Legal review notice: This is a comprehensive working draft prepared for review by qualified Kenyan legal counsel. It should be checked against NestIQ's actual legal entity, technical architecture, contracts, vendors, data flows, retention practices and processing activities before publication.

1. Introduction

Welcome to NestIQ ("NestIQ", "we", "us", or "our").

NestIQ is a property management technology platform that enables property owners, landlords, property managers, tenants and other authorised users to manage properties, leases, rent, payments, maintenance requests, communications, documents and related property-management activities through our website, applications and related services (collectively, the "Services").

This Privacy Policy explains how NestIQ collects, receives, uses, stores, discloses, transfers, protects and otherwise processes personal data.

We recognise that privacy is a fundamental right and are committed to processing personal data lawfully, fairly, transparently and securely.

This Privacy Policy is intended to comply with applicable Kenyan data protection legislation, including, where applicable:

  • the Constitution of Kenya, 2010;
  • the Data Protection Act, 2019 (No. 24 of 2019);
  • the Data Protection (General) Regulations, 2021;
  • the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021;
  • applicable regulations, guidance, directions and determinations issued by the Office of the Data Protection Commissioner ("ODPC"); and
  • other applicable laws and regulations of Kenya.

Where applicable, NestIQ may also comply with other data protection laws that apply to particular users, transactions, jurisdictions or processing activities.

IMPORTANT: This Privacy Policy is intended to be reviewed and approved by qualified Kenyan legal counsel before publication. Where there is any conflict between this policy and applicable law, the applicable law shall prevail.

2. Definitions

Data Controller means a person or entity that determines the purposes and means of processing personal data.

Data Processor means a person or entity that processes personal data on behalf of a Data Controller.

Data Subject means an identified or identifiable natural person to whom personal data relates.

Personal Data means information relating to an identified or identifiable natural person.

Sensitive Personal Data means personal data classified as sensitive under applicable Kenyan law, including, where applicable, information relating to health, biometric data, property details, marital or family details, genetic data, religious or philosophical beliefs, sexual orientation and other categories recognised by law.

Processing includes collecting, recording, organising, storing, retrieving, consulting, using, disclosing, transmitting, combining, restricting, erasing or destroying personal data.

Services means NestIQ's websites, applications, dashboards, APIs, software, communications and other services.

3. Who We Are

NestIQ is operated by:

  • Legal Entity: [INSERT FULL LEGAL ENTITY NAME]
  • Trading Name: NestIQ
  • Registration Number: [INSERT]
  • Registered Address: [INSERT]
  • Principal Place of Business: [INSERT]
  • Email: [INSERT PRIVACY EMAIL]
  • Telephone: [INSERT]
  • Data Protection Officer / Privacy Contact: [INSERT NAME OR ROLE]
  • Privacy Email: [INSERT]

For purposes of applicable data protection legislation, NestIQ may act as either a Data Controller, a Data Processor, or both, depending upon the particular processing activity.

4. Scope of This Privacy Policy

This Privacy Policy applies to personal data processed through:

  • the NestIQ website;
  • NestIQ tenant portals;
  • landlord and property-manager dashboards;
  • mobile or web applications;
  • payment-related functionality;
  • lease and tenancy-management functionality;
  • maintenance and work-order functionality;
  • customer support;
  • email, SMS and other communications;
  • APIs and integrations;
  • documents uploaded to NestIQ;
  • authentication and account-management systems; and
  • other services operated by or on behalf of NestIQ.

This Privacy Policy does not necessarily apply to third-party websites, applications, payment providers, landlords, property managers or other services that may be accessed through NestIQ. Those organisations may have their own privacy policies and data-processing practices.

5. Personal Data We May Collect

Depending on how you use NestIQ, we may collect different categories of personal data.

5.1 Identity Information

This may include full name; username; account identifier; date of birth where necessary; nationality where necessary; government-issued identification information where legally necessary; passport information where necessary; profile photograph where voluntarily provided; signature; verification information; and information required to authenticate your identity.

