Legal

Privacy Policy

Effective date: 19 June 2026

Sabula 256 (“we”, “us”, “our”) is committed to protecting your personal data. This Privacy Policy explains what information we collect when you use the Platform, why we collect it, how we use and share it, and your rights under the Uganda Data Protection and Privacy Act, 2019 (“DPPA”).

By using the Platform you consent to the practices described in this Policy. If you do not agree, please stop using the Platform and contact us to close your account.


1.Who We Are (Data Controller)

Sabula 256 is the data controller responsible for your personal data. Our contact details are:


2.What Personal Data We Collect

We collect the following categories of personal data:

2.1 Account & Identity Data

  • Mobile phone number (used as your unique identifier and for OTP authentication)
  • Account creation date and last login timestamp
  • Admin status flag (internal use)

2.2 Financial & Transaction Data

  • Wallet balance (UGX)
  • Deposit and withdrawal amounts, timestamps, and statuses
  • Mobile Money number used for payment (may differ from registered number)
  • Relworx internal reference numbers for each transaction
  • Stakes placed, market selections, amounts, and outcomes

2.3 Usage & Technical Data

  • IP address and approximate geolocation (country/city)
  • Device type, browser type, and operating system
  • Pages visited, features used, and session duration (via Supabase analytics)
  • Error logs and crash reports

2.4 Communications Data

  • SMS OTP delivery logs (via Twilio) — we do not store the OTP codes themselves
  • Support emails or messages you send to us

2.5 Data We Do Not Collect

We do not collect national ID numbers, passport details, physical addresses, or payment card details. We do not knowingly collect data from persons under 18.


3.How We Use Your Data

PurposeLegal Basis (DPPA)
Account creation and authentication via phone OTPPerformance of contract
Processing deposits and withdrawals via RelworxPerformance of contract
Calculating and distributing market payoutsPerformance of contract
Sending SMS OTP codes for login (via Twilio)Performance of contract
Detecting fraud, abuse, and money launderingLegitimate interest / legal obligation
Complying with Ugandan financial regulations and tax obligationsLegal obligation
Improving Platform features and fixing bugsLegitimate interest
Sending service notifications (e.g. market settlement, withdrawal status)Performance of contract
Responding to support enquiriesLegitimate interest

We will not use your data for purposes incompatible with those listed above without your explicit consent.


4.How We Share Your Data

We share your personal data only as described below. We do not sell your data.

4.1 Relworx (Payment Processor)

We share your Mobile Money number and transaction amounts with Relworx to process deposits and disbursements. Relworx acts as a data processor on our behalf and is contractually bound to protect your data and use it only for payment processing. Relworx is regulated as a payment service provider and complies with the Uganda National Payment Systems Act, 2020.

4.2 Twilio (SMS Provider)

Your phone number is shared with Twilio Inc. (USA) solely for the purpose of delivering OTP SMS messages. Twilio processes data in the United States. We rely on Twilio's standard contractual protections for international transfers.

4.3 Supabase (Infrastructure)

Your account, wallet, and transaction data is stored in Supabase's cloud database. Supabase Inc. acts as a data processor under our instructions. Data may be stored in servers located outside Uganda. We rely on appropriate contractual safeguards for these transfers.

4.4 Legal & Regulatory Disclosure

We may disclose your data to government authorities, law enforcement, the Uganda Revenue Authority, or financial regulators where required by law or court order.

4.5 Business Transfer

If Sabula 256 is acquired, merged, or its assets are transferred, your data may be transferred as part of that transaction. We will notify you if this occurs and your data will remain subject to this Policy.


5.International Data Transfers

Your data may be transferred to and processed in countries outside Uganda, including the United States (Twilio, Supabase). Where we make such transfers, we ensure appropriate safeguards are in place, including contractual clauses that require the recipient to protect data to a standard equivalent to that required under the DPPA.


6.Data Retention

Data CategoryRetention Period
Account & identity data (active accounts)Duration of account + 5 years
Transaction & financial records7 years (tax/regulatory obligation)
Betting history (stakes, outcomes, payouts)5 years after account closure
SMS OTP delivery logs90 days
Technical logs & IP data12 months
Support correspondence3 years

After the applicable retention period, data is securely deleted or anonymised.


7.Your Rights Under the DPPA

Under Uganda's Data Protection and Privacy Act, 2019, you have the following rights:

  1. Right of access. You may request a copy of the personal data we hold about you.
  2. Right to rectification. You may request correction of inaccurate or incomplete data.
  3. Right to erasure. You may request deletion of your data where we no longer have a legal basis to retain it. Note that financial and transaction records must be retained for regulatory periods regardless.
  4. Right to object. You may object to processing based on our legitimate interests where your situation warrants it.
  5. Right to data portability. You may request your data in a structured, machine-readable format.
  6. Right to withdraw consent. Where processing is based on consent, you may withdraw it at any time. This will not affect the lawfulness of prior processing.
  7. Right to lodge a complaint. You have the right to complain to the Personal Data Protection Office of Uganda if you believe we have mishandled your data.

To exercise any of these rights, email us at joelukwago1@gmail.com. We will respond within 30 days.


8.Security

  1. We use industry-standard security measures including TLS encryption in transit, encrypted storage, and row-level security policies on our database.
  2. Access to production data is restricted to authorised personnel via multi-factor authentication.
  3. We regularly review and update our security practices.
  4. No system is completely secure. If you believe your account has been compromised, contact us immediately at joelukwago1@gmail.com.
  5. In the event of a personal data breach that affects your rights, we will notify you and the relevant authority as required by the DPPA.

9.Cookies & Tracking

The Platform uses essential session cookies to maintain your login state (managed by Supabase Auth). We do not use advertising or third-party tracking cookies. Browser local storage may be used to preserve UI preferences. You can disable cookies in your browser settings, but this will prevent you from logging in.


10.Children's Privacy

The Platform is not directed at persons under 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from someone under 18, we will delete it immediately and close the account. If you believe a child has registered, contact us at joelukwago1@gmail.com.


11.Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by SMS or a notice on the Platform at least 7 days before they take effect. The “Effective date” at the top of this page will always reflect the current version.


12.Contact & Complaints

For data protection enquiries, access requests, or complaints:

If you are not satisfied with our response, you may contact the Personal Data Protection Office of Uganda (under the National Information Technology Authority — NITA-U).