Privacy Policy

How Greenloop Foundation handles and protects personal information.

Effective Date: 8 September 2026 · Last Updated: 8 September 2026

Privacy Policy

Greenloop Foundation ("Greenloop Foundation", "we", "us", or "our") respects your privacy and is committed to protecting the personal information entrusted to us.

This Privacy Policy explains how we collect, use, store, protect, disclose and otherwise process personal information when you visit or use bsw.greenloop.co.bw, interact with our services, communicate with us, or otherwise engage with us.

We are committed to handling personal information responsibly and transparently and to complying with applicable data protection and privacy laws, including the Botswana Data Protection Act, 2024, as well as applicable international data protection laws and regulations where they apply to our activities.

This Privacy Policy should be read together with any applicable Terms and Conditions, Cookie Policy and other notices that may be provided to you when you interact with our services.

1. Who We Are

Greenloop Foundation is responsible for the processing of personal information described in this Privacy Policy.

For purposes of applicable data protection legislation, Greenloop Foundation may act as a data controller or equivalent entity where we determine the purposes and means of processing personal information.

Where we process personal information on behalf of another organisation, we may instead act as a data processor or equivalent service provider and will process that information in accordance with the instructions and contractual requirements applicable to that relationship.

If you have questions about this Privacy Policy or how your information is handled, you may contact us using the contact details provided on our website.

2. Our Commitment to Privacy

We follow the principles of responsible data protection and privacy.

Where applicable, we seek to ensure that personal information is:

  • Processed lawfully, fairly and transparently.
  • Collected for specific, legitimate and clearly communicated purposes.
  • Limited to information that is adequate, relevant and reasonably necessary.
  • Accurate and kept up to date where appropriate.
  • Retained only for as long as reasonably necessary.
  • Protected against unauthorised access, disclosure, alteration, loss or destruction.
  • Processed in a manner that respects the rights and interests of individuals.
  • Subject to appropriate technical and organisational safeguards.

These principles are consistent with internationally recognised data protection standards, including the core principles reflected in the GDPR.

3. Personal Information We May Collect

Depending on how you interact with Greenloop Foundation, we may collect different categories of personal information.

This may include:

3.1 Information You Provide Directly

When you contact us, submit an enquiry, register for a service, complete a form, request information or otherwise communicate with us, we may collect:

  • Full name.
  • Email address.
  • Telephone or mobile number.
  • Organisation or company name.
  • Job title or position.
  • Physical or postal address.
  • Information contained in your enquiry or communication.
  • Any other information that you voluntarily provide to us.

3.2 Technical Information

When you visit our website, certain technical information may automatically be collected, including:

  • IP address.
  • Browser type and version.
  • Device type.
  • Operating system.
  • Language preferences.
  • Time zone.
  • Pages visited.
  • Date and time of visits.
  • Referring website or source.
  • Website interaction information.
  • Error and diagnostic information.

We use this information primarily to operate, secure, maintain and improve our website and services.

3.3 Cookies and Similar Technologies

Our website may use cookies, pixels, tags, local storage and similar technologies.

These technologies may be used for:

  • Essential website functionality.
  • Security.
  • Remembering preferences.
  • Website performance.
  • Understanding how visitors use our website.
  • Analytics.
  • Improving our services.
  • Marketing or advertising, where applicable.

Where applicable law requires consent for non-essential cookies or similar technologies, we will request that consent before using them.

You may also be able to control cookies through your browser or our cookie-management tools.

4. How We Use Personal Information

We may process personal information for purposes including:

  • Providing and administering our services.
  • Responding to enquiries and requests.
  • Communicating with you.
  • Managing our relationship with clients, partners and stakeholders.
  • Providing customer support.
  • Processing registrations or applications.
  • Managing accounts where applicable.
  • Improving our website, products and services.
  • Monitoring website performance and security.
  • Detecting, preventing and investigating fraud, abuse and security incidents.
  • Maintaining business, financial and operational records.
  • Complying with legal and regulatory obligations.
  • Establishing, exercising or defending legal claims.
  • Sending information, updates or marketing communications where permitted by law.
  • Conducting legitimate business, administrative and analytical activities.
  • Protecting the rights, property and safety of Greenloop Foundation, our users and other persons.

