Skip to content

Data Processing Addendum

Language notice. This document is provided in English, which is the authoritative version under our Terms of Service. Your browser can auto-translate it for reading, but legal nuance may be lost in translation. For clarification in your language, please contact us.

support@proptraka.ke

This Data Processing Addendum forms part of the agreement between PROPTRAKA VENTURESand the Customer. It governs how PropTraka processes your tenants' and guarantors' personal data ("Tenancy Data") on your behalf, as your Data Processor, in line with the Kenya Data Protection Act, No. 24 of 2019(the "Act") and the Data Protection (General) Regulations, 2021 (Legal Notice No. 263 of 2021) (the "Regulations").

Defined Terms

The following defined terms are used throughout this Addendum:

  • "Act" or "DPA 2019" — the Kenya Data Protection Act, No. 24 of 2019, and any regulations made under it (including the Regulations).
  • "Regulations" — the Data Protection (General) Regulations, 2021 (Legal Notice No. 263 of 2021).
  • "PropTraka", "we", "us", "our" — PropTraka, a product of PROPTRAKA VENTURES, of P.O. Box 44875–00605, Nairobi, Kenya, registered with the Office of the Data Protection Commissioner (ODPC) as a Data Controller under Registration No. 684-4423-0396(valid 7 July 2026 – 7 July 2028).
  • "Customer", "you", "your" — the landlord, property manager, or agent who holds a PropTraka account and uses the platform to manage properties and tenancies.
  • "Tenancy Data"— personal data relating to the Customer's tenants and guarantors that PropTraka processes on the Customer's documented instructions to deliver the tenancy-management service (for example tenant and guarantor name, phone number, email address, national ID number, KRA PIN, date of birth, and rent and payment records).
  • "Platform Data" — personal data that PropTraka processes for its own purposes as an independent Data Controller(for example TrustTraka™ scoring signals, ARDO™ analytics, fraud-prevention signals, account and usage telemetry, and PropTraka's own good-practice KYC and tax records). See the Independent Controller section (clause 1.13).
  • "Data Subject"— an identified or identifiable natural person to whom personal data relates; in the tenancy context, principally the Customer's tenants and guarantors.
  • "Sensitive Personal Data" — personal data of the kinds treated as sensitive under s.2 of the Act, which in Kenya expressly includes property details, family details, and biometric data.
  • "Sub-processor"— a third party engaged by PropTraka to process Tenancy Data on the Customer's behalf, as listed in Annex A.
  • "Controller" and "Processor" — a data controller and data processor as defined in s.2 of the Act(the party that determines the purpose and means of processing, and the party that processes on the controller's behalf, respectively).

1.1 Scope, Roles and Order of Precedence

This Data Processing Addendum ("DPA", or "Addendum") governs PropTraka's processing of Tenancy Dataon the Customer's behalf. It applies whenever, in using the platform, PropTraka processes personal data for which the Customer is the Controller.

For Tenancy Data:

  • the Customer is the Data Controller; and
  • PropTraka is the Data Processor, processing only on the Customer's documented instructions.

This split reflects the roles test in s.2 of the Act (who determines the purpose and means of processing) and is decided activity-by-activity, not platform-wide.

Where this Addendum conflicts with the Customer Terms on a data-protection matter concerning Tenancy Data, this Addendum prevails. Nothing in this Addendum limits or reduces the parties' respective statutory obligations under the Act.

1.2 Processing Only on Documented Instructions (s.42(2)(b))

PropTraka shall process Tenancy Data only on the documented instructions of the Customer — including with regard to transfers of Tenancy Data outside Kenya — unless required to do otherwise by a law to which PropTraka is subject, in which case PropTraka shall inform the Customer of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest (s.42(2)(b) of the Act; Reg 24(2)(b)).

The Customer's documented instructions are:

  1. this Addendum;
  2. the Customer Terms and the configuration of the platform features the Customer chooses to use; and
  3. any further written instructions the Customer gives (for example through account settings or support requests) that are consistent with the platform's functionality.

PropTraka shall inform the Customer without undue delay if, in its opinion, an instruction infringes the Act or the Regulations.

