1. Who we are
MOBIpawa is a program operating in Kenya. We are the data controller for personal information collected through /index.php.
2. What we collect
If you are a beneficiary
- Identity data — full name, national ID or passport number, date of birth, gender, phone number, county and sub-county of residence.
- Disability data — nature of mobility impairment, mobility support used, assistive devices, and any notes you provide. This is special-category data and is treated with the highest confidentiality.
- KYC documents — scans or photographs of your national ID, disability card, or supporting letters. These are stored encrypted and are never public.
- Livelihood data — intended use of the carrier, route plan, expected daily income, prior experience.
- Consent records — a record of when and how you consented to specific uses of your data (e.g. publishing your story).
If you are a donor
- Name, email, phone (optional), and the amount and date of each contribution.
- If you choose to donate anonymously, your name is not published — but we still keep a private record for audit and to comply with anti-money-laundering rules.
- We do not store full card numbers. Payments are processed by DPO, a regulated payment provider.
If you are a partner
- Organization name, contact person, email, phone, website, and the scope of your engagement.
If you just visit
- Minimal server logs (IP address, user agent, page requested, timestamp) for security and troubleshooting.
- No third-party advertising trackers. No fingerprinting. No selling of data.
3. Why we collect it
- To verify your eligibility and confirm who you are.
- To raise funds for your carrier and report transparently to donors and partners.
- To procure, customize, deliver, and transfer a carrier that fits your mobility needs.
- To contact you about your application, your campaign, or your carrier.
- To meet our legal obligations, including anti-money-laundering and tax reporting.
- To improve the program through aggregate, anonymised reporting.
4. Lawful basis
Under the Kenya Data Protection Act 2019, we process your data on the following bases:
- Consent — for special-category data (disability information) and for publishing your story.
- Contract — to deliver the program you applied to.
- Legal obligation — for anti-money-laundering, tax, and audit requirements.
- Legitimate interests — for security, fraud prevention, and service improvement, balanced against your rights.
5. Who we share it with
We share personal data only where necessary, and only with:
- Payment providers (e.g. DPO) — to process contributions.
- Procurement and logistics partners — to source, customize, and deliver your carrier.
- Verification partners — to confirm identity and disability status.
- Regulators and law enforcement — where required by law.
- Auditors — under a confidentiality agreement, for financial audit.
We do not sell your personal data. We do not share disability data with donors or the public, ever.
6. Identity documents
Uploaded KYC documents — national IDs, passports, disability cards — are:
- Stored in a directory that is not web-accessible.
- Servable only through a PHP script that checks your session and role before streaming the file.
- Accessible only to you and the verification team.
- Logged — every view of a KYC document is recorded in an append-only audit log.
7. Cookies and analytics
We use a single session cookie to keep you signed in. We do not use third-party advertising cookies, tracking pixels, or behavioural profiling.
If we later add privacy-respecting analytics (e.g. self-hosted, no personal identifiers), this page will be updated in advance.
8. How long we keep it
- Beneficiary records — for as long as you participate in the program, plus seven years for financial audit.
- KYC documents — same as above, then securely deleted.
- Donation records — seven years, as required for financial audit and anti-money-laundering.
- Session data — until you sign out or your session expires.
- Server logs — 90 days.
- Contact messages — two years.
9. How we protect it
- Passwords are hashed with Argon2ID and are never stored in plain text.
- All traffic to the production site is over HTTPS.
- KYC files are stored outside the web root and streamed only through an authenticated endpoint.
- Every material action — approvals, allocations, ownership transfers, KYC views — is written to an append-only audit log.
- Access to production systems is restricted to authorised staff.
10. Your rights
Under Kenyan law you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete data we no longer need, subject to legal retention requirements.
- Object to processing based on legitimate interests.
- Withdraw consent at any time for processing that relies on consent — for example, publishing your campaign page.
- Lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya.
To exercise any of these, write to privacy@mobipawa.org. We respond within 30 days.
11. Children
MOBIpawa is for adults (18+). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
12. International transfers
Our servers are in Kenya. Payment processing may involve the transfer of minimal data to jurisdictions where DPO Group operates. Where such transfers occur, we require appropriate safeguards as required by Kenyan law.
13. Changes
We may update this policy from time to time. Material changes will be announced on the platform and, where required, by email.
14. Contact
Data Protection Officer —
privacy@mobipawa.org
General enquiries —
hello@mobipawa.org,
or our contact form.
This document is a plain-language summary and does not constitute legal advice.