Privacy Policy
Effective: 10 August 2026
This Privacy Policy explains how Hitaji Technologies LLC, a Delaware limited liability company doing business as Fundify (“Fundify”, “we”, “us”, or “our”), collects and uses personal data through our websites, applications, support, and related services (“Service”). It also explains your choices and rights.
This notice applies where Fundify decides why and how personal data is processed. For personal data submitted by a club or organisation (“Customer”) to its Fundify workspace, Customer generally controls the processing and Fundify acts on its instructions. In that case, direct requests about the workspace data to Customer first. Our Data Processing Addendum governs that processing.
1. Who is responsible for your data
Hitaji Technologies LLC is the entity responsible for the processing described in this policy. We are organised in Delaware, United States, and our principal operations are in Uganda. For account, billing, security, support, and website data, we generally act as controller. For personal data a Customer places in its Fundify workspace, we generally act as processor on that Customer’s instructions.
2. Personal data we collect
2.1 Data you provide
- Account details such as name, email, password hash, and profile image.
- Contact, support, survey, and feedback communications.
- Billing contact, subscription, invoice, and transaction references.
- Club and member records, including roles, contributions, loans, fines, assets, income, expenses, distributions, meeting notes, audit events, and documents.
- Prompts, messages, and feedback submitted to AI features.
2.2 Data collected automatically
- IP address, browser, device, operating system, and request metadata.
- Authentication events, session identifiers, timestamps, and security logs.
- Feature interactions, error reports, performance traces, and audit history.
- Approximate location inferred from IP address.
2.3 Data from others
We may receive your data from a Customer administrator who invites you or records a transaction concerning you, from Google when you choose Google sign-in, from Stripe about payments, or from service providers helping us prevent abuse and operate the Service. We do not receive your Google password or complete payment-card credentials.
3. Why and on what basis we process data
| Purpose | Typical legal basis |
|---|---|
| Provide accounts, workspaces, reports, support, and requested features | Perform a contract; Customer instructions |
| Process subscriptions, invoices, and payments | Perform a contract; legal obligation |
| Authenticate users, prevent fraud, secure and troubleshoot the Service | Legitimate interests; legal obligation |
| Send service, security, billing, and administrative messages | Perform a contract; legitimate interests |
| Improve functionality and understand aggregated usage | Legitimate interests |
| Send optional marketing communications | Consent or legitimate interests, where permitted |
| Meet legal requests, enforce terms, and establish legal claims | Legal obligation; legitimate interests |
Where consent is the basis, you may withdraw it at any time without affecting earlier processing. We do not sell personal data or use club financial records for targeted advertising.
4. AI features
When an authorised user invokes an AI feature, Fundify sends the prompt, conversation context, and relevant information retrieved from the Customer workspace to OpenAI to generate a response. Do not place data in a prompt unless you and Customer are authorised to process and share it. AI output and related activity may be logged for security, reliability, and auditability. We do not use Customer Data to train our own general-purpose AI models.
5. How we disclose data
We may disclose personal data:
- Within a Customer workspace. Visibility depends on Customer-configured roles; administrators and treasurers may have broader access.
- To service providers. Providers host data, deliver email, process payments, monitor errors, store documents, protect forms, rate-limit traffic, and provide AI features. Current providers are listed on our Subprocessors page.
- For legal and safety reasons. We may preserve or disclose data where reasonably necessary to comply with law, protect people or rights, investigate abuse, or establish legal claims.
- In a corporate transaction. Data may transfer in a merger, financing, reorganisation, or sale, subject to appropriate confidentiality and applicable law.
- With your direction or consent.
6. International transfers
Fundify and its providers may process data outside Uganda, including in the United States and other countries where our providers operate. We use legally recognised safeguards appropriate to the transfer, such as contractual protections, transfer assessments, and provider security commitments. Customers can review relevant processing terms in our DPA.
7. Retention
We keep personal data only as long as reasonably necessary for the purposes described here, including providing the Service, meeting legal and accounting duties, resolving disputes, and securing the platform.
- Account data is retained while the account is active.
- A deleted club normally remains recoverable for 30 days, after which its active-database records are deleted.
- Backups rotate on a separate schedule; deleted data may remain isolated in backups until overwritten and is not restored except for disaster recovery.
- Billing, security, audit, and legal records may be retained longer where reasonably necessary or legally required.
Retention for Customer-controlled data may also be set by Customer. Deletion means removal from active systems or irreversible de-identification, subject to the exceptions above.
8. Security
We use risk-appropriate safeguards including TLS in transit, provider encryption at rest, access controls, hashed passwords, optional two-factor authentication, tenant and role checks, audit logging, monitoring, and incident-response procedures. No service is completely secure. You must protect credentials, configure permissions carefully, and notify us promptly of suspected compromise.
9. Your rights and choices
Depending on applicable law, you may ask to be informed about and access your personal data; correct, update, block, erase, or restrict it; object to certain processing or direct marketing; receive portable data; withdraw consent; and challenge certain solely automated decisions. You may also complain to Uganda’s Personal Data Protection Office or another competent regulator.
To exercise a right, email hello@contact.usefundify.com. We may verify your identity. If the request concerns Customer-controlled workspace data, we may direct it to Customer or assist Customer in responding. You may unsubscribe from marketing using the link in the message; essential service messages will continue.
10. Cookies
We use cookies and similar storage for authentication, security, and user preferences. See our Cookie Policy.
11. Children
Fundify is not directed to people under 18, and they may not create an account. We do not knowingly collect a child’s personal data through the Service. Contact us if you believe this has occurred.
12. Changes to this policy
We may update this policy as the Service or law changes. We will post the updated version and, for material changes, provide reasonable advance notice through the Service or by email unless urgent legal or security circumstances require otherwise.
13. Contact
For privacy questions, rights requests, or complaints, contact our privacy team at hello@contact.usefundify.com. Please use the subject “Privacy Request”. You may also lodge a complaint with the Personal Data Protection Office of Uganda.