Data Protection (ODPC)
1. Scope
This page summarises how EzRent Kenya Ltd handles personal data under the Kenya Data Protection Act, 2019("the Act") and the regulations and guidance issued by the Office of the Data Protection Commissioner (ODPC). It complements our Privacy Policy and our Terms of Service.
2. Roles: controller and processor
EzRent operates in two distinct roles depending on whose data is being processed:
- Data controller, for personal data of landlords and property managers who hold accounts with us, for marketing-site visitors, and for our own staff and suppliers.
- Data processor, for personal data of tenants, applicants, guarantors, and other individuals that our customers (landlords / property managers) upload to the platform. In these cases the customer is the controller and decides why and how the data is used; we process it strictly on the customer's documented instructions.
Where we act as a processor, the relationship is governed by a Data Processing Addendum (DPA) which forms part of the Terms of Service. A standalone DPA is available on request.
3. ODPC registration
EzRent is preparing its registration with the ODPC as both a data controller and a data processor under sections 18 and 19 of the Act. Our registration certificate number will be published here once issued.
4. Lawful processing
We will only process personal data on one of the lawful bases set out in section 30 of the Act: consent, performance of a contract, compliance with a legal obligation, protection of a vital interest, public interest, or legitimate interest. The bases relied on for each category of processing are set out in our Privacy Policy.
5. Tenant data and M-Pesa flows
Tenant data uploaded by landlords (names, contact details, IDs, ledgers, lease documents) is stored in encrypted form. M-Pesa transaction data received from Safaricom Daraja is matched to invoices and is retained for audit and tax purposes. Webhook callbacks are signed, IP-restricted, and idempotent, so a replayed or tampered callback cannot post duplicate or fraudulent entries.
6. KRA eTIMS data
Where a landlord enables KRA eTIMS transmission, invoice data (taxpayer identifier, line items, totals) is transmitted to KRA in line with eTIMS technical specifications. EzRent does not collect or transmit personal data of tenants to KRA beyond what is required for the receipt to be valid.
7. Data subject rights
Data subjects (landlords, tenants, applicants) can exercise their rights under Part V of the Act, access, correction, objection, deletion, restriction, and portability, by writing to privacy@ezrent.co.ke. We respond within the statutory time limit of 30 days, with one possible extension of a further 60 days for complex requests, in which case we will notify the requester.
Tenants whose data was uploaded by a landlord should first direct requests to the landlord, who is the controller. If a landlord fails to respond, the tenant may contact us and we will assist in line with the underlying DPA.
8. Data Protection Impact Assessments (DPIAs)
EzRent maintains a DPIA for the platform overall and refreshes it when material changes are made (new processing activities, new sub-processors, changes to data flow). Customers processing data that triggers a controller-side DPIA obligation can request our latest DPIA summary to support their assessment.
9. Cross-border transfers
Personal data may be transferred outside Kenya to sub-processors providing email, SMS, error monitoring, object storage, and hosting. Such transfers rely on the conditions in section 49 of the Act, including appropriate safeguards and, where relevant, contractual clauses equivalent to standard contractual clauses adopted by the ODPC or the European Commission.
10. Security measures
- TLS 1.2+ for data in transit; AES-256 for data at rest;
- Role-based access control: admin, manager, agent, accountant;
- Multi-factor authentication available for all account roles;
- Immutable audit log for financial-record changes;
- Signed and IP-restricted M-Pesa callbacks; idempotent processing;
- Secret management with rotation;
- Background checks for staff with production access;
- Annual penetration testing and quarterly vulnerability scans.
11. Breach notification
If we become aware of a personal data breach likely to result in risk to data subjects, we will notify affected customers (controllers) without undue delay and in any case within 72 hours of becoming aware, and we will report to the ODPC as required by section 43 of the Act. Tenants whose data was uploaded by a landlord will be notified by that landlord; we provide template language and incident details to make this fast.
12. Sub-processors
Our current sub-processors are listed in our Privacy Policy. We will publish a dedicated sub-processor register, including category of processing and country of operation, when the public Trust Centre is launched. Customers will be given at least 30 days' notice of any material new sub-processor and an opportunity to object.
13. Retention
Personal data is retained only for as long as needed for the purposes set out in the Privacy Policy or to meet legal obligations under Kenyan tax, anti-money-laundering, and consumer-protection law. Where a customer exits, exported data can be deleted within 30 days of confirmation, subject to legal retention requirements.
14. Complaints and ODPC contact
Concerns can be raised with us at privacy@ezrent.co.ke. Individuals also have the right to lodge a complaint with the ODPC at odpc.go.ke.