Data Protection Policy

Version: 1.0

Effective Date: 29 November 2025

Owner: Board of Directors, QUEPAY LTD

1. Introduction and Scope

QUEPAY LTD (“QuePay”, “we”, “us”, “our”) is a Kenyan-registered technology company providing payment automation solutions through hardware (Smart ATM Controller – PLC), merchant web and Android platforms, and a consumer mobile application.

This Data Protection Policy governs all personal data processed by QuePay in the course of its business activities, including data of end-users, merchants, employees, and any other natural persons.

2. Definitions

  • Personal data: Any information relating to an identified or identifiable natural person
  • Processing: Any operation performed on personal data (collection, storage, use, disclosure, etc.)
  • Data subject: The natural person to whom personal data relates
  • Controller: QUEPAY LTD
  • Processor: Any third party processing personal data on our behalf

3. Data Protection Principles (Section 25, KDPA)

QuePay commits to processing all personal data in accordance with:

  1. Lawfully, fairly, and in a transparent manner
  2. For explicit, specified, and legitimate purposes only
  3. Adequately, relevantly, and limited to what is necessary
  4. Accurately and kept up to date where necessary
  5. Retained only for as long as necessary
  6. With appropriate security, integrity, and confidentiality
  7. With full accountability – QuePay takes responsibility for compliance

4. Categories of Personal Data Processed

CategoryExamplesData Subjects
Identity dataFull nameUsers & merchants
Contact dataPhone number, email addressUsers & merchants
Transaction dataM-Pesa records, amounts, timestampsUsers & merchants
Technical dataDevice ID, IP address, logsUsers & merchants
Usage dataTransaction history, features usedUsers & merchants

We do not collect special-category data or data of children under 18.

5. Lawful Bases for Processing (Section 30, KDPA)

Processing ActivityPrimary Lawful BasisSecondary Basis
Provision of payment servicesPerformance of contractLegal obligation
Transaction processingPerformance of contract & Legal obligation
Fraud prevention & securityLegitimate interestsVital interests
Regulatory & tax reportingLegal obligation
System analyticsLegitimate interests
Direct marketingExplicit consent

6. Data Retention Periods

Data CategoryRetention PeriodLegal Basis
Transaction records7 years from transactionPMLA, Tax Procedures Act
Account data7 years after closureSame
Logs & device IDs1 yearSecurity
BackupsMax 90 daysDisaster recovery

7. Data Subject Rights (Sections 26–32, KDPA)

You have the right to:

  • Be informed • Access (within 14 days) • Rectification • Erasure • Restriction • Portability • Objection • Not be subject to automated decisions

Submit requests to: dpo@quepay.co.ke (free of charge)

8. Third-Party Processors & International Transfers

ProcessorServiceLocationSafeguards
DigitalOcean LLCCloud infrastructureUSADPA + SCCs
Amazon Web ServicesBackup storageUSADPA + SCCs
InfobipSMS gatewayGlobalDPA + SCCs
Google Analytics / Microsoft ClarityAnalyticsUSAAnonymised + DPA
Safaricom PLCM-Pesa APIKenyaJoint-controller agreement

9. Security of Processing (Regulation 19)

  • TLS 1.2+ encryption in transit
  • AES-256 encryption at rest
  • Role-based access control & mandatory MFA
  • Annual penetration testing & vulnerability scans
  • Daily backups (90-day max)
  • Secure development lifecycle (SDL)
  • Annual employee data protection training

10. Data Breach Notification

We will:

  1. Detect & contain within 24 hours
  2. Notify ODPC within 72 hours (where required)
  3. Inform affected data subjects without undue delay if high risk
  4. Document every breach (Section 43, KDPA)

11. Governance & Accountability

  • DPO: Not yet appointed (start-up phase). Board assumes responsibility. Appointment by 31 Dec 2026 or earlier if required.
  • DPIAs: Conducted for all new high-risk processing
  • RoPA: Records of Processing Activities maintained
  • All staff & contractors sign confidentiality clauses

12. Marketing & Consent

Direct marketing (SMS/email/WhatsApp) only with prior, explicit, documented consent — withdrawable at any time.

13. Complaints

Contact us first at dpo@quepay.co.ke
Or lodge a complaint with:
Office of the Data Protection Commissioner
Email: complaints@odpc.go.ke

14. Review & Updates

This Policy is reviewed annually or after any material change in processing activities.

Approved by the Board of Directors
QUEPAY LTD
29 November 2025