MICROX LOA PRIVACY POLICY
Privacy information for authorized MicroX LOA users and participating financial organizations.
Summary
MicroX LOA is a Loan Officer Application provided by MSIS for authorized microfinance operations. The application processes employee account information, loan and client information, device details, photographs, and location data required for field operations, route tracking, loan servicing, security, and audit purposes.
Full Policy
MicroX LOA ("the App") is a Loan Officer Application provided by Myanmar Software Integrated Solutions for use by authorized employees and participating financial organizations.
This Privacy Policy explains what information the App collects, why it is used, how it is protected, and the choices available to users.
1. Information We Collect
Depending on the features enabled by your organization, the App may collect the following information.
1.1 Account and Employment Information
- Username and staff identifier
- Staff name and assigned office
- User role and permissions
- Authentication and session information
1.2 Client and Loan Information
- Client identification and contact information
- Loan account information
- Loan applications and repayment schedules
- Repayment and collection records
- Loan location and supporting documents
1.3 Location Information
- Precise GPS latitude and longitude
- Date and time of location capture
- Route and movement information
- GPS accuracy, speed, bearing, and altitude, when available
When an authorized user starts an active route-tracking session, location collection may continue while the App is running in the background or is not actively displayed.
1.4 Photos and Files
- Loan-location photographs
- Documents or images selected or captured by the user for authorized loan-processing activities
1.5 Device and Technical Information
- Device identifier
- Device platform and application version
- Network type and connection status
- Battery percentage
- IP address, request logs, error information, and security events
2. How We Use Information
The collected information may be used to:
- Authenticate users and enforce assigned permissions
- Process loan applications and repayments
- Support field collection and loan servicing
- Record and verify loan locations
- Record loan-officer routes during authorized tracking sessions
- Display live and historical routes to authorized supervisors
- Synchronize offline transactions when network access is restored
- Prevent fraud, unauthorized access, and misuse
- Diagnose errors and improve application reliability
- Meet audit, accounting, contractual, and regulatory obligations
We do not use precise location information for advertising.
3. Background Location Disclosure
MicroX LOA may collect location data when an authorized route-tracking session is active, including when the App is closed or not in use.
This information is used to record field routes, verify operational visits, and display loan-officer locations to authorized supervisors.
5. Information Sharing
Information may be accessible to:
- The user's authorized organization
- Authorized supervisors, administrators, and auditors
- MSIS personnel who require access for support or maintenance
- Infrastructure or hosting providers operating under confidentiality and security obligations
- Government or regulatory authorities when required by law
Personal information is not sold to advertisers or data brokers.
6. Data Security
Reasonable technical and organizational safeguards are used, including:
- Encrypted HTTPS communication
- Authentication and permission controls
- Restricted administrative access
- Security and audit logging
- Secure storage and backup controls
- Device and session validation
No electronic storage or transmission method can be guaranteed to be completely secure.
7. Offline Storage
When the device has no network connection, authorized operational information may be stored temporarily on the device and uploaded when connectivity is restored.
Offline data should be encrypted and removed after successful synchronization, logout, or according to the organization's retention policy.
8. Data Retention
Information is retained only for as long as necessary for operational, contractual, accounting, audit, security, and legal requirements.
The following retention periods must be confirmed before this policy is published:
- GPS route history: 90 days
- Diagnostic and security logs: 180 days
- Loan records and supporting photographs: according to the financial organization's approved regulatory retention policy
- Offline device data: until successful synchronization, followed by secure deletion
9. User Rights and Choices
Subject to applicable law and organizational policy, users may request:
- Access to their personal information
- Correction of inaccurate information
- Deletion of eligible information
- Information about how their data is used
- Withdrawal of optional consent
Location permission can be changed using the device settings. Disabling location access may prevent route tracking and other location-dependent features from functioning.
Organization-managed accounts should be disabled or deleted through the organization's administrator.
10. Children's Privacy
MicroX LOA is an enterprise application intended for authorized adult employees and is not designed for use by children.
11. Changes to This Policy
This policy may be updated when the App's functionality, legal requirements, or organizational practices change.
The effective date will be updated when material changes are published.
12. Contact
For questions, privacy requests, or complaints, contact:
Publication Checklist
Before publishing this policy, confirm and replace all placeholders for:
- MSIS full legal company name
- Privacy or support email
- Registered company address and telephone number
- GPS retention period
- Photo and loan-record retention period
- Hosting and cloud service providers
- Analytics and crash-reporting services or SDKs, if any
- The exact circumstances in which background location is collected
https://microx.myansis.com/privacy/microx-loa
The published policy should be an active, publicly accessible HTTPS page that does not require login. The Privacy Policy link should also be available inside the App, including from the login page and the Settings or About page.