Wirich Ventures LTD - Privacy Policy
Privacy Notice Updated in June 2025
Definitions
Account: means a profile created by a User on any Wirich platform or Wirich product.
Cookies: A cookie is a small data file that is transferred to your computer or mobile device. It enables us to remember your account log-in information, IP addresses, web traffic, number of times you visit, browser type and version, device details, date and time of visits.
Data Protection Legislation: means the Kenya Data Protection Act 2019, Kenya Data Protection Regulations 2021 and any other applicable legislation on the protection of personal data in Kenya.
Personal Data: Any information that can be used to identify a living or natural person including email address, date of birth, mobile number, residential address, payment card, financial information such as bank account number, etc.), government-issued Identity credentials (e.g. national ID number, international passport, driver’s licence number, etc), or taxpayer identification number. It may also include information that is linked to you, for example, your internet protocol (IP) address, log-in information, information about your device or device’s web browser.
Services: means any products, applications, features, related websites, tools, software, offerings or any service offered by Wirich to you or accessed by you.
Sites: means any platform including but not limited to mobile applications, websites and social media platforms.
User: means an entity (“merchant”) or individual, who uses the Services or accesses the Sites and has agreed to use the end services of Wirich.
Sensitive Personal Data: means details about your race or ethnicity, religious or
philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, genetic, biometric data or any other category defined from time to time by the applicable Data Protection Legislation.
We are Wirich Ventures Limited (Wirich), a company incorporated under the laws of Kenya with offices at Norther By-Pass, Mocathi Building, Kiambu. For any access request, questions, or inquiries about how we use your Personal Data and our privacy practices, please contact us at info@wirich-ventures.com
Definition and Interpretation
Wirich and its affiliates (“we”, “us”, “our” collectively, “Wirich”) is committed to protecting the rights and privacy of individuals in accordance with the Data Protection Legislation. This Privacy Notice (“Notice”) is designed to give you information on our privacy practices, the measures we take to protect the security of the data and to help you understand your rights and choices when we collect or process your Personal Data.
This Privacy Notice is applicable to all Wirich Services accessed by you.
Our privacy principles
Wirich focuses on the following core principles:
- To empower the individual: Wirich wants you to be in charge of and to make voluntary choices about your Personal Data.
- To keep and secure Personal Data: We take responsibility in ensuring that appropriate security measures are put in place and your Personal Data is protected.
- To be transparent and to educate Users: For you to know what Personal Data is, how we collect it, for what purposes it is collected and how we secure it.
- To abide by local laws: Our privacy practices may vary among the countries in which we operate to reflect local practices and legal requirements.Specific privacy notices may apply to some of our products and Services. Please visit the webpage or digital assets of the specific product or service to learn more about our privacy and information practices in relation to that product or service.
- To ensure that Personal Data collected is up to date: We take steps to ensure that Personal Data collected is accurate.
- To collect and store Personal Data on a “need to collect” basis: Wirich collects
Personal Data to perform its services to for the users in accordance with retention obligations and requirements imposed by applicable laws.
Highly Regulated Services and Data Handling
Wirich Ventures LTD operates within highly regulated financial service areas, specifically facilitating payments via mobile money and conducting Know Your Customer (KYC) checks. We partner with established and regulated institutions to provide these services responsibly and securely.
Payment Processing (M-Pesa): We facilitate payments using M-Pesa, a mobile money service provided by Safaricom PLC. M-Pesa is a highly regulated service under the oversight of the Central Bank of Kenya (CBK). Our relationship with Safaricom PLC for M-Pesa services is governed by a Service Level Agreement (SLA), ensuring adherence to operational standards, security protocols, and regulatory compliance. When you use M-Pesa through our app, we request your phone number, which is essential for initiating and confirming transactions. This phone number is inherently tied to your M-Pesa account and associated information held by Safaricom PLC, as per their regulatory requirements and privacy policies.Identity Verification/KYC (KRA): For our Know Your Customer (KYC) obligations, we collect your Kenya Revenue Authority (KRA) Personal Identification Number (PIN). The KRA is a government agency responsible for tax administration in Kenya. The KRAPIN is a critical piece of information for verifying your identity and complying with legal and regulatory requirements, including anti-money laundering (AML) andcounter-terrorism financing (CTF) laws. By collecting your KRA PIN, we link your identity to your financial and tax details held by the KRA, as mandated for financial service providers.Firebase Cloud Messaging (FCM): We share necessary data with Firebase Cloud Messaging (FCM), a service provided by Google, solely for the purpose of sending you push notifications and ensuring reliable delivery of communications related to our services. Our use of FCM adheres to Google's policies and is regularly reviewed for complianceOur commitment to data protection extends to our partnerships with these regulated entities. We ensure that our data sharing practices comply with the Data Protection Legislation and that our partners maintain appropriate confidentiality and security measures, providing the same or equally robust protection of your Personal Data as outlined in this Privacy Notice and as required by applicable data protection laws.
