Privacy Policy – Komiti App
Last Updated: 09 September 2025
Overview
Komiti is a mobile chit-fund platform available on iOS and Android (Play Store). The app facilitates contributors and organizers to manage group savings and rotations, with support for JazzCash and Easypaisa wallets as payment methods.
Komiti operates under the jurisdiction of the Constitution of the Islamic Republic of Pakistan, 1973 and is further subject to the Prevention of Electronic Crimes Act, 2016 (PECA) and other applicable financial regulations. Participation is limited to individuals aged 18 years or above.
Data Collection
Data collected includes:
- Wallet Information (Payment Methods): JazzCash and Easypaisa details for contributions and payouts.
- Identity & Contact: Name, email, phone number.
- KYC Documentation: CNIC/ID card, passport, or driving license, plus a selfie.
- Additional Documents: Utility bill and bank statement, when required for disbursements.
Data Use
Collected information is used for:
- Managing chit-fund activities (creation, payments, contribution tracking).
- Identity verification and regulatory compliance.
- Processing payments via JazzCash/Easypaisa.
- Sending OTPs, service alerts, marketing notifications, and updates.
Data Storage & Security
All user data is stored in encrypted databases managed by RYT (parent company) with access controls, monitoring, and audits to ensure protection against unauthorized access.
Data Sharing
User data is not shared with marketing or third-party advertisers. However, disclosure may occur:
- To regulatory authorities under Pakistani law.
- In the event of legal disputes, investigations, or as required by courts.
- Specifically, to comply with the Anti-Money Laundering Act, 2010 and SBP/SECP AML-CFT Regulations.
Retention & Deletion
- General Data: On account deletion request, reviewed within 7 business days, data is retained for 30 days before permanent deletion.
- KYC Data: Retained for a minimum of 5 years under the Anti-Money Laundering Act, 2010 and AML/CFT regulations.
- Inactive Accounts: Data is retained securely for 90 days before deletion.
User Rights
- Credentials (username, password) can be updated via OTP verification.
- Data access or deletion requests can be submitted via support.
- KYC data deletion is subject to legal retention requirements and cannot be removed before the mandatory 5-year period.