M-PennyM-PENNYEvery penny, empowered← Back

M-Penny CPA Non-Disclosure Agreement

Natcrest Holdings Company Ltd (trading as M-Penny) · Version 1.0 · Effective from 1 September 2026

This M-PENNY CPA REVIEWER NON-DISCLOSURE AGREEMENT is issued by Natcrest Holdings Company Ltd, trading as M-Penny, and takes effect on the Effective Date stated on the cover.

Important: The Reviewer becomes bound only through a clear affirmative electronic acceptance step. This NDA protects information; it does not itself authorise access to Customer Data or expand the scope of any Review.

1. About this NDA

1.1 This NDA is between Natcrest Holdings Company Ltd, trading as M-Penny (Natcrest), and the individual Reviewing CPA whose verified Portal account records affirmative acceptance (Reviewer).

1.2 It governs Confidential Information accessed, received, generated, observed or inferred through reviewer onboarding, the Portal, an Allocation Notice, an Accepted Allocation, Review Materials, communications, quality review, a complaint, an investigation or related compliance activity.

1.3 This NDA supplements and forms part of the Contract Documents. It applies only to the Reviewer's work through M-Penny and does not create a contract between the Reviewer and a Customer or Merchant, authorise the Reviewer to bind Natcrest or a Customer, or make the Reviewer Natcrest's employee, partner, agent or representative.

1.4 This NDA does not independently authorise access to Customer Data, create an audit, assurance, certification, tax-agent or statutory engagement, or expand an Accepted Allocation.

1.5 Nothing in this NDA transfers ownership of Customer Data, Natcrest intellectual property or Reviewer Work Product, or grants a general right to use, retain, copy or disclose Confidential Information.

2. Definitions

2.1 In this NDA, unless the context requires otherwise:

2.1.1 Accepted Allocation means an Allocation Notice that the Reviewer has affirmatively accepted through the Portal or another method recorded by Natcrest.

2.1.2 Allocation Notice means the electronic notice specifying the scope, Review Materials, deadline, fee, required Review Outcome and any special professional requirement for a proposed Review.

2.1.3 Confidential Information has the meaning in clause 4.

2.1.4 Contract Documents means this NDA, the M-Penny CPA Reviewer Policy (Policy), each Accepted Allocation, Schedule 1 to the Policy, any accepted written fee schedule and any other document expressly incorporated before acceptance.

2.1.5 Customer or Merchant means the business customer whose information or proposed tax treatment is the subject of a Review, consistently with the Policy and the M-Penny Terms of Service.

2.1.6 Customer Data means information, records, documents and personal data submitted to, generated in, transmitted through or made accessible to the M-Penny service by or for a Customer, excluding Natcrest's own system, usage and security data to the extent separately controlled by Natcrest.

2.1.7 Effective Date means the approved date stated on the cover.

2.1.8 M-Penny means the platform, Portal and trading identity operated by Natcrest and does not denote a separate legal person.

2.1.9 Natcrest means Natcrest Holdings Company Ltd, trading as M-Penny.

2.1.10 Portal means the CPA reviewer subsystem through which Natcrest onboards Reviewers, offers or allocates Reviews, provides Review Materials, receives Review Outcomes and maintains related records.

2.1.11 Review means the professional task described in an Accepted Allocation and the Policy. It includes return preparation and submission only for an authorised Review-and-Filing Allocation.

2.1.12 Review Materials means the records, snapshot, notes, computation, filing draft and other information made available for a Review.

2.1.13 Review Outcome means the Reviewer's recorded conclusion and supporting feedback, including a sufficient, insufficient or qualified outcome.

2.1.14 Reviewer or Reviewing CPA means the individual professional accepted by Natcrest to perform Reviews through the Portal and whose verified account records acceptance of this NDA.

2.1.15 Reviewer Work Product means the Review Outcome, reasons, clarifications and other original professional content created by the Reviewer for an Accepted Allocation.