- Personal data we may collect about youWe may collect, use or process Personal data such as:
- Identity Data: Information such as, your full name, your government-issued identity number, and your date of birth. This data will be used for verification to offer ourservices.We also collect copy(ies) of your passport, driving licence or other any government issued identity card, a photograph or image in photo or video form (if applicable) and any other registration information you may provide to prove you are eligible to use our Services and in compliance with regulatory requirements on Know YourCustomer (KYC), Know-Your-Business (KYB) and Anti-Money Laundering Laws (AML) and regulations;
- Contact Data: This includes your country of residence, contact address, email address, contact number, details of the device you use and billing details. This data will be used for verification in order to offer our services.
- Log/Technical Data: When you access Wirich Services, our servers automaticallyrecord information that your browser sends whenever you visit a website, links you have clicked on, length of visit on certain pages, unique device identifier, information on your page interaction (e.g., scrolls and clicks), log-in information, internet protocol (IP) address, location and other device details.
- Financial Data: Information, such as your bank account number, card details, Kenya Revenue Authority (KRA) pin, international bank account number (IBAN), sort code, beneficiary details, the merchant’s name and location, the date and the total amount of transaction, and other information provided by financial institutions or merchants.
- Transactional Data: This is information relating to a payment or transaction when as a merchant (using one or more of our payment processing Services) or as a User, are using our products or Services.
- Marketing and Communications Data: This includes a record of your decision to subscribe or withdraw from receiving marketing materials from us or from our third parties.In addition it includes the content of your communication with us through mobile calls, call recordings, online chats or other means of communication.
- Records of your discussions with us, if we contact you and if you contact us.We may also collect, store, use and transfer non-Personal Data or anonymized data such as statistical or demographic data.As a principle, we do not collect any Sensitive Personal Data. However, if we do collect any Sensitive Personal Data, we will ensure compliance with the Data Protection Legislation.This Privacy Notice applies to Wirich Services only.
- How we get your personal data and why we have itThe Personal Data we have about you is directly made available to us when you:
- sign up or register to use a Wirich Account.
- use any of our Services or receive transfers through any of our Services.
- contact our customer support team or correspond with us.
- fill in our online forms or respond to surveys.
- apply for employment opportunities we advertise.
- register for and attend our webinars, events or online discussions.
- contact us for other reasons.We may also collect Personal Data about you from third party sources, such as credit bureaus, merchants, fraud prevention agencies, identity verification providers, and other publicly available sources such as online directories and websites for due diligence checks. Specifically, your M-Pesa registered phone number provides a link to information held by Safaricom PLC, and your KRA PIN provides a link to information held by the Kenya Revenue Authority, which we utilize for verification purposes as mandated by regulatory requirements.
- The legal basis for using your personal dataThe legal basis we rely on for processing your Personal Data are:Your consent: Where you agree to us collecting and using your Personal Data.We have a contractual obligation: Without your Personal Data, we cannot provide our Services.We have a legal obligation: We have a legal obligation and responsibility to act incompliance with applicable laws, legislations and regulations to prevent fraud by verifying your identity, terrorism financing, proliferation financing and money laundering.To ensure we are fully compliant with all applicable financial legislations such as Anti-Money Laundering and Counter Terrorist Financing Laws.We have a legitimate interest: In certain instances, and as permitted by law, we may rely on legitimate interests in our business to process your Personal Data.These may include sharing your data with our affiliates or protecting against fraud by checking your identity before providing you with a service.
- How we may use your personal dataWe may use your Personal Data that we collect to:
- Create and manage any Accounts you may have with us, verify your identity, provide our Services, and respond to your inquiries.
- Process your payment and other transactions (including authorization, clearing, chargebacks and other related dispute resolution activities) and provide other payment related services to you. This includes facilitating mobile money transactions through M-Pesa.
