Privacy notice
Privacy Notice
This notice explains what personal data Koya Labs Ltd collects when you convert between Kenyan Shillings and Bitcoin, why we collect it, who we share it with, how long we keep it, and the rights you hold over it under the Kenya Data Protection Act, 2019.
- Version
- 2.0
- Effective
- 1 August 2026
- Last updated
- 25 July 2026
Introduction and who we are
Koya Labs Ltd ("Koya", "we", "us", "our") is a private limited company incorporated in Kenya under Registration No. PVT-MA15BD72. We operate the koyabank.com platform, which provides conversion between Kenyan Shillings and Bitcoin, together with related remittance services.
This Notice explains what personal data we collect, why we collect it, how we use and protect it, and the rights you hold over it under the Kenya Data Protection Act, 2019 (the "DPA") and the regulations made under it.
Koya Labs Ltd is the data controller for personal data processed through our website, our mobile interfaces, our WhatsApp and Telegram channels, and our customer support interactions. Being the controller means we decide what data is collected and why, and we are accountable for how it is handled.
Who this notice covers
This Notice applies to everyone whose personal data we process, whether or not you complete an account. That includes visitors to our website, people who begin identity verification and do not finish it, people who transact with us as guests, registered customers, and people who contact our support channels without holding an account.
How to read this notice
Sections 1 to 14 are the notice itself. Addendum A lists the categories of processor we rely on. Addendum B sets out the separate, mandatory basis on which we process identity and source of funds data for anti money laundering purposes. Every section is linkable: use the contents list above, or copy the address bar once you have jumped to a section.
Personal data we collect
What we hold, with an example of each and the reason we hold it.
We collect only what we need to operate a regulated conversion service safely and lawfully. The table below sets out each category, concrete examples of what falls inside it, and the purpose it serves. Where data comes from a third party rather than directly from you, that is stated.
| Category of data | Examples | Purpose |
|---|---|---|
| Identity and verification data | Full legal name, national ID or passport number, date of birth, nationality, photograph, liveness selfie, KRA PIN. Collected through our KYC provider, Sumsub. | To verify that you are who you say you are and to meet our anti money laundering and counter terrorist financing obligations. |
| Contact data | Phone number, email address, physical and postal address. | To reach you about your transactions, to send service notifications, and to satisfy customer due diligence record keeping. |
| Financial and transaction data | M-Pesa account reference, transaction amounts, currency pairs, Bitcoin wallet and receiving addresses, payment channel used, and your transaction history. | To execute conversions and remittances, to settle them correctly, and to keep the records that tax and AML law require. |
| Device and technical data | IP address, device identifiers, browser type, operating system, and approximate geolocation. | To keep accounts secure, to detect fraud, and in part to distinguish diaspora from domestic users so that we route the service correctly. |
| Communications data | Customer support messages sent through the website, WhatsApp or Telegram, and our replies. | To answer your questions, to resolve disputes, and to keep an accurate record of what was agreed. |
| Risk and compliance data | Sanctions and politically exposed person screening results, internal risk tier classification, and transaction monitoring flags. | To meet our legal obligations to screen and monitor, and to protect customers and the platform from financial crime. |
Categories of personal data processed by Koya Labs Ltd, with purposes.
- Category of data
- Identity and verification data
- Examples
- Full legal name, national ID or passport number, date of birth, nationality, photograph, liveness selfie, KRA PIN. Collected through our KYC provider, Sumsub.
- Purpose
- To verify that you are who you say you are and to meet our anti money laundering and counter terrorist financing obligations.
- Category of data
- Contact data
- Examples
- Phone number, email address, physical and postal address.
- Purpose
- To reach you about your transactions, to send service notifications, and to satisfy customer due diligence record keeping.
- Category of data
- Financial and transaction data
- Examples
- M-Pesa account reference, transaction amounts, currency pairs, Bitcoin wallet and receiving addresses, payment channel used, and your transaction history.
- Purpose
- To execute conversions and remittances, to settle them correctly, and to keep the records that tax and AML law require.
- Category of data
- Device and technical data
- Examples
- IP address, device identifiers, browser type, operating system, and approximate geolocation.
- Purpose
- To keep accounts secure, to detect fraud, and in part to distinguish diaspora from domestic users so that we route the service correctly.
- Category of data
- Communications data
- Examples
- Customer support messages sent through the website, WhatsApp or Telegram, and our replies.
- Purpose
- To answer your questions, to resolve disputes, and to keep an accurate record of what was agreed.
- Category of data
- Risk and compliance data
- Examples
- Sanctions and politically exposed person screening results, internal risk tier classification, and transaction monitoring flags.
- Purpose
- To meet our legal obligations to screen and monitor, and to protect customers and the platform from financial crime.
How and why we use your data
We use the personal data described above for the following purposes.
- To create and administer your account, including verifying your identity before you can transact.
- To process currency conversions and remittances, and to settle them to the destination you specify.