2.1.16 Security Incident means an actual or suspected unauthorised access, disclosure, loss, copying, alteration, corruption, destruction, exfiltration, malware infection, credential compromise, misdirected communication, device loss, unauthorised AI or cloud upload, or other compromise affecting Confidential Information, Customer Data, Review Materials or the Portal.

2.1.17 personal data has the meaning given by applicable Kenyan data-protection law.

2.2 References to a law include amendments and successor provisions in force from time to time. Including and similar expressions do not limit the words preceding them.

3. Acceptance and legal effect

3.1 The Reviewer becomes bound only after a clear affirmative electronic-acceptance step, such as clicking or tapping an acceptance control that identifies or links this NDA, before Portal access or the first allocation.

3.2 Applying to become a Reviewer, receiving credentials, signing in, receiving an Allocation Notice or passively using the Portal without the clear acceptance step is not, by itself, acceptance.

3.3 Natcrest will preserve a reliable electronic record of the Reviewer’s verified identity, NDA version, date and time of each acceptance, affirmative action, Portal account, cumulative acceptance count and any material reacceptance.

3.4 Electronic acceptance and related records may be retained and used as evidence to the extent permitted by Kenyan law.

3.5 This NDA takes effect when the affirmative acceptance is recorded on or after the Effective Date. No physical signature, witness, attestation or separate execution page is required.

4. Confidential Information

4.1 Confidential Information means all non-public information disclosed, made available, observed, generated or accessed by the Reviewer through Natcrest or an allocation, in any form and whether or not marked confidential, including:

4.1.1 Customer and Merchant identities, Customer Data, account and user information, personal data and sensitive personal data;

4.1.2 tax records, KRA PINs and tax particulars, filing drafts, financial statements, transaction, payment, invoice, payroll and other financial or business records;

4.1.3 business plans, pricing, forecasts, operations, commercial information and professional communications;

4.1.4 Review Materials, Allocation Notices, allocation details, Review Outcomes, Reviewer Work Product, comments, clarifications and quality-review discussions;

4.1.5 fraud, misconduct, complaint, security, vulnerability and investigation information;

4.1.6 M-Penny software information exposed to the Reviewer, workflows, templates, logic, product plans, technical architecture, security measures and non-public Portal information;

4.1.7 access credentials, one-time passcodes, authentication devices, access links and security records;

4.1.8 Natcrest pricing, reviewer fees, internal controls and operational processes;

4.1.9 notes, extracts, screenshots, copies, summaries, analyses, compilations or derivatives that contain or reveal protected information; and

4.1.10 the existence and substance of non-public communications concerning a Customer, Merchant or allocation.

4.2 Information remains confidential where a reasonable professional would understand it to be confidential, including where it was disclosed orally, observed on screen, remembered rather than copied, contained in a derived document, combined with other information or disclosed without a confidentiality marking.

4.3 A non-public compilation, relationship, analysis, inference or context remains confidential even if individual elements are public. No residual-knowledge exception permits the Reviewer to use identifiable or derived Confidential Information merely because it is remembered.

5. Exclusions

5.1 Information is excluded from Confidential Information only to the extent the Reviewer demonstrates with reliable contemporaneous evidence that it:

5.1.1 was lawfully known to the Reviewer without restriction before disclosure;

5.1.2 became public through no breach of the Contract Documents or other duty;

5.1.3 was lawfully received from an independent third party without a duty of confidence;

5.1.4 was independently developed without access to or use of Confidential Information; or

5.1.5 must lawfully be disclosed under a binding legal, professional or regulatory obligation, subject to clauses 13 and 14.

5.2 An exclusion does not apply merely because individual parts are public where the non-public compilation, relationship, analysis or context remains confidential.

5.3 Information is not public merely because it was accessed through compromised credentials, unlawfully disclosed, posted to a restricted forum, circulated without authority, discoverable through prohibited scraping or reverse engineering, or disclosed in breach of another duty.

