Privacy notice
The lawful bases, scope, safeguards, retention limits and permitted disclosures governing personal, tenancy, property and payment data processed through Rentivia, together with your enforceable rights and remedies under the Kenya Data Protection Act, 2019 and its subsidiary regulations.
The lawful bases, scope, safeguards, retention limits and permitted disclosures governing personal, tenancy, property and payment data processed through Rentivia, together with your enforceable rights and remedies under the Kenya Data Protection Act, 2019 and its subsidiary regulations. The numbered provisions below contain the detailed conditions and should be read together.
1. Identity, scope and regulatory role
Rentivia is a rental and property management service operating in Kenya. In these policies, 'Rentivia', 'we', 'us' and 'our' refer to the operator of the Rentivia service, whether the reference concerns a contractual obligation, the legal operator or product functionality. When a landlord or property manager uploads or creates tenant, unit, lease, invoice, maintenance or payment records, that customer ordinarily determines the purpose and means of processing and acts as data controller, and Rentivia ordinarily acts as data processor on documented instructions. That allocation may differ where Rentivia independently determines a processing purpose, including platform security, fraud prevention, billing, statutory compliance and service analytics. Nothing in these policies constitutes legal advice, and each party remains responsible for its own compliance obligations.
2. Categories and sources of personal data
Rentivia may process account identifiers, contact details, role and organisation data, property and tenancy records, lease and billing information, M-PESA transaction references and status metadata, support correspondence, uploaded documents, consent records, device and browser attributes, approximate network location, access logs and audit events. Referral cash-out may require verified identity information and a KRA PIN for fraud prevention, payout and buyer-initiated invoicing records. Rentivia does not require or request an M-PESA PIN, and customers must not upload passwords, PINs or excessive identity documents.
3. Purposes and lawful grounds
Data is processed to create and secure accounts; provide invoicing, reconciliation, reporting, communication, maintenance and tenant-portal functions; diagnose incidents; prevent abuse; administer subscriptions; respond to rights requests; and comply with accounting, tax, court or regulatory duties. Depending on the context, processing relies on performance of a contract, steps requested before entering a contract, compliance with a legal obligation, legitimate interests that are not overridden by the individual's rights, or consent where consent is the legally appropriate basis. A customer remains responsible for identifying and documenting its own lawful basis for tenant and property data.
4. Automated assistance and human review
Rentivia may use rules, matching logic and AI-assisted tools to classify records, propose payment matches, draft communications, identify anomalies or summarise portfolio data. Material financial, tenancy, enforcement or access decisions must remain subject to an authorised user's review where required by the product workflow. Customers must verify generated content and must not treat an automated suggestion as legal, tax, accounting or professional advice.
5. Recipients, service providers and disclosure
Access is limited to authorised customer users, Rentivia personnel with an operational need, and contracted providers supporting hosting, database, authentication, email, SMS, monitoring, customer support and M-PESA connectivity. Providers receive only the information reasonably required for their function and are engaged under confidentiality and data-protection obligations appropriate to the service. Rentivia may disclose information where required by law, court order or a competent authority, or where reasonably necessary to protect users, the service, the operator's rights or the public from fraud, abuse or material harm.
6. International processing
Some infrastructure or service providers may process data outside Kenya. Before a restricted transfer, Rentivia will use a transfer mechanism or safeguard recognised by applicable Kenyan data-protection law, assess the recipient and destination as appropriate, and limit the transferred fields to the operational purpose. A customer must not configure an integration or export that causes an unlawful transfer.
7. Retention, backup and deletion
Retention depends on record type, contractual need, dispute exposure, fraud prevention and legal obligations. Financial, tax, payment and audit records may be retained for at least seven years or for a longer period required by law; active account records remain available while the service is provided. After closure, data not subject to a preservation requirement is deleted, anonymised or returned through controlled operational cycles, while encrypted backup copies expire according to backup rotation and are not restored for ordinary business use.
8. Individual rights and verification
Subject to the Data Protection Act, 2019 and lawful exceptions, an individual may request information about processing, access, correction, objection, restriction, deletion or a portable copy. Rentivia may require proportionate identity or authority verification, may route a tenant request to the relevant landlord as controller, and may retain a minimal request record to demonstrate compliance. A request does not require deletion of records that must be preserved for legal claims, accounting, fraud prevention, security or another lawful ground.
9. Security and incident handling
Rentivia applies risk-based technical and organisational measures intended to protect confidentiality, integrity and availability, including encrypted transport, controlled access, workspace separation, server-side secret handling, audit logging, monitoring and backup procedures. No internet service can guarantee absolute security. Customers must secure their devices, use unique credentials, limit staff privileges and promptly report suspected compromise; Rentivia may reset sessions, restrict access or preserve logs when investigating an incident.
10. Complaints, children and policy changes
Privacy questions may be sent to info.rentiviagroup@gmail.com and complaints may also be made to the Office of the Data Protection Commissioner where applicable. Rentivia is a business and tenancy administration service and is not directed to children under 18; customers must not deliberately create child accounts unless a lawful, documented basis and appropriate safeguards exist. Material changes are published with an updated effective date and, where required, additional notice or renewed consent.