- To comply with anti money laundering, counter terrorist financing and tax law, including record keeping and any reporting we are required to make.
- To prevent, detect and investigate fraud, and to monitor transactions for indicators of financial crime.
- To provide customer support and to resolve disputes and complaints.
- To send you service notifications about your account and your transactions, such as confirmation that a conversion has settled or that your verification result is ready.
- To secure the platform, including detecting unauthorised access and protecting against abuse.
- To understand how the platform is used so that we can improve it, using aggregated and, where possible, anonymised information.
- To send you marketing communications, only where you have given consent, and only until you withdraw it.
We do not use your personal data for purposes that are incompatible with the ones listed here. If that ever changes, we will tell you before the new use begins.
Legal bases for processing
Under the Kenya Data Protection Act, 2019, every use of personal data must rest on a lawful basis. We rely on four.
- Consent
- Where you have freely given us permission for a specific purpose, such as marketing communications or non essential cookies. You may withdraw consent at any time, and withdrawing it does not affect processing that already took place while it was in force.
- Performance of a contract
- Where processing is necessary to provide the service you asked for, such as executing a conversion or paying out to the wallet or M-Pesa number you gave us.
- Compliance with a legal obligation
- Where the law requires it, including customer due diligence, sanctions screening, transaction monitoring, record retention and reporting under anti money laundering and tax legislation. This basis does not depend on your consent and cannot be withdrawn.
- Legitimate interests
- Where we have a genuine business interest that does not override your rights, such as preventing fraud, securing the platform and improving the service. We weigh our interest against your rights and freedoms before relying on this basis, and we do not rely on it where the impact on you would be disproportionate.
International data transfers
Our infrastructure is hosted in the European Union, in Frankfurt, Germany. Some of our processors also operate outside Kenya.
Where personal data is transferred outside Kenya, we make sure appropriate safeguards are in place, consistent with the Kenya Data Protection (General) Regulations, 2021. In practice that means contractual data protection clauses with each processor, obliging them to protect the data to the standard the DPA requires and limiting what they may do with it.
Data security
We apply technical and organisational measures appropriate to the sensitivity of the data we hold.
- Data is encrypted in transit using TLS, and encrypted at rest.
- Encryption keys for sensitive data are managed through a dedicated key management service, separate from the systems that use them.
- Access is controlled by role. Staff are granted the minimum access their work requires, and access to sensitive customer data is logged.
- Systems that handle customer funds are separated from systems that serve the public website.
- We keep audit records of administrative actions taken against customer accounts.
We describe our measures in general terms on purpose. Publishing the specific architecture of a financial platform would help an attacker more than it would help you. If you are a regulator or an auditor and need detail, contact us using the details in section 14.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Office of the Data Protection Commissioner and, where the law requires, you directly.
Data retention
How long each category is kept, and what sets the period.
We keep personal data only as long as we need it, or as long as the law requires us to. Anti money laundering law sets a floor we cannot go below, which is why some records outlive the closure of your account.
| Category of data | Retention period | Basis |
|---|---|---|
| KYC and identity data | At least 7 years from the end of the relationship | Anti money laundering and counter terrorist financing record keeping obligations. |
| Transaction records | At least 7 years | Tax and anti money laundering obligations. |
| Marketing data held with consent | Until consent is withdrawn, or 2 years of inactivity, whichever comes first | Consent. There is no obligation to keep it once consent ends. |
| Customer support records | 3 years from the last interaction | Handling disputes and complaints, and evidencing what was agreed. |
| Rejected or incomplete onboarding data | 12 months from collection | Fraud prevention, and evidencing why an application was not completed. |
Retention schedule. Where two bases apply, the longer period governs.
- Category of data
- KYC and identity data
- Retention period
- At least 7 years from the end of the relationship
- Basis
- Anti money laundering and counter terrorist financing record keeping obligations.
- Category of data
- Transaction records
- Retention period
- At least 7 years
- Basis
- Tax and anti money laundering obligations.
- Category of data
- Marketing data held with consent
- Retention period
- Until consent is withdrawn, or 2 years of inactivity, whichever comes first
- Basis
- Consent. There is no obligation to keep it once consent ends.
- Category of data
- Customer support records
- Retention period
- 3 years from the last interaction
- Basis
- Handling disputes and complaints, and evidencing what was agreed.
- Category of data
- Rejected or incomplete onboarding data
- Retention period
- 12 months from collection
- Basis
- Fraud prevention, and evidencing why an application was not completed.
Your rights
The Kenya Data Protection Act, 2019 gives you the following rights over your personal data. You can exercise any of them using the contact details in section 14, and we will respond within the time the law allows.
- Right to be informed
- To know what personal data we hold about you, why we hold it, and who we share it with. This Notice is how we meet that obligation.
- Right of access
- To obtain a copy of the personal data we hold about you.
- Right to rectification
- To have inaccurate personal data corrected, and incomplete data completed.