6. Permitted purpose

6.1 The Reviewer may use Confidential Information only to:

6.1.1 assess whether to accept an allocation, to the minimum extent needed;

6.1.2 perform an Accepted Allocation within its defined scope;

6.1.3 submit and clarify the Review Outcome and, for an authorised Review-and-Filing Allocation, the Customer-approved return through the approved KRA channel;

6.1.4 comply with a lawful professional obligation;

6.1.5 respond to a properly authorised quality review, complaint, investigation or audit; or

6.1.6 exercise or defend a legal right under the Contract Documents.

6.2 The Reviewer must not use Confidential Information for another client engagement, private benefit, competition with Natcrest, development of a competing product or service, marketing, profiling, identifiable benchmarking, unrelated research, commercial analytics, Customer solicitation, business-opportunity identification, case studies, teaching, presentations, social-media content, media commentary, personal record keeping beyond lawful necessity, or any purpose not expressly authorised.

6.3 The Reviewer may use general professional skills, experience and know-how that do not reveal, reproduce, depend upon or permit identification of Customer Data, Natcrest Confidential Information or another person's protected material. This clause grants no licence over identifiable, derived or memorised Confidential Information.

7. Confidentiality and access restrictions

7.1 The Reviewer must keep Confidential Information strictly confidential, protect it with at least reasonable care and the higher care appropriate to confidential tax, financial, security and personal data, and use it only for the permitted purpose.

7.2 Access is personal to the verified individual Reviewer and limited to the minimum information required for the relevant Accepted Allocation.

7.3 The Reviewer must not share Portal credentials; allow another person to view Review Materials; delegate a Review; use an assistant, employee, partner, firm, subcontractor or consultant; seek informal advice by disclosing protected information; or appoint a further subprocessor without Natcrest's prior specific written approval and satisfaction of every professional, confidentiality, security and data-protection condition.

7.4 Every approved person must be bound by written obligations at least as protective as the Contract Documents, receive only necessary access and cease access when the authorised need ends. The Reviewer remains responsible for that person's conduct to the extent provided by law and contract.

7.5 No disclosure is permitted merely because the recipient is another accountant, professional adviser, colleague, friend, relative or member of the Reviewer's firm.

8. Secure handling and Portal use

8.1 The Reviewer must maintain proportionate technical and organisational safeguards appropriate to the nature, sensitivity and volume of information involved.

8.2 At minimum, the Reviewer must:

8.2.1 use only the Reviewer's verified Portal credentials and protect passwords, one-time passcodes, authentication devices and access links;

8.2.2 use a secure, supported device, current protective software, device access controls and a private and reasonably secure connection;

8.2.3 prevent shoulder surfing and unauthorised viewing, avoid public or shared computers, and access only assigned allocations;

8.2.4 keep Review Materials within approved systems, preserve their integrity and avoid altering or deleting source records;

8.2.5 sign out after use and comply promptly with authorised credential resets, containment directions and security instructions; and

8.2.6 notify Natcrest immediately of suspected compromise and cooperate with a proportionate security investigation.

8.3 The Reviewer is responsible for activity authorised or caused by the Reviewer and for failure to use required safeguards, but is not absolutely liable for every action performed through valid credentials to the extent an event was caused or materially contributed to by Natcrest's security failure or unlawful conduct.

9. Prohibited copying, storage, disclosure and AI use

9.1 Unless technically necessary for an Accepted Allocation and expressly authorised by Natcrest, the Reviewer must not:

9.1.1 take screenshots, screen recordings or photographs; download, print, copy, scrape, bulk-extract, transcribe or locally archive Review Materials;

9.1.2 save information to a personal device or removable medium, forward it to personal email, transmit it through WhatsApp or another unapproved channel, or store it in a personal or unapproved cloud service;

9.1.3 upload information to a public generative-AI service, personal AI account, AI assistant, online summariser, transcription or translation service, document-conversion platform, unapproved cloud tool, model-training environment or other third-party processing tool; or

9.1.4 share Confidential Information with another person or retain it after the authorised purpose ends.

