M-PennyM-PENNYEvery penny, empowered TERMS OF SERVICE →
Legal

Privacy Policy

Effective from 1 September 2026 · Version 1.0 · Data Protection Act, 2019 (Kenya)

This M-PENNY PRIVACY POLICY (Policy) explains how Natcrest Holdings Company Ltd, trading as M-Penny, handles personal data in connection with the M-Penny Service.

Important: This Policy is a transparency notice. It is not blanket consent to every use of personal data and does not replace the data-processing terms required where Natcrest processes personal data on a Customer's instructions.

Contents

  1. About this Privacy Policy
  2. Who we are
  3. Scope of the Policy
  4. Our roles as controller and processor
  5. Personal data we process
  6. How we obtain personal data
  7. Why we process personal data and our lawful bases
  8. Customer controlled personal data
  9. M-Pesa, eTIMS and other integrations
  10. AI-assisted processing and automated decisions
  11. Communications and direct marketing
  12. Cookies and similar technologies
  13. How we share personal data
  14. International transfers
  15. Retention, Account closure and deletion
  16. Security and personal-data breaches
  17. Data-subject rights
  18. Children's personal data
  19. Privacy complaints
  20. Changes to this Policy
  21. Contact information

1.About this Privacy Policy

1.1 This Policy explains what personal data Natcrest collects or receives, where it comes from, why and on what lawful basis it is processed, who it may be shared with, how long it may be retained, the safeguards applied, and the rights available to data subjects.

1.2 It applies to identifiable natural persons whose personal data is processed through M-Penny, including prospective and current Customers, sole proprietors, directors, owners, authorised representatives, Authorised Users, support contacts, website or application users, and persons whose information is included in Customer Data.

1.3 This Policy covers the M-Penny website, applications, Accounts, support channels, communications and related services made available by Natcrest (Service). It does not apply to information that does not identify or relate to an identifiable natural person, including properly anonymised information.

1.4 A third-party service connected to M-Penny may process personal data for its own purposes under its own privacy notice. Where a materially different or regulated feature is introduced, Natcrest or the relevant provider will give any additional privacy notice, disclosures, lawful-basis information and consent request required before the new processing begins.

1.5 Receiving, reading or acknowledging this Policy does not by itself amount to consent. Where consent is the proper lawful basis, Natcrest will request it through a separate, specific and affirmative choice.

2.Who we are

2.1 The operator of M-Penny is Natcrest Holdings Company Ltd, a private company incorporated in Kenya under Company Registration No. PVT-ZE186LV6 and trading as M-Penny (Natcrest, we, us or our).

2.2 Natcrest's physical address is Pride House, Kitengela, Kajiado County, Kenya, and its postal address is P.O. Box 817-00242, Kitengela, Kenya.

2.3 In this Policy, Customer has the meaning given in the M-Penny Terms of Service; Authorised User means an individual permitted by a Customer to use its Account; Customer Data means information, records, documents and personal data submitted to, generated in, transmitted through or made accessible to the Service by or for a Customer; and data subject means the identifiable individual to whom personal data relates.

2.4 The verified privacy and support contact for Natcrest is stated in clause 21. Nothing in this Policy designates that contact or any other individual as Natcrest's statutory Data Protection Officer.

3.Scope of the Policy

3.1 This Policy applies where Natcrest determines why and how personal data is processed as a controller and where Natcrest processes personal data on a Customer's documented instructions as a processor. The role depends on the actual processing activity, not merely the label used by a party.

3.2 The Service is presently an accounting-first business platform for Kenyan micro, small and medium enterprises. Current or contemplated functionality may support Account administration, bookkeeping, invoicing, expense, sales, stock and financial-record management, M-Pesa-oriented reconciliation, tax and eTIMS readiness, business reporting, customer support, identity and business verification, and AI-assisted insights.

