Legal

Privacy Policy

Last updated: January 2026 · Compliant with Kenya Data Protection Act 2019

KaddyAI LTD is committed to protecting your privacy. This Policy explains how we collect, use, and protect your personal data in accordance with the Kenya Data Protection Act 2019.

Quick Navigation

1. Introduction & Data Controller2. Data We Collect3. How We Use Your Data4. Data Sharing5. Cookies6. Data Security7. Data Retention8. Your Rights (Kenya Data Protection Act 2019)9. Marketing Communications10. Compliance & Contact

1. Introduction & Data Controller

This Privacy Policy explains how KaddyAI LTD ("KaddyAI", "we", "us", "our"), a company registered in Kenya with its principal place of business in Nairobi, collects, uses, stores, and protects your personal data when you use the KaddyAI Platform. KaddyAI LTD is the data controller for all personal data processed through the Platform. This Policy is compliant with the Kenya Data Protection Act 2019 ("DPA") and the Kenya Data Protection (General) Regulations 2021. By using our Platform, you consent to the collection and use of your personal data as described in this Policy.

2. Data We Collect

We collect the following categories of personal data:

• Account Information: your name, email address, phone number, date of birth, and any identity verification documents submitted during KYC verification.

• Transaction Data: details of all plays, deposits, withdrawals, and reward payments made through the Platform, including amounts, timestamps, and associated market identifiers.

• Device & Usage Data: IP address, device identifiers, browser type, operating system, session duration, pages visited, features accessed, and approximate geographic location derived from IP address.

• Cookies & Analytics Data: data collected through cookies, pixel tags, and analytics tools about how you interact with the Platform (see Section 5).

• Referral Tracking Data: information about referral links you create or click, and the status of users you refer, used to calculate and pay referral rewards.

• Communications: messages you send to our support team, community content you post, and market descriptions you create.

3. How We Use Your Data

We process your personal data for the following purposes:

• Service Provision: to create and manage your account, process plays and payouts, resolve markets, and provide all core Platform features.

• Payment Processing: to facilitate deposits and withdrawals via M-Pesa, SasaPay, and other payment providers, including fraud prevention and regulatory compliance.

• Market Moderation: to review market content, investigate suspected violations of our Terms, and maintain the integrity of the Platform.

• Analytics & Improvement: to understand how users interact with the Platform, identify technical issues, and develop new features and improvements.

• Marketing Communications: to send you product updates, promotional offers, and information about new features — only where you have provided your consent or where we have a legitimate interest under the DPA. You may opt out at any time.

• Legal Compliance: to comply with our obligations under Kenyan law, including tax reporting, anti-money laundering requirements, and cooperation with regulatory or law enforcement authorities.

4. Data Sharing

We do not sell your personal data to third parties. We share your data only in the following circumstances:

• Payment Processors: we share transaction data with M-Pesa (Safaricom PLC) and SasaPay as necessary to process deposits and withdrawals.

• Analytics Providers: we use third-party analytics tools that process aggregated and pseudonymised usage data to help us understand Platform performance.

• Legal Requirements: we will disclose your data to law enforcement, regulators, or courts where required to do so by applicable Kenyan law, or where necessary to protect the rights, property, or safety of KaddyAI, our users, or the public.

• Business Transfers: in the event of a merger, acquisition, or sale of KaddyAI LTD, your data may be transferred to the acquiring entity, subject to equivalent privacy protections.

All third-party service providers are contractually obligated to protect your data and to use it only for the purposes for which it was shared.

5. Cookies

We use the following categories of cookies on the Platform:

• Session Cookies: essential cookies that expire when you close your browser session and are necessary for the Platform to function.

• Analytics Cookies: persistent cookies that help us understand user behaviour and improve the Platform. These may be set by third-party analytics providers.

• Preference Cookies: cookies that remember your language, display, and other preferences to enhance your experience.

You may disable non-essential cookies through your browser settings or through our cookie preference centre. Please note that disabling cookies may affect the functionality of some Platform features.

6. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

• Encryption of data in transit using TLS 1.2 or higher

• Encryption of sensitive data at rest

• Role-based access controls limiting data access to authorised personnel only

• Regular security audits and penetration testing

• Incident response procedures for data breaches

While we take data security seriously, no system is completely secure. In the event of a data breach affecting your rights, we will notify you and the Office of the Data Protection Commissioner (Kenya) in accordance with the DPA.

7. Data Retention

We retain your personal data for as long as your account is active on the Platform. Upon account closure, we will delete or anonymise your personal data, subject to the following retention requirements:

• Financial Records: transaction data is retained for 7 years from the date of the transaction, as required by Kenyan tax and financial regulations.

• Legal Claims: data may be retained for longer periods where necessary to defend or pursue legal claims.

• Safety & Fraud Prevention: limited data may be retained to prevent re-registration by users suspended for serious violations.

8. Your Rights (Kenya Data Protection Act 2019)

Under the Kenya Data Protection Act 2019, you have the following rights in relation to your personal data:

• Right of Access: you may request a copy of the personal data we hold about you.

• Right to Correction: you may request correction of inaccurate or incomplete personal data.

• Right to Deletion: you may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to retention requirements.

• Right to Portability: you may request your personal data in a structured, machine-readable format.

• Right to Object: you may object to the processing of your personal data for direct marketing or where processing is based on our legitimate interests.

To exercise any of these rights, please visit our Privacy Center or contact us at privacy@kaddyai.co. We will respond to all verified requests within 21 days in accordance with the DPA.

9. Marketing Communications

We will only send you marketing communications where you have expressly consented or where we have a legitimate interest under the DPA. You may opt out of marketing communications at any time by: (a) clicking the unsubscribe link in any marketing email; (b) adjusting your notification settings in the Platform; or (c) contacting us at privacy@kaddyai.co. Opting out of marketing will not affect transactional communications related to your account.

10. Compliance & Contact

This Privacy Policy is governed by the Kenya Data Protection Act 2019 and the Kenya Data Protection (General) Regulations 2021. For privacy enquiries, data subject requests, or complaints, please contact:

Privacy Officer: privacy@kaddyai.co

KaddyAI LTD, Nairobi, Kenya

You also have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya (ODPC) if you believe your data rights have been violated.

Want to manage your privacy preferences or submit a data request?

Visit our Privacy Center →