9.2 Any expressly permitted copy or download must be limited to the minimum necessary, protected by encryption or equivalent safeguards, stored only in the approved location, inaccessible to unauthorised persons, logged where required and securely deleted when the authorised purpose ends.

9.3 No Customer Data or Confidential Information may be used to train, fine-tune, test, evaluate or improve an AI or machine-learning model.

9.4 An ordinary offline professional tool is permitted only where it does not expose information to a third party and its use otherwise complies with the Contract Documents.

10. Customer Data and subprocessor obligations

10.1 Natcrest acts as controller for personal data used to manage reviewer onboarding, identity, professional verification, security, payment, compliance and the relationship. For Customer-controlled personal data supplied for an allocation, the Customer ordinarily acts as controller, Natcrest as processor and the Reviewer as Natcrest's authorised subprocessor.

10.2 The actual data-protection role follows the processing purpose and means, not merely a contractual label.

10.3 This NDA is not a substitute for the written processor-subprocessor particulars in Schedule 1 to the Policy and does not independently authorise Natcrest or the Reviewer to access or disclose Customer Data. Access may begin only after the applicable Customer-facing authorisation, notice and data-processing requirements have been satisfied.

10.4 The Reviewer must process Customer Data only on Natcrest's documented lawful instructions and for the Accepted Allocation, and must:

10.4.1 apply data minimisation and purpose limitation;

10.4.2 restrict access to the minimum necessary and prevent independent use;

10.4.3 maintain appropriate technical and organisational safeguards;

10.4.4 appoint no further processor and permit no cross-border transfer or remote access without Natcrest's prior specific written approval and every lawful safeguard;

10.4.5 reasonably assist with data-subject rights, lawful regulatory enquiries, data-protection impact assessments, incidents and audits;

10.4.6 return or securely delete Customer Data as directed;

10.4.7 preserve evidence concerning a Security Incident; and

10.4.8 continue protecting any information lawfully retained under clause 16.

10.5 The Reviewer must notify Natcrest promptly if an instruction appears to infringe applicable data-protection law and may pause the affected processing pending lawful clarification.

11. Security incidents and personal-data breaches

11.1 The Reviewer must notify Natcrest immediately after becoming aware of a Security Incident and, in every event, within twenty-four hours after awareness.

11.2 The initial report must provide the information then reasonably available, including:

11.2.1 when and how the incident was discovered;

11.2.2 the affected systems, allocations and information;

11.2.3 known or likely recipients or persons with access;

11.2.4 containment and mitigation steps already taken;

11.2.5 evidence preserved; and

11.2.6 further action proposed or required.

11.3 The Reviewer must provide continuing updates, contain and mitigate the incident, preserve evidence, follow lawful instructions and reasonably cooperate with investigation, remediation and notification.

11.4 The Reviewer must not conceal an incident, destroy evidence, contact affected Customers or data subjects independently, make a public statement, admit liability for Natcrest, or notify a regulator unless Natcrest authorises the step or law or a binding professional duty requires it.

11.5 A lawful mandatory report remains permitted. Where lawful and practicable, the Reviewer must coordinate with Natcrest in advance and limit the report to what is required.

11.6 Natcrest will assess and discharge applicable notice duties under law and Customer instructions. This NDA does not state that every Security Incident is notifiable to the ODPC or affected persons.

12. Customer and Merchant contact

12.1 The Reviewer must not use Confidential Information to identify, locate, contact or solicit a Customer or Merchant.

12.2 Unless Natcrest gives specific written approval for an allocation, the Reviewer must not:

12.2.1 communicate directly with a Customer using information obtained through M-Penny;

12.2.2 request information outside the approved workflow;

12.2.3 offer separate professional services, invoice the Customer or seek payment from the Customer;

12.2.4 represent themselves as the Customer’s accountant, auditor or tax agent, except solely as the Customer’s appointed tax agent within an authorised Review-and-Filing Allocation, or represent themselves as Natcrest’s employee, partner or representative; or

12.2.5 disclose the existence, materials or outcome of an allocation.

