Master Terms of Service
Legally binding terms governing SACCO subscriptions, managerial duties, automated Core Banking API integrations, and statutory SASRA filing workflows.
1. Parties, Scope & Legal Framework
These Terms of Service ("Agreement") constitute a binding contract between SacComply Technologies Limited ("SacComply", "we", "our", or "us") and the licensed cooperative society ("SACCO", "Subscriber", or "you") subscribing to the SacComply statutory risk-visibility and SASRA regulatory filing platform.
By accessing the SacComply dashboard ([https://saccomply.co.ke](https://saccomply.co.ke)) or integrating with our Machine-to-Machine API gateway, you warrant that you are an authorized representative (Chief Executive Officer, General Manager, Board Chairman, or designated Compliance Officer) with legal authority to bind the SACCO to these terms.
This platform operates under the regulatory supervision of the Sacco Societies Regulatory Authority (SASRA) pursuant to the Sacco Societies Act (Cap 490B), the Sacco Societies (Deposit-Taking Sacco Business) Regulations 2010, and the Sacco Societies (Non-Deposit Taking Business) Regulations 2020.
2. Role-Based Governance & Approval Segregation
SacComply enforces statutory segregation of duties in strict compliance with SASRA corporate governance guidelines:
manager)Authorized to upload financial trial balances, trigger automated Core Banking pushes, generate draft SASRA returns (Forms 1–9), and submit finalized returns to the Board for formal review. Managers cannot approve their own generated returns.
board_chair)Vested with fiduciary sign-off authority. The Board Chair reviews management submissions, inspects ratio breach early-warnings, and executes immutable cryptographic approvals or rejects returns back for management recalculation.
3. Machine-to-Machine (M2M) API Gateway Terms
SACCOs utilizing automated Core Banking pushes via secret keys (sk_live_...) agree to:
- Key Confidentiality: Store API credentials securely in environment variables or key vaults. SacComply stores only one-way SHA-256 hashes of provisioned keys and cannot recover lost secret keys.
- Rate Limits: API usage is throttled at 120 requests per minute per tenant key to safeguard high availability.
- Idempotency & Data Integrity: When pushing month-end batches, SACCOs should provide standard
idempotency_keyheaders to protect against network duplication. - No Credential Sharing: API keys must not be shared with unauthorized third parties or unverified contractors.
4. Subscription Plans, Billing & Payment Terms
Access to SacComply features is governed by the SACCO's active subscription tier (Free, Starter, or Pro). Subscriptions renew automatically on a monthly or annual billing cycle via Paystack / M-PESA Business Till.
| Plan Tier | Pricing (KES) | Statutory Return Generation | Core Banking API Keys |
|---|---|---|---|
| Free | KES 0 | Sample Form 1 & 2 | 1 Test Key |
| Starter | KES 25,000 / mo | Forms 1, 2, 4, 6 | 1 Production Key |
| Pro (Tier 1 & 2 DT) | KES 65,000 / mo | All 9 SASRA Forms + ZIP/Excel | Unlimited Keys + Webhooks |
5. Service Level Agreement (99.9% Uptime) & Termination
SacComply guarantees a 99.9% monthly uptime SLA for all core statutory reporting and API endpoints, excluding scheduled maintenance announced 48 hours in advance.
Upon account cancellation or subscription termination, SACCO administrators have a 30-day export window to download all historical return archives, signed snapshot hashes, and Excel workbooks before tenant resources are securely purged in accordance with our data retention schedule.
Have questions about our SASRA legal compliance or DPA 2019 governance?
Our dedicated legal and compliance counsel is available to review custom SACCO Data Transfer Agreements.