Skip to document
LandPassport
TermsPrivacy
LANDPASSPORT / LEGAL

Privacy Policy

Understand what we collect, why we need it, and the choices you have about your information.

Last updated 15 September 2026Uganda · Website, Buyer & Partner apps
On this page
  1. 01Who is responsible for your information
  2. 02Information you provide
  3. 03Information from other people and sources
  4. 04Device, usage and location information
  5. 05Social sign-in, passkeys and biometrics
  6. 06Why we use information and our legal basis
  7. 07Sensitive information and children
  8. 08Who receives information
  9. 09Public listings and private case records
  10. 10Storage and processing outside Uganda
  11. 11Cookies and information saved on your device
  12. 12Matching, calculations and assisted content
  13. 13How long we keep information
  14. 14Security and incidents
  15. 15Your privacy rights
  16. 16How to request access, correction or deletion
  17. 17Communication choices
  18. 18Complaints and the Ugandan regulator
  19. 19Updates to this Policy
Your information. Your choices.

You can request access, correction or account deletion without signing in. Start with the contact below.

hello@embiro.com

01Who is responsible for your information

Embiro Technologies (U) Limited operates LandPassport and determines how personal information is used to run its website, buyer app, partner app and platform services. For those activities we act as a data controller. Our contact address is 4 Norfolk Gardens, Kyambogo, Kampala, Uganda. Send privacy requests to hello@embiro.com with “Privacy” in the subject line.

A seller, surveyor, advocate, valuer, lender, payment provider or partner organisation may separately determine how it uses information for its own service or legal obligations. That party may be an independent controller with its own privacy notice. Where we process information solely on an organisation’s documented instructions, our role and responsibilities depend on that arrangement. We will help identify the relevant party for your request.

This Policy is framed around Uganda’s Data Protection and Privacy Act, Cap. 97 (originally enacted in 2019), and the Data Protection and Privacy Regulations, 2021. It explains our practices and commitments; it does not remove rights granted by those laws or any other law that applies to you.

02Information you provide

The information needed depends on the feature you choose and your role. It may include:

  • Account and profile information: name, email, phone number, preferred contact details, account role and organisation membership.
  • Buying preferences: intended use, preferred areas, budget, available cash, financing assumptions, timing, saved parcels and progress through your buying plan.
  • Transaction and evidence records: enquiries, case messages, uploaded documents, title and parcel references, ownership or authority information, professional findings, consents, agreements and dispute correspondence.
  • Partner information: organisation details, mandates, professional credentials, assignments, submitted findings and approval or audit history.
  • Payment-related records where a relevant service is used: beneficiary details, amounts, references, receipts, reconciliation and refund status. The payment provider may collect further information directly under its own notice.
  • Support requests, feedback, consent choices and the information you provide when exercising a privacy right.

03Information from other people and sources

We may receive information about you from an authorised representative, organisation administrator, seller, buyer, professional, payment provider or a lawful public source relevant to a case. For example, an administrator may invite you, or an authorised professional may submit a report containing a landowner’s name.

Public availability does not remove privacy protections. We must have an applicable lawful basis, respect source restrictions, limit collection to what is needed and provide required information about indirect collection. If you supply another person’s information, ensure you have authority and a lawful basis to do so, and give them this notice where appropriate. Do not upload entire identity or financial records when a limited extract will suffice.

04Device, usage and location information

Our systems and infrastructure providers process technical information needed to deliver and protect the service, such as IP address, browser or device information, request time, session identifiers, errors, security events and access logs. Website analytics help us understand page visits, referral sources, device categories, product interactions and service performance. Where configured, PostHog uses a persistent identifier to relate visits and events, and the signed-in buyer experience may associate that identifier with an account ID. Experiments may record which page variation was shown and subsequent actions. The current analytics integration disables session replay and automatic capture of every interaction, but explicitly recorded events and error information can still be personal data.