12.3 Any authorised direct communication must remain within scope, use the approved channel where practicable, be recorded and comply with professional, confidentiality and data-protection duties. Ordinary Customer communication remains routed through M-Penny.

12.4 The limited twelve-month non-circumvention restriction and its exceptions are governed only by the Policy. This NDA creates no second or inconsistent restraint.

13. Professional duties and lawful disclosure

13.1 The Reviewer must comply with applicable Kenyan law and binding professional requirements, including the Accountants Act, applicable regulations, current ICPAK requirements, the IESBA Code as adopted or recognised in Kenya, tax law and data-protection law.

13.2 Confidentiality is subject to any legal or professional right or duty to disclose, including a binding obligation concerning non-compliance with laws and regulations, professional misconduct, crime, fraud, tax evasion, public safety or regulatory cooperation.

13.3 Nothing in this NDA requires the Reviewer to conceal fraud or illegality, facilitate tax evasion, mislead a regulator, destroy evidence, breach NOCLAR or another binding professional obligation, continue an unlawful instruction, or waive a right to report misconduct to ICPAK, KRA, the ODPC, law enforcement or another competent authority.

13.4 A lawful disclosure must be limited to what is legally or professionally required, made through the proper channel, supported by verified authority, documented appropriately and preceded by notice to Natcrest where lawful and practicable.

13.5 Professional confidentiality does not authorise unnecessary disclosure or unauthorised Customer contact.

14. Compelled disclosure

14.1 If the Reviewer receives a court order, statutory notice, regulator request, summons or other demand concerning Confidential Information, the Reviewer must verify the demand and issuing authority and notify Natcrest promptly where lawful.

14.2 The Reviewer must preserve relevant information, reasonably cooperate in seeking clarification or confidentiality protection, disclose only the minimum legally required, use a secure disclosure method, maintain a record of what was disclosed and continue protecting all remaining information.

14.3 This clause does not obstruct an urgent or mandatory statutory or professional report.

15. Inadvertent access and protected material

15.1 The Reviewer must notify Natcrest immediately if the Reviewer receives information not intended for them, accesses another reviewer's allocation or an unassigned Customer record, receives information beyond the defined scope, or encounters material that appears subject to legal professional privilege or another protected status.

15.2 The Reviewer must stop further access, avoid copying, using or relying on the material, preserve it securely and follow Natcrest's lawful containment instructions.

15.3 Inadvertent disclosure does not, by itself, waive confidentiality, privilege or another protection to the extent recognised by law.

15.4 The Review and Review Outcome are not represented as legally privileged merely because this clause applies.

16. Return, deletion and limited retention

16.1 At the end of an allocation, on suspension or termination, or on Natcrest's lawful request, the Reviewer must stop using Confidential Information, return it where directed, securely delete authorised local copies, remove it from personal systems and unapproved locations, cease Portal access and confirm deletion in writing where reasonably requested.

16.2 The Reviewer may retain only the minimum information required by a binding legal or professional obligation, litigation hold or competent-authority direction.

16.3 Any lawfully retained information must, where lawful, be identified to Natcrest, isolated from active systems, access-restricted, protected under this NDA, used only for the binding retention purpose and securely deleted when that obligation ends.

16.4 Convenience, custom, personal record keeping or possible future usefulness does not justify retention.

16.5 Nothing requires deletion where deletion would breach binding law, a professional duty, litigation hold or competent-authority direction.

17. Ownership and limited rights

17.1 The Customer retains its lawful rights in Customer Data. Natcrest and its licensors retain their rights in M-Penny, the Portal, software, documentation, workflows, templates, branding and system-generated content.

