MPenny TERMS OF SERVICE →
Legal

Privacy Policy

Last updated: June 2026 · Version 1.0 · Data Protection Act, 2019 (Kenya)
This Policy explains how M-Penny Ltd collects, uses, shares, protects and retains personal data, and the rights you have, in line with the Kenya Data Protection Act, 2019 and the regulations and guidance of the Office of the Data Protection Commissioner ("ODPC"). It forms part of, and should be read with, our Terms of Service.

Contents

  1. Who we are
  2. Data we collect
  3. How & why we use it
  4. Lawful bases
  5. Who we share with
  6. Cross-border transfers
  7. AI processing
  8. Security
  9. Retention
  10. Your rights
  11. Marketing & cookies
  12. Children
  13. Changes
  14. Contact & complaints

1.Who we are

M-Penny Ltd (Nairobi, Kenya) is the data controller for personal data processed through the M-Penny platform, and is (or is in the process of being) registered with the ODPC. Where we process data on behalf of your business — for example contact details of your own customers that you enter — your business is the controller and M-Penny acts as a data processor under the Terms.

2.Data we collect

CategoryExamples
Identity & businessOwner name, business name, KRA PIN, location, photo/logo, ID details where required for KYC
Contact & accountPhone number, email, username, hashed password/PIN, plan and subscription status
Payment identifiersM-Pesa till/paybill/phone, bank references, transaction IDs (we do not store your M-Pesa PIN or full card numbers)
Financial recordsInvoices, expenses, quotations, ledger, stock, payroll inputs, tax positions, and customer/supplier details you enter or import
Credit dataWhere you apply for credit and consent: affordability, repayment and CRB-related data
Usage & deviceLog data, device/browser type, IP address, app interactions, and cookies/local storage
Referral dataReferral codes, who referred whom, and reward/payout records

3.How & why we use it

4.Lawful bases

We rely on: performance of our contract with you; compliance with legal obligations (for example tax and AML); your consent for optional processing such as credit assessment and marketing (which you may withdraw at any time); and our legitimate interests in securing, operating and improving the service, balanced against your rights.

5.Who we share with

We share personal data only as needed to run the service and as the law allows:

We do not sell your personal data.

6.Cross-border transfers

Some providers (for example cloud and AI infrastructure) may process data outside Kenya. Where this happens, we ensure an appropriate basis and safeguards for the transfer as required by the Data Protection Act, including contractual protections and, where relevant, your consent.

7.AI processing

Some features use artificial intelligence to summarise regulations, generate guidance, business intelligence and marketing content. Prompts are processed by our AI provider via secure server-side calls; we instruct our provider not to use your content to train their models. AI outputs are for information only and may be inaccurate — please review before relying on them. Our AI does not make legally or financially significant decisions about you without human involvement.

8.Security

We protect data with encryption in transit and at rest, role-based access controls, audit logging, and secret management. Passwords and PINs are hashed and are not visible to M-Penny staff. No system is perfectly secure; you must keep your credentials and one-time passcodes confidential and tell us promptly of any suspected compromise. We will notify you and the ODPC of a notifiable personal-data breach as required by law.

9.Retention

We keep personal data for as long as your account is active and as needed to provide the service. Tax and accounting records are retained for the period required by Kenyan law (generally at least five (5) years). After applicable periods we delete or irreversibly anonymise data, except where we must keep it to meet legal, regulatory, audit or dispute-resolution obligations.

10.Your rights

Subject to the Data Protection Act, you have the right to: be informed; access your data; correct inaccurate data; request deletion; restrict or object to certain processing; data portability; and withdraw consent. To exercise a right, contact privacy@mpenny.ke; we will respond within the timeframes the law requires. Some data may need to be retained for legal reasons even after a deletion request.

11.Marketing & cookies

We send service and transactional messages necessary to operate your account. We send marketing only with your consent, and you can opt out at any time. The app uses cookies and local storage to keep you signed in, remember preferences and measure usage; you can control these through your device or browser, though some features may not work without them.

12.Children

M-Penny is for businesses and is not directed to children under 18. We do not knowingly collect children's data; if you believe we have, contact us and we will delete it.

13.Changes

We may update this Policy from time to time. We will post the updated version with a new date and, for material changes, give notice in-app. Continued use after changes take effect means you accept the updated Policy.

14.Contact & complaints

Data protection queries and requests: privacy@mpenny.ke. M-Penny Ltd, Nairobi, Kenya. If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (odpc.go.ke).

This Policy is provided in good faith and should be reviewed and finalised by a licensed Kenyan data-protection practitioner before commercial launch, and kept current as data flows, processors and regulations change.

© 2026 M-PENNY LTD · ALL RIGHTS RESERVED · TERMS OF SERVICE · HOME