koya

Privacy notice

Privacy Notice

This notice explains what personal data Koya Labs Ltd collects when you convert between Kenyan Shillings and Bitcoin, why we collect it, who we share it with, how long we keep it, and the rights you hold over it under the Kenya Data Protection Act, 2019.

Version
2.0
Effective
1 August 2026
Last updated
25 July 2026

Introduction and who we are

How to read this notice

Personal data we collect

What we hold, with an example of each and the reason we hold it.

Categories of personal data processed by Koya Labs Ltd, with purposes.

Category of data
Identity and verification data
Examples
Full legal name, national ID or passport number, date of birth, nationality, photograph, liveness selfie, KRA PIN. Collected through our KYC provider, Sumsub.
Purpose
To verify that you are who you say you are and to meet our anti money laundering and counter terrorist financing obligations.
Category of data
Contact data
Examples
Phone number, email address, physical and postal address.
Purpose
To reach you about your transactions, to send service notifications, and to satisfy customer due diligence record keeping.
Category of data
Financial and transaction data
Examples
M-Pesa account reference, transaction amounts, currency pairs, Bitcoin wallet and receiving addresses, payment channel used, and your transaction history.
Purpose
To execute conversions and remittances, to settle them correctly, and to keep the records that tax and AML law require.
Category of data
Device and technical data
Examples
IP address, device identifiers, browser type, operating system, and approximate geolocation.
Purpose
To keep accounts secure, to detect fraud, and in part to distinguish diaspora from domestic users so that we route the service correctly.
Category of data
Communications data
Examples
Customer support messages sent through the website, WhatsApp or Telegram, and our replies.
Purpose
To answer your questions, to resolve disputes, and to keep an accurate record of what was agreed.
Category of data
Risk and compliance data
Examples
Sanctions and politically exposed person screening results, internal risk tier classification, and transaction monitoring flags.
Purpose
To meet our legal obligations to screen and monitor, and to protect customers and the platform from financial crime.

How and why we use your data

How we share your data

We do not sell your personal data

International data transfers

Data security

Data retention

How long each category is kept, and what sets the period.

Retention schedule. Where two bases apply, the longer period governs.

Category of data
KYC and identity data
Retention period
At least 7 years from the end of the relationship
Basis
Anti money laundering and counter terrorist financing record keeping obligations.
Category of data
Transaction records
Retention period
At least 7 years
Basis
Tax and anti money laundering obligations.
Category of data
Marketing data held with consent
Retention period
Until consent is withdrawn, or 2 years of inactivity, whichever comes first
Basis
Consent. There is no obligation to keep it once consent ends.
Category of data
Customer support records
Retention period
3 years from the last interaction
Basis
Handling disputes and complaints, and evidencing what was agreed.
Category of data
Rejected or incomplete onboarding data
Retention period
12 months from collection
Basis
Fraud prevention, and evidencing why an application was not completed.

Your rights

Right to be informed
To know what personal data we hold about you, why we hold it, and who we share it with. This Notice is how we meet that obligation.
Right of access
To obtain a copy of the personal data we hold about you.
Right to rectification
To have inaccurate personal data corrected, and incomplete data completed.
Right to erasure
To ask us to delete personal data. This right is limited: where anti money laundering or tax law requires us to keep a record, we cannot delete it until that period expires, and we will tell you when that is.
Right to object
To object to processing carried out on the basis of our legitimate interests. Where you object, we stop unless we can show compelling grounds that override your rights.
Right to data portability
To receive the personal data you gave us in a structured, commonly used and machine readable format, and to have it transmitted to another controller where that is technically feasible.
Right to lodge a complaint
To complain to the Office of the Data Protection Commissioner if you believe we have handled your data unlawfully. You do not have to raise it with us first, although we would like the chance to put it right.

Exercising a right costs nothing

Cookies

Children's privacy

Automated decision making

No purely automated adverse decision

Changes to this notice

Contact us

Data controller

Koya Labs Ltd

Prestige Building, Ngong Road Highridge, Westlands Nairobi, Kenya

Registration
PVT-MA15BD72
Attention
Data Protection Officer

Supervisory authority, Kenya

Office of the Data Protection Commissioner

Britam Tower, Hospital Road Upper Hill Nairobi, Kenya

Third party processors

Categories of processor engaged by Koya Labs Ltd.

Category
KYC and identity verification
Provider
Sumsub
Purpose
Identity and liveness verification
Location
European Union
Category
Cloud hosting
Provider
Amazon Web Services
Purpose
Platform infrastructure
Location
EU, Frankfurt
Category
Payment processing
Provider
Safaricom Daraja and backup providers
Purpose
Transaction execution
Location
Kenya
Category
Digital asset custody
Provider
Custody partner
Purpose
Bitcoin safekeeping and settlement
Location
International

AML and KYC data processing notice

Why we may be unable to explain a decision in full