3.3 Direct eTIMS transmission, production M-Pesa payment functionality, automated collection or splitting of Customer money, credit disbursement, affordability or creditworthiness assessment, CRB access or reporting, micropayment billing, SMS functionality and other regulated financial features are not treated by this Policy as live merely because they appear in a demonstration, test environment or roadmap.

3.4 This Policy does not represent that Natcrest holds a banking, lending, non-deposit-taking credit, digital-credit, payment-service, e-money, remittance, custody or other financial-services licence, or that M-Penny currently provides a regulated financial service.

4.Our roles as controller and processor

4.1 Natcrest acts as a controller where it determines the purpose and essential means of processing. Depending on the interaction, these controller activities may include:

4.1.1 prospective-customer enquiries, Account registration, Customer and Authorised User administration, contracting, subscription and billing administration;

4.1.2 Service security, authentication, access records, fraud prevention, identity and business verification, compliance and risk management;

4.1.3 customer support, complaints, service communications, lawful direct marketing for Natcrest's own services, Service performance analysis and improvement; and

4.1.4 compliance with legal duties and the establishment, exercise or defence of legal claims.

4.2 Natcrest acts as a processor where a Customer uploads, imports or connects personal data about its customers, employees, contractors, suppliers or other counterparties and instructs Natcrest to process that information through M-Penny for the Customer's business purposes.

4.3 For Customer-controlled processing, the Customer ordinarily determines the purpose of processing and remains responsible for its privacy notices, lawful basis, data accuracy and documented instructions. Natcrest will process the personal data only on documented lawful instructions, including the applicable Contract Documents, unless Kenyan law requires otherwise.

4.4 Applicable data-processing terms will supplement the M-Penny Terms of Service and address the processing subject matter, duration, nature and purpose; personal-data and data-subject categories; confidentiality; security; subprocessors; assistance; incidents; audits; and return or deletion. This public Policy is not a substitute for those terms.

4.5 Natcrest will not use identifiable Customer-controlled third-party personal data for independent advertising, unrelated profiling, sale or rent, or to train a third-party general-purpose AI model, unless a new use is lawfully authorised, transparently disclosed and supported by every additional safeguard required by law.

5.Personal data we process

5.1 The personal data processed depends on the person's relationship with Natcrest, the features used, the information supplied by the Customer and the permissions granted. It may include:

5.1.1 identity and contact information, such as name, telephone number, email address, business address and role;

5.1.2 Account, authentication and security information, such as username, password hash, one-time authentication records, permissions, access history and security events;

5.1.3 business-registration, ownership, beneficial-ownership, authorised-representative and verification information, which may include identification-document particulars where proportionate and lawfully required;

5.1.4 KRA PIN, tax identifiers, invoices, receipts, sales, expenses, stock, bookkeeping, payroll inputs, tax-related records and other financial or business records submitted or generated through the Service;

5.1.5 transaction references and reconciliation information manually entered, imported or received through an activated connection authorised by the Customer;

5.1.6 personal data about the Customer's customers, suppliers, employees, contractors and other counterparties contained in Customer Data;

5.1.7 plan, subscription, payment-status and billing information, but not a Customer's M-Pesa PIN or full payment-card credentials;

5.1.8 device, browser, Internet Protocol address, log, diagnostic, security and Service-usage information;

5.1.9 support enquiries, complaints, correspondence, call or message records, and marketing preferences;

5.1.10 connected-account permissions, integration settings and technical metadata;

5.1.11 fraud, verification, sanctions, compliance and risk information where proportionate to the Service and lawfully obtained; and

5.1.12 inputs provided to an enabled AI-assisted feature, the resulting summaries, classifications, forecasts or insights, and limited technical records needed to operate and secure the feature.

5.2 A business or financial record is not automatically sensitive personal data. Natcrest applies the statutory definition and treats information as sensitive personal data only where it falls within a protected category under applicable law.

