Back to FOBO Control

FOBO Control - Privacy Policy

Effective date: 03 June 2021 · Last updated: 01 January 2026

This Privacy Policy explains how FOBO Technologies Ltd ("FOBO", "we", "us") collects, uses, shares, and protects personal data processed through the FOBO Control platform (the "Service"), in compliance with the Data Protection Act, 2019 (Kenya) ("DPA") as enforced by the Office of the Data Protection Commissioner ("ODPC").

This policy covers the FOBO Control Service only. Data collected through our marketing website is governed by the separate Website Privacy Policy at fobotechnologies.co.ke .

1. Controller and Processor Roles

FOBO acts as a data controller for account and billing data relating to Customer itself; the organization that signs up for the Service (business registration details, authorized user names, contact information, and API credentials).

FOBO acts as a data processor on Customer's behalf for personal data Customer submits or generates through the Service about its own end customers or members; such as phone numbers, transaction records, and message recipients. Customer remains the data controller for that data and is responsible for having a lawful basis to collect and share it with us. Where required, the relationship for processor-role data is additionally governed by a Data Processing Agreement between FOBO and Customer.

2. What We Collect

  • Account data: Customer's business name, registration details, authorized user names, email addresses, and phone numbers.
  • Transaction data: M-Pesa transaction references, amounts, timestamps, phone numbers of payers/payees, and status, generated through C2B, B2C, and B2B flows.
  • Messaging data: recipient phone numbers and delivery status for bulk SMS and USSD sessions initiated through the Service.
  • Technical data: API request logs, IP addresses, and authentication events, retained for security and audit purposes.

We do not collect national ID numbers, passwords to Customer's own systems, or full M-Pesa PINs, these are never transmitted through or visible to the Service.

3. Legal Basis for Processing

  • Contractual necessity: processing account and transaction data is required to provide the Service under our agreement with Customer;
  • Legal obligation: retaining transaction records to meet anti-money laundering, tax, and financial record-keeping obligations under Kenyan law;
  • Legitimate interest: securing the Service, detecting fraud, and maintaining audit logs.

4. Sharing of Data

We share data only as necessary to provide the Service:

  • With Safaricom's M-Pesa/Daraja platform, to execute payment instructions Customer initiates;
  • With SMS and USSD network providers, to deliver messages Customer sends;
  • With cloud infrastructure and hosting providers, under contractual confidentiality and security obligations;
  • With regulators, auditors, or law enforcement, where required by Kenyan law, including under the Proceeds of Crime and Anti-Money Laundering Act, 2009.

We do not sell personal data processed through the Service.

5. International Transfers

Where infrastructure providers process data outside Kenya, we ensure the transfer complies with Section 48 of the DPA, including verification of adequate safeguards or contractual protections equivalent to those required under Kenyan law.

6. Data Retention

Transaction and account data is retained for as long as the Customer relationship is active, and afterward for the period required by applicable Kenyan financial record-keeping and anti-money laundering obligations. API logs are retained for a shorter period sufficient for security monitoring, after which they are deleted or anonymized.

7. Security

We apply encryption in transit and at rest for sensitive fields, role-based access controls, API key rotation, and regular review of third-party processors. No system is completely secure, and we cannot guarantee absolute protection against unauthorized access.

8. Data Subject Rights

Individuals whose data is processed through the Service (such as a Customer's members or transaction counterparties) may exercise their DPA rights - access, correction, deletion, objection, and data portability - by contacting the relevant Customer directly, as Customer is the data controller for that data. Where FOBO acts as controller (Section 1), individuals may contact us directly using the details in Section 10.

Any data subject may also lodge a complaint with the Office of the Data Protection Commissioner, Kenya odpc.go.ke.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes affecting how Customer or Customer's end users' data is processed will be communicated to Customer in advance where reasonably practicable.

10. Contact and Data Protection Officer

Questions about this Policy or data rights requests may be directed to our Data Protection Officer at dpo@fobotechnologies.co.ke