WANJIBOTSLIMITED
Services Shop About Contact Legal Staff Portal →
Legal & policies
  • All policies
  • About us
  • Contact us
  • Privacy Policy
  • Terms & Conditions
  • Refunds & Cancellation
  • Cookie Policy
  • Data Protection
  • POS User Agreement
  • Subscription Terms
  • Acceptable Use
Questions?

Write to wanjibotslimited1@gmail.com or call +254 741 883 550.

Home / Legal / Data Protection

Data Protection

Your rights under the Data Protection Act, 2019, and how to use them · Last reviewed 21 September 2026

Our Privacy Policy says what we hold and why. This page is the practical half: what you are entitled to ask for, how to ask, what we will need from you, and what happens if you are not satisfied.

Your rights

RightWhat it means in practice
To be informedTo know what we collect and why, before or at the time we collect it. That is what the Privacy Policy is for.
Of accessTo be told whether we hold data about you, and to receive a copy of it.
To correctionTo have wrong or incomplete data put right. If your name is misspelt on a tenancy or your phone number is out of date, tell us and we will fix it.
To deletionTo have data deleted where we no longer have a lawful reason to keep it. See the limits below.
To objectTo tell us to stop using your data for a particular purpose, including marketing — which we will stop immediately, no questions asked.
To restrictTo have us pause using your data while a dispute about its accuracy or our basis for holding it is sorted out.
To portabilityTo receive the data you gave us in a common machine-readable format, or to have it sent to someone else where that is technically feasible.
Not to be subject to automated decisionsWe do not make decisions about you by automated means alone. A person always decides.

How to make a request

  1. Write to us at wanjibotslimited1@gmail.com with DATA REQUEST in the subject line, or bring it in writing to either branch.
  2. Tell us which right you are using and, if you can, what the request is about — a tenancy, a job application, transactions in a particular month. We can answer a specific request much faster than a general one.
  3. Prove who you are. We will ask for ID. This protects you: we are not going to hand your records to somebody who emailed us using your name. If you are asking on someone else's behalf, we need their written authority.
  4. We acknowledge it and give you a reference.
  5. We answer within 30 days. If a request is genuinely complex we may extend that, but we will tell you before the 30 days are up, and why.

There is no charge. If a request is repetitive or clearly excessive we may charge a reasonable fee for the extra work, or explain why we are not acting on it — but we will say so rather than simply going quiet.

What we can and cannot delete

We will delete what we can. Some records we are not permitted to delete, and it is fairer to say so plainly than to promise otherwise:

We can deleteWe cannot delete
  • Marketing contact details
  • An unsuccessful job application and its documents
  • Enquiry correspondence once it is closed
  • Shop account details where there is no outstanding order
  • Data we collected but no longer need
  • Transaction and accounting records inside the 7-year tax retention period
  • SIM registration KYC held under regulatory requirement
  • Tax invoices already transmitted to KRA
  • Records relevant to a live dispute, investigation or legal claim
  • The internal audit trail, which is unalterable by design

Where we cannot delete something, we will tell you which rule requires us to keep it and for how long — and we will still stop using it for anything beyond that purpose.

Our internal audit trail

Every action in our system is written to a log that records who did it, when, from where, and what the record looked like beforehand. That log is append-only: it cannot be edited or deleted by anybody, including our own directors and administrators, and it is regularly checked for tampering.

We are explicit about this because it cuts both ways. It is why we can prove what happened to your transaction. It is also why we cannot remove entries from it on request. The log concerns what our staff did, not your personal life, and we treat it as accounting evidence.

Staff and job applicants

Staff have the same rights as everyone else, and can exercise them without it affecting how they are treated. Employment records are kept for 7 years after leaving, as employment and tax law require. Unsuccessful applications are deleted after 12 months unless you have asked to stay on file.

Note for staff: your activity in the system is logged, and your manager and the auditor can see it. That is a condition of having access to money and records, it is disclosed to you before you are given a login, and it exists to protect honest people as much as to catch dishonest ones.

If you are not satisfied

Come back to us first — say what we got wrong and we will look again. If that does not settle it, you have the right to complain to:

The Office of the Data Protection Commissioner (ODPC)
Kenya's data protection regulator, who can investigate and order us to act. Their current contact details and online complaint form are published on the ODPC website.

You may complain to the ODPC whether or not you have come to us first. We will not penalise you for it in any way, and we will co-operate fully with any enquiry they make.

This document is published by Wanjibots Limited, a company registered in Kenya. If anything here is unclear, ask us before you rely on it — we would rather explain it than have you guess.

Version of 21 September 2026. We will post a notice on this page when it changes materially, and the date above will change.

WANJIBOTSLIMITED
About us Contact us Privacy Terms Refunds Cookies All policies
📞 +254 741 883 550 💬 WhatsApp 📧 wanjibotslimited1@gmail.com
© 2026 Wanjibots Limited. All rights reserved.