Privacy Policy
Effective 2026-10-06 · NyumbaPMS
This policy explains what personal data NyumbaPMS handles, why, who it is shared with, how long it is kept and what your rights are. It is given under section 29 of the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021 (together, "the Act"). It forms part of our Terms of Service.
1. Who we are and who is responsible for your data
NyumbaPMS is provided by NyumbaPMS. Who is responsible for your data depends on how you appear in the service:
- If you have a NyumbaPMS account (an owner, staff member, property owner or tenant using the portal), we are the data controller for your account details and how you use the service.
- If you are a tenant, occupant, prospect, guarantor, property owner or supplier recorded by a landlord or manager, that landlord or manager is the data controller for your records, and we are their data processor: we keep and process the records for them, on their instructions, under the processing terms in section 12 of our Terms. Questions about those records, and requests to see, correct or delete them, go to your landlord first; we help them answer. If you cannot reach your landlord, you can contact us and we will pass your request on.
2. What we collect and where it comes from
- Account details (from you): name, phone number, email (optional), a hashed password, whether the phone is verified, two-step sign-in settings, your role in an organization, and the version of the Terms you accepted and when.
- Landlords' records (from the landlord and their staff, by typing or importing): tenants' and occupants' names, phone numbers, emails, ID or passport numbers where the landlord asks for them, next of kin or emergency contacts, leases, rent and deposit amounts, invoices, payments, receipts, balances, meter readings, inspection notes, repair requests, notes, letters and notices, documents and photos.
- Payments (from Safaricom, Paystack or the landlord's bank): transaction codes, amounts, dates, account references, and the payer's name and phone number as the provider gives them.
- Electronic signatures: the name typed when signing, the phone number the code was sent to, the time of signing, the IP address and the browser used, and a fingerprint of the signed document.
- Messages: SMS, WhatsApp, email and push messages sent through the service, their delivery status, USSD sessions (phone number and choices made), and replies such as STOP or YES. Questions asked of the assistant and its answers.
- Technical records: an audit log of important actions (who did what and when, with the IP address and browser), sign-in attempts and security alerts, error reports, and counts of how often the installed app is opened and on which kind of phone (with no personal data). We do not keep request bodies, passwords or sign-in codes in logs.
Sensitive data. The Act treats family details (such as the names of a spouse, children or next of kin), health information and some property details as sensitive. Landlords should record these only when they need them and have a lawful reason. We do not ask for biometric data, and the service is not designed to hold health records.
3. Why we use it and our lawful basis
| Purpose | Lawful basis under section 30 of the Act |
|---|---|
| Creating and running your account, signing you in, sending sign-in codes | Performance of our contract with you |
| Keeping landlords' records, sending invoices, receipts, reminders, notices and statements, the tenant portal, USSD and payment prompts | The landlord's contract with the tenant and the landlord's legitimate interests; we act on the landlord's instructions |
| Billing landlords for their plan and SMS credit, and keeping tax records | Contract and legal obligation (including the Tax Procedures Act, 2015) |
| Security, fraud prevention, the audit log, fixing faults | Our legitimate interest in a safe and reliable service, and legal obligation to keep data secure |
| The assistant | The landlord's instructions, once an owner switches it on |
| News about NyumbaPMS sent to account holders | Consent, which you can withdraw at any time |
| Answering courts, the Data Protection Commissioner and other authorities | Legal obligation |
We do not sell personal data, show advertising, or use it for profiling. No decision that has a legal or similarly significant effect on anyone is made by the service alone without a person: reminders and late notices follow rules the landlord sets, and the assistant cannot change anything without a person's confirmation.
4. Who we share it with
We use these providers (sub-processors) to run the service. Each gets only what it needs for its part and is bound by written terms to protect it:
- Our hosting provider (DigitalOcean, Frankfurt, Germany (EU)): the database, files and backups.
- Africa's Talking: SMS and the USSD menu (phone numbers and message text).
- Safaricom (Daraja): M-Pesa payment confirmations and payment prompts (phone number, amount, reference).
- Paystack, only for landlords who use it instead of a Paybill: the payment prompt (phone number, amount, reference, and the tenant's email where given).
