This is the partner-facing terms-of-service for integrating with the DiGii Sente Payment Gateway. By checking the agreement box on signup, you accept the terms below. Have your legal team review before going to production. Contact developers@digiisente.com for any clause you need adjusted in a bespoke partner contract.
1. Parties and acceptance
This Agreement is between K2 Telecom Ltd, the operator of DiGii Sente (“DiGii”, “we”, “us”) and the business that signed up for a developer-portal account (“Partner”, “you”). By checking the agreement box on signup, the Partner's authorised representative confirms they have authority to bind the Partner business to these terms.
2. What the Gateway is
A REST API that lets the Partner request, refund, and query payments on Uganda's DiGii Sente wallet rail and partnered mobile-money rails (MTN MoMo, Airtel Money). The API exposes the endpoints documented at /docs. DiGii may add, deprecate, or change endpoints on 30 days notice via email to the Partner's registered contact address.
3. Sandbox vs Production
- Sandbox keys are issued automatically upon admin approval after signup. Sandbox calls do not move real money and use a dedicated test float. Sandbox transactions may be reset by DiGii at any time without notice.
- Production (LIVE) keys are issued only after the Partner passes the production checklist in the developer portal, signs any required commercial addendum, and DiGii has completed its own KYC review.
4. Security obligations
- Treat secret keys (
sk_test_…,sk_live_…) as bearer credentials. Never embed in mobile apps, browser code, public repos, or chat. Rotate immediately if exposed via the /dashboard/keys screen. - Verify HMAC signatures on every webhook delivery using your endpoint secret. Reject payloads with timestamps older than 5 minutes (replay protection).
- Maintain a current IP allowlist on your LIVE keys. We will not deliver requests from IPs outside the list.
- Enable 2FA on the Partner's dashboard account before requesting LIVE access. Required for every dashboard user that can see secret keys.
5. Data handling
- DiGii will collect, store, and process customer phone numbers, transaction references, amounts, and (where the rail provides them) customer names solely to execute payment requests submitted by the Partner.
- The Partner is responsible for collecting the customer's consent to share their phone number with DiGii for the purpose of payment processing.
- Both parties operate in accordance with the Uganda Data Protection and Privacy Act, 2019. Cross-border processing is limited to AWS infrastructure within Africa (af-south-1).
6. Fees and settlement
- Per-transaction fees are quoted at the time of integration and confirmed in a written commercial addendum before LIVE keys are issued.
- Sandbox use is free of charge.
- Settlement to the Partner's DiGii wallet (or bank, where configured) happens same business day for wallet-rail transactions and within 24 hours for MoMo-rail transactions.
- DiGii may withhold settlement for transactions flagged for fraud review until the review completes (typically 48 hours).
7. Rate limits and abuse
The default sandbox + production rate limit is 60 requests per minute per partner. High-volume partners may request a higher cap via the dashboard. DiGii may temporarily throttle or suspend keys that generate sustained error rates above 50% or that show patterns indicative of fraud, brute-force, or abuse.
8. Webhooks
The Partner must respond to webhook deliveries with HTTP 2xx within 10 seconds. Failures are retried with exponential backoff over a 7-day window. After 7 days of failed delivery, the event is moved to the failed-events table and is not retried automatically. The Partner may manually retry any failed delivery from the dashboard.
9. Suspension and termination
- Either party may terminate this Agreement on 30 days written notice.
- DiGii may suspend Partner access immediately, without notice, if (a) the Partner breaches Section 4 (security), (b) the Partner is suspected of fraud, money laundering, or terrorist financing, or (c) Bank of Uganda or a court directs the suspension. DiGii will inform the Partner of the reason as soon as the suspension is legally permissible to disclose.
- On termination, the Partner's keys are revoked. The Partner retains the right to settlement of any completed transactions and to access historical transaction data for 6 months.
10. Liability
Neither party is liable for indirect, incidental, or consequential damages. DiGii's aggregate liability for any claim arising from this Agreement is capped at the fees paid by the Partner in the 12 months preceding the claim. The Partner indemnifies DiGii against third-party claims arising from the Partner's misuse of the API, breach of security obligations, or failure to obtain customer consent.
11. Bank of Uganda compliance
DiGii operates under Bank of Uganda's electronic-payments framework. The Partner acknowledges that DiGii may share Partner transaction data with Bank of Uganda or other regulators as required by Ugandan law, including under the Anti-Money Laundering Act, 2013 and the Financial Institutions Act, 2004.
12. Governing law and disputes
This Agreement is governed by the laws of the Republic of Uganda. Disputes are resolved first by good-faith negotiation, then by mediation in Kampala, and finally by the courts of Uganda.
13. Updates to this Agreement
DiGii may revise this Agreement and will notify the Partner via the registered contact email at least 30 days before any material change takes effect. Continued use of the API after the effective date constitutes acceptance.
14. Contact
For any question about this Agreement: developers@digiisente.com.
K2 Telecom Ltd, Kampala, Uganda. DiGii Sente Developer Portal.