Parcel coordinates and the areas in your buying plan describe land or your preferences; they are not necessarily your current location. If a feature requests your device location, camera, photo library or notifications, you can control the permission through your device. Refusing an optional permission may affect that feature without preventing unrelated use. An approximate location may also be inferred by infrastructure providers from an IP address.

05Social sign-in, passkeys and biometrics

When you choose an available Google, Apple or LinkedIn sign-in option, we receive the account identifier and profile information authorised in that provider’s sign-in flow, such as your name and email address, and authentication tokens needed to complete or maintain the connection. Apple may provide a relay email address. We do not receive your provider password. The provider processes its own login activity under its privacy notice.

Passkeys use a public credential to prove that your device or credential manager can respond to a challenge. LandPassport receives the public key, credential identifier and verification information. The passkey private key and any fingerprint, face template or device PIN used to unlock it are handled by your device or credential provider; they are not sent to LandPassport. Your credential provider may synchronise passkeys under its own settings.

If you choose an authenticator app, setup uses a secret displayed as a QR code and manual key. Treat both as confidential. We process the information needed to verify codes and maintain recovery or security state. Email codes and security notices are delivered through our email provider. Never send authentication secrets to support.

06Why we use information and our legal basis

Ugandan law generally requires prior consent unless a statutory exception applies. We do not treat acceptance of this Policy as consent to every possible use, and we do not assume that a broad “legitimate interests” label permits any processing.

We use information necessary to perform your contract or take steps you request before a contract: creating and securing an account, saving your plan, responding to enquiries, coordinating an authorised service, managing a case and handling payment or support records. Necessary fraud prevention and investigations may rely on the applicable statutory exception for preventing or investigating offences, or on a legal obligation, depending on the circumstances.

Where processing is required or authorised by law, we use that basis for the specific obligation, such as responding to a valid legal demand or retaining a required transaction record. Optional marketing, optional permissions and processing without another applicable exception require an appropriate, specific consent. We will explain a materially different purpose and establish the required legal basis before using information for it.

You can withhold optional information or withdraw consent for future consent-based processing. That does not undo earlier lawful processing or prevent processing independently required by law. If information is necessary for an account, identity check, professional service or transaction, we will explain the consequence of not providing it; the requested service may be unavailable.

07Sensitive information and children

Land transactions can involve sensitive financial, identity, family and ownership information. We limit access and collection to the relevant purpose. Information subject to special protection under Ugandan law requires the applicable additional safeguards and lawful conditions; an ordinary account consent is not permission to collect unrelated sensitive records.

Our accounts and transactional services are intended for adults aged 18 and over. Do not create an account for a child. A lawful land matter may involve a child’s interest or an estate; any necessary information must be handled through an authorised representative and the legal conditions for processing children’s data, including parental or guardian consent where required. Contact us if a child has supplied information inappropriately so we can assess and address it.

08Who receives information

We share information only for an identified purpose and with appropriate access restrictions. Depending on your activity, recipients include:

  • People you authorise to act for you, and the partner organisation or case participants who need it to carry out the requested work. Organisation administrators may manage membership and see work records associated with their organisation.
  • Named sellers, advocates, surveyors, valuers, lenders and payment providers when needed for the service you request, subject to the applicable legal basis and arrangement.
  • Technology providers supporting hosting, databases, document storage, email, security, app delivery and analytics. Our stack includes Vercel, Neon, Cloudflare R2, Resend, PostHog and Expo; the specific information each handles depends on its function and configuration. Apple, Google and LinkedIn also process information when you choose their services.
  • Competent authorities or professional advisers where disclosure is lawfully required or otherwise permitted for a specific investigation, legal claim or compliance obligation. We assess the scope and limit disclosure as appropriate.
  • A successor in a lawful business reorganisation or transfer, subject to confidentiality, an appropriate legal basis and notice of a material change to who controls your information.

09Public listings and private case records

Information submitted for a public listing, such as a parcel description, selected photos and location, may be visible to anyone and indexed or copied by others. Do not put private identity documents, signatures, bank details or unnecessary personal information in public content.

