Effective date: 03 June 2021 · Last updated: 01 January 2026
This Privacy Policy explains how FOBO Technologies Ltd ("FOBO", "we", "us") collects, uses, shares, and protects personal data processed through the FOBO Control platform (the "Service"), in compliance with the Data Protection Act, 2019 (Kenya) ("DPA") as enforced by the Office of the Data Protection Commissioner ("ODPC").
This policy covers the FOBO Control Service only. Data collected through our marketing website is governed by the separate Website Privacy Policy at fobotechnologies.co.ke .
FOBO acts as a data controller for account and billing data relating to Customer itself; the organization that signs up for the Service (business registration details, authorized user names, contact information, and API credentials).
FOBO acts as a data processor on Customer's behalf for personal data Customer submits or generates through the Service about its own end customers or members; such as phone numbers, transaction records, and message recipients. Customer remains the data controller for that data and is responsible for having a lawful basis to collect and share it with us. Where required, the relationship for processor-role data is additionally governed by a Data Processing Agreement between FOBO and Customer.
We do not collect national ID numbers, passwords to Customer's own systems, or full M-Pesa PINs, these are never transmitted through or visible to the Service.
We share data only as necessary to provide the Service:
We do not sell personal data processed through the Service.
Where infrastructure providers process data outside Kenya, we ensure the transfer complies with Section 48 of the DPA, including verification of adequate safeguards or contractual protections equivalent to those required under Kenyan law.
Transaction and account data is retained for as long as the Customer relationship is active, and afterward for the period required by applicable Kenyan financial record-keeping and anti-money laundering obligations. API logs are retained for a shorter period sufficient for security monitoring, after which they are deleted or anonymized.
We apply encryption in transit and at rest for sensitive fields, role-based access controls, API key rotation, and regular review of third-party processors. No system is completely secure, and we cannot guarantee absolute protection against unauthorized access.
Individuals whose data is processed through the Service (such as a Customer's members or transaction counterparties) may exercise their DPA rights - access, correction, deletion, objection, and data portability - by contacting the relevant Customer directly, as Customer is the data controller for that data. Where FOBO acts as controller (Section 1), individuals may contact us directly using the details in Section 10.
Any data subject may also lodge a complaint with the Office of the Data Protection Commissioner, Kenya odpc.go.ke.
We may update this Privacy Policy from time to time. Material changes affecting how Customer or Customer's end users' data is processed will be communicated to Customer in advance where reasonably practicable.
Questions about this Policy or data rights requests may be directed to our Data Protection Officer at dpo@fobotechnologies.co.ke