- Protect against and prevent fraud, un-authorized transactions, claims and other liabilities.
- Communicate with you about products, newsletters, advertisements, offers, programs and promotions of Wirich, financial institutions, merchants and other partners. You have the right to opt-out of this at any time.
- Send communication on service updates (downtime, service support, regulatory notices, etc)
- Communicate with you to resolve an inquiry, complaint or concerns with your Account. We also use your contact data to send you one-time passwords (OTP) for account authentication via short messaging service (SMS), email, WhatsApp or other electronic mediums.
- Evaluate and improve our business, including developing new products and Services.
- Establish, exercise and defend legal rights, as necessary.
- When our app requests access to specific data or device functionalities (e.g., your contact list for fund transfers, or permission for push notifications), we will provide a clear and comprehensive explanation within the app regarding the precise purpose of this data access at the time of the request.
- Your data protection rightsBy virtue of the Data Protection Legislation, below are the rights you have as a User in relation to your Personal Data:
- Right to be informed on how we process your data. This Privacy Notice explains our privacy practices.
- Right to request for access to all or copies of your Personal Data by signing into your Account or contacting us. We will not share personal data with other individuals.
- Right to request that Wirich delete or erase your Personal Data. Please note that this is limited and only applies where the continued processing of your Personal Data has no legal justification.The exception to this right is where the applicable law requires Wirich, as a regulated financial services institution, to retain a historical archive of your personal data tofulfil regulatory requirements or where we retain a core set of your personal data to ensure we do not inadvertently contact you in future, where you object to your data being used for marketing purposes.
- Right to correct or rectify any Personal Data that you provide which may be incorrect, out of date or inaccurate. You also have the right to ask us to update information you think is incomplete or outdated.
- Right to opt-out of direct marketing. You have a right to ask us not to contact you for marketing purposes by adjusting your notification preferences on the settings page of our Sites or by opting out via the unsubscribe link in marketing emails we send you.
- Right to object to processing: You have the right to object to or restrict the processing of your Personal Data in certain circumstances.Please note that where you object to or restrict us from processing your Personal Data, we might be unable to provide our Services to you.
- Right to not be subject to a decision based solely on automated processing.
- Right to request that we move or transfer your Personal Data across differentServices we provide, or have it moved or transferred from us to another company in a structured, commonly used and machine-readable format. The exception to this right is where your request is not technically feasible or possible.You can exercise your rights at no cost. However, we are permitted by law to refuse your request in certain circumstances or where your request is excessive, or manifestly unfounded. We may charge you a reasonable fee for the exercise of your right to move or transfer your data. If we decide to charge a fee, we will inform you before treating your request.If you wish to exercise any of your rights set out above, please contact us at info@wirichventures.comWhere we are unsure of your identity, we might ask you for proof of your identity for security reasons, before dealing with your request.Where a third party exercises any of these rights on your behalf, we would need sufficient proof that you have authorised them to act on your behalf.
Right to request that Wirich delete or erase your Personal Data.
You have the right to request that Wirich delete or erase your Personal Data. To initiate this process, please visit our dedicated user data deletion portal at
https://www.wi-money.com/delete-account.html. You will be required to enter your login credentials
(email and password) and confirm your request by clicking the 'delete' button. Please note that this right is limited and only applies where the continued processing of your Personal Data has no legal justification. The exception to this right is where the applicable law requires Wirich, as a regulated financial services institution, to retain a historical archive of your personal data to fulfil regulatory requirements or where we retain a core set of your personal data to ensure we do not inadvertently contact you in future, where you object to your data being used for marketing purposes.
- Disclosing your personal dataWe may disclose or share your Personal Data with third parties as may be reasonably necessary for the purposes set out in this Notice.We share Personal Data with external third parties in the following limited circumstances:
- We provide such information to our subsidiaries or affiliated entities for the purpose of processing Personal Data on our behalf.We require that these parties agree to process such information based on our instructions, implement appropriate confidentiality and security measures and comply with the Data Protection Legislation.
- We share your data with our third-party providers or service providers, financial partners or suppliers for the purpose of effectively providing our Services.These services include identity verification and fraud prevention, customer service and support, analytics, payment facilitation by our banking and financial service partners including the card networks, communication service providers andinformation technology services
- We may share your Personal Data to comply with a subpoena, court order, summons, police or other law enforcement agencies, regulatory requests (which may be outside your country of residence) or as required by law.
