Official document
Privacy Policy
Version 3Published 25 August 2026
2. Privacy Policy
Version 1.0 | Effective date: [Not configured]
2.1 Data controller
[Not configured] is the data controller for core platform operations and may also act as a data processor
for limited institutional-client services. Contact the Data Protection Officer or privacy lead at [Not configured].
ODPC registration number(s): [Not configured].
2.2 Information collected
Identity and KYC data: name, date of birth, national ID or passport details, images, selfie and verification video.
Contact and account data: phone number, email, address, username, account role and authentication records.
Financial and credit data: loan requests, offers, income or employment evidence, bank or mobile-money evidence,
existing commitments, repayment history and platform trust indicators.
Transaction data: M-Pesa checkout IDs, receipt numbers, amounts, dates, reversals and reconciliation status.
Contract data: accepted terms, signatures, timestamps, IP address, device/browser information and document
hashes.
Technical data: logs, security events, cookies, approximate location derived from IP and support communications.
Dispute and compliance data: complaints, evidence, fraud reports, regulatory requests and investigation records.
2.3 Purposes and lawful bases
PesaPact processes personal data to perform contracts, take requested pre-contract steps, comply with legal
obligations, protect legitimate interests such as fraud prevention and security, and obtain consent where consent is
the appropriate lawful basis.
Purposes include onboarding, KYC, matching, displaying proportionate profile information, generating agreements,
processing or recording payments, reminders, support, dispute handling, security, analytics, regulatory reporting and
legal claims.
2.4 Data minimisation and lender access
Lenders should ordinarily see verification status and only the information reasonably necessary to assess a
particular request. Raw ID documents, selfies and verification videos must not be made generally visible to lenders.
PesaPact will not access or upload a user’s phone contacts, call logs, private messages or media library for debt
collection or public-shaming purposes.
2.5 Sensitive data and automated decisions
Biometric or similarly sensitive verification data will be processed only where lawful, necessary and protected by
enhanced security. PesaPact will explain any material automated profiling used for eligibility, ranking, fraud
detection or trust scoring.
Where a decision producing significant effects is made solely through automated processing, PesaPact will provide
the safeguards required by Kenyan law, including an appropriate opportunity for human review where applicable.
2.6 Sharing
The borrower or lender who is a party to a proposed or completed transaction.
Identity-verification, cloud-hosting, communications, analytics, security and customer-support providers under
written data-protection obligations.
Safaricom, M-Pesa and other authorised payment participants as necessary to process and reconcile transactions.
Professional advisers, insurers, auditors and lawful debt-recovery service providers where necessary.
CBK, ODPC, courts, law-enforcement agencies and other authorities where lawfully required.
A successor in a lawful merger, acquisition or restructuring, subject to appropriate safeguards.
2.7 International transfers
Where personal data is stored or accessed outside Kenya, PesaPact will use a lawful transfer mechanism and
appropriate safeguards. Hosting locations and principal processors must be identified in the production policy:
Hosting: [Not configured]. Processors: [Not configured].
2.8 Retention
KYC, transaction, contract, complaint and audit records will be retained only for the period required by law,
regulatory expectations, limitation periods, fraud prevention and the defence of claims. A detailed retention schedule
must be approved before launch.
Proposed schedule: account profile while active plus [Not configured] years; executed loan and transaction records for [Not configured] years
after closure; unsuccessful KYC material for a limited period unless fraud review requires longer; security logs for a limited period as set out in the retention schedule ([Not configured] years baseline).
2.9 User rights
Subject to lawful limitations, a data subject may request access, correction, deletion, restriction, objection, portability
where applicable, withdrawal of consent, and review of certain automated decisions. Requests should be submitted
to [Not configured].
A person may complain to the Office of the Data Protection Commissioner. PesaPact will not penalise a user for
exercising a privacy right.
2.10 Security and breaches
PesaPact will apply role-based access, encryption in transit and at rest where appropriate, secure secret
management, logging, backups, vulnerability management, staff confidentiality, processor due diligence and
incident response.
Where a personal-data breach creates the applicable risk threshold, PesaPact will notify the ODPC and affected
data subjects within the legally required period.
2.11 Cookies and communications
Strictly necessary cookies may operate without optional consent where permitted. Analytics or marketing
technologies will be disclosed and controlled through an appropriate consent mechanism.
Service messages about KYC, contracts, payments, security and arrears are not marketing. Marketing messages
require a lawful basis and an effective opt-out.
2.12 Children
PesaPact is not intended for persons under eighteen years old and does not knowingly enter loan arrangements
with minors.