We will not use personal information for purposes that are incompatible with the purpose for which it was originally collected unless we have a lawful basis to do so or are otherwise permitted or required by applicable law.

The principles of purpose limitation and data minimisation are also recognised internationally under the GDPR and similar privacy frameworks.

5. Lawful Basis for Processing

Where applicable data protection law requires a lawful basis for processing personal information, we may rely on one or more of the following:

Consent

Where you have provided valid consent, we may process your personal information for the purposes explained when that consent was obtained.

You may withdraw consent at any time, subject to applicable legal limitations.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Contract

We may process information where necessary to enter into or perform a contract with you.

Legal Obligation

We may process personal information where necessary to comply with a legal, regulatory or statutory obligation.

Legitimate Interests

Where permitted by law, we may process personal information where necessary for our legitimate interests, provided those interests do not override your applicable rights and freedoms.

Vital Interests

Where legally permitted, we may process information where necessary to protect someone's vital interests.

Public Interest or Other Lawful Grounds

Where applicable, we may process information on another lawful basis recognised under the applicable data protection legislation.

Where special or sensitive categories of personal information are processed, we will apply any additional legal requirements that apply to such information.

6. Sensitive Personal Information

Certain information may receive enhanced protection under applicable data protection legislation.

Depending on the applicable law, this may include information relating to areas such as:

  • Health.
  • Biometric information.
  • Genetic information.
  • Financial information.
  • Identity information.
  • Children's information.
  • Racial or ethnic information.
  • Religious or philosophical beliefs.
  • Sexual orientation or related information.
  • Criminal or alleged criminal conduct.
  • Other categories designated as sensitive or special categories by applicable law.

We will only collect or process sensitive personal information where there is a lawful and appropriate reason to do so and where additional safeguards are required by law.

Where sensitive information is not necessary for a particular service or purpose, we ask that you do not provide it.

7. Information About Children

Our services are not intended to knowingly collect personal information from children in circumstances where parental or guardian consent is required by applicable law.

Where we become aware that personal information relating to a child has been collected unlawfully or without the required authorisation, we will take reasonable steps to address the situation in accordance with applicable law.

Where services are specifically directed towards children, additional privacy notices, parental or guardian consent mechanisms and safeguards may apply.

8. How We Share Personal Information

We do not sell your personal information.

We may share personal information where reasonably necessary with:

  • Employees and authorised representatives.
  • Service providers and technology providers.
  • Hosting and infrastructure providers.
  • Website and software providers.
  • Professional advisers.
  • Auditors and consultants.
  • Payment or financial service providers, where applicable.
  • Business partners where necessary to provide a requested service.
  • Government authorities, regulators or law enforcement agencies where required or permitted by law.
  • Courts, tribunals or other legal authorities.
  • Other parties where you have provided appropriate consent.

Where third parties process personal information on our behalf, we seek to require appropriate confidentiality, security and data protection obligations through contracts or other appropriate safeguards.

9. Third-Party Services

Our website or services may use third-party services such as:

  • Website hosting providers.
  • Cloud infrastructure providers.
  • Analytics services.
  • Communication services.
  • Security services.
  • Payment providers.
  • Customer relationship management systems.
  • Marketing and communications platforms.
  • Social media integrations.
  • Other technology providers necessary to operate our services.

These providers may process personal information on our behalf or independently, depending on the nature of their services.

Where a third party processes information on our behalf, we will take reasonable steps to ensure that appropriate contractual and technical safeguards are in place.

Third-party services may have their own privacy policies, and we encourage you to review them where appropriate.

10. International Transfers of Personal Information

Your personal information may be stored or processed in Botswana or in another country where we, our service providers or business partners operate.

Where personal information is transferred across borders, we will take reasonable steps to ensure that the transfer is lawful and that appropriate safeguards are implemented as required by applicable data protection legislation.