- Right to erasure
- To ask us to delete personal data. This right is limited: where anti money laundering or tax law requires us to keep a record, we cannot delete it until that period expires, and we will tell you when that is.
- Right to object
- To object to processing carried out on the basis of our legitimate interests. Where you object, we stop unless we can show compelling grounds that override your rights.
- Right to data portability
- To receive the personal data you gave us in a structured, commonly used and machine readable format, and to have it transmitted to another controller where that is technically feasible.
- Right to lodge a complaint
- To complain to the Office of the Data Protection Commissioner if you believe we have handled your data unlawfully. You do not have to raise it with us first, although we would like the chance to put it right.
Exercising a right costs nothing
We do not charge a fee for responding to a rights request, and making one will never affect the service you receive. We will ask you to verify your identity before we act, because handing your data to someone impersonating you would be the very harm these rights exist to prevent.
Children's privacy
Koya does not knowingly collect personal data from anyone under 18, and our services are not offered to minors. Identity verification is designed to detect this at onboarding.
If we identify an account as belonging to a minor, we will close it. If you believe a minor has provided us with personal data, contact us using the details in section 14 and we will act.
Automated decision making
Parts of our risk scoring and sanctions screening are automated. Automation is what makes it possible to screen every transaction rather than a sample.
Automation is not, however, what decides the outcome. Every sanctions or politically exposed person name match, and every transaction flagged as elevated risk, is reviewed by a member of our compliance team before any account restriction or transaction rejection takes effect.
No purely automated adverse decision
We do not restrict an account or reject a transaction on the basis of an automated decision alone. A human reviews the case first. If a decision goes against you, you may ask for the reason and ask us to reconsider it, using the contact details in section 14.
Changes to this notice
We review this Notice periodically and update it when our processing changes or when the law does. The current version and its date are shown at the top of this page, and the notice is always published at koyabank.com.
Where a change is material, we will communicate it to you directly, by email or in the app, rather than relying on you to notice a new date here. Continuing to use the service after a change takes effect means the updated Notice applies to you.
Contact us
For any question about this Notice, or to exercise any of the rights in section 9, contact our Data Protection Officer. If you are not satisfied with our response, you have the right to complain to the Office of the Data Protection Commissioner, and you can do so directly.
Data controller
Koya Labs Ltd
Prestige Building, Ngong Road Highridge, Westlands Nairobi, Kenya
- Privacy
- privacy@koyabank.com
- Registration
- PVT-MA15BD72
- Attention
- Data Protection Officer
Supervisory authority, Kenya
Office of the Data Protection Commissioner
Britam Tower, Hospital Road Upper Hill Nairobi, Kenya
- Website
- www.odpc.go.ke
Third party processors
The table below lists the categories of processor we rely on to operate the service, what each does, and where it operates. We name a provider only where that fact is already public.
| Category | Provider | Purpose | Location |
|---|---|---|---|
| KYC and identity verification | Sumsub | Identity and liveness verification | European Union |
| Cloud hosting | Amazon Web Services | Platform infrastructure | EU, Frankfurt |
| Payment processing | Safaricom Daraja and backup providers | Transaction execution | Kenya |
| Digital asset custody | Custody partner | Bitcoin safekeeping and settlement | International |
Categories of processor engaged by Koya Labs Ltd.
- Category
- KYC and identity verification
- Provider
- Sumsub
- Purpose
- Identity and liveness verification
- Location
- European Union
- Category
- Cloud hosting
- Provider
- Amazon Web Services
- Purpose
- Platform infrastructure
- Location
- EU, Frankfurt
- Category
- Payment processing
- Provider
- Safaricom Daraja and backup providers
- Purpose
- Transaction execution
- Location
- Kenya
- Category
- Digital asset custody
- Provider
- Custody partner
- Purpose
- Bitcoin safekeeping and settlement
- Location
- International
AML and KYC data processing notice
This addendum explains the separate basis on which we process the identity, address and source of funds data we collect for customer due diligence.
That data is processed under Kenya's Proceeds of Crime and Anti-Money Laundering Act (POCAMLA) and the Virtual Asset Service Providers Act, 2025. Processing it is a legal obligation, not a matter of consent, which means you cannot withdraw it while the obligation lasts and we cannot delete the records early.
Providing this data is mandatory
You cannot use Koya's services without providing it. That is a requirement of the law we operate under, not a commercial preference.
Where the data is not provided, or where screening produces a positive sanctions or politically exposed person match that survives review, the consequences may include any of the following.
- Restriction of your account, in whole or in part.
- Rejection of a specific transaction.
- Refusal of service, or termination of the relationship.
A positive screening match is never acted on automatically. It is reviewed by our compliance team first, as described in section 12.
Why we may be unable to explain a decision in full
In some circumstances the law prevents us from telling you that a report has been made about a transaction, or from explaining the detail behind a compliance decision. Where that applies we will tell you as much as we lawfully can. This restriction comes from the anti money laundering framework, and it applies to every regulated institution in Kenya.