Private evidence, account information and case records are subject to role and case permissions. A recipient who lawfully receives a report or transaction record may have an independent duty to keep it. Removing content from LandPassport cannot guarantee removal from another controller’s lawful records or from copies already made outside our control. We will explain available correction or removal steps.

We do not sell personal information or provide private buyer plans or identity documents to advertisers. We do not authorise a professional partner to reuse case information for unrelated marketing merely because they can access it for an assignment.

10Storage and processing outside Uganda

LandPassport uses cloud services whose infrastructure and support operations may be outside Uganda. For example, our configured application and database infrastructure includes the Frankfurt region in Germany; other providers may use distributed locations. This means information may be processed abroad rather than exclusively within Uganda.

Before an overseas transfer, we must establish the protection required by section 19 of the Data Protection and Privacy Act: protection at least equivalent to that required by the Act in the destination country, or the data subject’s consent as permitted by law. Provider contracts, access controls and transfer assessments form part of the safeguards we must consider; using a well-known cloud provider alone is not proof of compliance.

Where consent is the required transfer basis, we must request it specifically and explain the transfer rather than infer it from a visit to this page. Contact us to ask which providers or destination locations are relevant to your information and about the safeguards or lawful basis used.

11Cookies and information saved on your device

The website and apps use session cookies or equivalent local storage to maintain sign-in and security state. The native apps use device secure storage for authentication information where supported; web versions use browser storage. Welcome-screen completion, preferences and unfinished buying-plan progress may be saved on your device so you can resume.

A guest buying plan can exist on the device before sign-in. When you proceed with an account, the relevant onboarding flow can associate it with that account. Clearing app data, removing the app, clearing browser storage or using a different device can affect local drafts; a local save is not a promise of cross-device backup.

You can control browser storage and device permissions through their settings. Blocking essential storage may stop sign-in or draft recovery. Website analytics use Vercel Web Analytics and, where configured, PostHog. PostHog can use cookies and local storage across LandPassport subdomains; visitor and experiment identifiers can persist between visits. Clearing them can reset those identifiers, although signing in may associate later activity with your account again. Infrastructure may process request and usage information even when a measurement does not use an advertising cookie. Any new non-essential tracking requiring consent must be explained and offered with the required choice before use.

12Matching, calculations and assisted content

The platform may use your plan and parcel information to filter or order results and calculate budget scenarios. These results are decision aids based on the inputs and rules described in the product, not a final decision about credit, legal ownership or investment suitability.

If an automated result appears wrong, you can ask us to explain or review it and correct inaccurate information. Where a decision falls within the statutory protection against solely automated decisions significantly affecting a person, you may exercise the applicable right to require reconsideration or a decision not based solely on automated processing, subject to the law’s conditions.

If an assisted drafting or analysis feature uses an external model provider, we must identify the relevant purpose and data use before introducing it to the affected workflow. This Policy does not give blanket permission to send private identity, financial or case documents to an AI service or to train a model on them.

13How long we keep information

We retain identifiable information only for as long as necessary for the stated purpose or another retention ground permitted by law. The period depends on the record, service, applicable statutory requirements, an active dispute or legal hold, and whether the information is needed to explain or evidence an action. We do not apply one blanket period to every category.

Account and plan information is needed while providing the account and requested services. Short-lived codes and sessions have security lifetimes. Case, payment, agreement, evidence and audit records can require longer retention than a profile because they establish what happened in a transaction or support a legal obligation or claim. A correction may add a superseding record rather than silently alter the history.

Document deletion is subject to its retention classification and any applicable evidence or legal hold. Closing an account does not automatically erase all related evidence, another person’s records or a land registry entry. Backups may retain restricted copies until their normal replacement cycle. Where retention is no longer justified, we must delete, destroy or de-identify the information appropriately. Ask us for the period or criteria applicable to a specific record and the reason for any refused deletion.

14Security and incidents

We use measures suited to the risks, including encrypted connections, authentication, restricted document access, role-based permissions, additional verification for sensitive operations and audit records. Our processors must be subject to appropriate instructions and safeguards. No system can eliminate every risk, so protect your devices and report suspicious access promptly.

