Privacy Policy

1.0 Introduction

Your privacy is important to us. This privacy statement explains the personal data Tupay collects, how Tupay processes it, and for what purposes.

This statement should be read together with the Terms and Conditions of Use for other Tupay products and services. Where there is a conflict, this statement will prevail.

This statement applies to all customers, suppliers, agents, merchants, dealers and all visitors frequenting any of Tupay premises.

2.0 Definitions

References to

2.1 "You" means:

i) Customer- the person who subscribes to, uses or purchases any of our products and services or accesses our websites and includes any person who accesses any of the products and services you have subscribed to.

ii) Any agent, dealer and/or merchants who has signed an agreement with us and is recognized as a merchant or agent in accordance with any applicable laws or regulations.

iii) Any visitor that is a person (including contractors/subcontractors or any third parties) who gains access to any Tupay premises.

iv) Any partner who has been contracted by Tupay and executed a partner contract.

3.0 Statement Details

3.1 Collection of Information

3.1.1 We collect your personal information with your knowledge and consent when you do any of the following (please note that this list is not exhaustive):

a) register for a specific product or service, including but not limited to Tupay and Tupay-powered services;

b) buy, subscribe to or use a Tupay product or service online, on the cloud, on a mobile or other device

c) subscribe to Tupay or third-party premium rates services, Short Message Service (SMS), email or social media platforms;

d) ask Tupay for more information about a product or service or contact Tupay with a query or complaint;

e) respond to or participate in a survey, marketing promotion, prize competition or special offer;

f) visit, access or use Tupay or third-party websites;

g) We may also collect your information from other organizations including credit-reference bureaus, fraud prevention agencies and business directories;

h) We may collect your information when you interact with us as a supplier, agent, merchant or dealer as prescribed in this statement;

i) We also collect information when you visit any of our premises.

3.2 What Information is collected?

The information we collect and store about you includes but is not limited to the following:

3.2.1 Your identity, phone number, location and device Id. You can optionally provide your name, photograph, address, identity document type and number, date of birth, email address, age and gender.

3.2.2 Your can optionally provide credit or debit-card information, information about your bank account numbers and SWIFT codes or other banking information.

3.2.3 Your transaction information when you use our Tupay service.

3.2.4 Your preferences for particular products and services, based on information provided by you or from your use of Tupay’s (or third party) network, products and services.

3.2.5 You can optionally provide your name and profiling information such as level of education, income brackets, etc. collected as part of surveys conducted by Tupay and their agents on behalf of Tupay.

3.2.6 Your contact with us, such as when you: call us or interact with us through social media, email, register your biometric information such as your voice, finger prints etc.

3.2.7 Your contact list can be accessed upon your permission and the contacts you select will be collected.

3.2.i8 Your mobile money payment confirmation sms can be accessed upon your permission to process payments.

3.3 Use of Information

We may use and analyse your information for the following purposes:

3.3.1 Processing products and services that you have bought from Tupay or from third parties;

3.3.2 Billing you for products or services or taking the appropriate amount of credit from you;

3.3.3 Responding to any of your queries or concerns;

3.3.4 Verifying your identity information through publicly available and/or restricted government databases in order to comply with applicable regulatory requirements;

3.3.5 Carrying out credit checks and credit scoring;

3.3.6 Keeping you informed generally about new products and services and contacting you with offers or promotions based on how you use our or third-party products and services unless you opt out of receiving such marketing messages (you may contact Tupay at any time to opt out of receiving marketing messages);

3.3.7 to comply with any legal, governmental or regulatory requirement or for use by our lawyers in connection with any legal proceedings;

3.3.8 In business practices including to quality control, training and ensuring effective systems operations;

3.3.9 To protect our network including to manage the volume of use of our service;

3.3.10 To understand how you use our products and services for purposes of developing or improving products and services;

3.3.11 Preventing and detecting fraud or other crimes;

3.3.12 For research, statistical, survey and other scientific or business purposes;

3.3.13 Provide aggregated data (which do not contain any information which may identify you as an individual) to third parties for research and scientific purpose;

3.3.14 Administer any of our online platforms/websites.

3.3.15 Contact lists are saved for ease of access of preferred contacts.

3.3.16 SMS confirmation from mobile money payments.

3.4. Categories of Data

Categories of Personal Data as defined in the Data Protection Act may be processed depending on the particular types of products and services you have subscribed to.

3.5. Lawful Basis for processing your information

We will process your personal information based on any of the lawful basis provided for under the Data Protection Law:

3.5.1 The performance of a Product/Service Agreement with you;

3.5.2 Tupay’s legitimate business interests;

3.5.3 Compliance with a mandatory legal obligation;

3.5.4 Consent you provide;

3.5.5 Public interest;

3.5.6 Your vital interest.

3.6. Retention of Information

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements.
We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, the need to comply with our internal policy and the applicable legal, regulatory, tax, accounting or other requirements.

