Privacy Policy
Last updated 28 July 2026
1. About this policy
This policy explains how Sakenora ("Sakenora", "we", "us") handles personal data in connection with the Sakenora property management platform, available at https://sakenora.com, through the resident web portal, and through the mobile app (together, the "Platform").
Sakenora is sold to property management businesses and landlords. We call them Clients. Clients use the Platform to manage their buildings, units, leases, rent and maintenance. The people who live in those units use the resident portal and mobile app. We call them Residents.
This policy is written to meet the requirements of the Data Protection Act, 2019 of Kenya ("the DPA"). Where we operate in Somalia and Somaliland, we apply the same standard.
Please read section 3 carefully. It explains the most important thing in this policy: for most Resident data, your landlord or property manager is in charge, not us.
2. Who to contact
| Purpose | Contact |
|---|---|
| Data protection questions, and to exercise your rights | support@sakenora.com |
| General support | support@sakenora.com |
| Postal address | Nairobi, Kenya |
Our registration with the Office of the Data Protection Commissioner is held under registration in progress.
3. Controller and processor — the important distinction
The DPA distinguishes between a data controller (who decides why and how personal data is processed) and a data processor (who processes personal data on behalf of a controller).
3.1 We are the CONTROLLER for Client account data
We are the data controller for personal data relating to our Clients and their staff: names, email addresses, phone numbers, login credentials, two-factor settings, language preference, subscription and billing records, and support correspondence. If you are a Client or a member of a Client's staff, bring your requests directly to us.
We are also the controller for personal data submitted through the public website, such as contact-form enquiries.
3.2 We are the PROCESSOR for Resident data
We are a data processor for personal data about Residents that a Client enters into, or generates within, the Platform.
The Client — the landlord or property management business — is the data controller for that data. They decide which residents to record, what to collect, how long to keep it, and what to do with it. We hold it on their behalf, under their instructions.
This means:
- Residents should send most data protection requests to their landlord, not to Sakenora. See section 9.
- We do not sell Resident data.
- We do not use Resident data to market to Residents.
- We do not use Resident data for our own purposes beyond the limited operational purposes in section 6.4.
- If we receive a request from a Resident that belongs with their Client, we will redirect them and, where appropriate, notify the Client.
3.3 Where the roles meet
There are narrow areas where we act as controller even for data originating with a Resident — our security logs, fraud and abuse prevention records, and technical records we must keep to run and defend the service. We keep this to the minimum necessary.
4. What personal data the Platform holds
4.1 Client staff accounts (we are controller)
- Full name, email address, phone number
- Password, stored only as a cryptographic hash — we never store or see it in readable form
- Two-factor authentication secret where enabled, encrypted at rest
- Language preference
- Subscription, invoice and payment records
4.2 Resident records (Client is controller; we are processor)
- Full name and phone number
- Email address — optional. Many Residents have no email recorded, and the Platform is designed to work without one.
- National identification number
- Photograph and uploaded identity documents
- Emergency contact: name, phone number, relationship
National ID numbers and identity documents are sensitive. They are collected by the Client for tenant verification. The Client is responsible for having a lawful basis and for collecting no more than necessary.
4.3 Property and lease data
Buildings, floors, units and sections; leases including dates, rent and deposit; signed lease and contract documents.
4.4 Financial data
- Invoices, line items and tax amounts; payments and receipts
- M-Pesa transaction records — paying phone number, amount, and M-Pesa receipt number, received from Safaricom's Daraja API
- Manual payment proofs uploaded by Residents — a reference number and an image or PDF of a receipt
- Client subscription payments processed through our payment processor
We never store payment card numbers. Card payments are made off-site on our payment processor's systems and are not transmitted to or retained by us.
4.5 Operational data
Maintenance requests including photographs; expense records; vendor records; water meter readings; vacate notices; announcements; contact-form submissions.
4.6 Electronic signatures
Where a Resident signs a document in the Platform we record the name typed, a signature image where one was drawn, a cryptographic hash of the exact document signed, the date and time, and the IP address used.
This record exists so the signature can be shown to be genuine and the document proved unaltered. It is evidence, and is retained for as long as the signed document is retained.
4.7 Audit and security logs
The Platform records who created, updated or deleted records, when, and from which IP address.
4.8 What we do not do
We do not run advertising on the Platform. We do not use third-party advertising or behavioural tracking cookies. We do not sell personal data. We do not carry out automated decision-making producing legal effects for any individual.
SMS notifications are not currently in use. An SMS gateway is planned but not integrated at the date of this policy. We will update this policy before any SMS messaging goes live.
5. Where the data comes from
- From Clients and their staff — at onboarding and through ordinary use.
- From Clients, about Residents — staff enter resident details, lease terms and charges.
- From Residents directly — when they view their account, raise a maintenance request, upload a payment proof, give notice, or sign a document.
- From Safaricom (M-Pesa) — payment confirmation returned by the Daraja API.
- From our payment processor — confirmation of a Client's subscription payment.
- Automatically — IP address, timestamps and audit entries generated by use.
6. Why we process personal data, and our lawful basis
Where Sakenora is the controller, the bases we rely on are below. Where the Client is the controller, the Client is responsible for identifying its own lawful basis for Resident data.
6.1 To provide the Platform — performance of a contract with the Client.
6.2 To bill and collect payment — performance of a contract, and legal obligation for tax and accounting records.
6.3 To communicate about the service — performance of a contract, and legitimate interests.
6.4 To keep the Platform running, secure and correct — legitimate interests. Audit logging, security monitoring, abuse prevention, backups, debugging, and verifying unit counts for billing. Where this touches Resident data it is limited to operating the service; it is not used to build profiles or for marketing.
6.5 To handle website enquiries — consent, or steps taken at the person's request before entering a contract.
6.6 To comply with the law and defend legal claims — legal obligation and legitimate interests.
6.7 Processing Resident data — our contract with the Client, acting on the Client's documented instructions. We do not process Resident data for any purpose the Client has not instructed, except where the law requires it, in which case we will tell the Client unless prohibited.
7. Who we share data with
We do not sell personal data.
| Provider | What they receive | Why |
|---|---|---|
| Safaricom PLC (M-Pesa / Daraja) | Paying phone number, amount, reference | Rent payments in Kenya. Safaricom is an independent controller of the payment data it holds. |
| Payment processor | Client billing contact details, amount, card details entered directly on their systems | Client subscription payments. |
| Hostinger International, with servers in the European Union | All Platform data as stored and backed up | Hosting the application, database and files. |
| Email delivery (SMTP) | Recipient address and message content | System email such as password resets, invoices and notices. |
Where these act as our processors we require them by contract to protect the data, process it only on our instructions, and apply appropriate security.
Tenant separation. The Platform is multi-tenant and each Client's data is logically separated. One Client cannot see another Client's data.
Legal and corporate disclosures. We may disclose personal data where required by law, court order or a competent regulator, and where necessary to establish or defend legal claims. In a merger or sale of assets, data may transfer as part of that transaction; we will give notice and the recipient remains bound by equivalent protections.
8. Cross-border transfer of data
Sections 48 and 49 of the DPA restrict transferring personal data outside Kenya.
Where the Platform is hosted: Hostinger International, with servers in the European Union.
Where personal data is transferred outside Kenya we rely on one or more of: the transfer being necessary to perform a contract with the data subject; necessary for a contract concluded in the data subject's interest; appropriate safeguards obliging the recipient to apply standards equivalent to the DPA; or the data subject's informed consent. We keep records of transfers and safeguards and make them available to the ODPC on request.
Somalia and Somaliland. Data protection law in the region is less developed than in Kenya. Somalia has adopted data protection legislation in recent years but its supervisory framework is still being established, and Somaliland has no equivalent comprehensive statute or supervisory authority.
We do not treat that as a licence to apply a lower standard. We apply the Kenyan DPA as our baseline everywhere. Residents and Clients there receive the same security controls, retention practices, breach handling and rights described here, as a contractual commitment. Where local law is stricter, we comply with that as well.
9. Your rights
Part V of the DPA gives you the right to be informed, of access, to object, to correction, to deletion of false or misleading data, to restrict processing, and to data portability. Where we rely on consent you may withdraw it at any time; withdrawal does not affect processing already carried out.
9.1 If you are a Client or a member of a Client's staff
Contact support@sakenora.com. We may ask you to verify your identity. We will respond without undue delay and within the period the DPA requires.
9.2 If you are a Resident — please read this
Your landlord is the data controller for your data. Send your request to them, not to us.
They chose to record your information, they decide what to keep, and they are legally answerable to you for it. They also have direct access to your record and can correct it immediately. Their contact details are on your lease, your invoices, or in the portal.
If you contact us anyway we will tell you who your Client is, point you to them, and where appropriate let them know. We are not permitted to correct, delete or hand over your record on our own initiative. If your Client instructs us to act, we will.
When you can come to us directly: if your concern is about Sakenora's own handling of data — our security, our audit logs, our website contact form, or a breach affecting our systems — contact support@sakenora.com.
9.3 Complaints
You may complain to the Office of the Data Protection Commissioner (ODPC), Kenya. We would prefer you raise it with us first — or, as a Resident, with your landlord first.
10. How long we keep data
| Data | Retention |
|---|---|
| Client staff accounts | Life of the subscription, then deleted or anonymised per 10.2 |
| Client subscription and billing records | As required by Kenyan tax and accounting law |
| Resident records, leases, invoices, payments, maintenance | The Client decides. Retained while their account is active and as instructed, subject to 10.2 |
| Signed documents and signature records | Alongside the document, for as long as it is retained — they are evidence of validity |
| Audit and security logs | 7 years from the entry, unless needed for an open investigation or claim |
| Website contact-form submissions | 7 years from last contact |
| Backups | Rolling cycle of 30 days, then overwritten. Deleted live data persists in backups until the backup expires. |
For Residents: your landlord decides how long your record is kept. Tenancy, tax and evidential requirements often mean years after a tenancy ends. Ask them.
10.2 When a Client leaves. Data is available for export for 30 days after termination. After that we delete or irreversibly anonymise it within 90 days, except where required by law or needed to defend a legal claim. Deletion from backups follows the backup cycle.
11. How we protect data
As required by section 41 of the DPA:
- Encryption in transit — served over HTTPS/TLS.
- Passwords are never stored in readable form — one-way cryptographic hashes only.
- Two-factor authentication (TOTP) available, with the secret encrypted at rest.
- Role-based access control — staff see only what their role permits.
- Tenant isolation — each Client's data is logically separated.
- Audit logging — creation, update and deletion logged with acting user and IP.
- Session controls — sessions held server-side and expire after inactivity.
- Restricted internal access — personnel access data only where necessary to operate, support or secure the service, and that access is logged. Personnel are bound by confidentiality.
- No card data on our systems.
- Backups taken regularly and retained on the cycle above.
No system is perfectly secure. We do not promise the Platform can never be compromised. We promise appropriate measures, and that we will act promptly and honestly if something goes wrong.
Your part: keep your password secret, do not share your account, use two-factor authentication where offered, and tell us or your landlord immediately if you suspect someone else has access.
12. If there is a data breach
Where we are the controller: we will notify the ODPC without undue delay and, where feasible, within seventy-two (72) hours of becoming aware. Where there is a real risk of harm we will also notify affected data subjects in writing without undue delay.
Where we are the processor (Resident data): we will notify the affected Client without undue delay and give them what they need to meet their own obligations. The Client, as controller, is responsible for notifying the ODPC and its Residents. We will support them.
We keep an internal record of breaches and action taken, whether or not notification was required.
13. Children
The Platform is not designed for use by children. Clients may record a child's details as part of a household or emergency contact record; where they do, the Client is the controller and is responsible for the additional care section 33 of the DPA requires. If you believe a child's data has been recorded inappropriately, contact the relevant Client or support@sakenora.com.
14. Cookies
The Platform uses a small number of strictly necessary cookies and no advertising or analytics cookies. See our Cookie Policy.
15. Changes to this policy
We may update this policy. The "Last updated" date will change. If a change materially affects how we handle personal data we will give Clients advance notice by email or in the Platform. Clients are responsible for informing their own Residents where relevant.
16. Contact and complaints
Data protection and rights requests: support@sakenora.com General support: support@sakenora.com Post: Sakenora, Nairobi, Kenya ODPC registration: registration in progress
You may also complain to the Office of the Data Protection Commissioner, Kenya.