Afriland First Bank South Sudan

Privacy Policy

First Bank Connect  ·  Last updated May 15, 2026

Contents

  1. Introduction
  2. Data We Collect
  3. Financial Data
  4. Biometric Authentication
  5. Camera & QR Scanning
  6. Device Fingerprinting
  7. How We Use Your Data
  8. How We Share Your Data
  9. Data Retention
  10. Security Measures
  11. Your Rights
  12. Children’s Privacy
  13. Policy Changes
  14. Contact Us

1. Introduction

Afriland First Bank South Sudan (« the Bank », « we », « us », or « our ») operates the First Bank Connect mobile banking application (the « App ») available on Google Play and the Apple App Store. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the App.

By downloading, installing, or using First Bank Connect, you agree to the practices described in this policy. If you do not agree, please do not use the App.

This policy applies to:

  • All registered customers of Afriland First Bank South Sudan using the App
  • Visitors who browse the App without creating an account
  • All devices (Android and iOS) on which the App is installed

This policy is compliant with applicable data protection regulations including the General Data Protection Regulation (GDPR)Google Play Data Safety requirements, and the data protection guidelines of the Bank of South Sudan.

2. Data We Collect

We collect the following categories of information when you use First Bank Connect:

2.1 Account & Identity Information

  • Full name, phone number, and email address
  • Account number(s) and bank account details
  • Date of birth and national ID (collected during registration)
  • Profile photo (if provided)

2.2 Financial Information

  • Account balances and transaction history
  • Payment details (amounts, dates, recipients, references)
  • Bill payment records (electricity, merchants, etc.)
  • Transfer beneficiaries you save

2.3 Technical & Device Information

  • Device model, manufacturer, and operating system version
  • App version and session activity logs
  • IP address and network type (Wi-Fi / mobile data)
  • Device identifiers used for security (see Section 6)
  • Crash reports and performance diagnostics

2.4 Usage Data

  • Features and screens accessed within the App
  • Timestamps of logins and logouts
  • Error logs and failed authentication attempts

Data you choose NOT to provide: Some features may be unavailable if you decline to provide certain data (e.g., camera access disables QR scanning; declining biometric setup means PIN-only login). Core banking functions are always available via PIN authentication.

3. Financial Data Handling

As a mobile banking application, First Bank Connect processes sensitive financial information. We treat this data with the highest level of security and discretion.

3.1 What Financial Data We Process

  • Account balances retrieved in real time from Afriland First Bank South Sudan’s servers
  • Transaction records: amount, currency, date, time, description, and counterparty details
  • Payment instructions you initiate (transfers, bill payments, merchant payments)
  • OTP (one-time password) codes used for transaction authorization — never stored after use

3.2 How We Protect Financial Data

  • All data is transmitted over TLS 1.2+ encrypted connections
  • Every API request is signed with HMAC-SHA256 to prevent tampering
  • Access tokens are stored in the device’s secure hardware enclave (iOS Keychain / Android Keystore) — never in plain storage
  • Access tokens expire after 60 minutes and are refreshed securely
  • Financial data at rest is encrypted using AES-256

3.3 Currency & Multi-Account Support

The App supports multiple currencies (including SSP, USD, and others held at Afriland First Bank South Sudan). Each account’s currency is used as-is for payments and transfers — we do not silently convert or substitute currencies.

3.4 Regulatory Compliance

Financial transaction records are retained for a minimum of 7 years as required by financial regulations applicable to Afriland First Bank South Sudan. Transaction data may be disclosed to regulatory authorities (Bank of South Sudan, law enforcement) when legally required.

4. Biometric Authentication

Key commitment: Your biometric data (fingerprint or face scan) is processed entirely on your device. We never collect, transmit, or store your raw biometric data on our servers.

4.1 How Biometric Login Works

If you choose to enable biometric login, the App uses your device’s operating system APIs (Face ID / Touch ID on iOS, BiometricPrompt on Android) to verify your identity. The biometric template is stored exclusively in the device’s Secure Enclave or StrongBox hardware — a tamper-resistant chip isolated from the main processor.

4.2 What We Do NOT Do

  • We do not receive, store, or process your fingerprint or face image
  • We do not transmit biometric data over the network
  • We do not use biometric data for any purpose other than unlocking the App
  • We do not use biometrics for advertising, profiling, or analytics

4.3 Consent & Opt-Out

Biometric login is entirely optional. You can disable it at any time in the App settings or in your device’s system settings. Disabling biometric login reverts you to PIN-based authentication; all other features remain available.