NestIQ will only collect identification information where reasonably necessary for a lawful and specified purpose.

6. Contact Information

We may collect email address; telephone number; postal address; residential address; property address; emergency contact information; preferred communication method; and other contact information provided by you.

7. Tenant and Lease Information

Where NestIQ is used to manage a tenancy, we may process tenancy details; property details; lease commencement and expiry dates; rent amount and schedule; security deposit information; lease documents; notices; tenancy correspondence; tenant account information; authorised occupants; emergency contacts; landlord or property manager information; rental history; outstanding balances; payment receipts; maintenance requests; and other information necessary to administer a tenancy.

Some property or family information may constitute sensitive personal data under Kenyan law. Such information will only be processed where a lawful basis and appropriate safeguards exist.

8. Payment Information

NestIQ may facilitate payments through third-party payment providers. Depending on the payment method, we may process payment amount; transaction reference; payment date and time; currency; payment status; payer and recipient information; payment method; transaction identifiers; masked payment information; and reconciliation information.

Where payments are processed by third-party payment providers, such providers may independently process personal data under their own terms and privacy policies.

NestIQ does not intend to store complete payment-card numbers, CVV/CVC codes or equivalent authentication credentials unless expressly necessary and lawfully permitted.

9. Mobile Money Information

Where NestIQ supports mobile-money services, including M-PESA or other payment systems, we may process information required to initiate, confirm, reconcile or record transactions, including mobile telephone number, transaction reference, transaction amount, transaction status, transaction date and time, payer or recipient information, and information returned by the relevant payment provider.

10. Property and Maintenance Information

Where you use NestIQ to manage property, we may process property addresses, unit numbers, property descriptions, ownership or management information, tenancy information, maintenance requests, photographs, videos, work-order information, contractor information, repair history, utility information, meter readings, utility charges, inspection information, and other information reasonably necessary for property management.

11. Documents

Users may upload lease agreements, identification documents, receipts, invoices, inspection reports, maintenance documents, payment records, notices, correspondence, property documents and other documents necessary for property management.

Users must not upload personal data that is unnecessary for the relevant purpose.

12. Account and Authentication Information

We may collect email address, telephone number, authentication tokens, login information, magic-link information, account creation date, authentication timestamps, security logs, device information, IP address, session information, and information necessary to protect accounts from unauthorised access.

13. Technical and Usage Information

When you use NestIQ, we may automatically collect IP address, browser type, operating system, device type, device identifiers, approximate location derived from technical information where applicable, pages viewed, features used, timestamps, referral information, error logs, security events, performance information, network information and other diagnostic information.

14. Cookies and Similar Technologies

NestIQ may use cookies, local storage, session technologies, pixels and similar technologies for authentication, maintaining user sessions, security, remembering preferences, analytics, performance monitoring, fraud prevention, improving the Services and understanding how users interact with NestIQ.

Where required by applicable law, NestIQ will obtain appropriate consent before placing or using non-essential cookies. Users may be able to control certain cookies through browser or device settings. Disabling certain cookies may prevent some NestIQ features from functioning correctly.

15. How We Collect Personal Data

We may collect personal data directly from you; from your landlord or property manager; from an authorised representative; from another authorised user; from payment service providers; from identity or verification providers; from service providers; through your use of the Services; through cookies and similar technologies; from publicly available sources where legally permitted; or where otherwise permitted or required by law.

Under Kenyan law, personal data should generally be collected directly from the Data Subject, subject to statutory exceptions. Where we receive information about you from a landlord, property manager or other Data Controller, that party may be responsible for ensuring that it has a lawful basis to provide the information to NestIQ.