5.3 M-Penny is not designed for the routine collection of biometric, health, genetic, precise-location or children's personal data. A Customer must not upload high-risk or sensitive information unless the relevant feature is intended for it, the collection is necessary and proportionate, and every required lawful basis, additional condition and safeguard is in place.

5.4 Pseudonymised information remains personal data if it can reasonably be reconnected to a person. Information is treated as anonymised only where a person is not and cannot reasonably be identified from it, alone or together with other reasonably available information.

6.How we obtain personal data

6.1 Natcrest may obtain personal data:

6.1.1 directly from the data subject, including through registration, verification, subscription, support, complaints, communications and optional choices;

6.1.2 from a Customer, Authorised User or another person acting with lawful authority;

6.1.3 from a connected third-party service that the Customer has authorised and that is technically available;

6.1.4 from payment, authentication, communications, hosting or support providers to the extent needed for the relevant service;

6.1.5 from public registries or other reliable verification sources where the check is necessary, proportionate and lawful; and

6.1.6 automatically from use of the Service through logs, essential cookies, local storage and similar technical records.

6.2 Natcrest does not claim routine access to Safaricom, KRA, CRB, bank or government databases merely because a future connection is contemplated. Information is obtained through such a channel only if the connection is operational, lawful and authorised for the relevant use.

6.3 Where Natcrest obtains personal data indirectly for its own controller purposes, it will provide the required information within the applicable period unless the individual already has it or another lawful exception applies. Where the Customer is controller, the Customer remains responsible for providing the applicable notice and Natcrest will assist as required by law and the data-processing terms.

7.Why we process personal data and our lawful bases

7.1 Natcrest identifies a lawful basis before processing personal data and uses the information only for specified, explicit and legitimate purposes. The basis depends on the processing activity.

7.2 Natcrest may process personal data because it is necessary to take steps requested before entering a contract or to perform the contract, including to create and administer an Account, provide enabled Service functions, authenticate users, provide support, administer a subscription and deliver necessary service communications.

7.3 Natcrest may process personal data to comply with a legal obligation, including applicable company, tax, accounting, consumer, data-protection, court-order and regulatory requirements.

7.4 Natcrest may rely on a legitimate interest where the processing is necessary and proportionate and the interest is not overridden by the person's rights and freedoms. Such interests may include securing the Service, preventing fraud, managing operational risk, maintaining and improving functionality, handling complaints, keeping appropriate business records and establishing or defending legal claims. Natcrest will document the required assessment where appropriate.

7.5 Natcrest relies on consent where the law requires a voluntary, specific, informed and unambiguous choice, including for Natcrest's direct marketing and any optional processing that cannot properly rely on another basis. Consent may be withdrawn using the method provided, without affecting processing lawfully completed before withdrawal.

7.6 Where sensitive personal data is processed, Natcrest will identify both a lawful basis and the additional statutory condition required for that category and will apply enhanced safeguards. Natcrest will not use legitimate interests as a universal fallback.

7.7 Natcrest may process and retain personal data where necessary for the establishment, exercise or defence of a legal claim or another purpose expressly permitted by applicable law.

7.8 Where Natcrest acts as processor, the Customer determines and documents the lawful basis for the Customer-controlled processing. Natcrest's basis for carrying out the processing is the Customer's lawful documented instruction and the applicable controller-processor arrangement; this does not relieve either party of its own statutory obligations.

8.Customer controlled personal data

8.1 A Customer that submits or connects personal data about another person must:

8.1.1 have lawful authority to collect, use and disclose the information to Natcrest and to give each instruction;

8.1.2 provide every required privacy notice and identify and document an appropriate lawful basis;

8.1.3 collect and submit only information that is relevant, adequate and not excessive for the intended purpose;

8.1.4 take reasonable steps to keep the information accurate and current;

8.1.5 avoid uploading sensitive, children's or other high-risk personal data unless necessary, lawful and supported by appropriate safeguards; and

8.1.6 respond to data-subject requests and comply with its obligations as controller.