4.4 Retention

Biometric authentication keys are automatically removed when you uninstall the App, disable biometric login in settings, or perform a factory reset of your device.

5. Camera & QR Code Scanning

Key commitment: Camera access is used exclusively for real-time QR code scanning. We do not record, save, or transmit any images or video from your camera.

5.1 Purpose

The App requests camera permission only when you choose to use the Scan & Pay feature to scan merchant QR codes. The camera processes each frame locally on your device to detect and decode QR codes. No image data leaves your device.

5.2 What the QR Scanner Reads

QR codes used with First Bank Connect follow the format afbss-mba://merchant/<TILL_NUMBER>. The App extracts only the merchant till number from this code to pre-fill the payment form. No other QR content is stored or transmitted beyond what is needed to complete your payment.

5.3 Your Control

  • Camera permission is requested only when you open the QR scanner
  • You can decline the permission — manual entry of the till number is always available
  • You can revoke camera permission at any time in your device settings

5.4 No Third-Party Access

No third parties have access to your camera or to any camera data. The QR scanning library (mobile_scanner) operates entirely offline on your device.

6. Device Fingerprinting

For the security of your account and to comply with financial fraud prevention regulations, First Bank Connect collects a set of device-level identifiers to create a device fingerprint. This is a standard practice in mobile banking.

6.1 What We Collect for Fingerprinting

  • Device model and manufacturer
  • Operating system name and version
  • App version and build number
  • Screen resolution and density
  • Network connection type
  • A unique device installation ID (generated at first launch, not tied to hardware)

We do not collect your phone number’s SIM serial (IMSI), IMEI, MAC address, or any hardware identifier that uniquely identifies your physical device across apps.

6.2 Why We Collect This

  • Fraud detection: Detect logins from unknown or suspicious devices
  • Device registration: Validate that new devices are authorized by you via OTP
  • Security audit trails: Identify the device used in each session for dispute resolution
  • Regulatory compliance: Meet KYC/AML requirements applicable to digital banking

6.3 How It Is Transmitted

Device fingerprint data is sent with every authenticated API request via encrypted HTTP headers (X-Device-*X-OS-*X-App-*) over TLS 1.2+. It is also signed as part of the HMAC-SHA256 request signature.

6.4 Legal Basis

Device fingerprinting is processed on the basis of our legitimate interest in preventing fraud and protecting your account, and our legal obligation to comply with financial sector security regulations. This processing is necessary for the core security of the App and cannot be disabled while using the service.

7. How We Use Your Data

PurposeData UsedLegal Basis
Process banking transactions (transfers, payments)Account info, financial dataPerformance of contract
Authenticate your identity (PIN, biometric)Device ID, biometric (local)Performance of contract
Prevent fraud and unauthorized accessDevice fingerprint, IP, usage logsLegitimate interest / Legal obligation
Send you transaction notifications and alertsPhone number, emailPerformance of contract
Provide customer supportAccount info, transaction historyPerformance of contract
Comply with AML/KYC regulationsIdentity info, transaction dataLegal obligation
Generate receipts & PDF documentsTransaction dataPerformance of contract
Improve App performance and fix bugsCrash logs, usage dataLegitimate interest

We do not use your data for targeted advertising, sell your data to third parties, or use your data to build profiles for marketing purposes.

8How We Share Your Data

We do not sell or rent your personal information. We may share your data only in the following limited circumstances:

8.1 Afriland First Bank South Sudan

First Bank Connect is the official mobile interface for Afriland First Bank South Sudan. Your data is shared with the Bank’s core banking system to process all financial operations. This sharing is necessary to provide the service.

8.2 Service Providers & Technology Partners

We use carefully vetted third-party service providers who process data on our behalf and are bound by data processing agreements. These include:

  • Payment processors: to settle transfers and bill payments
  • SMS/OTP gateway: to deliver one-time passwords to your phone
  • Hosting and infrastructure providers: to run the API servers securely

These providers are not permitted to use your data for their own purposes.

