Privacy Policy
TANZANIA PULSES NETWORK
PEAICH PLATFORM
SECURITY AND DATA PROTECTION POLICY
Document Version: 1.0
Effective Date: 09 May 2026
Policy Owner: TPN Organization
Platform: Pulse Hub
Classification: Internal & Public Compliance Document
1. INTRODUCTION
Tanzania Pulse Network (TPN) Organization (“TPN”, “we”, “our”, or “us”) is committed to
protecting the confidentiality, integrity, availability, and lawful processing of all
information and personal data collected, processed, stored, or transmitted through the
Pulse Hub Platform (“Platform”).
This Security and Data Protection Policy establish the principles, controls, standards,
and procedures governing the protection of information assets, personal data, system
infrastructure, and digital services managed by TPN Organization.
This policy is designed to ensure compliance with:
• The Personal Data Protection Act, 2022 (United Republic of Tanzania)
• Tanzania Communications Regulatory Authority (TCRA) Regulations
• Cybercrimes Act, 2015
• Electronic Transactions Act, 2015
• Tanzania National ICT Policy
• Applicable international cybersecurity and privacy standards including ISO/IEC
27001 principles and General Data Protection best practices where applicable.
By accessing or using the Pulse Hub Platform, users acknowledge and agree to the
collection, use, storage, and protection of their information in accordance with this
Policy.
2. PURPOSE OF THE POLICY
The purpose of this Policy is to:
• Protect personal and organizational data against unauthorized access, misuse,
disclosure, alteration, destruction, or loss.
• Establish clear guidelines for lawful data processing and security management.
• Ensure compliance with Tanzanian laws and regulatory obligations.
• Promote transparency, accountability, and responsible data handling practices.
• Safeguard the rights and privacy of users, stakeholders, employees, and partners.
• Maintain business continuity and operational resilience against cyber threats and
security incidents.
3. SCOPE
This Policy applies to:
• All users of the Pulse Hub Platform
• TPN employees, consultants, contractors, and authorized third parties
• All systems, applications, servers, databases, APIs, cloud services, and
communication networks associated with Pulse Hub
• All personal, confidential, operational, financial, and technical data processed by
TPN Organization.
This Policy covers both digital and physical records managed by TPN Organization.
4. DEFINITIONS
4.1 Personal Data
Any information relating to an identified or identifiable natural person, including but not
limited to:
• Full name
• National ID number
• Phone number
• Email address
• IP address
• Location data
• Device identifiers
• User account credentials
4.2 Sensitive Personal Data
Data relating to:
• Financial information
• Health records
• Biometric information
• Authentication credentials
• Confidential business information
4.3 Processing
Any operation performed on data including:
• Collection
• Recording
• Organization
• Storage
• Retrieval
• Use
• Sharing
• Deletion
• Destruction
5. PRINCIPLES OF DATA PROTECTION
TPN Organization adheres to the following data protection principles:
5.1 Lawfulness and Fairness
Personal data shall be collected and processed lawfully, fairly, and transparently.
5.2 Purpose Limitation
Data shall only be collected for legitimate, specific, and clearly defined purposes.
5.3 Data Minimization
Only data necessary for operational and legal purposes shall be collected.
5.4 Accuracy
TPN shall ensure personal data is accurate, complete, and updated where necessary.
5.5 Storage Limitation
Data shall not be retained longer than necessary unless legally required.
5.6 Integrity and Confidentiality
Appropriate security measures shall protect data from unauthorized access, disclosure,
alteration, or destruction.
5.7 Accountability
TPN Organization shall maintain responsibility and demonstrate compliance with this
Policy and applicable laws.
