Privacy Policy
This policy explains what personal data Wanjibots Limited holds about you, why we hold it, who else sees it, how long we keep it, and what you can tell us to do with it. It applies to our branches, this website, our online shop, our property management service and our staff and job applicants.
1. Who is responsible
Wanjibots Limited is the data controller for the personal data described here. That means we decide what is collected and why, and we are answerable for it under the Data Protection Act, 2019.
Our contact point for anything to do with personal data is wanjibotslimited1@gmail.com, marked DATA REQUEST, or +254 741 883 550.
2. What we collect
| If you are… | We collect |
|---|---|
| A counter customer (mobile money, bank agency, airtime) | Your name, phone number, the amount and type of transaction, the reference, and — where the service or the law requires it — your ID number and signature in the register. |
| Registering a SIM | The details Airtel and the Communications Authority require for KYC: full name, ID or passport number, date of birth, photograph of the ID, the SIM serial and the number issued. |
| Buying from our shop | Name, phone, email, delivery address if you want delivery, what you ordered, and the payment reference (an M-Pesa code, for instance). We never see or store your PIN. |
| A tenant | Name, ID number, phone, the unit you occupy, your tenancy terms, rent and deposit paid, and your payment history. |
| A landlord | Name, ID or company details, KRA PIN, contact details, bank or M-Pesa details for payouts, and the properties we manage for you. |
| A business client | Company name, KRA PIN, contact people, delivery addresses, and your order and payment history. |
| A job applicant | What you put in your application and CV: name, contact details, ID number, education, work history and the documents you upload. |
| A member of staff | Employment records, pay and statutory deductions, next of kin, the documents your role requires, and a log of what you do in our system. |
| Visiting this website | Very little — see our Cookie Policy. We do not run advertising trackers. |
Some of this is sensitive personal data under the Act — copies of IDs, for example. We collect it only where a service or a regulator requires it, and we keep it behind stricter controls than anything else.
3. Why we hold it, and on what legal basis
| Purpose | Basis under the Act |
|---|---|
| To carry out the transaction or service you asked for | Performance of a contract with you |
| To meet KYC, anti-money-laundering and SIM registration rules, and to issue tax invoices through KRA eTIMS | Compliance with a legal obligation |
| To keep accurate accounting records, reconcile each day, and investigate a disputed transaction | Legal obligation, and our legitimate interest in running an honest business |
| To prevent and detect fraud and theft, including our internal audit trail | Legitimate interest, and legal obligation |
| To answer your enquiry, complaint or quotation request | Your request, and our legitimate interest |
| To send you a receipt, statement or service message | Performance of a contract |
| To send you marketing you asked for | Your consent — which you may withdraw at any time |
| To assess a job application | Steps taken at your request before a contract |
4. Who else sees it
We do not sell personal data. We never have and we will not. It is shared only where the service cannot work without it, or where the law requires it:
- Airtel Kenya and Safaricom — for mobile money transactions and SIM registration, because the transaction is theirs to complete and the KYC record is theirs to hold.
- Co-operative Bank, Equity Bank and KCB — for agency banking transactions carried out on their behalf.
- The Kenya Revenue Authority — tax invoice details, through eTIMS, as required by law.
- Landlords — a tenant's name, unit, rent status and payment history, which is the service the landlord has engaged us for.
- Our bank and payment providers — to move money in and out.
- Regulators, courts and law enforcement — where we are lawfully required to produce records. We provide what is asked for and no more.
- Our professional advisers — auditors and lawyers, under a duty of confidence.
Where we use a service provider to process data for us, they may use it only on our instructions and only for that purpose.
5. Where it is kept
Our operating records are held in Kenya, on systems we control, and backed up daily to encrypted archives, at least one copy of which is kept away from the premises. Where an email or hosting provider stores data outside Kenya, we satisfy ourselves that the transfer meets the requirements of Part VI of the Act before using it.
6. How long we keep it
| Record | Kept for |
|---|---|
| Transaction and accounting records | 7 years, as tax law requires |
| SIM registration KYC records | As long as the line is active, plus the period the regulator requires |
| Tenancy records | 7 years after the tenancy ends |
| Employment records | 7 years after employment ends |
| Unsuccessful job applications | 12 months, then deleted, unless you ask us to keep you on file |
| Enquiries and complaints | 3 years |
| CCTV, where installed | 30 days, unless kept for a specific investigation |
| The internal audit trail | Permanently — it is deliberately unalterable, and it records staff actions rather than customer details |
7. How we protect it
- Access is by named account only. Nobody shares a login, and each person sees only their own branch and only the screens their role needs.
- Administrators and finance staff must sign in with a password and a code from an authenticator app.
- Passwords are stored only as salted hashes — we cannot read yours, and neither can anyone who steals the database file.
- Sensitive fields such as ID and bank account numbers are masked from staff who have no reason to see them in full.
- Company documents can only be opened after a request giving a reason, approved by two different people, and every download is stamped and registered.
- Every change is written to an audit trail that cannot be edited or deleted, and which is checked for tampering.
- Backups are encrypted, fingerprinted and test-restored on a schedule.
No system is perfect. If a breach occurs that is likely to put you at real risk, we will notify the ODPC within 72 hours and tell you directly without undue delay.
8. Your rights
These are set out in full, with how to use them, on our Data Protection page. In short you may ask us to tell you what we hold, correct it, delete it, stop using it, give you a copy, or object — and you may complain to the ODPC.
9. Children
Our services are for adults. We do not knowingly collect data about anyone under 18 except where a parent or guardian is transacting on their behalf or where a tenancy or employment record properly requires it. If you believe we hold a child's data that we should not, tell us and we will remove it.
10. Changes
When this policy changes materially, we will post a notice on this page and change the review date at the top. Continuing to use our services after that means you accept the updated policy.
This document is published by Wanjibots Limited, a company registered in Kenya. If anything here is unclear, ask us before you rely on it — we would rather explain it than have you guess.
Version of 21 September 2026. We will post a notice on this page when it changes materially, and the date above will change.