UNGANI OS — Privacy Policy
1. Introduction
This Privacy Policy explains how UNGANI ("UNGANI," "we," "us," or "our") collects, uses, stores, and protects information when you use UNGANI OS (the "Platform" or "Service"). This policy is intended to align with the principles of the Kenya Data Protection Act, 2019.
By using UNGANI OS, you consent to the data practices described in this policy.
2. Information We Collect
Information you provide directly:
- Account registration details (name, email, phone number, company name, location)
- Business data you enter into the system (transactions, expenses, assets, tasks, documents, contacts, staff records)
- Communications with our support team
Information collected automatically:
- Login activity and timestamps
- Device/browser information, for security and troubleshooting purposes
- System activity logs (for audit and security purposes)
We do not collect sensitive personal data beyond what is necessary to operate the Service (e.g. we do not collect health, biometric, or similarly sensitive categories of data unless a Client voluntarily records such information within their own business records, in which case the Client is responsible for ensuring lawful basis for that data's collection).
3. How We Use Information
We use collected information to:
- Provide, operate, and maintain UNGANI OS
- Process account registration, billing, and support requests
- Maintain security, including audit logs and fraud/abuse prevention
- Communicate with Clients about their account, billing, or system updates
- Improve the platform based on aggregated, anonymized usage patterns
We do not sell Client business data to third parties.
4. Data Storage and Security
- Client data is stored using Supabase (PostgreSQL-based infrastructure) with role-based access controls and tenant-level data separation, so one Client cannot access another Client's data.
- We apply reasonable technical and organizational measures to protect data against unauthorized access, loss, or misuse, including encrypted storage, access controls, and audit logging.
- Deleted records are retained in a recoverable state for 30 days before permanent deletion.
- No system can guarantee absolute security; however, we continuously work to maintain reasonable and appropriate safeguards.
5. Data Access Within UNGANI
- UNGANI Admin staff do not access Client business data as a matter of routine. Access is limited to what is necessary to provide support, resolve technical issues, or ensure platform security.
- Clients (Owners/Admins) control access to their own business data and manage their own staff permissions.
- All data access is logged for accountability.
6. Data Sharing
We do not share Client data with third parties except where necessary to operate the Service, where required by law, or with the Client's explicit consent. The third parties (sub-processors) that may process data on our behalf are:
- Supabase - our database, authentication, and file storage provider. All Client data is stored here.
- Vercel - hosts the application and its serverless backend functions.
- Google - if a Client chooses to connect Google Drive for document storage, we request only the narrow "drive.file" permission (access limited to files UNGANI OS itself creates or opens - never a Client's full Drive), plus basic account identification.
- Safaricom (M-Pesa Daraja API) - processes payment transactions if a Client chooses to pay via M-Pesa.
- Our transactional email delivery provider - sends account, registration, and notification emails on our behalf.
We may also disclose data where required by law, regulation, or valid legal process.
7. Data Breach Notification
- If we become aware of a security breach likely to result in a risk to your rights or data, we will notify the Office of the Data Protection Commissioner (ODPC) within 72 hours, as required by the Data Protection Act, 2019.
- Where a breach is likely to result in a high risk to affected individuals, we will notify affected Clients without undue delay, with information about the nature of the breach and steps taken in response.
- For data a Client holds about their own customers or employees, the Client remains the data controller responsible for their own notification obligations; we will support them with the information needed to meet those obligations.
8. Data Retention and Deletion
- Client data is retained for as long as the account remains active.
- Upon cancellation, Clients may request a full export of their data. Data may be permanently deleted after 30 days following account closure, unless a longer retention period is required by law.
- Deleted individual records are recoverable for 30 days before permanent removal.
9. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data, subject to our retention obligations
- Request an export of your business data
- Withdraw consent where processing is based on consent
To exercise these rights, contact us using the details in Section 13.
10. Cookies and Similar Technologies
UNGANI OS may use minimal cookies or local storage strictly necessary for authentication and session management. We do not use cookies for third-party advertising or tracking purposes.
11. Children's Privacy
UNGANI OS is intended for business use by adults. We do not knowingly collect data from individuals under the age of 18.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to active Clients via the platform or email.
13. Contact Us
For questions about this Privacy Policy or to exercise your data rights:
- Email: info@ungani.com
- Phone: +254 743 353 831
- Website: ungani.com