpaygo.com

Physical Address:
Number 6 Nyati Close,
Off Addis Ababa Drive,
Lusaka, Zambia

14. Changes to this Notice

We may update this Privacy Notice from time to time to reflect changes in legal, regulatory, technological, or operational requirements.

The latest version of this notice will always be available on our website.

This notice is issued in accordance with the Data Protection Act No. 3 of 2021 of the Republic of Zambia.

© Digital Shared Services Limited (PayGo). All rights reserved.