6. INFORMATION WE COLLECT
The Pulse Hub Platform may collect the following categories of information:
6.1 Personal Information
• Full name
• Phone number
• Email address
• User profile information
• Organization or business details
• Login credentials
6.2 Technical Information
• IP address
• Browser type and version
• Device identifiers
• Operating system
• Network information
• Access timestamps
• Geographic location metadata
6.3 Usage Information
• Platform activity logs
• Transaction records
• Subscription information
• User interaction history
• Analytics and behavioral metrics
6.4 Security Information
• Authentication logs
• Failed login attempts
• Security event records
• Audit trails
• Access history
7. LEGAL BASIS FOR PROCESSING DATA
TPN Organization processes personal data under the following lawful bases:
• User consent
• Contractual necessity
• Compliance with legal obligations
• Protection of legitimate interests
• Regulatory requirements
• Public interest obligations where applicable
8. DATA COLLECTION METHODS
Information may be collected through:
• User registration forms
• Mobile and web applications
• Cookies and tracking technologies
• Customer support interactions
• API integrations
• Electronic communications
• Automated system monitoring tools
9. USE OF PERSONAL DATA
Collected data may be used for:
• User authentication and account management
• Service delivery and platform operations
• Security monitoring and fraud prevention
• Customer support services
• Compliance and regulatory reporting
• Performance analytics and system improvement
• Communication of updates and service notices
• Incident investigation and legal enforcement
TPN shall not sell personal data to third parties.
10. DATA SECURITY FRAMEWORK
TPN Organization implements a comprehensive security framework to safeguard all
information assets.
10.1 Administrative Security Controls
• Information security governance structure
• Security awareness and staff training
• Confidentiality agreements
• Role-based access management
• Vendor and third-party risk assessments
• Data classification procedures
10.2 Technical Security Controls
• End-to-end encryption
• SSL/TLS secure communications
• Multi-factor authentication (MFA)
• Firewalls and intrusion prevention systems
• Anti-malware and endpoint protection
• Secure API authentication
• Continuous system monitoring
• Vulnerability scanning and penetration testing
• Database encryption
• Backup and disaster recovery systems
10.3 Physical Security Controls
• Restricted server room access
• Surveillance systems
• Environmental controls
• Secure disposal of storage devices
• Visitor access management
11. ACCESS CONTROL POLICY
Access to data and systems shall be granted strictly on a need-to-know basis.
TPN Organization shall:
• Implement role-based access control (RBAC)
• Enforce strong password policies
• Require multi-factor authentication for privileged accounts
• Monitor and log administrative access
• Periodically review user permissions
• Immediately revoke unauthorized or inactive access
12. DATA SHARING AND DISCLOSURE
TPN may share information only under the following circumstances:
12.1 Authorized Service Providers
Third-party vendors supporting:
• Cloud hosting
• Payment processing
• Technical support
• Analytics services
• Communication systems
Such providers must comply with confidentiality and security obligations.
12.2 Legal and Regulatory Authorities
Information may be disclosed:
• Under court order
• To law enforcement agencies
• To TCRA or other regulatory authorities
• Where legally required under Tanzanian law
12.3 Business Transfers
Data may be transferred during mergers, acquisitions, restructuring, or asset transfers
subject to applicable legal safeguards.
13. INTERNATIONAL DATA TRANSFERS
Where data is transferred outside Tanzania:
• Adequate security safeguards shall be implemented.
• Transfers shall comply with Tanzanian data protection requirements.
• Third parties must maintain equivalent security and privacy protections.
14. DATA RETENTION
TPN shall retain data only for the duration necessary to:
• Fulfill operational purposes
• Meet contractual obligations
• Comply with legal and regulatory requirements
• Resolve disputes and enforce agreements
Upon expiration of retention periods:
• Data shall be securely deleted,
• anonymized, or
• archived in accordance with legal obligations.
15. USER RIGHTS
Users have the right to:
15.1 Right to Access
Request access to personal data held by TPN.
15.2 Right to Correction
Request correction of inaccurate or incomplete data.
15.3 Right to Erasure
Request deletion of personal data where legally permissible.
15.4 Right to Restrict Processing
Request limitation of certain processing activities.
15.5 Right to Object
Object to processing under specific circumstances.
15.6 Right to Data Portability
Request data in a structured and machine-readable format.
15.7 Right to Withdraw Consent
Withdraw consent at any time where processing relies on consent.
Requests may be submitted through official TPN communication channels.
16. COOKIES AND TRACKING TECHNOLOGIES
Pulse Hub may use cookies and similar technologies to:
• Improve platform performance
• Remember user preferences
• Enhance security
• Generate analytics
• Monitor usage patterns
Users may manage cookie preferences through browser settings.
17. INCIDENT RESPONSE AND BREACH MANAGEMENT
TPN maintains a formal Incident Response Plan for handling cybersecurity and data
breach incidents.
In the event of a security incident:
• Immediate containment measures shall be initiated.
• Investigations shall be conducted promptly.
• Affected systems shall be secured and restored.
