Paykit Kenya Limited and its affiliates (hereinafter, Paykit, we, us or our) are committed to protecting and respecting your privacy. This Privacy Policy (together with our Terms of Use) governs our collection, processing and use of our Users' and visitors of our Sites' Personal Information. Please find below some basic definitions which may help you to understand this Privacy Policy:
- Paykit affiliates: subsidiaries, parent companies, and companies under common control.
- Personal Information (personal data): any information which identifies you personally or which may help us to identify you (e.g. your name, address, e-mail address, trades etc.).
- Data subject: an identified or identifiable person (our User).
- Data controller: a company which processes personal data on behalf and upon instructions of the Data controller.
- Our Sites websites with the following domains such as Paykit.africa - our Platform used for providing our services to our merchants, clients and their customers as well as our mobile application and smart POS Devices.
- Personal data processing:any operation or set of operations performed on personal data (e.g., collection, storage, use, disclosure erasure).
- Other capitalized terms, not defined above, have the meanings as defined in the Terms of Use and the applicable data protection legislation (namely, the Data Protection Act No 24 of 2019).
The purpose of this Privacy Policy is to inform you of:
- who is Paykit and how you may contact us;
- the kinds of Personal Information which Paykit may collect about you, the reasons for collecting this information, how it may be used and for how long we will keep it;
- our use of information regarding IP addresses and our use of cookies;
- disclosure of Personal Information to third parties;
- information on international data transfer;
- your ability to access, correct, update, restrict use, ask us to transfer and / or delete your Personal Information;
- the extent of automated decision-making or profiling that we carry out using your Personal Information;
- the security measures we have in place to prevent the loss, misuse, or alteration of Personal Information under our control, and your rights to lodge a complaint.
Who is Paykit
Paykit is a company registered in Kenya. Our registered office is at 4th Floor, Stellato Complex, along Muthithi Road, Westlands, Nairobi, Kenya. Established in 2023 as a Payments service Provider, Paykit offers Payment, Agency and Merchant Services via website, mobile app, API and smart POS devices, providing simple and commercially attractive payments services across Africa.
Gathering and Use of Personal Information
We may collect your Personal Information if you use Paykit and open any kind of Account to use the Platform or perform any Transactions on the Platform. This is defined as collection for the purpose of provision of service(s) to you in accordance with our Terms of Use. Please note that if you refuse to share your Personal Information for this purpose we will not be able to provide our services to you.
The types of Personal Information which we collect may include:
- your name;
- your photographic identification;
- details from your identity documents (such as driver license, passport), number of the document, date of issue and expiration;
- your address;
- your phone number;
- your e-mail address;
- your IP address, Browser and Operating System information, geolocation details;
- your banking details including account numbers and payment card data;
- your date of birth;
- your employment details;
- your trades; and
- information on sources of your funds;
- your employment details;
- video footage identifying you.
We will process your Personal Information only for the purpose(s) of providing to you the service(s) that you ask us to provide you, to satisfy the legal obligations stemming from regulatory obligations that arise from providing you the service(s) and our legitimate interest. Based on our legal obligations and legitimate interest we may request other documents for your identity verification and the sources of your funds confirmation for the purposes of money laundering and fraud prevention. To know more about it please see our AML/KYC and Anti-Fraud policies.
We may use your Personal Information for the following purposes:
- to allow you to open and operate an E-wallet Account on the Platform;
- to enable you to complete Transactions on the Platform;
- if you contact us, to reply to your queries;
- to contact you via email or calls;
- to ensure security of your Account (for instance, if you make a request to disable 2-factor authentication on your account we can ask you to provide additional Personal Information to confirm your identity);
- to analyse use of our Sites;;
- as required for regulatory purposes such as Tax, prevention of Money Laundering, prevention of Fraud, adherence to Company statistical reporting obligations etc.;
- to provide you with information about products and promotions that may be of interest to you, from ourselves and third parties, although only if you have specifically agreed to receive such information;
- for market research e.g. surveying our Users' needs and opinions on issues, such as our performance etc. Unless consented, your data for this purpose would be anonymised.
Children's personal data
Please note that our services are exclusively offered to registered business and individuals at least 18 years old. We do not process any Personal Information of children under this age.