1.3 Reg 24(2)(a) Processing Particulars

As required by Reg 24(2)(a), the subject-matter and details of the processing are:

ParticularDetail
(a) Subject-matter of the processingAdministration of the Customer's tenancies through the PropTraka platform.
(b) Duration of the processingFor the term of the Customer's account, and thereafter only for the limited period needed to return or delete the data under clause 1.8 (subject to statutory retention the Customer or PropTraka is independently required to observe).
(c) Nature and purpose of the processingCollection, recording, organisation, storage, retrieval, use, transmission and erasure of Tenancy Data for the purposes of tenancy administration, rent collection and reconciliation, tenancy-agreement generation and e-signature, and Customer-initiated tenant communications.
(d) Type of personal dataTenant and guarantor name, phone number, email address, national ID number, KRA PIN, date of birth, and rent and payment records; uploaded financial documents (M-Pesa and bank statements, payslip / income data); government-ID images (front and back); biometric data — a selfie and facial-recognition verification against the ID captured during identity / TrustTraka™ screening; tenancy-agreement content; and any other Tenancy Data the Customer chooses to enter. Note that property details are Sensitive Personal Data under s.2 of the Act, as are the biometric and government-ID data above — see clause 1.14.
(e) Categories of Data SubjectsThe Customer's tenants and their guarantors (and, where applicable, prospective tenants/applicants the Customer screens).
(f) Obligations and rights of the ControllerThe Customer's obligations and rights are set out in this Addendum, the Customer Terms and the Act — including the Customer's duty to have a lawful basis for the processing it instructs, to give Data Subjects the required s.29 information, and its rights to instruct, audit, and require return or deletion of Tenancy Data.

1.4 Scope of Documented Instructions

PropTraka shall not:

  • process Tenancy Data for any purpose other than delivering the service the Customer has instructed;
  • sell, rent, or disclose Tenancy Data except as this Addendum permits or the Customer instructs; or
  • combine Tenancy Data with data from other sources for PropTraka's own purposes (that would fall under Platform Data and the Independent Controller section, clause 1.13, not this processor mandate).

The Customer warrants that its instructions, and its own processing of Tenancy Data, comply with the Act — including that the Customer has a valid lawful basis for the processing and has given Data Subjects the information required by s.29 (see also the tenant privacy notice in our Privacy Policy).

1.5 Confidentiality and Flow-Down (Reg 24(2)(c) and (b))

PropTraka shall ensure that every person authorised to process Tenancy Data — whether staff or Sub-processor personnel — is under an appropriate written obligation of confidentiality (or an appropriate statutory duty of confidentiality) (Reg 24(2)(c)) and processes Tenancy Data only on instruction (Reg 24(2)(b)). PropTraka shall limit access to Tenancy Data to personnel who need it to deliver the service.

1.6 Security of Processing (s.41(4); Reg 32)

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, PropTraka shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (s.41(4) of the Act; Reg 32), including as appropriate:

  • encryption of Tenancy Data in transit (TLS) and at rest;
  • measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems;
  • the ability to restore availability of and access to Tenancy Data in a timely manner after an incident (backups);
  • access controls, authentication (including passkeys), and audit logging; and
  • malware scanning of uploaded files before storage, with rejection of files that fail validation.

A summary of PropTraka's current security measures is published in the Privacy Policy (Data Localisation & Security, International Data Transfers) and is treated as Annex B to this Addendum.

1.7 Data-Breach Notification — 48 Hours (s.43(3))

Where PropTraka becomes aware of a personal-data breach affecting Tenancy Data, PropTraka shall notify the Customer without undue delay and in any event within forty-eight (48) hours of becoming aware of it (s.43(3) of the Act). The notification shall, to the extent known, describe:

  • the nature of the breach, including the categories and approximate number of Data Subjects and records affected;
  • the likely consequences of the breach;
  • the measures taken or proposed to address it and to mitigate its effects; and
  • a contact point for further information.

Where PropTraka cannot provide all the information at once, it may provide it in phases without undue further delay. This 48-hour processor→controller duty is distinct from, and does not replace, the Customer's own duty as Controller to notify the ODPC and affected Data Subjects where the Act requires (s.43(1)–(2); the Customer's notice window to the Commissioner is 72 hours of becoming aware). PropTraka shall provide reasonable assistance to the Customer in making those notifications.

1.8 Return or Deletion on Termination — At the Customer's Election

On termination or expiry of the Customer's account, PropTraka shall, at the Customer's election, either return the Tenancy Data to the Customer (in a commonly used, machine-readable format) or delete it, and delete existing copies, unless the Act or another applicable law requires PropTraka to retain it (Reg 24(2) read with the storage-limitation principle in s.25(g)).

  • The Customer may make this election in its account settings or by written request. On cancellation the Customer (or a Data Subject through the Customer) may request return or deletion; where no election is made, Tenancy Data is kept while the account is active and, after deletion, only for a limited recovery window before permanent purge.
  • Where PropTraka is independently required by law to keep certain records — chiefly financial and tax records under the Tax Procedures Act, 2015 (Cap. 469B), s.23 — that data is retained for the statutory period of five years, after which it is deleted, and remains subject to the security and confidentiality duties in this Addendum until then. PropTraka is not a POCAMLA reporting institution and does not retain records under a POCAMLA obligation.

