Privacy Policy
Not legal advice — draft pending advocate review
This document has not been reviewed or approved by a qualified Kenyan advocate. Every unresolved question
is marked [verify with counsel] in the source document. It must not be treated as a
representation that Dalfal has completed ODPC registration or any other regulatory step referenced below.
Questions: privacy@dalfal.com.
Contents
- Who We Are
- Scope of This Policy
- Kunde vs Fundi Verification
- What We Collect, Why, and Our Legal Basis
- Data We Do Not Collect
- Third Parties and Processors
- Retention Periods
- Cross-Border Transfers
- Security Measures
- Your Rights Under the Data Protection Act 2019
- Children's Data
- Breach Notification
- Marketing Communications
- Automated Decision-Making
- Changes to This Policy
- Governing Law
- Contact Us
- Open items for counsel
1. Who We Are
Dalfal ("the Operator", "we", "us", "our") operates the Dalfal marketplace, a two-sided services platform connecting customers ("Kunde") who post tasks with skilled workers ("Fundi") who bid on and complete them. Payments are processed through Paystack, over the M-Pesa and Airtel Money mobile-money rails in Kenya.
Data controller: Dalfal [registered legal entity name, company number, and registered office — to be inserted before publication]. Email: privacy@dalfal.com.
We process Fundi national-ID images and biometric selfie data, and intermediate mobile-money payments — categories that Kenya's Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021 list as mandatory-registration sectors regardless of turnover or headcount. We have not yet completed registration with the Office of the Data Protection Commissioner (ODPC) as of the version date above; our registration reference will be published here once registration is complete.
2. Scope of This Policy
This policy covers personal data we collect through the Dalfal app (Android and iOS), our backend services, the dalfal.com website, and account-related communications (login codes, payment notifications). It does not cover Fundis' own practices, or the practices of Paystack, Safaricom, or Airtel Kenya.
3. Kunde vs Fundi Verification
Kunde: verified by phone number only. We never collect a Kunde's selfie, national ID, or biometric data.
Fundi: because a Fundi enters customers' homes and receives real payouts, we require full KYC — a government ID and a live selfie taken in the app, checked against the ID portrait — before a booking can be accepted.
4. What We Collect, Why, and Our Legal Basis
Legal-basis labels use the six grounds in section 30 of the Data Protection Act No. 24 of 2019 (consent, contract, legal obligation, vital interests, public interest, legitimate interests).
| Category | Who | Why / legal basis | Retention |
|---|---|---|---|
| Verified phone number | Kunde, Fundi | Account identity; contract, s. 30(b) | Life of account + 12 months |
| Email address (also required by Paystack per transaction) | Kunde, Fundi | Login codes and Paystack transaction requirement; contract, s. 30(b) | Life of account + 12 months |
| Full name | Kunde, Fundi | Profile display and Paystack payout name; contract, s. 30(b) | Life of account + 12 months |
| Government ID image | Fundi only | KYC — sensitive personal data; explicit consent, s. 45 | Life of account + 2 years |
| Live selfie (taken in-app) | Fundi only | Face-match against ID; explicit consent, s. 45 | Life of account + 2 years |
| ID number (hashed) + last 4 digits | Fundi only | Duplicate-account prevention; contract / legitimate interest, s. 30(b)/(f) | Life of account + 2 years |
| Date of birth | Fundi only | Age and duplicate-account checks; explicit consent, s. 45 | Life of account + 2 years |
| Paystack payment/payout metadata | Kunde, Fundi | Payment operation and financial record-keeping; contract, s. 30(b) | 7 years from transaction |
| Push notification token | Kunde, Fundi | Transactional alerts; contract, s. 30(b) | Refreshed on login; deleted on closure |
| Task content and photos | Kunde, Fundi | Core marketplace function; contract, s. 30(b) | Life of account + 12 months |
| In-app messages | Kunde, Fundi | Job coordination; contract, s. 30(b) | Life of account + 12 months |
| Fundi declared service area | Fundi only | Task matching; consent (opt-in, revocable), s. 30(a) | Until revoked or account closure |
All periods above are interim working values pending sign-off from a qualified Kenyan advocate — see the "Open items for counsel" section below.
5. Data We Do Not Collect
- Kunde selfie or national ID document.
- Any national ID number in plaintext — only a cryptographic hash and the last 4 digits are retained for Fundis.
- Real-time or historical GPS location — the Fundi service area is a declaration, not a location log.
- Biometric data beyond the KYC selfie.
- Marketing or advertising identifiers.
6. Third Parties and Processors
- Paystack — our payment-technology provider. We share your phone number, email, name, and payment/payout amount to collect Kunde payments and disburse Fundi payouts. Paystack routes M-Pesa transactions through Safaricom PLC and Airtel Money transactions through Airtel Networks Kenya Limited. A Fundi's payout always goes to the number on their own Dalfal account record; we populate this field ourselves and never accept a Kunde-supplied number for it (see Terms of Service section 9.8).
- Google Firebase Cloud Messaging — Android push notifications (device token and notification text only).
- Apple Push Notification service — iOS push notifications (device token and notification text only).
- Object-storage provider — stores KYC images and task photos privately; region and provider to be confirmed before production KYC launch.
- One-time code and face-match providers — not yet finalised in production.
