Skip to main content

Privacy Policy

Effective date: 2026-05-24 · Version 1.0

1. Who we are

The NamPost Innovation Sandbox (nampost-sandbox.na) is operated by Namibia Post Limited (NamPost) through its ICT division acting as scheme operator under the NamPost Postal-Financial Innovation Framework (NPIF). The sandbox operates under joint supervision by the Bank of Namibia (BoN) and the Namibia Financial Institutions Supervisory Authority (NAMFISA).

This Privacy Policy covers nampost-sandbox.na, the participant portal, the regulator Observation Deck, and sandbox APIs at api.nampost-sandbox.na. It does not cover the NamPost retail website (nampost.com.na), MyNamPost app, or PostFin — those services have separate privacy notices.

Data controller: Namibia Post Limited, 175 Independence Avenue, Windhoek, Namibia. Contact: sandbox@nampost.com.na

2. What data we collect and why

We collect organisation details, contact persons, application narratives, API usage metadata, audit trails, support tickets, and synthetic persona selections for programme administration, regulatory reporting, platform operations, and security.

We do not collect in default sandboxes: production national ID numbers; live grant beneficiary PII; real SmartCard PANs; production MoF/GRN files; live customer MSISDNs. All sandbox data uses synthetic personas only. Uploading production beneficiary files is prohibited.

CategorySourcePurpose
Organisation detailsApplication formNPIF intake; eligibility; testing agreement
Contact personsApplication + portalProgramme communication; breach notification
API usage metadataKong + audit logPSD-12 monitoring; regulator reporting
Audit trailAudit log (system records)Immutable evidence for BoN/NAMFISA

3. How we use your information

Programme administration; regulatory reporting (monthly progress; PSD-12 preliminary incident notice ≤24h); platform operations; security; application status and expiry communications.

We do not: sell personal data; train external AI models on participant production data in default namespaces; make automated final licensing decisions (human case officer review required).

4. Who we share data with

Bank of Namibia and NAMFISA for programme supervision; NamPost ICT sub-processors for platform operations; AWS (af-south-1) for cloud hosting with appropriate DPAs.

5. International transfers

Default hosting: AWS af-south-1 (Cape Town). Other regions require programme-office approval and transfer impact assessment.

6. Retention

Audit logs: 7 years. Application + testing agreement: programme + 3 years. Support tickets: 2 years. API metadata (hot): 13 months. Synthetic seed in namespace: sandbox duration + 30 days.

7. Your rights

Access, correct (via dashboard settings), erasure of contact data post-exit (subject to audit retention), object where applicable. Requests: sandbox@nampost.com.na — response within 30 calendar days.

8. Security

Encrypted connections (TLS 1.2+); a tamper-proof audit chain (HMAC-SHA256); multi-factor sign-in (Keycloak); each participant isolated in its own space; quarterly security scans; an annual penetration test; and PSD-12 disaster recovery (restore within 2 hours, at most 5 minutes of data loss).

9. Cookies

Session cookie (httpOnly, Secure, SameSite=Strict); CSRF token. No third-party advertising or cross-site tracking.

10. Changes

Material changes published here with ≥14 days' email notice to active participants.

11. Complaints

complaints@nampost.com.na (consumer harm) · sandbox@nampost.com.na (programme) · NAMFISA (www.namfisa.com.na) · BoN (www.bon.com.na).

Questions about these legal documents? Contact our legal team at legal@nampost.com.na