16. Purposes for Processing Personal Data

16.1 Providing the Services

Including creating and managing accounts; managing properties; managing tenancies; managing leases; generating receipts; processing or facilitating payments; managing security deposits; recording rent balances; managing work orders; facilitating communications; providing tenant dashboards; providing landlord dashboards; providing customer support; and delivering requested services.

16.2 Contractual Obligations

We may process information where necessary to perform a contract, administer a tenancy, provide requested services, establish or manage an account, process transactions, or take steps requested before entering into a contract.

16.3 Legal and Regulatory Compliance

We may process personal data to comply with Kenyan law; comply with court orders; comply with lawful government requests; comply with tax, financial or regulatory obligations; prevent fraud; investigate unlawful activity; establish, exercise or defend legal claims; or protect rights and safety.

16.4 Security

We may process information to detect unauthorised access, prevent fraud, protect accounts, detect malicious activity, investigate security incidents, maintain system integrity, and protect NestIQ, users and third parties.

16.5 Product Improvement

Where legally permitted, we may use appropriately protected information to analyse system performance, identify errors, improve user experience, develop features, conduct statistical analysis, monitor reliability and improve security. Where practical, information used for analytical purposes will be aggregated, anonymised or pseudonymised.

17. Lawful Bases for Processing

NestIQ will process personal data only where a lawful basis exists. Depending upon the circumstances, this may include consent; performance of a contract; compliance with a legal obligation; protection of vital interests; performance of a task carried out in the public interest or exercise of official authority where applicable; legitimate interests, where recognised and applicable under Kenyan law; or another lawful basis permitted under applicable legislation.

Where processing is based on consent, consent will be requested in a manner that is informed, specific and capable of being withdrawn.

18. Consent

Where NestIQ relies upon consent, consent will be requested separately where appropriate; the purpose of processing will be explained; the categories of information involved will be explained; third-party sharing will be disclosed where applicable; international transfers will be disclosed where applicable; withdrawal will be available where legally applicable; and withdrawal will not affect processing lawfully conducted before withdrawal.

Consent will not be treated as freely given where the law requires another lawful basis or where consent is not appropriate for the relevant processing activity.

19. Marketing Communications

NestIQ may send transactional communications necessary to provide the Services, including payment confirmations, rent reminders, security notifications, lease notifications, maintenance updates, account notifications and service announcements. Where we send marketing communications, we will comply with applicable law and provide an appropriate means of opting out. Opting out of marketing will not necessarily prevent essential service communications.

20. Sharing Personal Data

NestIQ may disclose personal data where necessary and lawful to landlords; property managers; tenants; property owners; authorised representatives; contractors; maintenance providers; payment providers; banks and financial institutions; mobile-money providers; identity verification providers; cloud hosting providers; database providers; analytics providers; communication providers; customer-support providers; professional advisers; auditors; insurers; regulators; government authorities; courts and tribunals; law-enforcement agencies; and other service providers necessary to operate NestIQ.

We will not sell personal data to third parties as a commercial product unless expressly permitted by applicable law and transparently disclosed.

21. Landlords and Property Managers

A landlord or property manager may provide NestIQ with information concerning tenants, occupants, guarantors, emergency contacts, contractors or other persons. Where a landlord or property manager determines the purposes and means of processing that information, they may be the Data Controller and NestIQ may act as their Data Processor.

The landlord or property manager remains responsible for ensuring that their collection and disclosure of personal data to NestIQ is lawful. NestIQ will process such information according to the applicable agreement, documented instructions and applicable law.

22. Data Processors

Where required by law, NestIQ will enter into written agreements with Data Processors containing appropriate provisions concerning the subject matter and duration of processing, nature and purpose, categories of personal data and Data Subjects, controller instructions, confidentiality, security measures, deletion or return of data, auditing and other legally required matters.

23. Third-Party Service Providers

NestIQ may use third-party providers for cloud hosting, databases, authentication, email, SMS, payments, mobile money, analytics, customer support, security, monitoring, document storage, communications and infrastructure.

