Privacy Policy

Last updated: 1 July 2026  ·  Effective: 1 July 2026

Rafiki Technologies Limited complies with the Kenya Data Protection Act, 2019 (Cap. 411C) and the Data Protection (General) Regulations, 2021. We are committed to protecting your personal data and business information.

1. Who We Are

Rafiki Technologies Limited ("Rafiki", "we", "us") is the data controller for personal data collected through the Rafiki platform. We operate a cloud-based Point of Sale and ERP platform at rafikiatwork.com, serving businesses across Kenya.

2. Data We Collect

2.1 Account and Business Data

  • Business name, slug, type (e.g. pharmacy, retail), and city
  • Administrator name and email address
  • Password (stored as a bcrypt hash — we cannot recover your password)
  • Staff profiles: name, email, role, phone number (if provided)
  • Organisation settings including M-Pesa and KRA eTIMS configuration

2.2 Business Transaction Data

  • Sales records, receipts, and payment details
  • Inventory and stock movements
  • Purchase orders and supplier records
  • Customer names, phone numbers, and loyalty data (if your business collects them)
  • Financial records including VAT, payroll, and accounting entries

2.3 Technical and Usage Data

  • IP address and browser/device type (for security logging)
  • Login timestamps and session tokens
  • Feature usage patterns (used to improve the platform)
  • Error logs and performance metrics

3. How We Use Your Data

We process your data for the following purposes:

  • Service delivery: Operating the platform, processing transactions, and providing all features you have subscribed to
  • Authentication and security: Verifying identity, preventing unauthorised access, and detecting fraud
  • Compliance: Supporting your KRA eTIMS filing obligations and other regulatory requirements
  • Service improvement: Analysing usage patterns to improve features and fix bugs
  • Communication: Sending service notifications, invoices, and product updates (you may opt out of marketing emails)
  • AI features: Enterprise plan subscribers who enable AI forecasting will have their anonymised transaction data processed to generate predictions

4. Lawful Basis for Processing

Under the Kenya Data Protection Act, 2019, we process your personal data on the following lawful bases:

  • Contract: Processing necessary to provide the Service you have subscribed to
  • Legal obligation: Compliance with KRA, CAK, and other Kenyan regulatory requirements
  • Legitimate interests: Security monitoring, fraud prevention, and service improvement
  • Consent: Marketing communications and optional data features (you may withdraw consent at any time)

5. Data Storage and Security

Your data is stored on a dedicated virtual private server (VPS) in the European Union (OVH, France), which is subject to GDPR-equivalent data protection standards. We have entered into the necessary data processing agreements with our hosting provider.

Security measures include:

  • TLS encryption for all data in transit (HTTPS)
  • Encrypted passwords using bcrypt hashing
  • JWT-based session tokens with short expiry periods
  • Multi-factor authentication (MFA) available for all accounts
  • Role-based access control (staff see only what their role permits)
  • Regular security audits and penetration testing

We retain your data for the duration of your subscription plus 90 days after termination (to allow data export). After that period, data is permanently deleted.

6. Data Sharing

We do not sell your personal or business data. We may share data with:

  • OVH (hosting): For the purpose of operating our servers
  • Safaricom (M-Pesa): Payment transaction data necessary to process M-Pesa payments on your behalf
  • KRA (eTIMS): Fiscal receipt data required by law for eTIMS-enabled organisations
  • SMS provider: Phone numbers used for loyalty campaign messages (only if you enable this feature)
  • Law enforcement: When required by a valid court order or legal obligation under Kenyan law

7. Your Rights Under the Kenya DPA 2019

As a data subject, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate personal data
  • Right to erasure: Request deletion of your personal data (subject to legal retention obligations)
  • Right to object: Object to processing based on legitimate interests
  • Right to data portability: Receive your data in a machine-readable format
  • Right to withdraw consent: Withdraw consent for marketing or optional features at any time

To exercise any of these rights, email [email protected] with the subject line "Data Request". We will respond within 21 days as required by the Kenya DPA 2019.

8. Cookies

We use cookies to maintain your login session. See our Cookie Policy for full details.

9. Children's Privacy

The Service is intended for use by businesses and persons aged 18 and above. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy when our data practices change or when required by law. We will notify you by email and within the platform at least 14 days before any material changes take effect.

11. Contact and Complaints

For privacy questions or to exercise your rights, contact our Data Protection Officer:

Rafiki Technologies Limited — Data Protection Officer
Nairobi, Kenya
Email: [email protected]

If you are unsatisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya at odpc.go.ke.