Cookies
We use a browser feature known as a cookie, which assigns a unique identification to your computer or phone. Cookies are typically stored on your computer's hard drive. Information collected from cookies is used by us to evaluate the effectiveness of our Sites, analyse trends, and administer the Platform. The information collected from cookies allows us to determine such things as which parts of our Sites are most visited and difficulties our visitors may experience in accessing our Sites. With this knowledge, we can improve the quality of your experience on the Platform by recognising and delivering more of the most desired features and information, as well as by resolving access difficulties. Cookies are widely used on the internet and allow a website/portal to recognise a user's device without uniquely identifying the individual using the computer. These technologies help to make it easier for you to log on and use the site and to provide feedback to us as to which parts of the website you visit, so we can assess the effectiveness of the site and provide a better user experience or to serve Paykit adverts to you whilst browsing other sites. For more information about cookies, including how to see what cookies have been set and how to manage, block and delete them, see www.allaboutcookies.org. You may also be able to configure your browser not to accept cookies, although please bear in mind that this may affect your ability to use the services we provide.
Disclosure of personal information
We use the Personal Information for the purposes indicated at the time you provide us with such information, and/or otherwise for the purposes set out in this Privacy Policy and/or as otherwise permitted by law. We may make available the Personal Information that you provide to us for the limited purpose indicated for and during the provision of the service that you would have requested in particular to:
- our affiliates, agents and representatives;
- payment service providers and financial institutions;
- customer communications platforms;
- our contractors providing software for identity verification purposes;
- our contractors providing us information on sanctions lists from publicly accessible sources.
We may also share User's Personal Information with financial institutions, insurance companies or other companies in the case of a merger, divestiture, or other corporate re-organisation and notify you of such sharing of your information to be able to exercise any of your rights where applicable. We may also share Users' Personal Information with law enforcement or regulatory agencies, as may be required by law. In certain cases, we may not be able to inform you of such sharing of data due to legal restrictions. Any third party which receives or has access to Personal Information shall be required by us to protect such Personal Information and to use it only to carry out the services they are performing for you or for Paykit, unless otherwise required or permitted by law. Such a third party, except for regulatory authorities, would be contractually bound to adhere to the same security and confidentiality policies as Paykit and assume the same responsibilities as Paykit.
The legitimate exercise of any of your rights with Paykit will also be notified to be applied by any such third parties having been given access to your Personal Information. We will ensure that any such third party is aware of our obligations under this Privacy Policy and we will enter into contracts with such third parties by which they are bound by terms no less protective of any Personal Information disclosed to them than the obligations we undertake to you under this Privacy Policy or which are imposed on us under applicable data protection laws.
International data transfers
Our contractors and affiliates are situated at different locations (including countries located outside Kenya and the EU) and we sometimes need to transfer your personal data to third countries to provide our services to you. We strive to ensure adequate level of your personal data protection wherever our contractor is located. Be sure we may transfer your Personal Information only in the following cases:
- if the country where we transfer your Personal Information to provides the adequate level of personal data protection based on the relevant decision of European Commission (you may click here to see the list of such countries)
- if we take appropriate safeguards to ensure that your rights as data subject are protected;
- if any derogations for specific situations apply (for instance, if is such transfer is necessary for the establishment, exercise or defence of legal claims or for important reason of public interest).
Your Rights
You have the right to access your Personal Information and to require the correction, updating and blocking of inaccurate and/or incorrect data by sending an email to us at support@paykit.africa or where possible, you can do these actions in your account profile page yourself. Upon your written request at, we will inform you of the Personal Information relating to you that we hold and the use and general disclosure of your Personal Information. We will also give you a copy of the Personal Information we have retained. There may be a minimal charge for providing you additional copies of your Personal Information to cover administrative costs. You may also request the erasure of both the Account and Personal Information by sending an email to us at: support@paykit.africa. Paykit will action your request, unless we have a legal or regulatory obligation or overriding legitimate interest to store your Personal Information (for instance, in cases you have performed transactions).
You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete. Moreover, you have the right to restrict and object to the processing of your personal data in certain circumstances.
You may also ask us to transfer your Personal Information to another controller of your choice. To ensure the confidentiality, integrity and availability of your information to yourself, we may request you to confirm your identity by providing identification documentation and/or other methods prior to assisting you in exercising any of your rights. If you refuse to prove your identity, we may decline to take actions in respect of your data, save restricting processing, until we can ensure that such actions are the true wish of the data subject.
In the carrying out of our services we may use automated processing and profiling to reduce the risks of fraud, money laundering and abuse of our services. Through this automated processing, we carry out an analysis of your identification, transactional and behavioural patterns. We may not be able to provide you with some or all our services if you do not wish this automated processing to be carried out. If you feel that this processing might be detrimental to you, please contact us on support@paykit.africa and our compliance officer will review your application. Please note, if you make a request, we have one month to respond to you.
Security
We have implemented technical and organisational security measures to ensure the confidentiality, integrity and accountability of your Personal Information and to protect your Personal Information from loss, misuse, alteration or destruction. Such measures include:
- the pseudonymisation, encryption of personal data;
- 2-factor authentication;
- the access control;
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of our processing systems and services;
- the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident.