- We may share your Personal data where disclosure is reasonably necessary to:
- Satisfy any applicable law, regulation, legal process or enforceable governmental request.
- Detect or prevent fraud including investigation of potential violations to our Terms of Service. o Detect, prevent, or otherwise address security or technical issues, or
- Protect against imminent harm to the rights, property or safety of Wirich, its Users or the public as required or permitted by law.
- We have your consent, in some instances, we may provide a service through a third party, which would require us to share your Personal Data to third parties authorised by you to receive such Information.The use of your Personal Data by an authorised third party is subject to the third party's Privacy Notice and Wirich shall bear no liability for any breach which may arise from such authorization by you.
- If Wirich becomes involved in a merger, acquisition, or any form of sale of some or all of its assets, we may share your Personal Data with parties involved in thetransaction and any entity that acquires our business will continue to process your Personal Data in line with this Privacy Notice, or a revised version that we willcommunicate to you.
- Data security and retentionThe security of your Personal Data is important to Wirich. We are committed to protecting the information we collect. We maintain administrative, technical and physical controls designed to protect the Personal Data you provide, or we collect against loss or theft, as well as against any unauthorized access, risk of loss, disclosure, copying, misuse or modification.Other security measures include but are not limited to, secure servers, firewalls, data encryption and granting access only to specific employees in order to fulfil their job responsibilities.When you use any of your Accounts, we implore you to always use strong passwords (acombination of letters, numbers, upper and lower cases and special characters), enable two factor authentication on your Accounts, ensure you do not share your password with anyone, and that your login credentials are kept confidential at all times.We are committed to conducting our business in accordance with these principles in order to ensure that the confidentiality of your Personal Data is protected and maintained. We would take all reasonable steps to ensure that your Personal Data is secured and wellprotected.We will only retain Personal Data on our servers for as long as is reasonably necessary as long as we are providing Services to you. If you close your Account, your data is stored on our servers to the extent necessary to comply with regulatory and Anti-Money Laundering obligations and for the purpose of fraud monitoring, detection and prevention.Where we retain your Personal Data, we do so in compliance with limitation periods or retention obligations imposed by applicable law.
- MarketingWe may process your Personal Data in order to contact you or send you marketing content and communication about our products, services or surveys, where we have obtained your consent.You may exercise your right to object to such contact from us or opt out from the marketing communication.Please note that if you opt-out of marketing content, we may still send you messages relating to transactions and our Services, related to our ongoing business relationship.We may ask you for permission to send notifications to you, our Services will still work if you do not grant us consent to send you notifications.
- CookiesLike many other websites, we use cookies to distinguish you from other Users, to measure your engagement with our website and to customise and improve our Services. Depending on how you manage your cookies settings and preferences, we may place cookies on your device when you visit our website. We will only place advertising and analytics cookies if you consent or accept these cookies. Some browsers may automatically accept cookies, whilesome can be modified to decline cookies or alert you when a website wants to place acookie on your computer. If you do choose to disable non-essential cookies, it may limit your ability to get a full experience of our website.
- MinorsWirich services and applications are not directed at persons under the age of eighteen (18) and we do not collect any Personal Data knowingly or directly from individuals who fallwithin this category.Where you have any belief that Wirich has mistakenly or unknowingly collected information from a minor, please contact us to enable us to investigate and restrict such data collection.
- International data transfersOur business is global with affiliates and service providers located around the world. As such, we may need to transfer your Personal Data to help us provide you with our Services. Your Personal Data may be transferred to countries which may not have the same data protection laws as your country, but whenever we have to transfer or transmit your Personal Datainternationally, we will take reasonable steps to ensure your Personal Data is handled securely in compliance with the Data Protection Legislation.
- Updates to our privacy noticeFrom time to time, we may change, amend or review this Privacy Notice to reflect newServices or changes and place any updates on this page. All changes made will be posted on this page and where changes will materially affect you, we will notify you of this change by placing a notice online, on your Wirich dashboard or by email.
- Contact us
To exercise your rights or if you have any inquiries, comments or concerns with our privacy practices, please contact us at info@wirich-ventures.com.We will investigate and work on resolutions for your concerns within thirty (30) days and/or in accordance with the Data Protection Legislation.Where we require more time to resolve your inquiry, we would communicate with you. We may request additional details from you regarding your inquiries and keep records of your requests and resolution.