Privacy version 1

Privacy Notice

Effective and last updated: 23 July 2026

This notice explains how Saviku handles personal data when you use Savi on WhatsApp, Saviku websites, booking tools, verification services and transaction features. It is written with the Kenya Data Protection Act, 2019 and applicable regulations in mind.

1. Data we collect

CategoryExamples
Account and contactName, WhatsApp number, language, account and consent records.
Identity and trustGovernment-ID details, selfie or liveness media, verification result, payout identity, fraud and risk signals.
Listings and bookingsProperty or item details, URLs, photos, calendars, prices, location, provenance and booking history.
TransactionsDeal terms, payment references, status, fees, refunds, disputes and evidence. We do not ask for your payment PIN.
Messages and technical dataMessages sent to Savi, delivery events, IP and device metadata, logs, security events and cookies where used.

2. Why and on what basis we use it

We process data to provide requested services and perform contracts; obtain and record consent where required, including sensitive identity processing; meet legal duties relating to security, accounting, fraud prevention and lawful requests; and pursue legitimate interests such as protecting users, improving reliability and preventing abuse, after considering individual rights.

3. How we use data

We operate accounts, extract and verify listings, coordinate calendars, create transaction records, support payments through partners, prevent fraud, provide support, resolve disputes, measure usage and maintain security. Automated tools may flag risk or extract structured facts. High-impact adverse decisions should include appropriate human review where required.

4. Sharing

We may share the minimum necessary data with WhatsApp/Meta, cloud and database providers, identity-verification vendors, mapping and fraud-check providers, payment partners, professional advisers, public authorities acting lawfully, and transaction counterparties where the feature makes that clear. Providers must use data only for agreed purposes and protect it. Cross-border transfers require appropriate safeguards or another lawful basis.

5. Retention and security

We keep data only as long as needed for the stated purpose, contractual evidence, fraud prevention and legal obligations. Retention periods vary by record type. Identity media should be kept for the shortest practical period consistent with verification and law. We use access controls, encryption where appropriate, audit logs, secret management and minimisation, but no system is perfectly secure.

6. Your rights

Subject to Kenyan law, you may ask to be informed, access your data, object to processing, correct inaccurate data, request erasure of false or misleading data, restrict processing, and request data portability where applicable. You may withdraw consent prospectively without affecting processing already lawfully completed. See Data Rights and Deletion.

7. Children

Saviku is not intended for people under 18. Do not submit a child’s personal data unless a feature expressly supports it and you have lawful authority.

8. Contact and complaints

Email privacy@saviku.co. We may verify identity before fulfilling a request. You may also complain to Kenya’s Office of the Data Protection Commissioner.