Legal
Data protection
Last updated 18 September 2026
This notice is our public statement under the Data Protection Act, 2024 of Malawi and Part VIII of the Electronic Transactions and Cyber Security Act, 2016. It sits next to the privacy policy. If the two ever differ on a data-subject right, this notice wins.
Controller
389 Group Ltd, trading as Steadi Pay, Lilongwe, Malawi, is the data controller for Steadi Pay accounts, the merchant portal, the admin console, the website and support. Write to support@steadipay.ltd with the subject "Data protection".
Licensed collection partners process payment data for their own regulated services. They are not Steadi Pay. We send them only what is needed to start or confirm a payment.
Lawful bases
- Contract: creating an account, running checkout, webhooks, payout instructions you give us.
- Legal obligation: tax invoices, five-year financial records, lawful requests from Malawian authorities.
- Legitimate interests, balanced against your rights: security, fraud prevention, service logs, improving reliability.
- Consent: only where we ask for it and you can withdraw it as easily as you gave it.
We treat national ID numbers, TPIN, full bank account numbers and precise location as data that needs extra care. We do not collect special-category data such as health, biometrics or children's data for Steadi Pay. We do not offer accounts to anyone under 18.
Your rights under Malawian law
Subject to the limits in the Data Protection Act, 2024, you may:
- be told whether we hold personal data about you, and receive a copy;
- have inaccurate data corrected;
- request erasure where the Act allows (not where we must keep a payment or ledger row);
- restrict or object to processing that relies on legitimate interests;
- withdraw consent, where consent was the basis;
- ask for data portability of account data you provided, in a common machine-readable form;
- complain to us, and to the Malawi Data Protection Authority once it is receiving complaints.
We will answer within the time the Act requires. We may need to verify who you are. We will not charge a fee unless a request is excessive or repeated, as the Act allows.
We cannot erase a ledger entry, a confirmed payment, or an audit row. Those records are kept for five years. We can close the account so it is no longer used.
Security
Passwords are hashed. Provider API secrets are encrypted at rest and write-only. Sessions use a server-side store. Staff access is logged. MSISDNs are masked in logs and tickets. Card data never touches our servers. We apply access control so a merchant cannot see another merchant's data.
If a personal-data breach is likely to pose a high risk to you, we will notify the Authority and affected people as the Data Protection Act, 2024 requires.
Transfers outside Malawi
Personal data stays in Malawi unless a transfer is allowed under the Act: an adequacy finding, appropriate safeguards, or another permitted ground. Payment partners may process a transaction in the country where they are licensed. We do not send personal data abroad for advertising.
Processors
Hosting, email delivery and licensed payment partners act on documented instructions or, for partners, on their own licence. They may not use Steadi Pay personal data for their own marketing.
Children
Steadi Pay is not for children. We do not knowingly create a merchant or staff account for anyone under 18. If you believe we have, email us and we will close it.
Complaints
Start with support@steadipay.ltd or a ticket in the portal. You may also complain to the Malawi Data Protection Authority, and you keep any rights under the Consumer Protection Act and the Electronic Transactions and Cyber Security Act, 2016.