• Regulatory authorities may be notified where required.
• Affected users shall be informed where necessary.
Incident logs and forensic evidence shall be maintained securely.
18. BUSINESS CONTINUITY AND DISASTER RECOVERY
TPN Organization shall maintain:
• Data backup procedures
• Disaster recovery systems
• Business continuity plans
• Redundancy mechanisms
• Recovery testing procedures
Critical services shall be recoverable within defined operational timelines.
19. EMPLOYEE RESPONSIBILITIES
All employees and authorized personnel must:
• Protect confidential information
• Follow security procedures
• Report security incidents immediately
• Avoid unauthorized disclosure
• Use organizational systems responsibly
Violation of this Policy may result in disciplinary and legal action.
20. THIRD-PARTY SECURITY REQUIREMENTS
Third parties handling TPN data must:
• Maintain adequate security standards
• Sign confidentiality and data protection agreements
• Permit security assessments where necessary
• Report incidents affecting TPN data immediately
21. COMPLIANCE AND AUDIT
TPN Organization reserves the right to:
• Conduct security audits
• Monitor compliance activities
• Perform vulnerability assessments
• Review system logs and access records
Non-compliance may lead to:
• Access revocation
• Contract termination
• Legal action
• Regulatory reporting
22. POLICY REVIEW AND UPDATES
This Policy shall be reviewed periodically or whenever:
• Regulatory requirements change
• Security risks evolve
• Operational changes occur
• Significant incidents arise
Updated versions shall be communicated through official channels.
23. GOVERNING LAW
This Policy shall be governed and interpreted in accordance with the laws of the United
Republic of Tanzania.
Any disputes arising under this Policy shall be subject to Tanzanian jurisdiction and
applicable regulatory authorities.
24. CONTACT INFORMATION
For questions, requests, complaints, or concerns regarding this Policy or data protection
matters, contact:
TPN Organization
Pulse Hub Platform
Email: info@pulsestanzania.or.tz
Phone: +255 758 137 504
Address: Dar es Salaam, Tanzania
25. ACCEPTANCE OF POLICY
By accessing or using the Pulse Hub Platform, users acknowledge that they have read,
understood, and agreed to this Security and Data Protection Policy.
PEAICH PLATFORM
SECURITY AND DATA PROTECTION POLICY
Document Version: 1.0
Effective Date: 09 May 2026
Policy Owner: TPN Organization
Platform: Pulse Hub
Classification: Internal & Public Compliance Document
1. INTRODUCTION
Tanzania Pulse Network (TPN) Organization (“TPN”, “we”, “our”, or “us”) is committed to
protecting the confidentiality, integrity, availability, and lawful processing of all
information and personal data collected, processed, stored, or transmitted through the
Pulse Hub Platform (“Platform”).
This Security and Data Protection Policy establish the principles, controls, standards,
and procedures governing the protection of information assets, personal data, system
infrastructure, and digital services managed by TPN Organization.
This policy is designed to ensure compliance with:
• The Personal Data Protection Act, 2022 (United Republic of Tanzania)
• Tanzania Communications Regulatory Authority (TCRA) Regulations
• Cybercrimes Act, 2015
• Electronic Transactions Act, 2015
• Tanzania National ICT Policy
• Applicable international cybersecurity and privacy standards including ISO/IEC
27001 principles and General Data Protection best practices where applicable.
By accessing or using the Pulse Hub Platform, users acknowledge and agree to the
collection, use, storage, and protection of their information in accordance with this
Policy.
2. PURPOSE OF THE POLICY
The purpose of this Policy is to:
• Protect personal and organizational data against unauthorized access, misuse,
disclosure, alteration, destruction, or loss.
• Establish clear guidelines for lawful data processing and security management.
• Ensure compliance with Tanzanian laws and regulatory obligations.
• Promote transparency, accountability, and responsible data handling practices.
• Safeguard the rights and privacy of users, stakeholders, employees, and partners.
• Maintain business continuity and operational resilience against cyber threats and
security incidents.
3. SCOPE
This Policy applies to:
• All users of the Pulse Hub Platform
• TPN employees, consultants, contractors, and authorized third parties
• All systems, applications, servers, databases, APIs, cloud services, and
communication networks associated with Pulse Hub
• All personal, confidential, operational, financial, and technical data processed by
TPN Organization.
This Policy covers both digital and physical records managed by TPN Organization.
4. DEFINITIONS
4.1 Personal Data
Any information relating to an identified or identifiable natural person, including but not
limited to:
• Full name
• National ID number
• Phone number
• Email address
• IP address
• Location data
• Device identifiers
• User account credentials
4.2 Sensitive Personal Data
Data relating to:
• Financial information
• Health records
• Biometric information
• Authentication credentials
• Confidential business information
4.3 Processing
Any operation performed on data including:
• Collection
• Recording
• Organization
• Storage
• Retrieval
• Use
• Sharing
• Deletion
• Destruction
5. PRINCIPLES OF DATA PROTECTION
TPN Organization adheres to the following data protection principles:
5.1 Lawfulness and Fairness
Personal data shall be collected and processed lawfully, fairly, and transparently.
5.2 Purpose Limitation
Data shall only be collected for legitimate, specific, and clearly defined purposes.
5.3 Data Minimization
Only data necessary for operational and legal purposes shall be collected.
5.4 Accuracy
TPN shall ensure personal data is accurate, complete, and updated where necessary.
5.5 Storage Limitation
Data shall not be retained longer than necessary unless legally required.
5.6 Integrity and Confidentiality
Appropriate security measures shall protect data from unauthorized access, disclosure,
alteration, or destruction.
5.7 Accountability
TPN Organization shall maintain responsibility and demonstrate compliance with this
Policy and applicable laws.
6. INFORMATION WE COLLECT
The Pulse Hub Platform may collect the following categories of information:
6.1 Personal Information
• Full name
• Phone number
• Email address
• User profile information
• Organization or business details
• Login credentials
6.2 Technical Information
• IP address
• Browser type and version
• Device identifiers
• Operating system
• Network information
• Access timestamps
• Geographic location metadata
6.3 Usage Information
• Platform activity logs
• Transaction records
• Subscription information
• User interaction history
• Analytics and behavioral metrics
6.4 Security Information
• Authentication logs
• Failed login attempts
• Security event records
• Audit trails
• Access history
7. LEGAL BASIS FOR PROCESSING DATA
TPN Organization processes personal data under the following lawful bases:
• User consent
• Contractual necessity
• Compliance with legal obligations
• Protection of legitimate interests
• Regulatory requirements
• Public interest obligations where applicable
8. DATA COLLECTION METHODS
Information may be collected through:
• User registration forms
• Mobile and web applications
• Cookies and tracking technologies
• Customer support interactions
• API integrations
• Electronic communications
• Automated system monitoring tools
9. USE OF PERSONAL DATA
Collected data may be used for:
• User authentication and account management
• Service delivery and platform operations
• Security monitoring and fraud prevention
• Customer support services
• Compliance and regulatory reporting
• Performance analytics and system improvement
• Communication of updates and service notices
• Incident investigation and legal enforcement
TPN shall not sell personal data to third parties.
10. DATA SECURITY FRAMEWORK
TPN Organization implements a comprehensive security framework to safeguard all
information assets.
10.1 Administrative Security Controls
• Information security governance structure
• Security awareness and staff training
• Confidentiality agreements
• Role-based access management
• Vendor and third-party risk assessments
• Data classification procedures
10.2 Technical Security Controls
• End-to-end encryption
• SSL/TLS secure communications
• Multi-factor authentication (MFA)
• Firewalls and intrusion prevention systems
• Anti-malware and endpoint protection
• Secure API authentication
• Continuous system monitoring
• Vulnerability scanning and penetration testing
• Database encryption
• Backup and disaster recovery systems
10.3 Physical Security Controls
• Restricted server room access
• Surveillance systems
• Environmental controls
• Secure disposal of storage devices
• Visitor access management
11. ACCESS CONTROL POLICY
Access to data and systems shall be granted strictly on a need-to-know basis.
TPN Organization shall:
• Implement role-based access control (RBAC)
• Enforce strong password policies
• Require multi-factor authentication for privileged accounts
• Monitor and log administrative access
• Periodically review user permissions
• Immediately revoke unauthorized or inactive access
12. DATA SHARING AND DISCLOSURE
TPN may share information only under the following circumstances:
12.1 Authorized Service Providers
Third-party vendors supporting:
• Cloud hosting
• Payment processing
• Technical support
• Analytics services
• Communication systems
Such providers must comply with confidentiality and security obligations.
