Back to Legal
Data Protection Policy
Last updated: August 2026
1. Compliance Framework
Merry-Go is committed to protecting your data. We comply with:
- Kenya Data Protection Act (2019)
- GDPR (European Union)
- UK GDPR
- CCPA (California)
- POPIA (South Africa)
2. Data Protection Officer
Our Data Protection Officer is responsible for overseeing data protection compliance and handling data subject requests.
Email: dpo@merry-go.ac.ke
3. Data Flow
How your data moves through our system:
- Member initiates a contribution via STK Push
- Money enters the Merry-Go business Till
- Safaricom sends a webhook callback to our server
- Our backend triggers B2C disbursement to the treasurer
- Contribution records update in Firestore
4. Security Measures
- AES-256 encryption at rest
- TLS 1.3 encryption in transit
- SHA-256 PIN hashing
- OTP verification for device binding
- Role-based access controls
- Daily automated encrypted backups
- Continuous error and anomaly monitoring
5. Data Subject Rights
You have the right to:
- Access your data
- Request correction of inaccurate data
- Request erasure (subject to legal retention requirements)
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent
To exercise these rights, email dpo@merry-go.ac.ke.
6. Breach Response
In the event of a data breach affecting your personal information:
- Affected users are notified within 72 hours
- The Office of the Data Protection Commissioner (ODPC) is notified as required
- We investigate, contain, and remediate the breach
- A post-incident report is produced
7. Third-Party Processors
We work with the following data processors, all of whom are contractually bound to protect your data:
- Google Cloud Platform (Firebase) - infrastructure and storage
- Safaricom PLC - M-Pesa payment processing
- Meta (WhatsApp) - reminder delivery
8. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated to users.