SaccomplyPrudential Oversight
Sign In
Legal Agreements/terms

Master Terms of Service

v2026.1

Legally binding terms governing SACCO subscriptions, managerial duties, automated Core Banking API integrations, and statutory SASRA filing workflows.

Effective Date: August 1, 2026Jurisdiction: Republic of KenyaODPC Registered

1. Parties, Scope & Legal Framework

These Terms of Service ("Agreement") constitute a binding contract between SacComply Technologies Limited ("SacComply", "we", "our", or "us") and the licensed cooperative society ("SACCO", "Subscriber", or "you") subscribing to the SacComply statutory risk-visibility and SASRA regulatory filing platform.

By accessing the SacComply dashboard ([https://saccomply.co.ke](https://saccomply.co.ke)) or integrating with our Machine-to-Machine API gateway, you warrant that you are an authorized representative (Chief Executive Officer, General Manager, Board Chairman, or designated Compliance Officer) with legal authority to bind the SACCO to these terms.

Statutory Alignment

This platform operates under the regulatory supervision of the Sacco Societies Regulatory Authority (SASRA) pursuant to the Sacco Societies Act (Cap 490B), the Sacco Societies (Deposit-Taking Sacco Business) Regulations 2010, and the Sacco Societies (Non-Deposit Taking Business) Regulations 2020.

2. Role-Based Governance & Approval Segregation

SacComply enforces statutory segregation of duties in strict compliance with SASRA corporate governance guidelines:

Manager Role (manager)

Authorized to upload financial trial balances, trigger automated Core Banking pushes, generate draft SASRA returns (Forms 1–9), and submit finalized returns to the Board for formal review. Managers cannot approve their own generated returns.

Board Chair Role (board_chair)

Vested with fiduciary sign-off authority. The Board Chair reviews management submissions, inspects ratio breach early-warnings, and executes immutable cryptographic approvals or rejects returns back for management recalculation.

3. Machine-to-Machine (M2M) API Gateway Terms

SACCOs utilizing automated Core Banking pushes via secret keys (sk_live_...) agree to:

  • Key Confidentiality: Store API credentials securely in environment variables or key vaults. SacComply stores only one-way SHA-256 hashes of provisioned keys and cannot recover lost secret keys.
  • Rate Limits: API usage is throttled at 120 requests per minute per tenant key to safeguard high availability.
  • Idempotency & Data Integrity: When pushing month-end batches, SACCOs should provide standard idempotency_key headers to protect against network duplication.
  • No Credential Sharing: API keys must not be shared with unauthorized third parties or unverified contractors.

4. Subscription Plans, Billing & Payment Terms

Access to SacComply features is governed by the SACCO's active subscription tier (Free, Starter, or Pro). Subscriptions renew automatically on a monthly or annual billing cycle via Paystack / M-PESA Business Till.

Plan TierPricing (KES)Statutory Return GenerationCore Banking API Keys
FreeKES 0Sample Form 1 & 21 Test Key
StarterKES 25,000 / moForms 1, 2, 4, 61 Production Key
Pro (Tier 1 & 2 DT)KES 65,000 / moAll 9 SASRA Forms + ZIP/ExcelUnlimited Keys + Webhooks

5. Service Level Agreement (99.9% Uptime) & Termination

SacComply guarantees a 99.9% monthly uptime SLA for all core statutory reporting and API endpoints, excluding scheduled maintenance announced 48 hours in advance.

Upon account cancellation or subscription termination, SACCO administrators have a 30-day export window to download all historical return archives, signed snapshot hashes, and Excel workbooks before tenant resources are securely purged in accordance with our data retention schedule.

Have questions about our SASRA legal compliance or DPA 2019 governance?

Our dedicated legal and compliance counsel is available to review custom SACCO Data Transfer Agreements.

Contact Legal Counsel