Lawyer/Company Note: NestIQ should insert the actual providers here before publication.

  • [PAYMENT PROVIDER]
  • [MOBILE MONEY PROVIDER]
  • [CLOUD PROVIDER]
  • [DATABASE PROVIDER]
  • [EMAIL PROVIDER]
  • [SMS PROVIDER]
  • [AUTHENTICATION PROVIDER]
  • [ANALYTICS PROVIDER]
  • [SECURITY/CDN PROVIDER]

24. International Transfers

Some third-party service providers may process or store personal data outside Kenya. NestIQ will not transfer personal data outside Kenya except where permitted by applicable Kenyan law.

Depending on the circumstances, international transfers may rely upon appropriate safeguards; an applicable adequacy decision; contractual safeguards; necessity for contractual performance; legal claims; public interest; vital interests; legitimate interests where legally applicable; or explicit consent where required.

Sensitive personal data transferred outside Kenya requires additional safeguards and consent requirements under the Data Protection Act.

25. Data Security

NestIQ will implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, destruction, alteration, unauthorised disclosure, misuse, unlawful processing, malicious activity and other security threats.

Security measures may include encryption in transit; encryption at rest where appropriate; access controls; authentication controls; role-based permissions; secure credential management; logging and monitoring; backups; security testing; vulnerability management; incident-response procedures; staff confidentiality obligations; least-privilege access; secure development practices; and periodic review of security controls.

No electronic system can be guaranteed to be completely secure. Accordingly, while NestIQ will take reasonable and legally appropriate measures to protect personal data, NestIQ cannot guarantee absolute security.

26. Data Breaches

A personal data breach may include unauthorised access to, acquisition of, disclosure of, alteration of, destruction of or loss of personal data. NestIQ maintains procedures for detecting, assessing, containing, investigating and responding to personal data breaches.

Where a notifiable breach occurs and the legal threshold is met, NestIQ will notify the Data Commissioner within the period required by law. Where required, affected Data Subjects will also be notified.

27. Data Retention

NestIQ will retain personal data only for as long as reasonably necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law, necessary for legal claims, accounting or tax purposes, fraud prevention, regulatory compliance or another lawful purpose.

NestIQ will maintain a data-retention schedule identifying appropriate retention periods and review requirements. When personal data is no longer required, NestIQ may delete it, destroy it, anonymise it or pseudonymise it.

28. Legal and Financial Records

Deletion requests may be limited where NestIQ is legally required or legitimately entitled to retain information, including for tax, accounting, financial reconciliation, payment disputes, fraud prevention, regulatory compliance, legal proceedings, contractual enforcement or audit requirements.

29. Your Rights as a Data Subject

Subject to applicable law and lawful limitations, you may have the right to:

  1. be informed about processing of your personal data;
  2. access your personal data;
  3. object to processing;
  4. request correction of inaccurate or misleading information;
  5. request deletion or erasure where legally applicable;
  6. request restriction of processing;
  7. request data portability where applicable;
  8. withdraw consent where processing is based on consent;
  9. object to certain forms of direct marketing;
  10. request information concerning certain processing activities; and
  11. exercise other rights provided under Kenyan law.

30. Right of Access

You may request access to personal data held by NestIQ about you. We may require reasonable information to verify your identity before processing an access request.

31. Right to Rectification

If information held by NestIQ is inaccurate, incomplete, outdated or misleading, you may request that it be corrected. Where appropriate, NestIQ will take reasonable steps to correct the information.

32. Right to Erasure

You may request deletion of personal data where it is no longer necessary for the purpose for which it was collected, was processed unlawfully, retention is no longer authorised, another lawful basis for erasure exists, or applicable Kenyan law provides such a right. The right to deletion is not absolute.

33. Right to Restrict Processing

You may request restriction of processing where applicable, including where the accuracy of personal data is contested, processing is alleged to be unlawful, data is no longer necessary but is required for a legal claim, or an objection to processing is being considered.

