Effective Date: September 15, 2026
Governing Jurisdiction: Republic of Kenya
1. Agreement Scope & Product Addenda Structure
By creating an account, registering a Personal or Business Workspace, generating cryptographic API keys, or utilizing any component of the Nyota ecosystem, you agree to be bound by these Master Terms and our Privacy Policy.
Product-Specific Addenda
In addition to these Master Terms, your use of specific platform products is governed by individual, dedicated Product-Specific Addenda. In the event of a conflict between these Master Terms and a Product Addendum, the specific Product Addendum shall prevail for that product:
- Nyota ID Terms & Addendum: Governs automated KYC/KYB identity verification, 3D passive liveness detection, government registry lookups, and zero-charge failed check policies.
- Nyota Mail Terms & Addendum: Governs custom domain business email hosting, pooled mailbox storage, anti-spam thresholds, and automated IMAP migrations.
- Nyota Drive Terms & Addendum: Governs S3-compatible cloud object storage, zero-egress bandwidth guarantees, public vs. private bucket visibility, and 30-day trash auto-purging.
- Nyota SMS Terms & Addendum: Governs transactional SMS dispatches, local outbox campaign controls, CAK-compliant Branded Sender ID registrations, and carrier delivery disclosures.
2. Identity, Single Sign-On (SSO) & Workspace Governance
A. Central Identity Provider (IdP)
Access to all Nyota Imara subdomains and developer tools is authenticated through our centralized Identity Provider (accounts.nyotaimara.com). You agree to provide accurate, current, and complete account details (legal name, primary email address, phone number) and to keep your authentication credentials strictly confidential.
B. Personal vs. Business Workspaces
All data, API keys, and billing ledgers inside Nyota Imara are logically isolated within a Workspace (workspace_id):
- Personal Workspaces: Created automatically upon user registration for individual testing and personal infrastructure management. Personal Workspaces cannot invite team members or deploy multi-user Organizational Units.
- Business Workspaces: Multi-user environments created for corporate entities. The individual or entity that registers the Business Workspace is designated as the Workspace Owner.
C. Organizational Units (OUs) & Policy-Based Access Control (PBAC)
Business Workspaces support hierarchical Organizational Units (OUs) using materialized path structures (e.g., /executive/sales/field-ops). Resource access is governed by an automated, server-side Policy-Based Access Control (PBAC) engine.
The Workspace Owner and authorized administrators are strictly responsible for:
- Inviting and removing employee, contractor, or collaborator accounts;
- Assigning, modifying, and revoking JSON-based permission policies;
- Configuring department trees and OU resource boundaries; and
- Monitoring all API usage, file uploads, messaging campaigns, and financial charges incurred by invited workspace members.
3. Developer Platform, API Keys & Sandbox Isolation
A. Cryptographic Key Management
Workspace administrators may provision machine-to-machine (M2M) API keys:
- Live Production Keys (ny_live_...): Execute real operations against production carriers, registries, and storage nodes. Charges are billed directly to your live Nyota Wallet or credit line.
- Test Sandbox Keys (ny_test_...): Execute simulated operations in isolated sandbox environments with zero financial cost.
B. Secret Display & Revocation Policy
Nyota Imara displays secret API keys only once upon generation. We store only non-reversible SHA-256 cryptographic hashes of API keys in our database layers. We cannot retrieve, view, or restore a lost secret key.
If an API key is leaked, compromised, or exposed in client-side code, you must immediately revoke it via the Developer Dashboard. Nyota Imara accepts no liability for unauthorized data access, deleted assets, or financial charges resulting from compromised client credentials.
4. Central Billing, Nyota Wallet & Financial Shield Limits
A. Multi-Currency Accounting
Our billing engine operates on an integer-subunit ledger (e.g., KES cents, where 100 cents = KSh 1.00) supporting Kenyan Shillings (KES), US Dollars (USD), Nigerian Naira (NGN), Ghanaian Cedi (GHS), South African Rand (ZAR), and West African CFA franc (XOF) via Safaricom M-Pesa STK Push, Mobile Money, and PCI-DSS Level 1 tokenized Card payments.
B. Prepaid Nyota Wallet
- Non-Refundable Deposits: Funds deposited into your Prepaid Nyota Wallet are converted into platform credits. Wallet deposits are strictly non-refundable and cannot be redeemed for cash.
- Hold-and-Settlement Reserves: When an asynchronous operation is initiated (e.g., a KYC verification session or an SMS campaign queue), the system places an immediate credit hold (reservedCents) on your wallet balance. Final debit occurs upon successful execution. Incomplete, declined, or cancelled requests release holds back to your active balance in full.
C. Financial Shield Limits (Credit Limits & Budget Caps)
To protect customers from runaway API costs or infinite loops in client code:
- Platform Credit Limit: Granted to approved postpaid enterprise accounts.
- Client Budget Cap: Customizable monthly spending caps configured directly by workspace administrators.
Any mutating API request that would cause accrued charges to exceed either the platform credit limit or the client budget cap will be automatically rejected (402 Payment Required).
5. Delinquency, Grace Periods & Workspace Suspension
If an automated subscription renewal or invoice charge fails, the workspace undergoes the following automated lifecycle:
- Day 1 to 7 (Grace Period): Services continue operating normally while automated payment retries are executed against your fallback payment methods.
- Day 8 (Past Due / Read-Only Mode): If payment is not settled within 7 days, the workspace enters past_due status. Workspace members are restricted to Read-Only access (file uploads, new mailbox creation, and new verification sessions are blocked).
- Day 15 (Workspace Suspension): If the invoice remains unpaid after 15 calendar days, all workspace services are fully suspended, public CDN assets are taken offline, API keys are disabled, and mailbox dispatch queues are paused.