Where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, the Act requires immediate notification to the Authority. We must also follow applicable requirements and directions for informing affected people, investigating, containing the incident and enabling protective action. We do not replace Uganda’s requirements with a generic foreign-law notification deadline.

15Your privacy rights

Subject to the conditions, exceptions and procedures in applicable Ugandan law, you can request:

  • Confirmation of whether we hold your personal information, access to it, a description of it, and information about third parties or recipient categories that have had access.
  • Correction of inaccurate or incomplete information and, where the law permits, blocking, erasure or destruction of information that should no longer be processed.
  • An end to processing that meets the statutory grounds for objection, and an end to direct marketing. You may withdraw consent for consent-based processing.
  • The protection available for certain significant decisions based solely on automated processing, including the applicable review or reconsideration.
  • An explanation of an adverse response and information about how to complain to the Personal Data Protection Office or pursue another available legal remedy.

16How to request access, correction or deletion

Email hello@embiro.com with “Privacy request” in the subject, or write to our address above. State the account email or case reference, the information or action involved and how we can reply. You may ask to close your account and delete associated personal information through this route even if you can no longer access the app. An authorised representative may act with suitable evidence of authority.

We may request proportionate proof of identity or additional information to locate a record and protect it from disclosure to the wrong person. Do not send a full identity document unless requested through a suitable channel. Where a prescribed form is required, we will explain it and help you identify the form.

We will handle the request within the applicable statutory period and explain any lawful refusal, restriction or permitted fee rather than treating silence as a decision. In particular, the Act provides fourteen-day written-response requirements for the relevant notices to prevent processing and direct marketing. Different request types may have different rules. We will identify any information retained after an account-closure request and its basis.

17Communication choices

You can opt out of optional promotional messages through an available unsubscribe control or by emailing support. We must respect a direct-marketing objection and will not make marketing consent a condition of an unrelated service. Withdrawing marketing permission does not prevent necessary security, order, payment or dispute messages.

Push notifications depend on device permission and your app settings. Revoking that permission stops the relevant device notification channel; it does not necessarily close your account or change a separate email preference.

18Complaints and the Ugandan regulator

Please raise a privacy concern with us so we can investigate and respond. You may also complain to Uganda’s Personal Data Protection Office (PDPO), including where you are dissatisfied with our response or believe the law has been breached. Our internal process does not prevent access to the regulator or another legal remedy.

Use the official PDPO website at pdpo.go.ug for the current complaint process, prescribed forms and contact details. General enquiries can be directed to info@pdpo.go.ug. Keep copies of relevant correspondence and explain the processing, dates, affected information and outcome you seek. Do not send passwords or authentication secrets.

19Updates to this Policy

We will update the date when this Policy changes. We will communicate material changes through appropriate channels and seek fresh consent where the change requires it. A new notice does not retrospectively make an unlawful use lawful or remove rights that have already arisen.

For clarification, a copy of this notice, assistance with accessibility or any privacy request, contact hello@embiro.com. Support hours are 08:00–18:00 East Africa Time, Monday to Saturday. Those hours do not postpone a statutory deadline or an urgent security obligation.

Contact LandPassport

Embiro Technologies (U) Limited
4 Norfolk Gardens, Kyambogo, Kampala, Uganda
hello@embiro.com

08:00–18:00 East Africa Time, Monday to Saturday

Ugandan legal framework

These official resources explain the law and available public processes. The applicable law prevails if this document is inconsistent with it.

  • NITA-U: Data Protection and Privacy Act (Cap. 97), Electronic Transactions Act (Cap. 99), and Electronic Signatures Act (Cap. 98)
  • PDPO: Data Protection and Privacy Regulations, 2021, guidance and privacy rights
  • Personal Data Protection Office: complaints and current contact details
Back to top ↑
© 2026 LandPassport · Embiro Technologies (U) LimitedRead the Terms of Service →