17.2 No ownership of Confidential Information transfers to the Reviewer. The Reviewer receives only a limited, revocable, non-exclusive and non-transferable right to access necessary information for an Accepted Allocation.

17.3 Ownership and permitted use of Reviewer Work Product, and the Reviewer's rights in pre-existing methods, general know-how and unrelated materials, remain governed by the Policy.

17.4 This NDA does not state that Natcrest owns Customer or third-party information, transfer the Reviewer's entire professional knowledge, or create an unlimited licence over Customer Data.

18. Monitoring, investigation and compliance evidence

18.1 Natcrest may maintain proportionate acceptance, access, allocation, download or export, security, Review Outcome, incident and compliance records for legitimate service, legal, professional, security, fraud, data-protection and dispute purposes.

18.2 Natcrest may conduct a proportionate investigation or verification where there is a genuine confidentiality, security, professional or data-protection concern.

18.3 An audit or inspection must relate to the Reviewer's M-Penny obligations, be proportionate, protect unrelated client information, respect legal privilege and professional confidentiality, avoid unnecessary disruption and not authorise undisclosed surveillance for an unrelated purpose.

18.4 The Reviewer must provide information and reasonable cooperation necessary to demonstrate compliance, subject to the same safeguards.

19. Remedies

19.1 An actual or threatened breach may justify immediate restriction or suspension of Portal access, preservation measures, return or deletion directions, termination under the Policy, damages or another remedy available under law, and lawful reporting to a competent authority.

19.2 Either party may seek urgent interim or injunctive relief where the legal requirements are met. No clause is a conclusive admission that every breach causes irreparable harm or that damages are always inadequate.

19.3 The liability, indemnity, causation, mitigation, cap and claims provisions in the Policy govern. This NDA creates no automatic penalty, unlimited indemnity, invented liquidated damages or double recovery.

19.4 Accrued and undisputed fees for conforming work are not automatically forfeited because access is restricted or the relationship ends. Any withholding, set-off, indemnity or damages claim remains subject to the Policy, fair procedure and applicable law.

19.5 Nothing limits a liability, statutory right or remedy that cannot lawfully be limited.

20. Duration and survival

20.1 This NDA applies from affirmative acceptance and continues throughout the Reviewer relationship.

20.2 Confidentiality, restricted-use, security, return, deletion and related obligations survive termination for as long as the information remains confidential; for as long as Customer Data or personal data remains retained or accessible; and for every statutory or professional protection period applicable to the information.

20.3 Trade secrets remain protected indefinitely while they qualify for legal protection. A longer period applies where required by law, professional duty, legal hold or competent-authority direction.

20.4 Information ceases to be protected only through an express exclusion in clause 5, not merely through passage of time.

21. Contract document precedence

21.1 This NDA forms part of the Contract Documents defined in the Policy.

21.2 If Contract Documents conflict, mandatory law prevails, followed by: the Accepted Allocation for its specific scope, fee and deadline; Schedule 1 to the Policy for Customer-controlled personal-data processing; the Policy for the overall reviewer relationship; an accepted fee schedule for applicable fee particulars; and this NDA for its focused confidentiality and secure-handling subject matter.

21.3 For confidentiality only, the more protective obligation in the Policy or this NDA applies to the extent it operates consistently with mandatory law and Schedule 1.

21.4 This NDA does not expand the Reviewer's professional scope, authorise Customer Data access, override Customer rights, create tax-agent authority, weaken data-protection duties or override an Accepted Allocation's defined scope.

22. Complaints and disputes

22.1 A complaint concerning this NDA should be submitted in writing through the contact in clause 26 and should identify the Reviewer, relevant allocation, issue, supporting information and outcome sought without including unnecessary Customer Data.

22.2 Each party should preserve relevant evidence, communicate professionally and provide a fair opportunity to respond where urgency does not require immediate protective action.

22.3 If the ordinary process does not resolve the matter, either party may request good-faith escalation to an authorised representative. The parties will attempt resolution for thirty days after written escalation unless urgency or mandatory law requires earlier action.