8.3 Regulatory & Legal Disclosures

We may disclose your information to government authorities, regulators, or law enforcement when legally required to do so, including:

  • The Bank of South Sudan (regulatory oversight)
  • Tax authorities, financial intelligence units (AML/CFT compliance)
  • Courts or law enforcement (when subject to a valid legal order)

8.4 With Your Explicit Consent

In situations not covered above, we will ask for your explicit consent before sharing your personal information with any third party.

PDF Receipts: When you use the « Share » button on a receipt, the PDF is generated on your device and passed directly to your device’s native share sheet. We do not receive or store the shared file. Sharing is fully under your control.

9. Data Retention

Data TypeRetention PeriodReason
Financial transaction records7 years after transactionRegulatory/legal requirement
Account informationDuration of account + 3 years after closureLegal obligation, dispute resolution
Authentication & session logs90 daysSecurity audit trail
Device fingerprint recordsDuration of account + 1 yearFraud prevention, compliance
OTP codesDeleted immediately after use or expirySecurity (single-use)
Camera / QR dataNot stored — processed in memory onlyPrivacy by design
Biometric dataStored locally on device only; deleted on uninstallPrivacy by design
Crash & diagnostic logs30 daysApp stability improvements

After the applicable retention period, data is securely deleted or anonymised so that it can no longer be linked to you personally.

10. Security Measures

We implement industry-standard and banking-grade security controls to protect your personal and financial information:

  • Encryption in transit: All API communications use TLS 1.2+
  • Request signing: Every API request is signed with HMAC-SHA256 using a secret key; unsigned requests are rejected
  • Secure token storage: Authentication tokens are stored in the device’s hardware-backed secure storage (iOS Keychain / Android Keystore)
  • Short-lived tokens: Access tokens expire after 60 minutes; refresh tokens are rotated on each use
  • Device registration: New devices must be verified with an OTP before accessing your account
  • Rate limiting & retry protection: API endpoints are rate-limited to prevent brute-force attacks
  • PIN protection: Your PIN is never stored on device or transmitted in plaintext
  • Biometric isolation: Biometric data never leaves the device’s secure hardware
  • Production certificate pinning: The App validates the server’s TLS certificate in production builds

In the event of a security incident: If we become aware of a data breach that affects your personal information, we will notify you and the relevant authorities within the timeframe required by applicable law.

11. Your Rights

Depending on your country of residence, you may have the following rights regarding your personal data:

11.1 Right of Access

You can request a copy of the personal data we hold about you. We will respond within 30 days.

11.2 Right to Rectification

You can request correction of inaccurate personal data. For account details linked to your bank profile, please visit a branch or contact customer support.

11.3 Right to Erasure

You can request deletion of your personal data. Note that some data (financial transaction records) must be retained to meet legal and regulatory obligations and cannot be deleted on request.

11.4 Right to Data Portability

You can request an export of your transaction history and account data in a machine-readable format (CSV or JSON).

11.5 Right to Object

You can object to processing of your data for purposes based on legitimate interest (e.g., analytics). You cannot object to processing that is necessary for the performance of your banking contract or for legal compliance.

11.6 Account Deletion

You can request full account deletion by contacting us at quality@afrilandfirstbankss.com. Account deletion removes your access to First Bank Connect and initiates the data retention/deletion process as described in Section 9.

To exercise any of these rights, contact us at quality@afrilandfirstbankss.com or in writing at our Head Office. We will verify your identity before processing any request.

12. Children’s Privacy

First Bank Connect is intended for users who are at least 18 years of age and hold a valid Afriland First Bank South Sudan account. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.

13. Policy Changes

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the « Last updated » date at the top of this page
  • Display an in-app notification on your next login
  • For significant changes affecting your rights, we may send an email or SMS notice

Continued use of the App after a policy update constitutes acceptance of the revised terms. We encourage you to review this policy periodically.

14. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Afriland First Bank South Sudan

📍 Hai Cinema, PO BOX 640, Juba, South Sudan

📧 quality@afrilandfirstbankss.com

📧 firstbank_ss@afrilandfirstbankss.com

📞 +211 922 442 446

This Privacy Policy is governed by the laws of the Republic of South Sudan and applicable international data protection regulations. Any disputes arising from this policy shall be subject to the jurisdiction of South Sudanese courts.

First Bank Connect — Official mobile banking app of Afriland First Bank South Sudan

privacy@afrilandfirstbankss.com  ·  Licensed by the Bank of South Sudan

Privacy Policy · Version 1.0 · Last updated May 15, 2026