Last updated: October 2026
1. What we collect
Identity data: your full name, service number, rank, unit, date of birth details, sex, blood group, religion, and photographs of your national ID and military ID.
Verification data: a live face capture (two-pose liveness check) used solely to confirm that you are the person shown on your ID documents.
Account data: your email address, phone number, password (stored only as a secure hash), optional sign-in PIN, and biometric credentials registered on your own device.
Pay data: your salary grade, allowances, deductions, payment history, and the bank or mobile-money account you register for payout.
Next-of-kin data: names, relationships, and contact details of the people you choose to register.
Technical data: device identifiers, sign-in times, and a permanent audit log of actions taken on your account.
2. How we use it
To verify your identity before granting access, and to issue your digital ID card.
To calculate, process, and pay your salary, allowances, advances, and pension entitlements.
To investigate pay complaints, salary advances, and support tickets you raise.
To secure the system — detecting unauthorised access, freezing lost cards, and blocking compromised devices.
We do not sell your data, share it with advertisers, or use it for any commercial purpose.
3. Who can see your data
You can see and manage your own record at all times.
Finance officers and administrators can see personnel records only within the scope of their assigned role and unit, and every such action is recorded in a tamper-proof audit log.
Oversight roles (such as the Presidential and Chief of Staff dashboards) see aggregated statistics, not individual payout accounts, unless a specific case is escalated to them.
Your face-verification result is recorded as a pass/fail outcome; the check itself runs on secure servers and is never exposed to other users.
4. How we protect it
All data is encrypted in transit and stored in a secured, access-controlled database.
Passwords and PINs are stored only as one-way hashes — no one, including administrators, can read them.
Biometric sign-in credentials never leave your device; the portal stores only the public key needed to verify them.
Audit logs are append-only: they cannot be edited or deleted by anyone, including administrators.
5. Your rights and choices
You may correct your profile details, payout account, and next-of-kin entries at any time from the Settings and Next of Kin pages.
You may request closure of your account through Settings. Because pay records are official government records, historical payroll entries are retained as required by law even after an account is closed.
You may raise any privacy concern through the Contact page or the duty desk helpline (+211 914 632 893).
6. Retention
Payroll and service records are retained for the period required by government record-keeping regulations. Registration documents of rejected applicants are reviewed and removed once the decision is final.