1.9 Audit and Inspection Rights (Reg 24(2))

PropTraka shall make available to the Customer all information reasonably necessary to demonstrate compliance with this Addendum, and shall allow for and contribute to audits and inspections conducted by the Customer or an independent auditor the Customer mandates (Reg 24(2)), subject to reasonable conditions:

  • the Customer shall give at least 14 days' written notice, save where an audit is required by the ODPC or follows a breach;
  • audits shall take place during business hours, no more than once per year unless a regulator or a breach requires otherwise, and shall not unreasonably disrupt PropTraka's operations or compromise the confidentiality of other customers' data; and
  • PropTraka may satisfy an audit request by providing recent third-party audit reports, certifications, or its published security documentation where these reasonably address the Customer's questions.

1.10 Sub-processors — List, Prior Authorisation, Flow-Down, Continuing Liability (Reg 25)

The Customer authorises PropTraka to engage the Sub-processors listed in Annex A to process Tenancy Data, subject to this clause (Reg 25).

  • Prior authorisation. By accepting this Addendum, the Customer gives prior authorisation to the current Annex A Sub-processors. Acceptance at signup satisfies the Reg 25 prior-authorisation requirement.
  • Notice of changes. PropTraka shall notify the Customer of any intended addition or replacement of a Sub-processor (by updating Annex A and giving reasonable notice, for example by email or in-app notice) so the Customer has the opportunity to object on reasonable data-protection grounds before the new Sub-processor begins processing Tenancy Data. If the Customer objects and the parties cannot resolve the objection, the Customer may terminate the affected service.
  • Flow-down. PropTraka shall impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this Addendum, in particular on security, confidentiality, breach notification, and cross-border transfers (Reg 25).
  • Continuing liability. PropTraka remains fully liable to the Customer for the performance of each Sub-processor's data-protection obligations. Where a Sub-processor fails to meet those obligations, PropTraka remains responsible to the Customer for that failure.

1.11 Data-Subject Rights — Assistance and Allocation (Regs 7–13)

PropTraka shall provide the Customer with the functionality and reasonable assistance necessary to enable the Customer to respond to requests from Data Subjects exercising their rights under the Act and Regs 7–13 — including the rights of access (Reg 9), rectification (Reg 10), erasure (Reg 12), restriction (Reg 7), objection (Reg 8), and data portability (Reg 11), and rights in relation to automated decision-making.

Where a Data Subject sends a rights request directly to PropTraka in respect of Tenancy Data, PropTraka shall, without undue delay, direct the request to the relevant Customer (as Controller) and not respond substantively itself except on the Customer's instruction, save where the Act requires otherwise.

1.12 Cross-Border Transfers of Tenancy Data

PropTraka processes Tenancy Data using cloud infrastructure (principally Google/Firebase — see Annex A) that may store or process data on servers outside Kenya. PropTraka shall only transfer Tenancy Data outside Kenya where an appropriate safeguard under s.48–49 of the Act applies — for example the Sub-processor's data-processing agreement providing protections substantially equivalent to the Act, and, for Sensitive Personal Data, the consent basis in clause 1.14 (s.49). These transfers are part of the Customer's documented instructions under clause 1.2.

1.13 Independent Controller / Platform Data (Separate Role — Expressly NOT Joint)

Independently of the processing PropTraka performs on the Customer's instructions, PropTraka processes certain personal data as a Data Controller in its own right, determining the purposes and means of that processing itself. This includes:

  • TrustTraka™ — tenant risk-scoring signals used to produce a landlord-private advisory score;
  • ARDO™ — analytics and AI-assisted insights;
  • fraud prevention and platform security — including the cross-landlord duplicate-identity check described in our Privacy Policy;
  • analytics and product improvement — understanding and improving how the platform is used, using PostHog (PostHog Inc.) — product analytics, which processes tenant usage events keyed to an internal user ID plus IP address / approximate location; and
  • PropTraka's own account, usage, KYC and tax records — data PropTraka must process to run, secure, bill and lawfully operate the platform, and to meet its own KRA and tax obligations. (PropTraka is not a POCAMLA reporting institution.)

For each of these purposes:

  • PropTraka acts as an independent Data Controller, and the parties are NOT joint controllers. (Kenya's DPA 2019 has no equivalent to the GDPR Article 26 joint-controller regime; the roles here are decided by the s.2 "who determines purpose and means" test, activity-by-activity.)
  • PropTraka is responsible for establishing and documenting its own lawful basis for each purpose under s.30 of the Act (for example consent, legitimate interest, or legal obligation, as appropriate), and for meeting the Controller obligations for that processing itself.
  • The Customer is notthe Controller of this Platform Data and does not instruct PropTraka on it. Equally, PropTraka's processing here is not done "on the Customer's behalf".

For the account, usage, AML/KYC and tax records that PropTraka controls in its own right, the Customer may access, rectify, or erase their own personal data at any time from their Data & Privacy settings in the app, subject to the retention periods PropTraka is legally required to observe (for example KRA tax records).

Where the platform offers the Customer's tenants granular, unbundled, withdrawable opt-insfor the TrustTraka™, ARDO™ and product-improvement lanes, those opt-ins support PropTraka's independent-controller processing. Core tenancy administration must, and does, work with all of those platform opt-ins switched off (in line with the freely-given-consent and no-conditionality principles in s.32(4) and Reg 4(4)). Tenants can view and withdraw these three optional platform opt-ins at any time in the tenant portal under Settings (/portal/settings), or by emailing privacy@proptraka.ke. This withdrawal mechanism covers only the TrustTraka™, ARDO™ and product-improvement lanes described above — it does not affect the Customer's underlying processor-instruction basis for Tenancy Data or the tenant's Privacy Notice acknowledgement, which remain in place for core tenancy administration.

1.14 Sensitive Personal Data and Cross-Border Consent (s.2; s.49)

The parties acknowledge that under s.2 of the Act, "property details" are Sensitive Personal Data (as, in Kenya, are family details), and that the biometric data captured during identity / TrustTraka™ screening — a selfie and facial-recognition verification against the government ID — is also Sensitive Personal Data. Where the processing of Tenancy Data involves Sensitive Personal Data:

  • the Customer, as Controller, is responsible for ensuring a valid lawful basis for processing Sensitive Personal Data under s.44–45 of the Act(which generally requires the Data Subject's consent or another specified condition);
  • biometric identity verification relies on the Data Subject's consent, captured at onboarding, as its lawful basis under s.44–45; and
  • any transfer of Sensitive Personal Data outside Kenya requires the Data Subject's consent or another condition permitted by s.49 of the Act. Because PropTraka's infrastructure (Google/Firebase) processes data abroad, the Customer's documented instruction to use the platform includes ensuring, through the tenant privacy notice and onboarding consent, that the necessary consent has been obtained.

PropTraka shall support this by surfacing the required notice and consent capture in the tenant onboarding flow, and by applying the safeguards in clause 1.12.

Annex A — Sub-processors (Tenancy Data)

The following Sub-processors process Tenancy Data on the Customer's behalf. The separate payment controllers — Safaricom/M-Pesa and Paystack — are not PropTraka Sub-processors; they process payment data as their own independent controllers, as described in our Privacy Policy.

Sub-processorPurposeCross-border?
Google / Firebase (Google LLC)Cloud hosting, database (Firestore), authentication, storage; Google reCAPTCHA Enterprise — bot/fraud protection on signup and invite-accept (processes IP address and interaction signals)Yes — may process outside Kenya (see clauses 1.12, 1.14)
Google (Gemini)AI processing for ARDO™ features; processes tenant financial and identity-document content with partial redaction of third-party details (redacted, not anonymised)Yes
Anthropic (Claude)AI processing for ARDO™ features (advisory / fallback); processes tenant financial and identity-document content with partial redaction of third-party details (redacted, not anonymised)Yes
Meta Platforms — WhatsApp Business PlatformDelivery of Customer-initiated tenant messages (rent reminders, updates)Yes
Resend (Resend, Inc.)Cloud email delivery — transmits tenant name, email address and message content (agreements, reminders, invitations/OTPs)Yes
SentryApplication error monitoring (default server-side data scrubbing; we avoid sending user PII in error reports)Yes

Tenancy-agreement generation and e-signature are PropTraka's owncapability, running on the Google/Firebase infrastructure above; blank templates may optionally be fetched from the landlord's own Google Docs. There is no separate e-signature vendor, so this is covered by the Google/Firebase entry rather than a distinct Sub-processor.

Annex B — Security Measures

The technical and organisational measures in clause 1.6, as further described in the Privacy Policy (sections "Data Localisation & Security" and "International Data Transfers"), form Annex B.

Contact

For any data-protection matter under this Addendum, you may reach our Data Protection Officer:

  • Entity: PROPTRAKA VENTURES
  • Postal address:P.O. Box 44875–00605, Nairobi, Kenya
  • Email: privacy@proptraka.ke

Last Updated: 2 August 2026. Nairobi, Kenya.