Such safeguards may include:

  • Contractual protections.
  • Adequacy decisions or recognised equivalent mechanisms.
  • Appropriate security measures.
  • Data processing agreements.
  • Other legally recognised transfer mechanisms.

Where required by applicable law, we will provide additional information concerning international transfers and the safeguards used to protect your information.

11. Data Security

We take reasonable technical and organisational measures designed to protect personal information against:

  • Unauthorised access.
  • Unauthorised disclosure.
  • Unlawful processing.
  • Accidental loss.
  • Destruction.
  • Damage.
  • Alteration.
  • Other security threats.

Depending on the nature and sensitivity of the information, security measures may include:

  • Access controls.
  • Authentication mechanisms.
  • Encryption where appropriate.
  • Secure communications.
  • Network security controls.
  • Logging and monitoring.
  • Backups.
  • Staff confidentiality obligations.
  • Security testing and maintenance.
  • Incident response procedures.
  • Appropriate physical and organisational safeguards.

However, no internet transmission or electronic storage system can be guaranteed to be completely secure.

Accordingly, while we take reasonable measures to protect personal information, we cannot guarantee absolute security.

12. Data Breaches and Security Incidents

If we become aware of a personal information breach, we will assess the incident and take appropriate steps to contain, investigate and remediate it.

Where notification is required by applicable law, we will notify the relevant regulatory authority and/or affected individuals within the applicable statutory timeframes.

Notifications may include information about:

  • The nature of the incident.
  • The information affected.
  • Potential consequences.
  • Measures taken to address the incident.
  • Steps individuals can take to protect themselves.
  • Other information required by applicable law.

13. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.

Retention periods may depend on:

  • The nature of the information.
  • The purpose for which it was collected.
  • Our relationship with you.
  • Legal and regulatory requirements.
  • Accounting and record-keeping obligations.
  • Dispute resolution requirements.
  • Security requirements.
  • The establishment, exercise or defence of legal claims.

When personal information is no longer required, we will take reasonable steps to securely delete, destroy, anonymise or otherwise dispose of it in accordance with applicable requirements.

14. Your Privacy Rights

Subject to applicable law and any lawful exemptions, you may have rights concerning your personal information.

These may include the right to:

  • Be informed about the collection and use of your personal information.
  • Request access to personal information we hold about you.
  • Request correction or updating of inaccurate or incomplete information.
  • Request deletion or erasure of personal information in appropriate circumstances.
  • Request restriction of processing in appropriate circumstances.
  • Object to certain processing activities.
  • Withdraw consent where processing is based on consent.
  • Request portability of certain personal information where applicable.
  • Object to direct marketing.
  • Request information about international transfers.
  • Exercise rights relating to automated decision-making or profiling where applicable.
  • Lodge a complaint with the relevant data protection authority.

These rights are broadly consistent with internationally recognised privacy frameworks such as the GDPR, although the precise scope and conditions of each right depend on the law applicable to the individual and the processing activity.

15. How to Exercise Your Rights

If you wish to exercise a privacy right or make a request concerning your personal information, please contact us using the contact details provided on our website.

To protect personal information from unauthorised disclosure, we may need to verify your identity before processing certain requests.

We will respond to valid requests within the timeframe required by applicable law.

Where permitted by law, we may decline or limit a request where an applicable legal exemption or restriction applies. Where appropriate, we will explain the reason for our decision.

16. Direct Marketing

Where permitted by applicable law, we may communicate with you about our services, products, activities or other information that may be relevant to you.

Where consent is required, we will obtain appropriate consent before sending marketing communications.

You may unsubscribe from marketing communications at any time by using the unsubscribe mechanism included in the communication or by contacting us.

Unsubscribing from marketing communications will not necessarily stop important service, transactional, security or legally required communications.

17. Automated Decision-Making and Profiling

We may use automated systems or analytics technologies to understand website usage, improve our services or support operational activities.

We will not make decisions based solely on automated processing that produce legal or similarly significant effects on you unless such processing is permitted under applicable law and the required safeguards are in place.

Where applicable law provides rights relating to automated decision-making or profiling, those rights will be respected.

