Legal

Privacy Policy

Last updated: 23 September 2026

What this covers

MinistryFlow is a staff onboarding and payroll setup platform built and operated by Smartara, currently piloting with the Ministry of Health. This policy explains what personal information the platform collects, why, who can see it, and how it is protected.

Information we collect

When you create an account and submit an onboarding, reinstatement, or termination application, we collect:

  • Account details: full name, email address, username, and role.
  • Personal details you provide on the application form (e.g. date of birth, place of birth, nationality, marital status, national ID number).
  • Employment and payment details relevant to payroll setup (posting, grade, bank account information).
  • Uploaded documents required for your application type, for example a national ID card, birth certificate, TIN certificate, appointment letter, or posting notification.

How we use it

Your information is used only to process your onboarding, reinstatement, or termination application: verifying documents, determining applicable allowances, generating the SAL 1 salary advice form, and routing your application through the Accounts Office and Head of Department review stages to the Personnel Management Office.

Who can see your information

Access is restricted by role and enforced at the database level, not just in the app's screens:

  • You can always see your own application and its status.
  • Accounts Office and Head of Department reviewers at your ministry can see applications once submitted, never drafts.
  • A Super Admin can see all applications, for platform administration and account approval.
  • Your documents are never shared outside your ministry's review chain, and applicants never see the generated SAL 1 form.

Data storage and security

Data is stored with Supabase, encrypted in transit and at rest. Access to every table and uploaded document is governed by row-level security policies scoped to your account, role, and ministry, so a request that bypasses the app's UI is still restricted the same way. Passwords are never stored in plain text or visible to MinistryFlow staff.

How long we keep it

Application records and supporting documents are retained for as long as needed to administer your employment and payroll, and in line with the retention requirements of the ministry you applied to. If you believe your data should be reviewed or removed, contact us using the details below.

Your choices

You can update your display name and change your password at any time from the Settings tab in your dashboard. For any other correction, or a question about what data we hold about you, reach out via the Contact page.

Changes to this policy

We may update this policy as the platform evolves. Material changes will be reflected here with an updated date at the top of the page.

Contact

Questions about this policy or how your data is handled can be sent through the Contact page.