Only authorised personnel of Paykit have access to your Personal Information, and these personnel are required to treat the information as confidential. Where you have consented to, or we are obliged to pass on Personal Information to third parties to provide you with a requested service or in the carrying out of a regulatory or legal obligation, we will request that the same levels of technical and organisational security measure be applied through contractual arrangements, where possible. We conduct testing, assessment and evaluation of our technical and organisational measures effectiveness on a regular basis. Technical and organisational security measures in place will, from time to time, be reviewed in line with legal and technical developments. In the event of a personal data breach or the failure of the measures of protection of such information we will immediately notify you without undue delay.
Links
There may be links from our Sites to other sites and resources provided by third parties. This Privacy Policy applies only to our Sites. Accessing those third-party sites or sources requires you to leave our Sites. We do not control those third party sites or any of the content contained therein and you agree that we are in no way responsible or liable for any of those third party sites, including, without limitation, their content, policies, failures, promotions, products, services or actions and/or any damages, losses, failures or problems caused by, related to or arising from those sites. We encourage you to review all policies, rules, terms and regulations, including the privacy policies, of each site that you visit.
Retention of personal information
Unless you create an account with us and conduct transactions, we do not retain your payment method information. We will hold your Personal Information only for as long as it is necessary for the purposes described in this Privacy Policy and our own legal and regulatory requirements. In accordance with record keeping activities for Anti-Money Laundering, Tax and Company legal obligations and considering the period during which you may bring legal claims against us under the law of Kenya, we will retain Personal Information for a period of seven years after our User closes his or her Account and terminates legal relationships with us for seven years from the end of the tax period in which the User conducts his or her last transaction. Data stored for regulatory purposes only will be protected from unnecessary processing and will be held only for the purpose of being able to provide information or access to relevant authorities. Our data management infrastructure is hosted both on local company premises and remote backup locations.
Disposal of personal information
Once we do not have any obligation to providing you with a service you requested, nor an obligation to hold Personal Information for regulatory or legal purpose, we will anonymise or dispose of your Personal Information in line with acceptable industry and security standards so that this cannot be subsequently retrieved and associated to you. Where we cannot directly remove such records, such as in archived backups, we will retain a log of which Personal Information should be removed if ever the backup data is restored.
Marketing
You expressly consent to and authorize Paykit Kenya Limited (“Paykit”) to collect, use, and process your personal information to provide and improve its services, communicate with you, and send information or updates relevant to your use of the Paykit platform. From time to time, Paykit may also send you marketing or promotional communications relating to products and services offered by Paykit, its affiliated companies, subsidiaries, holding companies, or business partners within the Paykit group. Paykit Kenya Limited may also send information concerning your Paykit Account through digital channels, including but not limited to SMS, WhatsApp, and email, using the mobile phone number or email address associated with your account. These communications may include account updates, service notifications, security alerts, or other messages necessary for the effective management of your account and services. Paykit will only send you marketing or promotional communications if you have provided consent. You may withdraw that consent at any time by clicking the unsubscribe link, replying to the message sent, by contacting us at support@paykit.africa, or by adjusting your communication preferences in your account settings, where applicable. To enable the delivery of these communications, Paykit may share limited contact information, such as your name, phone number, or email address, with its affiliates and authorized service providers. All such entities are required to handle your personal data in strict compliance with the Kenya Data Protection Act, 2019, and related regulations, and may only use it for the purposes for which you have granted consent. Paykit will not sell or disclose your personal information to any unaffiliated third party for their independent marketing purposes without your explicit consent. support@paykit.africa.
Our data protection officer
Our Data Protection Officer is the person in charge of ensuring our company adheres to this privacy policy. This person is also the main contact for our Data Protection Supervisory Authority, the Data Protection Commissioner's Office (https://www.odpc.go.ke/). The Data Protection Officer may be contacted on compliance@paykit.africa.
Changes
Our Sites policies, content, information, promotions, disclosures, disclaimers and features may be revised, modified, updated, and/or supplemented at any time and without prior notice at the sole and absolute discretion of Paykit. If we change this Privacy Policy, will take steps to notify all users by a notice on Paykit's Site and will post the amended Privacy Policy on the Paykit's Site. If we consider that your rights may be affected by any such changes, we will request you to confirm your consideration and acceptance prior to continue our relationship with you. This current version of the Privacy Policy has last been amended on the 11th May 2026.
Fraud, phishing and email scams disclaimer
Please be notified that Paykit is not in any partnership with entities who represent themselves as customer support agents, providing customer support services via phone and/or social media and promise to help solve your issues for money. Remember - customer support is provided only via the Paykit website and is always provided free of charge. If you discovered what you believe is a fraud, phishing, or scam which impersonates Paykit, please email us at support@paykit.africa.