Last updated: 1 January 2026
Contents
Gigva Kenya Limited ("Gigva", "we", "us", or "our") is a software company registered in Kenya. We operate the Gigva platform, accessible at gigva.co.ke and its subdomains, which provides M-Pesa payment tracking, automated reconciliation, analytics, and related services to Kenyan small and medium businesses.
This Privacy Policy explains what personal and business data we collect when you use the Gigva platform, how we use that data, how we store and protect it, and what rights you have under the Kenya Data Protection Act 2019 (DPA 2019). It applies to all users of the Gigva platform, including account holders, authorised team members added to an account, and visitors to our website.
By creating a Gigva account or using the platform in any capacity, you confirm that you have read and understood this Privacy Policy. If you are using Gigva on behalf of a business, you confirm that you have authority to agree to this policy on that business's behalf.
This data is received via the Safaricom Daraja v2 API webhook when your M-Pesa Paybill or Till is registered with Gigva. You remain the data controller for your customers' transaction data; Gigva acts as a data processor on your behalf.
This data is collected automatically through our platform infrastructure and is used solely for service operation, security monitoring, and product improvement. It is not sold or shared with advertising networks.
We use your data only for the purposes described below. We do not sell your data, use it for advertising, or use your transaction data to train machine learning or AI models.
Your account data enables us to authenticate your identity and give you access to your Gigva account. Your M-Pesa transaction data is the core input that Gigva processes to reconcile payments, generate reports, and trigger alerts. Without this data, the service cannot function.
Transaction data, invoice data, and reconciliation rules are used to match incoming M-Pesa payments to open invoices, calculate revenue totals, produce aging reports, and generate the analytical outputs visible in your dashboard. All analytics outputs are derived from your own business data, Gigva does not combine your data with data from other businesses.
Your transaction data and the alert thresholds you configure are used to detect anomalies, trigger notifications, and send alert emails. These notifications are sent only to users you have authorised on your account.
Aggregated, anonymised usage data (not individual transaction records) may be used to identify how users interact with the platform, which features are most used, and where friction exists. This helps us prioritise product development. This analysis does not involve identifying individual users or businesses.
Contact form submissions and support emails are used to respond to your enquiry. We retain this correspondence to maintain continuity in our support relationship with you.
We may process and retain data to comply with applicable Kenyan laws, respond to lawful requests from regulatory or law enforcement authorities, or protect our legal rights in the event of a dispute.
Under the Kenya Data Protection Act 2019, we process your personal data on the following legal bases:
Contractual necessity: Processing your account data, transaction data, and invoice data is necessary to deliver the Gigva service you have subscribed to. Without this processing, we cannot fulfil our contractual obligations to you.
Legitimate interests: Processing usage data for platform improvement, security monitoring, and fraud detection is in our legitimate interest as a platform operator. We balance these interests against your rights and have determined they are proportionate.
Consent: Where we collect optional data, such as your phone number in a demo form, or notes from a call, we do so based on your voluntary provision of that information.
Legal obligation: We may process and retain data where required to comply with Kenyan law, including financial record-keeping requirements.
All Gigva platform data, including transaction records, account information, and invoice data, is stored on servers located in Kenya. No financial data or personal transaction data is transferred to servers outside Kenya without your explicit consent.
The following security measures are in place:
No security system is entirely impenetrable. In the event of a data breach that affects your personal or transaction data, we will notify affected account holders within 72 hours of becoming aware of the breach, in accordance with our obligations under the DPA 2019.
Gigva integrates with the following third-party services to operate the platform. Each service processes data only to the extent necessary for its function:
We do not use third-party analytics platforms that track your individual behaviour across other websites. We do not use advertising networks or permit third parties to place tracking cookies on the Gigva platform.
If you use Gigva's integration features to connect to third-party accounting software (such as QuickBooks or Xero), data you export from Gigva is governed by that third party's privacy policy from the point of export.
Under the Kenya Data Protection Act 2019, you have the following rights in relation to your personal data:
To exercise any of these rights, email hello@gigva.co.ke with the subject line "Data Rights Request" and a description of your request. We will respond within 21 days. We may ask you to verify your identity before processing the request.
If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya (ODPC).
Gigva uses only strictly necessary cookies required for the platform to function. These include:
We do not use advertising cookies, cross-site tracking cookies, or analytics cookies that report your behaviour to third-party services. We do not use Google Analytics, Meta Pixel, or any equivalent tracking service.
You may disable cookies in your browser, but doing so will prevent you from logging in to the Gigva platform.
We retain different categories of data for different periods, based on the purpose of the data and applicable legal requirements:
If you cancel your Gigva subscription and wish to retain a copy of your data, you should export it before cancellation. Transaction and invoice data is exportable in CSV format from the platform at any time.
When Gigva receives M-Pesa transaction data via the Daraja webhook, that data includes the phone number (MSISDN) of the customer who made the payment. This is your customer's personal data.
In this context, you are the data controller for your customers' data, you determine the purposes and means of processing. Gigva acts as a data processor on your behalf, processing your customers' payment data only to deliver the reconciliation and analytics service you have subscribed to.
You are responsible for ensuring that your collection and use of your customers' M-Pesa payment data complies with applicable data protection law, including obtaining any consents required by the DPA 2019. Gigva does not independently contact your customers or use their data for any purpose other than the service we provide to you.
We may update this Privacy Policy from time to time to reflect changes in how we operate the platform or to meet new legal requirements. When we make changes, we will update the "Last updated" date at the top of this page.
For material changes, such as changes to the categories of data we collect, how we use data, or who we share it with, we will notify active account holders by email at least 14 days before the change takes effect. Continued use of the platform after notification constitutes acceptance of the updated policy.
We encourage you to review this policy periodically.
If you have questions, concerns, or requests relating to this Privacy Policy or Gigva's data handling practices, contact us at:
Email: hello@gigva.co.ke
Post: Gigva Kenya Limited, Westlands, Nairobi, Kenya
We aim to respond to all privacy enquiries within 5 business days and to resolve substantive requests within 21 days. If you are not satisfied with our response, you may escalate to the Office of the Data Protection Commissioner of Kenya.
Questions about this policy? hello@gigva.co.ke · Terms of Service