8.2 A person whose data was supplied by an M-Penny Customer may first need to contact that Customer because the Customer controls the purpose and context. Natcrest will not use that distinction as a blanket reason to reject a request. It will verify authority, route the request to the relevant Customer and provide reasonable assistance where required.

8.3 Natcrest will not disclose Customer controlled information directly to a requester unless the requester's identity and authority have been appropriately verified and disclosure is authorised by the Customer or required by law.

8.4 Natcrest may refuse or suspend an instruction that appears unlawful, materially incomplete or inconsistent with the Contract Documents. Where Natcrest believes an instruction infringes applicable data-protection law, it will inform the Customer unless the law prohibits that notice.

9.M-Pesa, eTIMS and other integrations

9.1 An integration operates only when technically available, lawfully activated and authorised by the Customer. The Customer may need to grant separate permissions and accept the connected provider's terms and privacy notice.

9.2 For M-Pesa-oriented reconciliation, information may be manually entered by the Customer or, once an authorised production connection is available, imported or received through that connection. The information exchanged depends on the permissions granted. This reconciliation function does not mean Natcrest holds, controls or has unrestricted access to a Customer's M-Pesa account or funds.

9.3 M-Penny may organise tax-related records and support eTIMS readiness. Unless and until a live, authorised system integration is activated, M-Penny does not itself submit invoices, returns or filings directly to KRA. If a Customer activates the separate ‘File with M-Penny’ workflow, necessary Customer Data may be disclosed to the specifically appointed and verified CPA for review and filing under the Customer’s recorded authority, applicable processor or professional safeguards, and the product-specific notice. A filing made by that CPA as tax agent is not represented as direct filing by Natcrest.

9.4 A connected provider may be an independent controller for processing it determines, such as account security, regulatory compliance or operation of its own service. Natcrest remains responsible for its own configuration, disclosures, processor management and non-delegable legal duties.

9.5 A Customer may withdraw or disconnect an integration using the available controls or by contacting Natcrest. Disconnection may stop dependent functions and does not require deletion of information that Natcrest or the connected provider must lawfully retain.

10.AI-assisted processing and automated decisions

10.1 Where an AI-assisted feature is enabled, M-Penny may use relevant Customer Data to produce summaries, classifications, forecasts, alerts or business insights requested through the Service. Natcrest will apply data minimisation and will not send more personal data to an AI provider than is reasonably necessary for the enabled task.

10.2 AI-assisted outputs may be incomplete, inaccurate or unsuitable for a person's circumstances. They are informational tools and must be reviewed by a competent person before being used for a material accounting, tax, employment, financing, legal or business decision.

10.3 If an external AI provider is used, including optional Anthropic processing hosted in the United States where that feature is enabled, Natcrest will require confidentiality, security, retention and use controls appropriate to the risk. Natcrest will apply data minimisation and will not send identifiable or sensitive Customer-controlled personal data to an external AI provider unless the enabled purpose requires it and every applicable lawful basis, Customer authority, transfer safeguard and security control is in place. Natcrest will not permit such data to be used to train a third-party general-purpose AI model unless that use is separately and lawfully disclosed and authorised.

10.4 M-Penny does not currently make a decision based solely on automated processing that produces a legal or similarly significant effect on a person. A score, limit, forecast, projection or eligibility indication displayed in a demonstration, test or roadmap is not a credit decision, approval or offer.

10.5 Before significant automated decision-making is introduced, Natcrest will complete the required risk and impact assessment and provide meaningful information about the processing, its significance and likely consequences, together with the right to human intervention, to express a view and to challenge the decision where applicable.

11.Communications and direct marketing

11.1 Natcrest may send transactional, security, compliance, billing and support communications that are necessary to provide the Service, protect an Account, respond to a request or comply with law. These are not treated as direct marketing merely because they identify Natcrest or the Service.