- Day 60 (Decommission & Asset Purging): If an account remains delinquent for 60 consecutive calendar days, Nyota Imara reserves the right to decommission mailboxes, purge stored files from Cloudflare R2, and release registered identifiers.
6. Acceptable Use Policy (AUP)
You agree to use our platform and Services strictly for lawful business purposes. You shall not, and shall not permit any third party to:
- Communications Abuse: Send unsolicited commercial emails (SPAM), engage in phishing, forge email headers, or dispatch unauthorized SMS spam campaigns.
- Storage & CDN Abuse: Upload, host, or distribute malware, ransomware, cracked software, pirated media, child sexual abuse material (CSAM), or use public storage buckets as an open proxy or for DDoS reflection campaigns.
- API & Identity Abuse: Circumvent API rate limits (e.g., standard 60 requests/minute thresholds), attempt unauthorized vulnerability scanning, or submit fraudulent identity credentials, deepfaked selfie media, or synthetic identities through Nyota ID.
Violation of this Acceptable Use Policy constitutes grounds for immediate, permanent workspace suspension without prior notice or refund.
7. Intellectual Property & Bespoke Software Ownership
A. Nyota Imara Platform IP
Nyota Imara retains all right, title, and interest in and to the Nyota Core ecosystem, source code, database schemas, algorithms, API specifications, user interfaces, and trademarks. Nothing in these Terms grants you any ownership rights in our underlying platform infrastructure.
B. Customer Content
You retain full ownership and intellectual property rights in all data, files, documents, emails, and media you upload or process through our Services ("Customer Content"). You grant Nyota Imara a limited, non-exclusive, worldwide license to host, store, transfer, and display Customer Content solely as necessary to operate the Services.
C. Custom Software Studio Deliverables
Where Nyota Imara provides custom web, mobile (React Native), or enterprise engineering services under a separate Statement of Work (SOW):
- Upon full settlement of all project invoices, the Customer is granted a perpetual, non-exclusive, worldwide license to the bespoke frontend application code and custom design assets.
- The underlying proprietary Nyota Core infrastructure, shared APIs, and micro-services remain the exclusive intellectual property of Nyota Imara.
8. Warranties & Disclaimers
EXCEPT AS EXPRESSLY SET FORTH IN A WRITTEN ENTERPRISE SERVICE LEVEL AGREEMENT (SLA) SIGNED BY AN AUTHORIZED OFFICER OF NYOTA IMARA, THE SERVICES ARE PROVIDED STRICTLY ON AN "AS IS" AND "AS AVAILABLE" BASIS.
TO THE MAXIMUM EXTENT PERMITTED BY THE LAWS OF KENYA, NYOTA IMARA EXPRESSLY DISCLAIMS ALL WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING BUT NOT LIMITED TO:
- IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT;
- WARRANTIES THAT THE SERVICES WILL BE UNINTERRUPTED, TIMELY, SECURE, ERROR-FREE, OR FREE OF HARMFUL COMPONENTS; AND
- WARRANTIES REGARDING THE VERACITY OR ACCURACY OF THIRD-PARTY IDENTITY OR GOVERNMENT REGISTRY RECORDS RETURNED VIA NYOTA ID.
9. Limitation of Liability (3-Month Fee Cap)
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE KENYAN LAW:
- Exclusion of Consequential Damages: IN NO EVENT SHALL NYOTA IMARA, ITS PARTNERS, DIRECTORS, OFFICERS, EMPLOYEES, AFFILIATES, OR SUB-PROCESSORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, PUNITIVE, COVER, OR CONSEQUENTIAL DAMAGES (INCLUDING LOSS OF PROFITS, LOSS OF REVENUE, LOSS OF GOODWILL, LOSS OF DATA, OR BUSINESS INTERRUPTION), HOWEVER CAUSED, UNDER ANY THEORY OF LIABILITY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
- Aggregate Liability Cap: NYOTA IMARA’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE MASTER TERMS OR ANY SERVICES SHALL BE STRICTLY CAPPED AT THE TOTAL FEES ACTUALLY PAID BY YOU TO NYOTA IMARA FOR THE SPECIFIC SERVICE GIVING RISE TO THE CLAIM IN THE THREE (3) MONTHS IMMEDIATELY PRECEDING THE INCIDENT CAUSING LIABILITY.
10. Indemnification
You agree to defend, indemnify, and hold harmless Nyota Imara Technologies, its partners, officers, employees, and sub-processors from and against any claims, liabilities, damages, awards, losses, costs, or legal fees arising out of or relating to:
- Your breach of these Master Terms or the Acceptable Use Policy;
- Your Customer Content (including copyright infringement or illegal data uploaded to Nyota Drive);
- Your failure to obtain necessary biometric or data privacy consents from your end-users when integrating Nyota ID; or
- Unauthorized access to our Services resulting from your failure to secure developer API keys or workspace credentials.
11. Governing Law & Dispute Resolution
A. Governing Law
These Master Terms, and all claims or disputes arising out of or in connection with them, shall be governed by and construed in accordance with the substantive laws of the Republic of Kenya, without regard to conflict of law principles.
B. Informal Dispute Consultation
In the event of any dispute or claim, the parties shall first attempt in good faith to resolve the matter through informal executive consultations within thirty (30) calendar days of written notification.
C. Jurisdiction
If a dispute cannot be resolved through informal consultation, it shall be submitted to the exclusive jurisdiction of the competent courts located in Nairobi, Kenya.
12. Official Legal Contacts & Notices
All official legal notices, inquiries regarding these Master Terms, or enterprise SLA requests should be directed to: