Privacy Policy

Last updated: 31 August 2026

Zeno ("we", "us", "the Service") is a CRM, accounting and payroll platform for Kenyan businesses. This policy explains what personal data we collect, why, and the rights you have under the Data Protection Act, 2019 (Kenya) and its regulations. It applies to business owners and staff who use Zeno, and to their customers whose details are processed through the Service.

1. Who is responsible for your data

For account data of businesses using Zeno, we act as data controller. For the customer and supplier records a business keeps inside Zeno (names, phone numbers, invoices, payments), that business is the data controller and we act as its data processor. Contact for all data matters: privacy@zeno.com.

2. What we collect

  • Account data — name, email, phone, business details, KRA PIN, login credentials.
  • Business records — contacts, invoices, bills, payroll, fixed assets, and ledger entries entered by the business.
  • Payment data — M-Pesa and Kopo Kopo transaction details received via payment gateways: payer phone number, name, amount, receipt numbers. We never see or store M-Pesa PINs.
  • Billing data — your organisation's own setup-fee and monthly maintenance-fee payments to us, including phone number/email used to pay and payment status.
  • Receipt access data — when a customer uses a receipt link or the customer portal: the phone number they verify, one-time codes (stored hashed), and access sessions.
  • AI assistant data — questions you ask the assistant and the business records needed to answer them (see section 4), kept as a short chat history tied to your account.
  • Technical data — device/browser information and logs needed to keep the Service secure.

3. Why we process it (lawful basis)

  • To provide the Service — bookkeeping, invoicing, payments, receipts, payroll, and AI-assisted answers/drafts you request (performance of contract).
  • To meet legal duties — tax record-keeping under Kenyan law, including KRA requirements (legal obligation).
  • To send transactional messages — payment receipts and verification codes by SMS or email (legitimate interest / contract).
  • To bill you — processing your organisation's own setup and maintenance-fee payments (performance of contract).
  • To secure the Service — fraud prevention, audit logs (legitimate interest).

We do not sell personal data. We do not use it for third-party advertising.

4. Who we share it with

  • Safaricom (M-Pesa Daraja) and Kopo Kopo — to process payments you initiate or receive.
  • IntaSend — to process your organisation's own setup-fee and maintenance-fee payments to us.
  • Advanta — to deliver SMS receipts and verification codes.
  • Resend — to deliver email receipts and notifications.
  • Groq — to process the business data included in a message you send the AI assistant, solely to generate that response; only used when you actively use the assistant.
  • Supabase — our database and authentication host.

Some providers store data outside Kenya (including the EU and US). Where data leaves Kenya we rely on providers with appropriate safeguards, consistent with sections 48–49 of the Data Protection Act.

5. How long we keep it

Financial records are kept for at least five (5) years as required by Kenyan tax law, even after an account closes. Portal verification codes expire after 10 minutes; portal sessions after 30 days. AI assistant chat history is kept only as long as needed to keep the conversation coherent and is not used to train any model. Other personal data is deleted or anonymised when no longer needed.

6. How we protect it

  • Encryption in transit (HTTPS) and at rest; payment gateway credentials additionally encrypted with AES-256.
  • Verification codes stored only as one-way hashes.
  • Role-based access controls inside each business account, including which modules (CRM/Accounting/Payroll) and AI tools each account can reach.
  • Receipt links use unguessable random tokens; the customer portal requires phone verification.

7. Your rights

Under the Data Protection Act, 2019 you may:

  • ask what personal data we hold about you and get a copy (access);
  • correct inaccurate data (rectification);
  • ask for deletion where the law allows (erasure) — note tax records must be retained per section 5 above;
  • object to or restrict certain processing;
  • receive your data in a portable format.

Write to privacy@zeno.com. We respond within a reasonable time and at no cost, as the Act requires. If unsatisfied, you may complain to the Office of the Data Protection Commissioner (ODPC) — www.odpc.go.ke.

8. Customers of businesses using Zeno

If a business you paid uses Zeno, your phone number and payment details were provided to us by that business or by the payment network to issue your receipt. Direct your requests to that business first; we assist them in fulfilling your rights.

9. Changes

We will post any changes here and update the date above. Material changes will be notified inside the Service.