Anonymized information that can no longer be associated with you may be held indefinitely.

4.0 Disclosure of Information

4.1 Any disclosure of your information shall be in accordance with applicable law and regulations. Tupay shall assess and review each application for information and may decline to grant such information to the requesting party.

4.2 We may disclose your information to:

a) law-enforcement agencies, regulatory authorities, courts or other statutory authorities in response to a demand issued with the appropriate lawful mandate and where the form and scope of the demand is compliant with the law.

b) our subsidiaries, associates, partners, software developers or agents who are involved in delivering Tupay products and services you order or use;

c) Fraud prevention and Anti money laundering agencies, credit-reference agencies;

d) publicly available and/or restricted government databases to verify your identity information in order to comply with regulatory requirements;

e) debt-collection agencies or other debt-recovery organizations;

f) Survey agencies that conduct surveys on behalf of Tupay;

g) Emergency service providers when you make an emergency call (or where such disclosure to emergency service providers is necessary for your rescue, health and safety) including your approximate location;

h) Any other person that we deem legitimately necessary to share the data with.

4.3 Some of your information may be passed on to any person whom you receive money from or send or intend to send money to.

4.4 We shall not release any information to any individual or entity that is acting beyond its legal mandate.

4.5 We will get your express consent before we share your personal data with any third party for direct marketing purposes.

4.6 Direct Marketing

4.6.1 You may be required to opt in or give any other form of explicit consent before receiving marketing messages from us.

4.6.2 You can ask us to stop sending you marketing messages at any time by writing to us or by attending to us or contacting us at any time through the provided contacts.

4.6.3 Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a product, service already taken up, warranty registration, product or service experience or other transactions].

5.0 The Use of Cookies

5.1 We may store some information (using "cookies") on your computer when you visit our websites. This enables us to recognize you during subsequent visits. The type of information gathered is non-personal (such as: the Internet Protocol (IP) address of your computer, the date and time of your visit, which pages you browsed and whether the pages have been delivered successfully.

5.2 We may also use this data in aggregate form to develop customized services - tailored to your individual interests and needs. Should you choose to do so, it is possible (depending on the browser you are using), to be prompted before accepting any cookies, or to prevent your browser from accepting any cookies at all. This will however cause certain features of the web site not to be accessible.

6.0 The Use of Hyperlinks

6.1 Our websites may provide hyperlinks to other locations or websites on the Internet. These hyperlinks lead to websites published or operated by third parties who are not affiliated with or in any way related to us and have been included in our website to enhance your user experience and are presented for information purposes only.

6.2 We do not endorse, recommend, approve or guarantee any third- party products and services by providing hyperlinks to an external website or webpage and do not have any co-operation with such third parties unless otherwise disclosed. We are not in any way responsible for the content of any externally linked website or webpage.

6.3 By clicking on a hyperlink, you will leave the Tupay webpage and accordingly you shall be subject to the terms of use, privacy and cookie policies of the other website that you choose to visit.

7.0 Access to and Updating your Information

To update your information, go to https://selfcare.tupay.co.ke and sign in to my Tupay self-care to look at your personal information. You can change how we get in touch with you and your account details whenever you like.

8.0 Safeguarding and Protection of Information

Tupay has put in place technical and operational measures to ensure integrity and confidentiality of your data via controls around: information classification, access control, cryptography, physical and environmental security and monitoring and compliance.

9.0 International Data Transfers

From time to time we may need to transfer your personal information outside the country.

Where we send your information, we will make sure that your information is properly protected in accordance with the applicable Data Protection Laws.

10.0 Your Rights

Subject to legal and contractual exceptions, you have rights under data protection laws in relation to your personal data. These are listed below: -

a) Right to be informed that we are collecting personal data about you;

b) Right to access personal data that we hold about you and request for information about how we process it;

c) Right to request that we correct your personal data where it is inaccurate or incomplete;

d) Right to request that we erase your personal data noting that we may continue to retain your information if obligated by the law or entitled to do so;

e) Right to object and withdraw your consent to processing of your personal data. We may continue to process if we have a legitimate or legal reason to do so;

f) Right to request restricted processing of your personal data noting that we may be entitled or legally obligated to continue processing your data and refuse your request;

g) Right to request transfer of your personal data in [an electronic format].

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within reasonable time. Occasionally it could take us longer if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

11.0 How to Delete Your Data

These are the steps you can take to delete your data: -

1) Go to settings;

2) Click on Delete data;

12.0 How to Contact Us

Tupay
support@tupay.co.ke

13.0 Amendments to this Statement

Tupay reserves the right to amend or modify this statement at any time.