Privacy Policy

Last updated: March 31, 2026

1. Introduction

AdPesa ("we", "our", or "us"), operated by MAAT Systems East Africa Limited ("MAAT Systems"), is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data in compliance with the Kenya Data Protection Act, 2019 (the "DPA") and the regulations issued thereunder by the Office of the Data Protection Commissioner (ODPC).

By using the AdPesa mobile application or website (collectively, the "Platform"), you consent to the collection and use of your personal data as described in this Policy.

2. Data Controller

The data controller responsible for your personal data is:

MAAT Systems East Africa Limited
Website: maat-ea.com
Email: support@maat-ea.com
Kenya

3. Personal Data We Collect

We collect and process the following categories of personal data:

3.1 Account Information

  • Full name
  • Email address
  • Phone number (M-Pesa registered number)
  • Password (stored in encrypted form)

3.2 KYC (Know Your Customer) Data

  • Kenya National ID number
  • Photograph of your National ID card
  • Facial photograph (selfie for liveness verification)
  • Voice recording (for liveness verification)

3.3 Usage Data

  • Campaign viewing history and engagement data
  • Likes, comments, and bookmarks
  • Trivia answers and interaction timestamps
  • Device type, operating system, and app version

3.4 Financial Data

  • Earnings history
  • Withdrawal requests and payout records
  • M-Pesa transaction references

4. Legal Basis for Processing

Under the Kenya Data Protection Act, 2019 (Section 30), we process your personal data on the following lawful bases:

  • Consent: You provide explicit consent when creating an account and submitting KYC documents.
  • Contract: Processing is necessary for the performance of our service agreement with you (watching campaigns, earning, and withdrawing funds).
  • Legal obligation: We are required to verify user identities and maintain transaction records under Kenyan financial regulations.
  • Legitimate interest: To improve our Platform, prevent fraud, and ensure platform security.

5. How We Use Your Data

We use your personal data for the following purposes:

  • To create and manage your AdPesa account
  • To verify your identity through the KYC process
  • To deliver personalised campaign content to your feed
  • To calculate, track, and process your earnings
  • To process M-Pesa withdrawals
  • To communicate with you about your account and platform updates
  • To detect and prevent fraud, abuse, or unauthorised access
  • To comply with applicable Kenyan laws and regulations

6. Data Sharing

We do not sell your personal data. We may share your data with the following parties only as necessary:

  • Payment processors: M-Pesa (Safaricom) for processing withdrawals. Only your phone number and transaction amount are shared.
  • Campaign advertisers: Aggregated, anonymised viewing statistics only. Advertisers never receive your personal information.
  • Cloud infrastructure providers: For secure data hosting and storage, subject to data processing agreements.
  • Law enforcement: When required by Kenyan law, court order, or regulatory request.

7. Data Storage and Security

We implement appropriate technical and organisational measures to protect your personal data as required by Section 41 of the DPA, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure password hashing (bcrypt)
  • Access controls and role-based permissions for our team
  • Regular security assessments

KYC documents (ID images, selfies, voice recordings) are stored on encrypted servers and are accessible only to authorised verification personnel.

8. Data Retention

We retain your personal data for as long as your account is active and as required by law:

  • Account data: Retained while your account is active, and for 2 years after account deletion.
  • KYC documents: Retained for 7 years after account closure as required by anti-money laundering regulations.
  • Transaction records: Retained for 7 years as required by the Kenya Revenue Authority.
  • Usage data: Retained for 2 years, then anonymised for analytics.

9. Your Rights Under the Kenya DPA

Under the Kenya Data Protection Act, 2019 (Sections 26-28), you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to deletion: Request deletion of your personal data, subject to legal retention requirements.
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent: Withdraw your consent at any time. This does not affect the lawfulness of processing prior to withdrawal.

To exercise any of these rights, contact us at support@maat-ea.com. We will respond within 30 days as required by the DPA.

10. Cross-Border Data Transfers

Your data may be transferred to and processed in countries outside Kenya for cloud hosting purposes. In accordance with Section 48 of the DPA, we ensure that any such transfer is subject to appropriate safeguards, including data processing agreements that provide equivalent protection to the DPA.

11. Children's Privacy

AdPesa is not intended for use by persons under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a person under 18, we will delete it promptly.

12. Cookies and Tracking

Our website may use essential cookies for session management and security. We do not use third-party advertising trackers on the website. The mobile application does not use cookies.

13. Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with:

Office of the Data Protection Commissioner (ODPC)
P.O. Box 00200, Nairobi, Kenya
Website: www.odpc.go.ke

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes through the app or by email. Your continued use of the Platform after such changes constitutes acceptance of the updated Policy.

15. Contact Us

For questions or concerns about this Privacy Policy or our data practices, contact us at:

Email: support@maat-ea.com