22.4 If unresolved, either party may refer the dispute to a court or tribunal of competent jurisdiction in Kenya. Small Claims Court jurisdiction is preserved where applicable, as are urgent interim relief and statutory complaint, disciplinary or enforcement routes through ICPAK, KRA, the ODPC, law enforcement and other competent bodies.

22.5 A person is not required to exhaust Natcrest's internal process before using an urgent or mandatory statutory route.

23. Governing law

23.1 This NDA and every non-contractual obligation arising from it are governed by the laws of the Republic of Kenya.

23.2 Subject to clause 22, courts and tribunals of competent jurisdiction in Kenya may determine disputes. The parties do not agree to mandatory arbitration through this NDA.

24. Changes to this NDA

24.1 Natcrest may update this NDA prospectively for legal, regulatory, professional, security, operational or product reasons. The current version number and effective date will appear on the cover.

24.2 Natcrest will give clear notice of a materially adverse change where practicable or legally required and will require fresh affirmative acceptance where a change materially affects the definition of Confidential Information, permitted use, data use, security duties, liability exposure, survival, disclosure rights, dispute rights or professional obligations.

24.3 Continued Portal access does not by itself amount to blanket consent to an unexpected material change.

24.4 An Accepted Allocation ordinarily remains governed by the NDA version accepted for that allocation unless law requires otherwise or the parties expressly agree to the change.

24.5 Natcrest may make an urgent change required by law, a regulator or a serious security risk with shorter notice, but will explain the change, obtain reacceptance where required, and retain earlier versions and acceptance records for accountability and disputes.

25. General provisions

25.1 Notices. Natcrest may send operational notices to the Reviewer's verified email address or Portal account. A legal notice to Natcrest must be sent to support@mpenny.ke. A failed delivery notice means receipt has not occurred.

25.2 Assignment. The Reviewer may not assign, transfer or delegate this NDA or Portal access without Natcrest's prior written approval. Natcrest may assign this NDA as part of a genuine restructuring, financing, merger or sale of M-Penny only if the successor assumes Natcrest's applicable obligations and the Reviewer's material rights are not reduced.

25.3 No delegation. Professional eligibility, NDA acceptance and Portal access are personal. Approval of another person is governed by clauses 7 and 10 and does not release the Reviewer from responsibility to the extent provided by law and contract.

25.4 Entire agreement. The Contract Documents are the entire agreement on the reviewer relationship and replace earlier discussions on that subject. Clause 21 determines precedence. Nothing excludes fraud or a written representation on which a party reasonably relied.

25.5 No waiver. A failure or delay to exercise a right is not a waiver. A waiver must be clear and applies only to the specific circumstance for which it is given.

25.6 Severability. If a provision is invalid or unenforceable, it will be limited or removed only to the minimum extent necessary and the remainder will continue. Its lawful commercial purpose should be preserved where possible.

25.7 Third-party rights. A person who is not a party has no contractual right to enforce this NDA. This does not limit a Customer's, data subject's or regulator's independent statutory rights.

25.8 Language and interpretation. The English version controls unless Natcrest expressly states otherwise. Headings assist navigation and do not limit meaning.

25.9 Electronic records and mandatory law. Reliable electronic records may be retained and used as evidence as permitted by law. Nothing in this NDA overrides mandatory law.

26. Contact information

26.1 Natcrest Holdings Company Ltd (trading as M-Penny), Company Registration No. PVT‑ZE186LV6, Pride House, Kitengela, Kajiado County, Kenya; P.O. Box 817-00242, Kitengela, Kenya; email: support@mpenny.ke.

26.2 A communication should identify the Reviewer, relevant allocation and request without including passwords, PINs, one-time passcodes or unnecessary Customer Data.

Natcrest Holdings Company Ltd (trading as M-Penny) · Nairobi, Kenya · support@mpenny.ke