We do not sell your personal data, and we do not share it for advertising or marketing purposes.
7. Retention Periods
See the table in section 4 above. When an account is closed, we delete or anonymise personal data within the applicable retention window, except where retention is required by Kenyan law (for example, tax and accounting records) or necessary for the establishment, exercise, or defence of legal claims.
Retention after account deletion. Deleting your account ends your access immediately and removes your profile from other users, but we retain a reduced record for a defined period afterwards: a basic account record (phone, name, email, task/bid history, and a matching identifier used only for the re-registration review below, but not your KYC images) for 24 months from the deletion date, and payment/payout metadata for the existing 7-year window, for fraud prevention, dispute resolution, and legal claims. We may disclose this retained record to a competent Kenyan law-enforcement or judicial authority acting on a valid legal request during those periods; that disclosure possibility is a consequence of the retention, not the reason for its length. If you register again after a prior account of yours was deleted, your registration is not blocked and you are not told a prior account existed — it may be flagged for an internal, staff-only review comparing it against previously deleted accounts; that comparison and its result are never disclosed to you or any other user. [verify with counsel — this section does not describe the matching identifier as "irreversible": a fast, unsalted hash of a Kenyan phone number is not cryptographically irreversible on its own, so the protection relied on here is staff-only access control, not hash strength. Confirm the 24-month period and its legitimate-interest basis under Data Protection Act 2019 ss. 25(e) and 30(f), and confirm the anti-enumeration design against any Kenyan transparency obligation. As of this version this is the target retention policy — the current account- deletion handler performs an immediate hard delete with no post-deletion retention window; see `docs/compliance/data-retention-and-dsar.md`.]
8. Cross-Border Transfers
Under Data Protection Act 2019 section 48, a transfer of personal data outside Kenya must rest on proof of appropriate safeguards or a necessity ground (including necessity for contract performance). Section 49 additionally requires your explicit consent for any cross-border transfer of sensitive personal data (such as KYC images), plus confirmed safeguards.
- Paystack — phone number, email, name, payment amount — necessity for contract performance.
- Google LLC (USA) and Apple Inc. (USA) — push notification tokens and text — necessity for contract performance.
- Object-storage provider (region to be confirmed) — KYC images (Fundi only) — sensitive personal data, requires explicit consent plus confirmed safeguards.
We do not sell your personal data to third parties.
9. Security Measures
- Row-Level Security on our own self-hosted PostgreSQL database — not Supabase or any third-party database service.
- All traffic between the app and our servers is encrypted in transit (HTTPS/TLS).
- Encryption at rest — [verify: to be confirmed by the infrastructure team before this claim is made].
- Sessions expire automatically (24 hours for users, 8 hours for staff).
- KYC images live in a private object store with no public link; staff access requires explicit capability grant and is permanently logged.
- GPS and other metadata are stripped from all photos before storage.
- Phone numbers, ID numbers, and Paystack transaction identifiers are never written to system logs.
10. Your Rights Under the Data Protection Act 2019
Section 26 of the Act gives you the right to be informed, to access, to rectify, to erase, to object, to withdraw consent, and (where feasible) to data portability. Email privacy@dalfal.com with "Data Subject Request" in the subject line; we will verify your identity before acting and will not charge a fee for reasonable requests. You may also complain to the Office of the Data Protection Commissioner (ODPC) via odpc.go.ke.
Erasing your account ends your access immediately but does not erase every record on the spot — see section 7 above for the reduced record we retain after deletion, for how long, and why.
11. Children's Data
Dalfal is not directed at children. You must be at least 18 to create an account. If you believe a child has created an account, contact privacy@dalfal.com.
12. Breach Notification
Under Data Protection Act 2019 section 43, we will notify the ODPC without undue delay and, where feasible, within 72 hours of becoming aware of a breach presenting a real risk of harm to you, and will notify you directly in writing where the risk to you is real.
13. Marketing Communications
We do not currently send marketing messages — only transactional account and payment alerts. If that changes, we will obtain separate opt-in consent under Data Protection Act 2019 section 37 and provide a free opt-out in every message.
14. Automated Decision-Making
We do not currently make decisions that significantly affect you based solely on automated processing. Fundi KYC approval decisions are made by staff reviewing submitted documents manually.
15. Changes to This Policy
We will update the "Last updated" and "Version" date above when we change this policy, notify you in the app or by email if the change is material, and link you to the specific versioned URL that applies — never an unversioned "latest" page.
16. Governing Law
This policy is governed by the laws of the Republic of Kenya, including the Data Protection Act No. 24 of 2019 and its subsidiary Regulations. The competent supervisory authority is the Office of the Data Protection Commissioner (ODPC).
17. Contact Us
DalfalPrivacy and data-protection requests: privacy@dalfal.com
We aim to acknowledge your message within 2 business days. Also read our Terms of Service.
Open items for counsel before publication
The full itemised counsel-review backlog (14 numbered items covering ODPC registration, retention
periods, the lawful basis for Fundi biometric data, cross-border transfer safeguards, Paystack's
corporate/regulatory status, and more) is maintained in the source document
docs/legal/privacy-policy.md, in the "Open questions" section. This page is a published
rendering of that document; the source document is the working list counsel should review.