34. Data Portability

Where applicable and technically feasible, you may request that certain personal data be provided in a structured, commonly used electronic format or transmitted to another Data Controller.

35. Withdrawing Consent

Where processing is based on consent, you may withdraw your consent. Withdrawal will not affect the lawfulness of processing conducted before withdrawal.

36. How to Exercise Your Rights

Requests should be submitted to:

  • Privacy/Data Protection Contact: [INSERT]
  • Email: [INSERT PRIVACY EMAIL]
  • Postal Address: [INSERT]

Your request should include sufficient information to identify you, identify the relevant account where applicable, explain the request, and provide information reasonably necessary to process it. NestIQ may take reasonable steps to verify identity to prevent unauthorised disclosure.

37. Children

NestIQ's Services are primarily intended for persons who are legally capable of entering into the relevant agreements.

NestIQ does not knowingly seek to collect personal data from children except where permitted or required by law and where appropriate safeguards and parental or guardian consent are obtained where required.

Where a tenant, occupant, dependant or other person associated with a property is a child, information concerning that child should only be provided where necessary and lawfully.

38. Automated Decision-Making and Profiling

NestIQ may use automated processes for security monitoring, fraud detection, account protection, system optimisation, operational analytics or other legitimate purposes.

NestIQ will not make decisions producing legal or similarly significant effects solely through automated processing unless permitted by applicable law and appropriate safeguards are implemented.

39. Location Information

NestIQ may process approximate or technical location information where necessary for security, fraud prevention, service functionality, diagnostics, property-management functions or other disclosed purposes.

40. Communications

Communications between users and NestIQ may be processed for customer support, maintaining records, resolving disputes, improving services, security, preventing fraud, complying with legal obligations and administering contracts.

41. User Responsibilities

Users are responsible for ensuring that information they provide is accurate; they have authority and a lawful basis to provide information concerning another person; account credentials and magic links are kept confidential; uploaded documents are relevant and necessary; personal information is not unnecessarily disclosed through work orders or messages; and they comply with applicable privacy and data-protection laws.

42. Third-Party Websites and Services

NestIQ may contain links to third-party websites or integrate with third-party services. NestIQ is not responsible for the privacy practices, security, content or policies of independently operated third-party services.

43. Payment Providers

Where a user chooses to make a payment using a third-party payment service, the payment provider may independently process personal data and may have its own privacy policy, terms of service, security controls, transaction records, fraud-prevention systems and regulatory obligations.

44. Landlord and Tenant Relationships

NestIQ is a technology platform and does not necessarily become a party to the underlying landlord-tenant relationship. Where a landlord or property manager uses NestIQ to manage a tenancy, the landlord/property manager may determine processing purposes, NestIQ may process information on their behalf, and the landlord/property manager remains responsible for their lawful use of tenant information.

45. Legal Disclosure

NestIQ may disclose personal data where reasonably necessary to comply with a legal obligation, respond to lawful requests, comply with court orders, enforce contractual rights, protect NestIQ's rights or property, prevent fraud, investigate suspected unlawful conduct, protect users or the public, or establish, exercise or defend legal claims.

46. Corporate Transactions

If NestIQ undergoes a merger, acquisition, restructuring, sale of assets, financing, corporate reorganisation or similar transaction, personal data may be transferred as part of the transaction where lawful.

47. Data Protection by Design and Default

NestIQ will seek to incorporate privacy and data protection into the design and operation of its Services. This may include data minimisation, privacy-conscious defaults, access controls, encryption, pseudonymisation, secure authentication, limited retention, segregation of data, security testing and privacy impact assessments where required.

48. Data Protection Impact Assessments

Where NestIQ's processing is likely to result in a high risk to the rights and freedoms of Data Subjects, NestIQ may conduct a Data Protection Impact Assessment ("DPIA") before commencing or materially changing the relevant processing.