18. Cookies

Cookies may be used to help us operate and improve our website.

Cookies may be categorised as:

Strictly Necessary Cookies

These are required for essential website functionality and security.

Functional Cookies

These may remember preferences and settings.

Analytics Cookies

These help us understand how visitors use our website and improve performance.

Marketing Cookies

Where applicable, these may be used to support advertising, campaign measurement or personalised communications.

Where required by law, non-essential cookies will only be placed or activated after obtaining the appropriate consent.

You may change your cookie preferences or disable cookies through your browser settings, although doing so may affect certain website functionality.

19. Third-Party Websites

Our website may contain links to third-party websites, platforms or services.

We are not responsible for the privacy practices, security or content of third-party websites.

When you leave our website, we encourage you to review the privacy policy of the website or service you are visiting.

20. Accuracy of Personal Information

We aim to maintain accurate and reliable personal information.

If you believe that information we hold about you is inaccurate, incomplete or outdated, you may contact us and request that it be corrected.

We may take reasonable steps to verify the accuracy of requested changes.

21. Privacy by Design and Default

Where appropriate, we seek to incorporate privacy and data protection considerations into the design, development and operation of our services.

This may include:

  • Collecting only information reasonably required for a stated purpose.
  • Restricting access based on roles and responsibilities.
  • Applying appropriate security measures.
  • Limiting retention.
  • Using anonymisation or pseudonymisation where appropriate.
  • Reviewing privacy risks associated with new technologies or processing activities.

Privacy by design and privacy by default are recognised principles within modern international data protection frameworks.

22. Accountability

We seek to maintain appropriate policies, procedures and controls to demonstrate responsible handling of personal information.

Depending on the nature and scale of our processing activities, these may include:

  • Data protection policies.
  • Information security policies.
  • Data retention procedures.
  • Access controls.
  • Data processing agreements.
  • Privacy impact assessments where appropriate.
  • Incident response procedures.
  • Staff confidentiality and privacy obligations.
  • Records relating to processing activities where required.

23. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes to our services.
  • Changes in technology.
  • Changes to our processing activities.
  • Changes in applicable laws or regulatory requirements.
  • Changes to our privacy and security practices.

When we make material changes, we may provide additional notice where appropriate.

The "Last Updated" date at the top of this Privacy Policy indicates when it was most recently revised.

We encourage you to review this Privacy Policy periodically.

24. Complaints

If you have concerns about how we have handled your personal information, we encourage you to contact us first so that we can investigate and attempt to resolve the matter.

You may also have the right to lodge a complaint with the relevant data protection supervisory authority or regulator in accordance with applicable law.

For individuals located in jurisdictions such as the European Union or United Kingdom, this may include the relevant supervisory authority in their jurisdiction where the applicable legislation provides such a right.

25. Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have a concern regarding the handling of your personal information, please contact Greenloop Foundation through the contact information provided on our website.

Website: bsw.greenloop.co.bw

Email: [INSERT PRIVACY / DATA PROTECTION EMAIL]

Telephone: [INSERT TELEPHONE NUMBER]

Physical Address: [INSERT REGISTERED / BUSINESS ADDRESS]

Data Protection Contact / Officer: [INSERT NAME OR ROLE, IF APPLICABLE]

26. Governing Law

This Privacy Policy is primarily governed by the laws of Botswana, including applicable data protection and privacy legislation.

Where Greenloop Foundation processes personal information subject to the laws of another jurisdiction, the relevant provisions of that jurisdiction may also apply.

Nothing in this Privacy Policy is intended to limit any mandatory rights or protections provided to individuals under applicable law.

27. Important Notice

This Privacy Policy is intended to provide a comprehensive description of Greenloop Foundation's privacy practices and to support compliance with applicable data protection requirements.

Because privacy obligations depend on the specific nature of the organisation, its services, users, technology, data flows and jurisdictions in which it operates, this Privacy Policy should be reviewed alongside Greenloop Foundation's actual data processing activities and internal privacy and security controls.

Where there is a conflict between this Privacy Policy and a mandatory requirement of applicable law, the mandatory legal requirement will prevail.