11.2 Natcrest will send direct marketing for its own services only where it has obtained the express consent required by Kenyan law. A marketing message will identify its promotional nature and provide a clear, accessible and effective opt-out that does not impose a charge beyond the ordinary cost of using the channel.

11.3 A person may withdraw marketing consent or object to direct marketing at any time. Natcrest will stop the affected marketing and may retain a minimal suppression record to respect the opt-out. Opting out does not stop necessary contractual, security, billing, support or legal communications.

11.4 Natcrest will not use contacts contained in Customer-controlled data for its own marketing. If a referral or partner programme is later launched, its use of personal data will be governed by separately approved programme terms and any additional privacy notice or consent required.

12.Cookies and similar technologies

12.1 The M-Penny website or application may use cookies, local storage, session identifiers and similar technologies that are necessary to authenticate users, maintain security, remember essential settings and operate the Service.

12.2 Natcrest will not place or activate optional analytics, advertising or marketing technologies before obtaining any consent required by law. If such technologies are introduced, the Cookie Policy and available preference controls will identify their purpose, duration and relevant provider.

12.3 Blocking strictly necessary technologies may prevent an Account or feature from functioning. Browser or device controls may be used for other technologies, but those controls do not replace a consent mechanism where the law requires one.

13.How we share personal data

13.1 Natcrest shares personal data only where necessary for the Service, a lawful Customer instruction, a legal obligation, a legitimate corporate transaction or another disclosed and lawful purpose. Recipients may include:

13.1.1 the Customer and its properly authorised users and representatives;

13.1.2 hosting, database, infrastructure, security, authentication, communications, support, analytics and software providers acting under appropriate contractual controls;

13.1.3 payment, billing, identity-verification, M-Pesa, eTIMS or other integration providers, but only where the relevant connection or function is activated and authorised;

13.1.4 AI-service providers for an enabled feature, subject to the restrictions in clause 10;

13.1.5 professional advisers, auditors and insurers who have a need to know and appropriate confidentiality duties;

13.1.6 courts, regulators, law-enforcement bodies, tax authorities and other competent authorities where disclosure is required or lawfully permitted; and

13.1.7 a genuine prospective or completed financier, investor, purchaser, successor or reorganisation party, subject to confidentiality, due diligence limits and appropriate protection of affected persons.

13.2 Natcrest does not sell or rent personal data. It does not disclose personal data merely because disclosure is commercially convenient.

13.3 A service provider may process personal data only for the contracted purpose or another lawful purpose for which it independently assumes responsibility. Natcrest will use subprocessors under written data-protection obligations and will remain responsible to the extent required by law and the Contract Documents.

14.International transfers

14.1 M-Penny uses cloud-based services, and some personal data is or may be stored, accessed or otherwise processed outside Kenya. This may involve hosting, database, email, authentication, security, rate-limiting, support or AI services, depending on the production configuration and enabled features.

14.2 Before transferring personal data outside Kenya, Natcrest will identify a lawful transfer basis and implement the safeguards required by Kenyan law. Depending on the transfer, these may include a jurisdiction with commensurate protection, binding contractual safeguards, another legally recognised mechanism or a specific statutory exception.

14.3 Natcrest will not rely on blanket consent as the sole routine mechanism where another lawful transfer basis and safeguard is required. Sensitive personal data will receive the additional protection prescribed by law.

14.4 A person may request information about the material transfer safeguards that apply, subject to protection of confidential and security-sensitive information.

14.5 The primary production database is hosted in South Africa. Depending on the enabled production configuration, managed services may also process limited personal data in other provider regions through Vercel (application hosting and delivery), Upstash (delivery and cache), Resend (transactional email), Zoho Mail (business email) and optional Anthropic AI processing in the United States. Natcrest uses written provider and data-processing terms, data minimisation, access controls, encryption and the transfer basis and safeguards required by Kenyan data-protection law. Provider locations may change as infrastructure evolves, but a material change will be assessed, documented and reflected in this Policy or a product-specific notice before incompatible processing begins.