49. Data Protection Officer

Where required by applicable law, NestIQ will appoint a Data Protection Officer ("DPO") or otherwise designate an appropriate privacy contact.

  • DPO/Privacy Contact: [INSERT]
  • Email: [INSERT]

50. Data Controller and Data Processor Registration

Where registration is legally required, NestIQ will register with the Office of the Data Protection Commissioner as a Data Controller and/or Data Processor as applicable.

  • ODPC Registration Status: [INSERT AFTER LEGAL REVIEW]
  • Data Controller Registration Number: [INSERT IF APPLICABLE]
  • Data Processor Registration Number: [INSERT IF APPLICABLE]

51. Complaints

If you believe that NestIQ has processed your personal data unlawfully or has otherwise violated your privacy rights, please contact us first so that we can investigate and attempt to resolve the matter.

Privacy Complaints Email: [INSERT]

52. Right to Complain to the ODPC

Nothing in this Privacy Policy limits your right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya. You may contact the ODPC through its official channels if you believe your rights under applicable data-protection law have been infringed.

53. Confidentiality

NestIQ will require employees, contractors and authorised persons who process personal data to maintain appropriate confidentiality and comply with applicable security and data-protection requirements.

54. Changes to This Privacy Policy

NestIQ may amend this Privacy Policy from time to time to reflect changes to our Services, technology, data-processing activities, third-party providers, applicable law, regulatory guidance, security improvements or other legitimate operational requirements.

The updated Privacy Policy will be published through the relevant NestIQ Services. Where required by law, NestIQ will provide additional notice or obtain consent before implementing material changes.

55. Governing Law

This Privacy Policy shall be governed by and interpreted in accordance with the laws of the Republic of Kenya, except to the extent that mandatory applicable law provides otherwise.

56. Severability

If any provision of this Privacy Policy is determined by a competent authority or court to be unlawful, invalid or unenforceable, that provision shall be interpreted or modified to the minimum extent necessary to make it lawful, valid and enforceable. The remaining provisions shall continue in full force and effect.

57. No Waiver

Failure by NestIQ to enforce any provision of this Privacy Policy shall not constitute a waiver of its right to enforce that provision subsequently.

58. Entire Privacy Notice

This Privacy Policy, together with any applicable notices, consent forms, contractual terms, Data Processing Agreements and other privacy notices incorporated by reference, constitutes NestIQ's privacy notice concerning the relevant processing activities.

59. Contact Us

For questions, requests, complaints or concerns regarding privacy or personal data, contact:

  • NestIQ Legal Entity: [INSERT]
  • Address: [INSERT]
  • Email: [INSERT PRIVACY EMAIL]
  • Telephone: [INSERT]
  • Data Protection Officer / Privacy Contact: [INSERT]
  • DPO Email: [INSERT]

60. Privacy Request Notice

When contacting NestIQ regarding your personal data, please clearly state "DATA PROTECTION REQUEST" in the subject line where possible.

Please describe the request you are making and provide sufficient information for NestIQ to verify your identity and locate the relevant information.

Schedule 1 — Categories of Personal Data

CategoryExamplesTypical Purpose
IdentityName, ID information, signatureAccount, verification, contracts
ContactEmail, phone, addressCommunications
AccountUser ID, authentication recordsAccount management
TenantTenancy and lease informationProperty management
PropertyProperty/unit informationProperty management
FinancialRent, balances, transaction referencesPayments and accounting
PaymentTransaction IDs, payment statusPayment processing
MaintenanceWork orders, photos, descriptionsRepairs
DocumentsLeases, receipts, noticesAdministration
TechnicalIP address, browser, deviceSecurity and functionality
CommunicationsMessages and support requestsCustomer support
SecurityLogs, authentication eventsSecurity and fraud prevention

Schedule 2 — Categories of Data Subjects

  • tenants and prospective tenants;
  • landlords and property owners;
  • property managers;
  • authorised representatives;
  • occupants;
  • guarantors;
  • emergency contacts;
  • contractors and maintenance providers;
  • employees and prospective employees;
  • customer-support users;
  • website visitors;
  • business partners; and
  • other persons whose information is lawfully provided to NestIQ.