- Meta (WhatsApp), only where the landlord has set it up: phone numbers and message text.
- An email provider: emails such as statements, receipts and password resets.
- Your browser's push service (for example Google or Apple), only if you switch on notifications: a device address and the alert text.
- Sentry, where set up: error reports, sent without personal data.
- OpenAI, only when an owner switches on the assistant: the question and the records needed to answer it, with phone numbers, emails and ID numbers removed first. OpenAI does not use data sent through its API to train its models.
We also disclose data when the law requires it (for example a court order, a request from the Data Protection Commissioner or the Kenya Revenue Authority), to protect someone's safety, or to a company that takes over the service under the same promises, after telling you. Landlords decide what they share with their own staff, property owners, advocates and suppliers.
5. Data outside Kenya
Some providers keep or process data outside Kenya, including our hosting provider (DigitalOcean, Frankfurt, Germany (EU)), Meta, OpenAI and Sentry. We transfer data abroad only as sections 48 to 50 of the Act allow: to countries or providers with appropriate safeguards for personal data, under written terms that protect it at least as well as the Act, and we keep a record of these transfers. We send each provider as little as we can. Ask us for details of the safeguards for a particular provider.
6. How long we keep it
- Landlords' records: while the landlord's account is open. After it closes, the landlord has 30 days to export them, and we delete them within 90 days, except what the law requires us to keep. While an account is open, the landlord decides how long to keep each tenant's records.
- Financial records: invoices, payments and receipts are never edited away. Mistakes are corrected with a reversal, so records can be checked later. Our own invoices to landlords are kept for at least five years, as tax law requires.
- Account details: while the account is open, then up to 12 months to deal with questions and disputes, unless the law requires longer.
- Messages: the text and address of a sent message are cleared after 730 days; the record that it was sent, and when, stays with the tenant's records.
- Assistant questions: deleted after 90 days. Sign-in codes: deleted after a few days.
- Audit log and signing records: kept as long as the records they relate to, because they show who did what and are evidence.
- Backups: kept securely for up to a year, and then they expire.
7. Your rights
Under section 26 and Part IV of the Act you have the right to:
- be told how your personal data is used;
- see the personal data held about you and get a copy;
- have wrong or misleading data corrected, and data that is no longer needed or was unlawfully held deleted;
- object to its use, and ask for its use to be restricted;
- receive data you gave in a structured, commonly used format, and have it sent to someone else, where technically possible;
- withdraw consent at any time, where consent is the basis, without affecting what was done before; and
- refuse direct marketing. We honour such a request within 7 days.
Account holders can ask us directly at the address below. For records a landlord keeps, ask the landlord, and we help them answer. We may need to confirm who you are before we act, and we answer within the time the Act and its regulations set. Some rights are limited where the law requires records to be kept (for example payment records). If you are not satisfied, you can complain to the Office of the Data Protection Commissioner (www.odpc.go.ke).
8. Security and breaches
See security and your data for how we protect records: separate data for each landlord, hashed passwords, verified phones, two-step sign-in, an audit log that cannot be changed, encrypted provider keys, HTTPS and daily backups. If a breach of personal data creates a real risk of harm, we tell the Data Protection Commissioner within 72 hours of becoming aware of it where we are the controller, tell the landlord within 48 hours where we are their processor, and tell the people affected as soon as practicable.
9. Cookies and device storage
We use only the cookies needed to keep you signed in and to protect forms. Your browser also keeps your light or dark choice, and, if you use the installed app, pages and forms saved for offline use (such as meter rounds and repair reports) until they are sent. There are no tracking, analytics or advertising cookies, and no third-party trackers.
10. Children
Accounts are for adults. We do not knowingly create accounts for children. Landlords may record the names of children living in a unit only where they need to, and are responsible for having a lawful basis under section 33 of the Act.
11. Changes to this policy
If this policy changes in a way that matters, the effective date at the top changes and signed-in users are asked to read and accept it before they continue.
12. Contact
Questions, requests and complaints about personal data: support@nyumbapms.com · Terms of Service