15.Retention, Account closure and deletion

15.1 Natcrest retains personal data only for as long as reasonably necessary for the disclosed purpose, a lawful Customer instruction, security, an active Account or subscription, or an applicable legal, tax, accounting, audit, regulatory, complaints or dispute requirement.

15.2 Retention is assessed by reference to the nature and sensitivity of the information; the purpose and duration of the relationship; legal record-keeping duties; applicable limitation periods; fraud and security needs; unresolved complaints or claims; the Customer's role and instruction; and the technical time needed for secure backup rotation.

15.3 Account, contractual, subscription and billing records may be retained for the relationship and the period needed to establish transactions, meet legal obligations and manage claims. Tax, accounting, corporate and payment records are retained for the longer period required by the applicable law governing the relevant record.

15.4 Customer-controlled personal data will, on termination, be returned, exported, restricted, anonymised or deleted in accordance with the Customer's lawful instruction, the supported Service capability, the data-processing terms and mandatory retention law. A Customer should export records it is legally required to keep before closing its Account.

15.5 Information may remain in protected backups until it is removed through the ordinary secure rotation cycle. While retained, backup information will not be restored for ordinary use except where needed for security, disaster recovery, investigation or legal compliance.

15.6 Natcrest may preserve information subject to a legal hold, regulatory request, fraud or security investigation, or unresolved complaint or claim. Access will be restricted to the purpose requiring retention.

15.7 Properly anonymised information may be retained for statistics, security, analysis and product improvement where re-identification is not reasonably possible and the use is lawful.

16.Security and personal-data breaches

16.1 Natcrest maintains technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected according to the nature of the information, the processing context, current risk and reasonable implementation capability.

16.2 Confirmed controls include encryption of personal data at rest, bcrypt-based password hashing and email-based one-time-password authentication. Natcrest supplements these with access-control, logging, backup, vendor-management and incident-response measures to the extent implemented and operationally verified for the production Service.

16.3 No system is completely secure. Natcrest does not promise that a breach or interruption can never occur, but will investigate suspected incidents, contain and remediate them where reasonably possible, preserve appropriate records and comply with legally required notices.

16.4 Where Natcrest is controller and a breach meets the statutory notification threshold, Natcrest will notify the Office of the Data Protection Commissioner without delay and within seventy-two hours after becoming aware of the breach, and will notify affected persons where required by law.

16.5 Where Natcrest is processor, it will notify the relevant Customer without delay and, where reasonably practicable, within forty-eight hours after becoming aware of a personal-data breach affecting that Customer's data, and will provide information and assistance reasonably available to support the Customer's response.

16.6 Customers and Authorised Users must protect credentials and one-time passcodes, use appropriate permissions, remove former users promptly, secure connected devices and notify Natcrest promptly of suspected compromise. These responsibilities do not exclude Natcrest's liability for its own breach or another responsibility that cannot lawfully be excluded.

17.Data-subject rights

17.1 Subject to applicable law and any lawful limitation, a data subject may have the right to:

17.1.1 be informed about the collection and use of personal data;

17.1.2 obtain access to personal data and information about its processing;

17.1.3 request correction of inaccurate or incomplete personal data;

17.1.4 request deletion or erasure where the legal conditions are met;

17.1.5 object to processing, including an absolute objection to direct marketing;

17.1.6 request restriction of processing in the circumstances prescribed by law;

17.1.7 receive or transmit eligible personal data in a structured, commonly used and machine-readable format where the right to portability applies;

17.1.8 withdraw consent at any time where processing relies on consent; and

17.1.9 not be subject to a solely automated decision producing legal or similarly significant effects, and to obtain the safeguards required where such processing is lawfully used.