Schedule 3 — Retention Framework

NestIQ shall maintain an internal retention schedule specifying the category of personal data, purpose, lawful basis, retention period, responsible department, review frequency, deletion/anonymisation procedure, applicable legal retention requirement and approved exceptions.

Exact periods: [TO BE COMPLETED FOLLOWING LEGAL AND ACCOUNTING REVIEW]

Schedule 4 — Third-Party Processors

ProviderServiceData ProcessedLocationRole
[INSERT]PaymentsTransaction data[INSERT][INSERT]
[INSERT]Mobile MoneyTransaction data[INSERT][INSERT]
[INSERT]Cloud HostingApplication data[INSERT][INSERT]
[INSERT]DatabaseAccount/property data[INSERT][INSERT]
[INSERT]EmailContact/communication data[INSERT][INSERT]
[INSERT]SMSPhone/communication data[INSERT][INSERT]
[INSERT]AuthenticationAccount/authentication data[INSERT][INSERT]
[INSERT]AnalyticsTechnical/usage data[INSERT][INSERT]

Schedule 5 — Legal and Regulatory Framework

This Privacy Policy should be interpreted alongside applicable:

  • Constitution of Kenya, 2010;
  • Data Protection Act, 2019;
  • Data Protection (General) Regulations, 2021;
  • Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021;
  • applicable ODPC regulations and guidance;
  • applicable consumer-protection legislation;
  • applicable electronic-transactions legislation;
  • applicable tax and accounting legislation;
  • applicable financial-sector requirements;
  • applicable telecommunications/mobile-money requirements; and
  • other applicable laws and regulations.

Lawyer Review — Items Requiring Confirmation Before Publication

  • Exact legal entity operating NestIQ
  • Company registration details
  • Registered office
  • Privacy email
  • Data Protection Officer/contact
  • ODPC Data Controller registration status
  • ODPC Data Processor registration status
  • Whether NestIQ qualifies for any registration exemption
  • Exact categories of personal data actually collected
  • Exact sensitive personal data actually collected
  • Actual payment providers
  • Actual M-PESA/Daraja architecture
  • Actual Paystack architecture
  • Actual cloud/database providers
  • Actual email/SMS providers
  • Actual authentication provider
  • Actual analytics providers
  • Countries in which data is stored or processed
  • International transfer safeguards
  • Data Processing Agreements with third parties
  • Data retention schedule
  • Cookie implementation
  • Marketing consent mechanism
  • Children's-data procedures
  • Data breach response procedure
  • DPIA requirements
  • Data Subject request procedure
  • Security policy
  • Internal access-control policy
  • Employee confidentiality obligations
  • Backup and deletion procedures
  • Tenant/landlord controller-processor allocation
  • Legal basis for each processing activity
  • Whether any automated decision-making/profiling is used
  • Whether NestIQ processes biometric data
  • Whether NestIQ processes government identification documents
  • Whether NestIQ processes health or other sensitive information
  • Applicable accounting/tax retention requirements
  • Final governing-law and dispute-resolution wording
  • Final publication and consent mechanism

Legal Disclaimer

This document is a comprehensive working draft prepared for legal review and does not constitute legal advice, legal representation or a guarantee of compliance with Kenyan law.

NestIQ should have a qualified Kenyan advocate and, where appropriate, a qualified data-protection professional review this Privacy Policy against NestIQ's actual technical architecture, contracts, processing activities, vendors, data flows, security controls and business model before publication.

No provision of this document should be interpreted as replacing advice from qualified Kenyan legal counsel or the requirements of the Office of the Data Protection Commissioner.

↑ Back to top