12.2 Legal and Regulatory Authorities
Information may be disclosed:
• Under court order
• To law enforcement agencies
• To TCRA or other regulatory authorities
• Where legally required under Tanzanian law
12.3 Business Transfers
Data may be transferred during mergers, acquisitions, restructuring, or asset transfers
subject to applicable legal safeguards.
13. INTERNATIONAL DATA TRANSFERS
Where data is transferred outside Tanzania:
• Adequate security safeguards shall be implemented.
• Transfers shall comply with Tanzanian data protection requirements.
• Third parties must maintain equivalent security and privacy protections.
14. DATA RETENTION
TPN shall retain data only for the duration necessary to:
• Fulfill operational purposes
• Meet contractual obligations
• Comply with legal and regulatory requirements
• Resolve disputes and enforce agreements
Upon expiration of retention periods:
• Data shall be securely deleted,
• anonymized, or
• archived in accordance with legal obligations.
15. USER RIGHTS
Users have the right to:
15.1 Right to Access
Request access to personal data held by TPN.
15.2 Right to Correction
Request correction of inaccurate or incomplete data.
15.3 Right to Erasure
Request deletion of personal data where legally permissible.
15.4 Right to Restrict Processing
Request limitation of certain processing activities.
15.5 Right to Object
Object to processing under specific circumstances.
15.6 Right to Data Portability
Request data in a structured and machine-readable format.
15.7 Right to Withdraw Consent
Withdraw consent at any time where processing relies on consent.
Requests may be submitted through official TPN communication channels.
16. COOKIES AND TRACKING TECHNOLOGIES
Pulse Hub may use cookies and similar technologies to:
• Improve platform performance
• Remember user preferences
• Enhance security
• Generate analytics
• Monitor usage patterns
Users may manage cookie preferences through browser settings.
17. INCIDENT RESPONSE AND BREACH MANAGEMENT
TPN maintains a formal Incident Response Plan for handling cybersecurity and data
breach incidents.
In the event of a security incident:
• Immediate containment measures shall be initiated.
• Investigations shall be conducted promptly.
• Affected systems shall be secured and restored.
• Regulatory authorities may be notified where required.
• Affected users shall be informed where necessary.
Incident logs and forensic evidence shall be maintained securely.
18. BUSINESS CONTINUITY AND DISASTER RECOVERY
TPN Organization shall maintain:
• Data backup procedures
• Disaster recovery systems
• Business continuity plans
• Redundancy mechanisms
• Recovery testing procedures
Critical services shall be recoverable within defined operational timelines.
19. EMPLOYEE RESPONSIBILITIES
All employees and authorized personnel must:
• Protect confidential information
• Follow security procedures
• Report security incidents immediately
• Avoid unauthorized disclosure
• Use organizational systems responsibly
Violation of this Policy may result in disciplinary and legal action.
20. THIRD-PARTY SECURITY REQUIREMENTS
Third parties handling TPN data must:
• Maintain adequate security standards
• Sign confidentiality and data protection agreements
• Permit security assessments where necessary
• Report incidents affecting TPN data immediately
21. COMPLIANCE AND AUDIT
TPN Organization reserves the right to:
• Conduct security audits
• Monitor compliance activities
• Perform vulnerability assessments
• Review system logs and access records
Non-compliance may lead to:
• Access revocation
• Contract termination
• Legal action
• Regulatory reporting
22. POLICY REVIEW AND UPDATES
This Policy shall be reviewed periodically or whenever:
• Regulatory requirements change
• Security risks evolve
• Operational changes occur
• Significant incidents arise
Updated versions shall be communicated through official channels.
23. GOVERNING LAW
This Policy shall be governed and interpreted in accordance with the laws of the United
Republic of Tanzania.
Any disputes arising under this Policy shall be subject to Tanzanian jurisdiction and
applicable regulatory authorities.
24. CONTACT INFORMATION
For questions, requests, complaints, or concerns regarding this Policy or data protection
matters, contact:
TPN Organization
Pulse Hub Platform
Email: info@pulsestanzania.or.tz
Phone: +255 758 137 504
Address: Dar es Salaam, Tanzania
25. ACCEPTANCE OF POLICY
By accessing or using the Pulse Hub Platform, users acknowledge that they have read,
understood, and agreed to this Security and Data Protection Policy.