17.2 A request may be sent to the verified contact in clause 21. It should describe the right being exercised, the relevant Account, Customer or interaction, and sufficient information to locate the data. A requester should not send a password, PIN, one-time passcode or unnecessary sensitive personal data.

17.3 Natcrest may request proportionate information to verify identity, authority and the scope of the request. An authorised representative may act for a data subject if Natcrest can reasonably verify the authority and identity involved.

17.4 For Customer-controlled personal data, Natcrest may refer the request to the Customer and assist the Customer. Natcrest will not disclose information or alter Customer-controlled records without appropriate authority merely because a request has been made.

17.5 Natcrest will respond within the period prescribed by applicable law. If a request is refused, limited or delayed, Natcrest will give the reason and information about available recourse where the law requires it.

17.6 A right may be limited by another person's rights, legal professional privilege, confidentiality, security, statutory record-keeping, prevention or detection of crime, legal claims or another lawful exemption. Natcrest will apply an exemption only to the extent justified.

18.Children's personal data

18.1 M-Penny is a business platform intended for adults who are legally capable of acting for a business. It is not directed to children, and an individual who creates or administers an Account must be at least eighteen years old.

18.2 Customer Data may nevertheless contain information about a child if a Customer submits it for a lawful business purpose. The Customer must establish lawful authority, apply the heightened protections required by Kenyan law, provide the required notice and avoid unnecessary collection.

18.3 Natcrest does not claim to operate a general age-verification or parental-consent system. If Natcrest learns that children's personal data has been processed without an appropriate basis or safeguard, it may restrict the processing, seek instructions, delete the information where lawful or take another proportionate corrective step.

19.Privacy complaints

19.1 A privacy question, rights request or complaint should be sent to the verified contact in clause 21 with enough information to identify the person, relevant Account or Customer, the processing complained of, supporting information and the outcome sought.

19.2 Natcrest may verify identity, request clarification and coordinate with the relevant Customer where Natcrest acts as processor. It will acknowledge and handle the matter within the requirements and periods prescribed by applicable law.

19.3 A person may complain to the Office of the Data Protection Commissioner through its official complaint portal at www.odpc.go.ke, by email to complaint@odpc.go.ke, or at the Office's published address, including P.O. Box 30920-00100 G.P.O., Nairobi, Kenya. Official details should be checked on the ODPC website because they may change.

19.4 Nothing in this Policy requires a person to complete Natcrest's internal process before using a statutory complaint route, seeking urgent relief or pursuing another remedy available under Kenyan law.

20.Changes to this Policy

20.1 Natcrest may update this Policy prospectively to reflect changes in law, the Service, technology, vendors or processing practices. The current version number and effective date will appear on the cover.

20.2 Natcrest will give appropriate advance notice of a materially adverse or unexpected change where practicable or legally required, using the Account, email, website, application or another suitable channel.

20.3 Continued use does not by itself provide consent for a new incompatible purpose. Where a change requires consent, a new lawful basis, a product-specific notice or renewed acceptance, Natcrest will complete that step before the new processing begins.

20.4 An update will not retrospectively remove rights or authorise processing that was unlawful when undertaken. Earlier versions may be retained for accountability and dispute purposes.

21.Contact information

21.1 Operator: Natcrest Holdings Company Ltd (trading as M-Penny), Company Registration No. PVT-ZE186LV6, Pride House, Kitengela, Kajiado County, Kenya; P.O. Box 817-00242, Kitengela, Kenya.

21.2 Privacy enquiries, data-subject requests and privacy complaints may be sent to .

21.3 When contacting Natcrest, include sufficient information to identify the relevant person, Account, Customer and request. Do not send passwords, PINs, one-time passcodes or unnecessary sensitive personal data.

© 2026 NATCREST HOLDINGS COMPANY LTD (TRADING AS M-PENNY) · ALL RIGHTS RESERVED · TERMS OF SERVICE · HOME