This notice explains how mjengoPay handles personal data across the platform, including workforce operations, supplier records, and payment workflows.
This Privacy Notice explains how mjengoPay collects, uses, stores, shares, and protects personal data processed through the mjengoPay platform.
This Notice should be read together with the mjengoPay Business Terms of Service and any applicable data processing addendum or feature-specific privacy terms.
Depending on the feature used, mjengoPay may process account, workforce, supplier, payment, and security data.
mjengoPay processes data to deliver the service, secure the platform, support customers, run payment workflows, maintain records, and comply with law.
In many cases, the customer controls the worker, supplier, and operational data it chooses to enter into mjengoPay and acts as the data controller for that information.
mjengoPay may act as a processor when handling such data on the customer's behalf and may also act as an independent controller for account management, platform security, fraud prevention, support, compliance, billing, and service administration.
mjengoPay may share data with trusted service providers and infrastructure partners where necessary to operate the service.
Some mjengoPay providers or systems may process or store data outside Kenya. Where cross-border transfers occur, mjengoPay will use reasonable safeguards appropriate to the service and legal requirements.
mjengoPay uses administrative, technical, and organisational safeguards designed to protect personal data, but no online system can be guaranteed to be completely secure or uninterrupted.
mjengoPay retains data for as long as needed to provide the service and for reasonable periods afterward where necessary for legal, audit, security, backup, fraud-prevention, dispute, or operational reasons.
Where applicable law gives data subjects rights of access, correction, objection, deletion, restriction, portability, or complaint, requests can be directed to the relevant customer controller or to mjengoPay, depending on the role mjengoPay is performing for the data in question.
If your company uses Bring Your Own Paybill (BYOP) to pay from its own M-Pesa business account, mjengoPay processes additional data to connect to and operate that account on your instruction.
For BYOP, your company is the controller of its own M-Pesa account data and the worker and supplier data it pays. mjengoPay acts as your processor and authorised agent when it uses your credentials to initiate transactions you have authorised, and as an independent controller for the fee, audit, security, and tax records arising from providing the service.
When you use Scan to Pay, mjengoPay sends the document to a configured AI service to extract supplier, purchase, and payment details. The extraction cannot authorise a payment; an authorised user must review and confirm the result through mjengoPay’s normal payment controls.
Failed source files are deleted promptly. Successfully extracted source files that are not linked to a payment are deleted after 30 days. Documents linked to payments are retained with the payment record for applicable audit, dispute, legal, and financial-record purposes.
Privacy questions can be sent to hello@mjengopay.com.