Effective Date: September 15, 2026
Regulatory Framework: Kenya Data Protection Act (2019) & ODPC Alignment
1. Introduction & Statutory Scope
This Unified Privacy Policy governs the collection, processing, storage, transit encryption, and deletion of personal, corporate, and telemetry data across the entire Nyota Core ecosystem, including:
- Nyota Accounts & IAM (accounts.nyotaimara.com): Central identity provider, workspaces, policy-based access controls, and billing ledgers;
- Nyota ID (nyotaimara.com/nyota-id): Automated Know-Your-Customer (KYC) and Know-Your-Business (KYB) identity verification APIs;
- Nyota Mail (mailadmin.nyotaimara.com): Custom domain business email hosting, pooled storage allocation, and mail consoles;
- Nyota Drive (drive.nyotaimara.com): S3-compatible cloud object storage, global CDN edge delivery, and web file managers; and
- Nyota SMS (sms.nyotaimara.com): Transactional SMS, OTP delivery APIs, and campaign outbox systems.
We process personal data in strict compliance with the Kenya Data Protection Act (2019), statutory regulations issued by the Office of the Data Protection Commissioner (ODPC) Kenya, and international benchmarks (GDPR) governing cross-border transfers and sub-processor accountability.
2. Information We Collect
We collect only the minimum data necessary to operate resilient, secure, and legally compliant cloud infrastructure services.
A. Account & Profile Information
- Individual Users: Full legal name, verified email address, MSISDN phone number (E.164 format), date of birth, profile avatars, and multi-factor authentication credentials.
- Business Workspaces: Registered business name, corporate workspace identifiers, billing contact details, physical address, and Kenya Revenue Authority (KRA) PIN tax certificate disclosures.
- Organizational Units (OUs): Internal department hierarchies, team assignments, and Policy-Based Access Control (PBAC) rules.
B. Identity Verification Data (Nyota ID & Self-Dogfooding KYC/KYB)
- Individual KYC: Government ID metadata (document type, issuing authority, document number, date of expiry), verification session IDs, decision verdicts (verified, declined), rejection reason codes, and verification timestamps. Biometric 3D passive liveness checks run client-side/in-transit via Didit and are ephemeral.
- Corporate KYB: Certificate of Incorporation numbers, CR12 official document extracts, tax status registration numbers, and listed director disclosures.
C. Nyota Drive Storage Metadata & Object Data
- File Metadata: File display names, MIME content types, exact file sizes (in bytes), upload reservation tokens, S3 entity tags (ETags), and folder directory paths.
- Object Data: Binary objects, source code, documents, and media uploaded to your private or public storage allocations.
- Share Links & Security Rules: Share tokens, access expiration timestamps, salted bcrypt password hashes for password-protected shares, download counts, and revocation audit timestamps.
D. Network Telemetry, Security & Device Intelligence
- Authentication Logs: IP addresses, Internet Service Provider (ISP), derived city/country geolocation, user-agent browser signatures, and device fingerprint hashes.
- Operational Telemetry: REST API access metrics, Class A operations (writes, mutations, state changes), Class B operations (reads, object downloads), and rate-limiting bucket tracking.
3. Legal Bases for Processing Under the Kenya Data Protection Act (2019)
In accordance with Section 30 of the Kenya Data Protection Act (2019), Nyota Imara processes personal data under the following lawful bases:
- Performance of a Contract: Processing is necessary to provision your workspaces, host your mailboxes, route your SMS dispatches, store your files on Nyota Drive, authenticate API calls, and maintain uptime SLAs.
- Compliance with Legal Obligations: Processing corporate KRA PINs, Certificate of Incorporation records, and transaction ledgers is required to comply with Kenyan tax laws, corporate registry obligations, and anti-money laundering (AML) frameworks.
- Legitimate Interests: Monitoring network telemetry, recording authentication anomalies, running device fingerprinting, and rate-limiting API endpoints are necessary to protect our infrastructure against cyber threats, credential stuffing, and billing fraud.
- Explicit Consent: Where you opt-in to biometric liveness checks, marketing updates, or authorize third-party OAuth applications, processing is based on your explicit consent, which may be withdrawn at any time.
4. Sub-Processor Disclosures & Third-Party Sharing
We do not sell, rent, or trade your personal or business data. To deliver enterprise-grade performance, we transmit data to trusted sub-processors operating under strict Data Processing Agreements (DPAs):
5. Ephemeral Biometric Vector Policy & Data Retention
A. Ephemeral Biometric Vector Policy
In accordance with ODPC data minimization principles, Nyota Imara does not permanently store or retain raw biometric 3D facial vector meshes or unencrypted identity document scans in primary relational databases. Biometric liveness frames processed through Nyota ID are handled ephemerally during active session execution by Didit.
B. Retention Lifecycles
- Nyota Drive Soft-Deletion (30 Days): Deleted files remain in the Trash bin for thirty (30) calendar days. On the 31st day, automated background sweepers permanently and irreversibly purge the binary object from database indexes and Cloudflare R2 servers.
- Abandoned Upload Reservations (24 Hours): Uncommitted upload reservations expire after 1 hour and are purged within 24 hours.
- Test Sandbox Data (24 Hours): Objects uploaded using test API keys (ny_test_...) are automatically purged after 24 hours.
- Financial Ledgers & Invoices (7 Years): Billing transaction logs and tax invoices are retained for seven (7) years in accordance with Kenyan tax laws.
- Account Termination: Upon verified request to terminate an account or workspace, linked files, API keys, and policies are permanently purged within 30 days.
6. Your Rights Under the Kenya Data Protection Act (2019)
As a data subject under the Data Protection Act (2019), you hold specific enforceable statutory rights:
- Right to be Informed: To receive clear, transparent disclosures about how your data is collected and processed (as set out in this Policy).
- Right of Access: To request confirmation of whether we hold personal data concerning you and to receive a copy of that data.
- Right to Rectification: To request the correction of inaccurate, outdated, or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): To request the permanent deletion of your personal data where there is no overriding legal ground for continued processing.
- Right to Object / Restrict Processing: To object to the processing of your data for direct marketing, profiling, or automated decision-making.
- Right to Data Portability: To receive your personal data in a structured, machine-readable format or request its transfer to another data controller.
To exercise any of these rights, contact our Data Protection Officer at privacy@nyotaimara.com. Requests are processed within the statutory 30-day timeline following identity verification.
7. Technical & Organizational Security Controls
We deploy multi-layered security controls to safeguard platform data:
- Transit Encryption: Enforced TLS 1.3 / HTTPS across all subdomains and API endpoints.
- Rest Encryption: AES-256 encryption across Cloudflare R2 object storage and relational database clusters.
- API Key Hashing: Secret API keys (ny_live_...) are stored exclusively as non-reversible SHA-256 hashes.
- Zero Trust Staff Access: Internal administrative tools are protected behind Cloudflare Access Zero Trust with mandatory hardware token Multi-Factor Authentication (MFA).
8. Data Protection Officer & Regulatory Complaint Contacts
If you have questions, concerns, or wish to exercise your data protection rights, please contact our designated compliance team:
Lodging a Complaint with the Regulator
If you believe your data protection rights have been infringed and we have not resolved your concern adequately, you have the right to lodge a formal complaint with the regulator: