Finclusivo / Qwant-AI, drafted in accordance with the Kenya Data Protection Act, 2019.
Read with our Terms
This Privacy Policy forms part of your legal agreement with Finclusivo and must be read alongside our Terms and Conditions (Version 1.1). Defined terms carry the same meaning as in the Terms and Conditions.
Introduction
This Privacy Policy explains how Finclusivo, Qwant-AI, and FinBuddy collect, use, store, share, protect, and delete personal data when you access or use our Services. It applies to all websites, applications, APIs, dashboards, tools, and platforms operated by Finclusivo, including finclusivo.com, qwant-ai.com, and chat.qwant-ai.com.
This Privacy Policy has been drafted in full compliance with the Kenya Data Protection Act, 2019 (DPA) and the eight data protection principles established under Section 25 of the DPA. These principles are substantively aligned with those under the EU General Data Protection Regulation (GDPR, Article 5), and are set out in detail in Section 3 of this Policy.
Where we provide Services directly to you, we act as a data controller. Where we process personal data on behalf of a Business User who is themselves a controller, for example, a fintech company using our API, we act as a data processor, and a Data Processing Agreement must be in place before processing begins.
This Privacy Policy does not replace any separate Data Processing Agreement, enterprise agreement, or business terms that may govern our relationship with Business Users or API customers.
1. Data Controller Information
The data controller responsible for personal data processed under this Privacy Policy is:
- Finclusivo
- Website: www.finclusivo.com | Product: www.qwant-ai.com
- Privacy Contact: support@qwant-ai.com
- ODPC Registration: [Registration number to be inserted upon confirmation from the ODPC]
Data Protection Officer (DPO): Finclusivo has appointed a Data Protection Officer as required under Section 24 of the DPA. The DPO can be contacted by any person regarding any matter relating to this Privacy Policy or the processing of personal data by Finclusivo. DPO Contact: support@qwant-ai.com (mark for the attention of the Data Protection Officer).
2. Key Definitions
The following definitions apply in this Privacy Policy and are consistent with the definitions in our Terms and Conditions (Version 1.1).
- “Personal Data” means any information relating to an identified or identifiable natural person, as defined under Section 2 of the DPA.
- “Sensitive Personal Data” means personal data falling within the categories specified under Sections 2 and 30 of the DPA, including financial data, health data, and data revealing racial or ethnic origin. Financial Data processed by Finclusivo constitutes Sensitive Personal Data and is subject to heightened protection under this Policy.
- “Financial Data” means any information relating to financial accounts, transactions, balances, statements, income, expenses, debts, investments, or business financial records processed through the Services.
- “Consumer User” means an individual accessing the Services for personal purposes outside any trade, business, or profession.
- “Business User” means a company, organisation, or individual accessing the Services for commercial, professional, or organisational purposes.
- “Processing” means any operation performed on personal data, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, erasure, or destruction.
- “DPA” means the Kenya Data Protection Act, 2019.
- “ODPC” means the Office of the Data Protection Commissioner of Kenya.
- “SCCs” means Standard Contractual Clauses, a data transfer safeguard mechanism for international transfers where no adequacy decision exists.
- “POCAMLA” means the Proceeds of Crime and Anti-Money Laundering Act, 2009 (Cap. 59B), as amended.
3. Data Protection Principles
All processing of personal data by Finclusivo is carried out in accordance with the eight data protection principles under Section 25 of the Kenya Data Protection Act, 2019. These principles are aligned with Article 5 of the EU GDPR. We are bound by each of these principles and can demonstrate compliance with them.
| Principle | What It Means for Finclusivo |
|---|---|
| 1. Lawfulness, Fairness, and Transparency | We process personal data only on a valid lawful basis. We are transparent about our processing through this Privacy Policy and do not process data in ways that are hidden, deceptive, or unexpected. |
| 2. Purpose Limitation | We collect personal data for specified, explicit, and legitimate purposes and do not process it in ways that are incompatible with those purposes without your separate consent. |
| 3. Data Minimisation | We collect only personal data that is adequate, relevant, and strictly limited to what is necessary for each specific feature or purpose. We do not collect data speculatively, in bulk, or beyond what each function requires. |
| 4. Accuracy | We take reasonable steps to ensure personal data is accurate and kept up to date. You can correct inaccurate data at any time through your account settings or by contacting us. |
| 5. Storage Limitation | We retain personal data only for as long as is necessary for the original purpose or as required by applicable Kenyan law. Specific retention periods are set out in Section 12. |
| 6. Integrity and Confidentiality | We use appropriate technical and organisational security measures to protect personal data from unauthorised access, loss, destruction, or disclosure. |
| 7. Accountability | We are responsible for our data processing activities and can demonstrate compliance with these principles through our DPO appointment, ODPC registration, Data Processing Agreements, consent records, and this Policy. |
4. Personal Data We Collect
We collect the minimum personal data necessary to deliver each specific Service or feature. The categories below describe precisely what we collect and for what purpose. We do not collect personal data beyond what is described here.
4.1 Account and Identity Information
Collected when you create an account or register for the Services, for the purpose of account creation, authentication, and management.
Required fields:
- Full name, email address, and phone number
- Password or authentication method. We store a hashed version only, never your plaintext password
- User role and account status
Optional / feature-dependent fields:
- Organisation name, business name, country, language preference, and profile details
If you sign in using a third-party provider (such as Google), we receive only the information that provider shares according to your settings and the provider’s own privacy policy. We never receive or store your third-party account password.
We do not collect, store, or require: bank passwords, M-PESA PINs, card PINs, internet banking passwords, card CVV numbers, or any authentication credentials belonging to financial institutions. You must not submit these through our Services. If you do so in error, contact us immediately at support@qwant-ai.com.
4.2 User Content and Financial Data
Collected when you use Qwant-AI, FinBuddy, or related financial Services by submitting content or uploading documents. This processing is necessary to deliver the financial intelligence features you have requested.
Important
Financial Data is Sensitive Personal Data under Section 30 of the DPA. It is processed only where you have provided separate, explicit consent at the point of upload or feature activation, not through your general acceptance of our Terms and Conditions. See Section 6.2 for full details.
We collect:
- Prompts, messages, instructions, and questions you submit
- Uploaded documents including bank statements, M-PESA statements, mobile money statements, receipts, invoices, screenshots, PDFs, CSV files, and spreadsheets
- Financial Data extracted from uploaded documents: transaction dates, amounts, merchant names, account references, balances, transaction categories, income, expenses, loan activity, repayments, and cash flow information
- Business financial records and data you provide directly
4.3 Usage and Technical Data
Collected automatically when you use our Services. We collect only what is necessary to keep the platform secure, functional, and improving.
- Log data: IP address, browser type, operating system, request date and time, pages visited, session identifiers, and error logs
- Usage data: features used, files uploaded, reports generated, access dates and times, and usage frequency
- Device information: device type, browser version, operating system version, app version, and connection type
- General location: country and region inferred from IP address, used for security monitoring and region-specific settings only. We do not collect precise GPS location without your explicit, feature-specific consent
4.4 Communications Data
If you contact us through email, support forms, WhatsApp, social media, or other channels, we collect your name, contact details, message content, attachments, and related communication records, to respond to your enquiry and maintain a record of our interactions.
4.5 Payment and Billing Data
If you purchase a paid plan or subscription, we collect: billing name, billing email, payment status, transaction reference number, subscription plan details, renewal status, and payment confirmation.
We do not store full card numbers, CVV numbers, mobile money PINs, or banking passwords. Payment card and mobile money processing is handled entirely by our licensed third-party payment processors. We never have access to your raw payment credentials.
4.6 Data Received from Third-Party Sources
We receive limited personal data from the following categories of third-party sources, where lawfully permitted:
- Authentication providers (e.g. Google Sign-In): basic profile information where you choose to sign in with a third-party account
- Payment processors: payment confirmation status and transaction reference numbers only, not card or banking credentials
- Fraud prevention and security providers: risk signals used to detect suspicious account activity or unauthorised access attempts
- Analytics providers: aggregated, pseudonymised usage signals to help us understand platform performance
4.7 Data We Do Not Collect
In giving effect to the data minimisation principle, we confirm that we do not collect:
- Banking passwords, PINs, card CVVs, or financial institution credentials of any kind
- Precise GPS location data, unless you explicitly enable a feature that requires it
- Personal data from individuals under the age of 18 (see Section 21)
- Health data, biometric data, political opinion data, or other special-category data, unless separately and expressly consented to for a specific named feature
- Data from data brokers, third-party marketing lists, or any commercial data sources
5. How We Collect Personal Data
We collect personal data through three channels:
- Directly from you: when you create an account, use our Services, upload documents, submit prompts, contact support, complete surveys, or voluntarily provide any other information
- Automatically: through log and usage tracking when you interact with our websites or applications, as described in Section 4.3
- From third parties: from authentication providers, payment processors, and security partners, as described in Section 4.6
We do not purchase personal data from data brokers, third-party marketing lists, or any other commercial data source.
6. Lawful Basis for Processing
Under Section 30 of the Kenya Data Protection Act, 2019, we are required to have a valid lawful basis for every processing activity. The following bases apply, each mapped to specific purposes.
6.1 Performance of a Contract
We process personal data where necessary to perform the Services you have requested, including creating and managing your account, responding to your prompts, managing subscriptions, providing customer support, and fulfilling our obligations under our Terms and Conditions.
6.2 Explicit Consent: Sensitive Personal Data and Financial Data
Under Section 30 of the DPA, processing Sensitive Personal Data, which includes Financial Data, requires explicit consent. This consent must be separate from your general acceptance of our Terms and Conditions.
We obtain this explicit consent through a dedicated consent prompt presented at the point you upload Financial Data or activate a financial analysis feature. This consent:
- (a) identifies precisely what Financial Data will be processed and for what specific purpose;
- (b) is freely given and not bundled with or conditional on acceptance of the Terms and Conditions;
- (c) is granular where you use multiple data sources, allowing you to consent to each independently;
- (d) is recorded with a timestamp and version reference linked to your account; and
- (e) may be withdrawn at any time through your account settings or by contacting us, without affecting your access to other Services that do not depend on that consent.
We also rely on consent for: optional AI model improvement (a separate opt-in under Terms Section 9.4), non-essential cookies and analytics, and subscription to marketing communications.
6.3 Legitimate Interests
We process personal data where necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. We rely on legitimate interests for:
- Fraud prevention, security monitoring, and abuse detection
- Debugging, error logging, and service reliability
- Enforcing our Terms and Conditions and protecting our platform and users
- Improving our Services using aggregated, anonymised, or de-identified data
Before relying on legitimate interests for any new processing activity, we conduct a balancing test to confirm the processing is necessary, proportionate, and does not unduly prejudice your interests, rights, or freedoms. The outcome of that test is documented internally.
6.4 Legal Obligation
We process or retain personal data where required by applicable Kenyan law, including the Tax Procedures Act, the Companies Act, POCAMLA, the Computer Misuse and Cybercrimes Act, court orders, or binding regulatory requests from the ODPC or other competent authorities.
6.5 Protection of Vital Interests and Legal Claims
We may process personal data where necessary to establish, exercise, or defend legal claims, investigate violations of our Terms, or protect the safety, rights, or property of users, Finclusivo, or the public.
Important
Acceptance of our Terms and Conditions alone does not constitute valid explicit consent to the processing of Financial Data under DPA Section 30. Explicit, separate consent is mandatory for Financial Data processing and is obtained through a dedicated consent mechanism at the point of processing.
7. How We Use Personal Data
We use personal data only for the specific purposes for which it was collected or to which you have separately consented. The table below maps each processing activity to its lawful basis.
| Purpose of Processing | Data Category | Lawful Basis |
|---|---|---|
| Create and manage your account | Account information | Contract |
| Authenticate identity and secure account access | Account information, usage data | Contract / Legitimate interests |
| Process prompts and generate AI responses | User content | Contract |
| Analyse uploaded financial documents and generate insights | Financial Data (Sensitive) | Explicit consent (s.6.2) |
| Categorise transactions and generate financial reports | Financial Data (Sensitive) | Explicit consent (s.6.2) |
| Provide customer support and respond to communications | Communications data | Contract / Legitimate interests |
| Manage billing, subscriptions, and payment verification | Payment and billing data | Contract |
| Prevent fraud, abuse, and security incidents | Usage and technical data | Legitimate interests / Legal obligation |
| Monitor performance, diagnose bugs, and improve reliability | Usage and technical data | Legitimate interests |
| Comply with AML, tax, and regulatory obligations | Account, financial, and identity data | Legal obligation |
| Optional AI model improvement (opt-in only) | User content (aggregated) | Separate explicit consent |
| Send marketing communications | Contact information | Consent |
| Research and service development | Anonymised / de-identified data only | Legitimate interests |
8. AI Processing and Model Improvement
8.1 How AI Is Used in Our Services
Qwant-AI and FinBuddy use artificial intelligence and machine learning to process your inputs and Financial Data, generate responses and insights, categorise transactions, summarise documents, and produce financial intelligence outputs. AI processing occurs in real time as you use the Services.
8.2 AI Training: Separate Consent Required
We do not use your personal data or Content to train, fine-tune, or improve our AI models, or those of any third party, without your separate, explicit, informed, and freely given consent. This is consistent with Section 9.4 of our Terms and Conditions.
Where we offer an optional AI improvement programme, we will:
- (f) present a distinct opt-in consent mechanism, completely separate from your general Terms acceptance;
- (g) clearly explain which data will be used, for what purpose, and for how long;
- (h) allow you to withdraw that consent at any time through your account settings or by contacting us; and
- (i) not affect your access to core Services if you decline or later withdraw consent.
Your general use of the Services does not constitute consent to AI model training.
8.3 AI Output Accuracy
AI-generated outputs may be inaccurate, incomplete, outdated, or unsuitable for your specific situation. They are informational outputs only and do not constitute professional financial, legal, tax, medical, or other regulated advice. Your obligations when relying on AI output are set out in full in Section 11 of our Terms and Conditions.
8.4 Third-Party AI Providers
Where our Services use third-party AI infrastructure, those providers process data under binding data processing agreements with Finclusivo. We apply the data minimisation principle to all data shared with third-party AI providers. Only the data strictly necessary to generate the output you have requested is shared with those providers. We do not share your full Financial Data profile with AI providers for purposes beyond your immediate request.
9. Automated Decision-Making
Our Services use automated processing, including AI and machine learning, to produce financial intelligence outputs, including transaction categorisation, cash flow analysis, financial health summaries, budget insights, and business decision-support content. This processing is disclosed in accordance with Section 32 of the DPA.
Where outputs generated by our Services are used by you, a Business User, or a third-party fintech, to make or inform decisions that significantly affect an individual, the following rights and responsibilities apply:
- You have the right to be informed that automated processing of your Financial Data is taking place and to understand the general logic involved.
- You have the right to request human review of any automated output that you believe is inaccurate, unfair, or has materially affected you.
- You have the right to object to automated processing of your Financial Data, in which case we will restrict or cease that processing where your objection is well-founded.
- You have the right to request correction of inaccurate underlying data on which automated outputs were based.
- Third parties who use our outputs to make significant decisions about you are independently responsible for their own compliance with the DPA, applicable CBK guidance, and all other relevant regulatory frameworks.
To exercise any of these rights, contact us at support@qwant-ai.com with the subject line “Automated Processing: Rights Request.” We will respond within 14 working days. This is also addressed in Section 13 of our Terms and Conditions.
10. Disclosure of Personal Data
We do not sell your personal data. We do not sell your Financial Data to advertisers, credit bureaux, data brokers, or any other commercial third parties.
We disclose personal data only in the following circumstances:
10.1 Service Providers and Processors
We share personal data with service providers and data processors who help us operate and deliver our Services. These providers process data only on our documented instructions, under binding data processing agreements, and may not use your data for their own independent purposes. Categories of providers include:
- Cloud and hosting providers (infrastructure and data storage)
- Third-party AI model providers (processing prompts and generating outputs)
- Payment processors (handling subscription and billing transactions)
- Authentication providers (enabling third-party sign-in)
- Analytics providers (pseudonymised platform performance data)
- Customer support tools (managing support tickets and communications)
- Security and fraud prevention providers (threat detection and access monitoring)
All service providers are contractually required to implement appropriate security measures and may not use your data for their own independent commercial purposes.
10.2 Business Users and Organisation Administrators
If you access the Services through a business, employer, school, or organisation account, administrators of that account may have access to account activity, uploaded content, reports, and usage data depending on the Service configuration. The organisation’s own policies and any applicable data processing agreements govern this access.
10.3 Legal, Regulatory, and Safety Disclosures
We disclose personal data to government authorities, courts, regulators, law enforcement, or the Financial Reporting Centre where we are legally required to do so, or where we have reasonable grounds to believe disclosure is necessary to:
- (j) comply with a binding legal obligation, court order, or regulatory request;
- (k) report suspicious transactions to the Financial Reporting Centre under POCAMLA;
- (l) protect the safety of users or the public; or
- (m) investigate, prevent, or respond to fraud, abuse, or unlawful activity.
We do not make voluntary disclosures beyond what is legally required or strictly necessary. Where legally permitted, we will notify you of any disclosure request relating to your data before or after the disclosure occurs.
10.4 Business Transfers
If Finclusivo is involved in a merger, acquisition, restructuring, or transfer of business, personal data may transfer as part of that transaction. Consistent with Section 34.3 of our Terms and Conditions, we will provide at least 30 days’ advance written notice where such a transfer materially affects the nature of the Services or the data processing described in this Policy. You may close your account before the transfer takes effect if you do not wish to continue.
10.5 Affiliates and Related Entities
We may share personal data with our affiliates and subsidiaries where strictly necessary to operate the Finclusivo ecosystem. Any affiliate receiving personal data is bound by this Privacy Policy and must process that data only for the specific, limited purpose for which it was shared. We do not share personal data with affiliates for their own independent marketing or commercial use without your separate consent.
10.6 User-Initiated Sharing
Where features allow you to share reports, outputs, files, or content with other users or third parties, information shared in that way is governed by the recipient’s own privacy practices. You are responsible for understanding those practices before sharing.
11. International Data Transfers
Finclusivo uses cloud infrastructure, AI services, analytics tools, and support platforms that are operated from locations outside Kenya. Your personal data may therefore be processed or stored in other countries.
11.1 Where Data May Be Transferred
The following categories of providers may process your data outside Kenya:
- Cloud and hosting infrastructure: servers may be located in the United States, European Union, or other regions depending on our infrastructure provider’s configuration
- Third-party AI model providers: primarily based in the United States
- Analytics providers: may process anonymised usage data in the United States or European Union
- Customer support tools: may be hosted in the United States or European Union
We will update this section when providers or transfer locations change materially.
11.2 Safeguards for International Transfers
In compliance with Section 49 of the DPA, we apply the following specific, named safeguards to all international data transfers:
- Standard Contractual Clauses (SCCs): Where we transfer personal data to providers in countries without a DPA adequacy determination, we enter into SCCs or equivalent contractual data transfer mechanisms. These impose DPA-equivalent data protection obligations on the receiving party.
- Data Processing Agreements: All third-party processors, whether based in Kenya or internationally, are required to sign binding data processing agreements before processing begins. These agreements limit their use of data strictly to our documented instructions, require appropriate security measures, and prohibit independent use of your data.
- Encryption in transit and at rest: All data transferred internationally is protected in transit using TLS/HTTPS encryption. Financial Data and sensitive personal data is encrypted at rest using appropriate encryption standards.
- Provider due diligence: Before engaging any international provider that will process personal data, we conduct due diligence on their data protection policies, security practices, and regulatory track record.
- Adequacy decisions: Where the ODPC issues an adequacy decision in respect of a specific country or territory, we will rely on that decision as the primary transfer mechanism for transfers to that jurisdiction.
12. Retention of Personal Data
We retain personal data only for as long as is necessary for the purpose for which it was collected, to comply with our legal obligations, and to support legitimate business purposes including security, dispute resolution, and fraud prevention. Retention periods reflect the data minimisation and storage limitation principles under Section 25 of the DPA.
12.1 Statutory Minimum Retention Periods
The following minimum retention periods are imposed by applicable Kenyan law. We are legally required to retain this data for the stated periods regardless of account deletion or deletion request. Deletion requests made during these periods will be noted but cannot be actioned for the categories listed below:
| Data Category | Minimum Retention Period | Legal Authority |
|---|---|---|
| Tax records and financial transaction records | 5 years | Tax Procedures Act, 2015 (s.23) |
| Accounting records and business financial records | 7 years | Companies Act, 2015 (s.686) |
| AML / KYC records and suspicious transaction reports | 7 years | POCAMLA, 2009 (s.43) |
| Billing and payment records | 7 years | Tax Procedures Act, 2015 |
| Consent records and processing audit logs | Duration of relationship + 3 years | DPA accountability obligation (s.25(h)) and dispute resolution |
Account deletion note
Deleting your account or requesting erasure will remove your active account data within 30 days. However, we are required by law to retain financial, AML, and billing records for the statutory periods listed above, regardless of account deletion. These records are held securely, are not accessible for general use, and are accessed only as required by law or for dispute resolution.
12.2 Data Retained Until You Delete It
The following data is held in your account until you choose to delete it or request deletion:
- Chat history and AI interaction records
- Uploaded documents and extracted Financial Data linked to your account
- Transaction categories, budgets, and financial reports you have generated
- Account preferences, settings, and recorded consent choices
When you delete personal data or request account deletion, we aim to remove it from active systems within 30 days, subject to the statutory retention obligations in Section 12.1.
12.3 Data Deleted Automatically
The following data is automatically deleted after a defined period without any action from you:
- Temporary processing files and extracted raw document text: deleted within 30 days of processing unless you have saved the output to your account
- Session data and temporary authentication tokens: deleted at session end
- Expired security and error logs: deleted after 90 days unless flagged in connection with an active security investigation
12.4 Retention Reviews
We conduct periodic reviews of retention periods and delete or anonymise personal data that is no longer required for its original purpose or any lawful secondary purpose. Where data can be anonymised rather than deleted, and where a legitimate analytical or research purpose exists, we may anonymise data in preference to outright deletion.
13. Your Data Controls
We give you meaningful, accessible controls over your personal data. Depending on the features available in your account, you can:
- Access and view your account information and settings at any time
- Update and correct your profile information directly in your account
- Delete individual chats, uploaded documents, and financial records
- Export your chat history and financial records in a portable format
- Download a copy of your account data
- Manage cookie preferences through our cookie banner or browser settings
- Opt out of the AI model improvement programme at any time through account settings
- Withdraw consent for Financial Data processing at any time. This may affect access to financial analysis features that depend on that consent
- Withdraw consent for marketing communications at any time using the unsubscribe link in any email, or by contacting us
- Request correction or deletion of personal data by contacting us directly
- Delete your account entirely
If a control is not yet available directly in your account settings, contact us at support@qwant-ai.com and we will assist you directly. All deletion and correction requests receive a response within the timelines set out in Section 14.
14. Your Rights Under the DPA
Under the Kenya Data Protection Act, 2019, you have the following rights as a data subject. These rights apply in addition to, and cannot be diminished by, our Terms and Conditions or any liability limitation in our agreements.
14.1 Right to Be Informed (Section 26, DPA)
You have the right to know that your personal data is being processed, the purposes of processing, and the categories of data involved. This Privacy Policy is the primary means by which we fulfil this obligation. For questions beyond what this Policy covers, contact our DPO.
14.2 Right of Access (Section 26(1)(a), DPA)
You have the right to request confirmation of whether we hold personal data about you and, if so, a copy of that data. A response to a verified access request will include: the categories of data held, the purposes of processing, the recipients to whom it has been disclosed, and the applicable retention period. We respond to verified access requests within 21 days.
14.3 Right to Correction (Section 26(1)(b), DPA)
You have the right to request correction of personal data that is inaccurate, incomplete, or misleading. Many corrections can be made directly through your account settings. For data that cannot be self-corrected, contact us at support@qwant-ai.com.
14.4 Right to Erasure (Section 26(1)(c), DPA)
You have the right to request erasure of personal data that is inaccurate, irrelevant, excessive, or was obtained unlawfully. This right is not absolute. It does not apply where retention is required by law (see Section 12.1) or where the data is necessary to establish, exercise, or defend legal claims. We will respond to verified erasure requests within 21 days and will clearly explain any applicable exception.
14.5 Right to Object (Section 26(1)(d), DPA)
You have the right to object to the processing of your personal data where that processing is based on legitimate interests or is carried out for direct marketing purposes. Where you object to legitimate-interests processing, we will cease unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
14.6 Right to Restrict Processing
You have the right to request that we restrict processing of your personal data in defined circumstances, for example, while the accuracy of data is being contested, or where you have objected and a decision is pending.
14.7 Right to Data Portability (Section 28, DPA)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to request that we transmit that data to another service provider where technically feasible. This is a statutory right under Kenyan law and applies to data processed on the basis of your consent or in performance of a contract with you.
14.8 Rights in Relation to Automated Processing (Section 32, DPA)
You have the right to be informed about automated processing that significantly affects you, to request human review of any such decision, and to object to automated processing of your personal data. See Section 9 of this Policy and Section 13 of our Terms and Conditions for full details.
14.9 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. You can withdraw consent through your account settings or by contacting us.
14.10 Right to Complain to the ODPC
If you are dissatisfied with how we handle your personal data or any rights request, you have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya (ODPC) at www.odpc.go.ke. We encourage you to contact our DPO first. We will make every effort to resolve your concern promptly and without requiring a formal regulatory complaint.
14.11 How to Exercise Your Rights
Contact us at support@qwant-ai.com with the subject line “Data Rights Request” and specify which right you wish to exercise. We may ask you to verify your identity before processing your request. We will respond within 21 days. Where we cannot fulfil a request due to a statutory retention obligation or other lawful exception, we will explain the reason and advise what alternatives are available.
15. Security
We implement appropriate technical, administrative, and organisational security measures to protect personal data from loss, misuse, unauthorised access, disclosure, alteration, and destruction. Our current security measures include:
- Encryption in transit: all data transmitted between your device and our Services is encrypted using HTTPS/TLS
- Encryption at rest: Financial Data and sensitive account data is encrypted at rest using appropriate encryption standards
- Access controls: role-based access controls limit access to personal data to authorised personnel only, on a need-to-know basis
- Authentication: multi-factor authentication options are available for user accounts and are required for administrative access to production systems
- Audit logging: all access to sensitive data systems is logged and subject to regular monitoring
- Security monitoring: we deploy anomaly detection and intrusion monitoring to identify and respond to threats
- Payload policies: we maintain strict policies against logging sensitive financial payloads in application logs or debugging tools
- Third-party security reviews: we conduct periodic due diligence on all service providers handling personal data
No online service can guarantee absolute security. You are responsible for keeping your login credentials confidential, using secure and up-to-date devices, and notifying us immediately at support@qwant-ai.com if you suspect any unauthorised access to your account.
16. Data Breach Handling
If we become aware of a personal data breach, we will act promptly to investigate, contain, and remediate the incident. Our response process includes:
- Internal investigation to determine the nature, scope, cause, and extent of the breach
- Containment measures to prevent further unauthorised access or data loss
- ODPC notification where required under Section 43 of the DPA, within the prescribed regulatory timeframe
- User notification where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, including a clear explanation of what happened, what data was involved, and what steps individuals can take to protect themselves
- Business User and regulatory notification where required by applicable law or contract
- Internal breach register recording all incidents, investigations, notifications sent, and corrective actions taken
If you believe your account has been compromised or you have reason to believe Finclusivo has suffered a data breach, contact us immediately at support@qwant-ai.com with the subject line “Security: Urgent.”
17. Marketing Communications
We send service-related messages, security notices, billing confirmations, product updates, and feature announcements as part of delivering the Services. These communications are sent on the basis of contract performance and legitimate interests and cannot be fully opted out of while your account is active.
We send marketing communications, including promotional content, newsletters, and new feature announcements, only where you have opted in to receive them. You may withdraw consent at any time by:
- Clicking the unsubscribe link in any marketing email
- Updating your notification preferences in your account settings
- Contacting us at support@qwant-ai.com
Unsubscribing from marketing communications does not affect your receipt of service-critical notifications such as security alerts or billing confirmations.
18. Cookies and Tracking Technologies
We use cookies and similar technologies to operate our Services, maintain secure sessions, remember your preferences, and analyse platform performance.
18.1 Essential Cookies
Essential cookies are strictly necessary for the Services to function, for example, to maintain your authenticated session, enforce security controls, and remember your cookie preferences. These are placed without requiring separate consent as they are technically required for the Services to operate.
18.2 Non-Essential Cookies
Non-essential cookies, including analytics cookies and optional personalisation tools, are placed only with your prior consent through our cookie banner. You can update your cookie preferences at any time through the cookie settings link on our website or through your browser settings.
18.3 No Targeted Advertising
We do not currently use cookies for targeted advertising, cross-context behavioural advertising, or profiling for commercial advertising purposes. We do not share your data with advertising networks. If this changes in the future, we will update this Policy, notify you as required under Section 23, and obtain appropriate consent before deploying advertising technologies.
18.4 Cookie Policy
A detailed Cookie Policy setting out the specific cookies we use, their purpose, their duration, and how to manage them is published separately at [www.finclusivo.com/cookies]. This Cookie Policy forms part of this Privacy Policy and should be read alongside it.
19. Business and Organisation Users
19.1 Controller and Processor Roles
Where a Business User provides Finclusivo with personal data relating to their own employees, customers, or third parties for processing, that Business User acts as the data controller for that data and Finclusivo acts as the data processor, processing that data only on the Business User’s documented instructions.
19.2 Data Processing Agreement
Where Finclusivo acts as a data processor for a Business User, a written Data Processing Agreement consistent with Section 43 of the DPA must be in place before any processing begins. Business Users may request a Data Processing Agreement template by contacting support@qwant-ai.com.
19.3 Business User Responsibilities
Where a Business User uploads or submits personal data relating to third parties, including employees, customers, suppliers, or agents, that Business User is solely responsible for:
- (n) holding a valid lawful basis for that processing under the DPA;
- (o) providing adequate and timely privacy notices to the individuals concerned;
- (p) obtaining all necessary consents where consent is the chosen lawful basis; and
- (q) complying with all applicable data protection, AML, and regulatory obligations.
19.4 Administrator Access
Administrators of a business or organisation account may access user accounts, content, usage data, billing details, and settings within that account depending on the Service configuration. The Business User is responsible for ensuring that administrator access is governed by appropriate internal policies and is consistent with the data protection rights of the individuals whose data is accessible.
20. Third-Party Services
Our Services may include, connect to, or link to third-party services including payment providers, authentication providers, cloud platforms, AI infrastructure, analytics tools, and partner integrations. Third-party services are governed entirely by their own terms and privacy policies. We are not responsible for the data practices, security, accuracy, or availability of any third-party service.
Where third-party services are material to how we process your personal data, the relevant provider category is identified in Section 10.1 and Section 11.1. Before connecting to or using any third-party service accessible through our platform, you should review that service’s own privacy policy.
21. Children and Minors
Our Services are not designed for or directed at individuals under the age of 18, particularly where the Services involve Financial Data processing, document uploads, AI analysis, business tools, or paid subscriptions.
We do not knowingly collect personal data from anyone under 18. If you are under 18, you must not use or attempt to register for these Services.
If you believe that a person under 18 has provided personal data to us, whether through account registration, content submission, or any other means, contact us immediately at support@qwant-ai.com. We will investigate and take appropriate action, including deletion of the relevant data where required.
22. Users Outside Kenya
Our Services are primarily designed for users in Kenya and are governed by the Kenya Data Protection Act, 2019. Users in other jurisdictions may have additional rights under their local laws, which we will respect to the extent required by applicable mandatory law.
- European Economic Area, United Kingdom, and Switzerland: you may have rights under the GDPR or equivalent legislation, including access, rectification, erasure, restriction, portability, and the right to object. You may also have the right to complain to your local supervisory authority.
- Nigeria: you may have rights under the Nigeria Data Protection Act, 2023, and the NDPR.
- South Africa: you may have rights under the Protection of Personal Information Act, 2013 (POPIA).
- Other jurisdictions: where local mandatory data protection laws apply to your use of our Services, we will respect those obligations to the extent required by applicable law.
To exercise rights under your local data protection law, contact us at support@qwant-ai.com. We will assess your request under applicable law and respond accordingly.
23. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We apply the same three-tier change framework used in our Terms and Conditions (Section 33):
- Category A (minor or cosmetic changes): typographical corrections, formatting updates, or clarifications that do not affect your rights or how we process your data. These take effect on the date published. No advance notice is required.
- Category B (material non-data changes): changes to our structure, contact information, or governance that do not affect how we process your personal data. We will provide at least 14 days’ advance notice by email or in-app notification before such changes take effect. Continued use of the Services after the effective date constitutes acceptance.
- Category C (data processing changes): any change to the categories of data we collect, the purposes for which we process it, the parties we share it with, the lawful basis we rely on, or the retention periods we apply. These changes require your affirmative, explicit consent before taking effect in relation to your account. We will not apply data processing changes to your account solely on the basis of your continued use of the Services.
If you do not accept a Category B or Category C change, you may close your account and request deletion of your data before the change takes effect. The effective date and version number of this Policy are displayed at the top of this document.
24. Contact Information
For any questions, requests, or concerns relating to this Privacy Policy or the processing of your personal data:
General Privacy Enquiries
- Email: support@qwant-ai.com (Subject: Privacy Enquiry)
- Website: www.finclusivo.com
Data Rights Requests (access, correction, erasure, portability, objection, consent withdrawal)
- Email: support@qwant-ai.com (Subject: Data Rights Request)
- Response time: 21 days
Data Protection Officer: Escalations and Urgent Matters
- Email: support@qwant-ai.com (Subject: DPO Escalation)
To Lodge a Complaint with the Regulator
- Office of the Data Protection Commissioner of Kenya (ODPC)
- Website: www.odpc.go.ke