Privacy Policy

Last Updated: January 2025

Your Privacy Matters: This Privacy Policy explains how we collect, use, protect, and share your personal information in compliance with the Kenya Data Protection Act, 2019.

1. Introduction

Welcome to our Point of Sale (POS) System. We are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy describes:

2. Data Controller Information

Data Controller: [Your Company Name]

Registration Number: [Your Business Registration Number]

Physical Address: [Your Business Address], Nairobi, Kenya

Email: privacy@yourcompany.co.ke

Phone: +254 XXX XXX XXX

Data Protection Officer: [DPO Name if applicable]

3. Information We Collect

3.1 Account Information

When you register for an account, we collect:

3.2 Transaction Data

During business operations, we collect:

3.3 Customer Information

We automatically collect customer data when M-Pesa payments are processed:

Note: Customer phone numbers are collected automatically from M-Pesa transactions to build customer profiles and purchase history.

3.4 Technical Information

We automatically collect:

4. How We Use Your Information

4.1 Primary Purposes

We use collected information to:

4.2 Communication

We may use your contact information to:

4.3 Legal Compliance

We may use your data to:

5. Legal Basis for Processing (Kenya Data Protection Act, 2019)

Processing Activity Legal Basis
Account creation and management Contract performance
Transaction processing Contract performance
Customer data collection (M-Pesa) Legitimate business interest
Analytics and reporting Legitimate business interest
Marketing communications Consent
Legal compliance Legal obligation

6. Data Sharing and Disclosure

6.1 Third-Party Service Providers

We may share your data with:

6.2 Legal Requirements

We may disclose your information if required by:

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new entity.

No Selling of Data: We do not sell your personal data to third parties for marketing purposes.

7. Data Security

7.1 Security Measures

We implement industry-standard security measures including:

7.2 M-Pesa Security

7.3 Your Responsibility

You must:

8. Data Retention

8.1 Retention Periods

Data Type Retention Period
Account information Duration of active account + 1 year
Transaction records 7 years (tax compliance)
Customer data 5 years from last transaction
Audit logs 3 years
Marketing data Until consent withdrawn

8.2 Deletion

After retention periods expire, data is securely deleted or anonymized unless legal obligations require longer retention.

9. Your Rights Under Kenya Data Protection Act, 2019

9.1 Right to Access

You have the right to request:

9.2 Right to Rectification

You can request correction of inaccurate or incomplete data.

9.3 Right to Erasure

You can request deletion of your data when:

9.4 Right to Restrict Processing

You can request limitation of data processing in certain circumstances.

9.5 Right to Data Portability

You can request your data in a machine-readable format for transfer to another service provider.

9.6 Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes.

9.7 Right to Withdraw Consent

Where processing is based on consent, you can withdraw consent at any time.

Exercising Your Rights: Contact us at privacy@yourcompany.co.ke to exercise any of these rights. We will respond within 30 days.

10. Customer Data and Consent

10.1 Customer Privacy

As a merchant using our system: