Privacy Policy
Last updated: August 10, 2026
Introduction
Singlbase Technologies Limited("Company", "we", "us", or "our"), company registration number PVT-2LAIMDM, operates SinglbasePM. This Privacy Policy explains how we collect, use, store, share, and protect personal data, and how it applies under the Data Protection Act, 2019 (No. 24 of 2019) of the Republic of Kenya and the Data Protection (General) Regulations, 2021.
Read this policy alongside our Terms of Service and Cookie Policy.
We describe here only what we actually do. Where a safeguard is a commitment we are working towards rather than one already in place, we say so rather than imply otherwise.
1. Our Role: When We Are a Controller and When We Are a Processor
Responsibility for personal data depends on who decides the purpose of the processing. Our role differs between the two kinds of data on the platform, and we act in both capacities:
- We are the Data Controller for the personal data of our direct customers (landlords, property managers, agents, and their team members) collected when an account is registered and used. We decide why that data is processed.
- We are the Data Controller for the direct relationship we have with a Tenant who uses the SinglbasePM tenant app: their app account and login credentials, their notification preferences, their device push tokens, and the security logs for their own sign-ins. We determine these purposes ourselves, so we are accountable for them directly to the Tenant.
- We are a Data Processor for the tenancy records a customer keeps about a Tenant: lease terms, rent and payment history, maintenance history, and property records. The customer is the Data Controller for that data. We process it on their documented instructions.
- Customers are responsible for establishing a lawful basis, and giving the required privacy notice, before entering another person's data into the Service.
This split matters in practice. If you are a Tenant and want to correct your lease record, your landlord or property manager decides that, and we will pass your request to them. If you want to delete your tenant app account or stop receiving push notifications, that is our decision to make and you can ask us directly.
2. Registration with the Office of the Data Protection Commissioner
Under the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, registration with the Office of the Data Protection Commissioner (ODPC) is mandatory for anyone processing personal data for the purpose of property management, including the selling of land. That obligation applies regardless of annual turnover or number of employees. The usual small-entity exemption does not apply to this sector.
This applies to our customers. If you use SinglbasePM to manage property, you are very likely required to register with the ODPC in your own name, whatever the size of your portfolio. Using our platform does not discharge that obligation and we cannot register on your behalf. You can register at dataportal.odpc.go.ke.
We do not claim any ODPC registration, certification, or approval that we do not hold. We hold no ISO, SOC 2, or PCI DSS certification of our own, and no government or regulatory licence. Where certification matters to a disclosure, for example card handling, we say which of our providers holds it, not us.
3. Personal Data We Collect
3.1 Account and registration data (customers)
- Full name, email address, and phone number.
- Business name, business registration number, KRA PIN, and VAT number, where you provide them for invoicing.
- Account preferences, language settings, and notification preferences.
- Support and correspondence records.
3.2 Tenant and third-party data entered by customers
Customers use the Service to record information about the people they let property to. Depending on how a customer configures it, this can include:
- Name, phone number, email address, postal address, and date of birth.
- National ID, passport, or military ID number, and the document type recorded.
- Identity-verification outcomes, where a customer requires an identity check. The Tenant's ID images and facial data are captured by and held at our verification partner (see the sub-processor table). They never reach our servers. We store only the result: pass or fail, the document type, and a failure reason.
- KRA PIN, where recorded for lease agreements.
- Lease terms, rent amounts, charges, deposits, invoices, and full payment history.
- Move-in and move-out records, property condition reports, and any photographs attached to them.
- Maintenance and complaint history, and messages sent through the Service.
- Signatures captured when a lease agreement is signed electronically, and the signed agreement itself.
For this category the customer is the Data Controller and we act on their instructions.
3.3 Subscription and billing data
- Subscription details: plan tier, billing interval, price, billing period dates, status, and any scheduled plan change.
- Payment method reference: a Paystack authorisation code, card brand, last 4 digits, and expiry month and year. We do not store, process, or transmit full card numbers, CVV codes, or PINs. Those are entered directly into Paystack's payment iframe and never reach our servers. Paystack states that it holds PCI DSS Level 1 certification; we do not.
- Tax identifiers: business legal name, KRA PIN, and VAT number where provided, used to generate invoices.
- Transaction history: date, amount, currency, payment channel, Paystack reference, status, and gateway response.
- Billing contact: an optional separate email address for invoices and renewal notices.
3.4 Rent payment data
M-Pesa and NCBA collection are optional integrations that a customer connects using their own merchant or bank credentials. Data flows to those providers only once a customer has enabled the integration for their own account.
- M-Pesa (Safaricom Daraja): where enabled, Tenant phone numbers are sent to Safaricom to initiate STK push requests, and we receive back transaction references and payment status. We never have access to, store, or transmit M-Pesa PINs.
- NCBA Bank: where enabled, account identifiers and transaction data are retrieved through NCBA's API for reconciliation, using credentials the customer supplies. Those credentials are held encrypted and are not visible to other users of the platform.
3.5 Technical and usage data
- Log data: IP address, browser and device type, and access timestamps, used for security monitoring and platform stability.
- Session data: authentication tokens held in cookies, and a trusted-device token where you choose to remember a device. See our Cookie Policy.
- Records of sign-in attempts and multi-factor authentication events.
We do not run analytics or advertising technology. We use no analytics provider, no advertising network, no social media tracking pixel, and no third-party crash-reporting service, on either the web platform or the mobile apps. If that changes we will update this policy and ask for consent before switching anything on.
4. Sensitive Personal Data
This section matters more for a property platform than it does for most software, and it is easily missed. Section 2 of the Data Protection Act, 2019 defines sensitive personal dataas data revealing a person's race, health status, ethnic social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details including the names of a person's children, parents, or spouse, sex, or sexual orientation.
Property details and family details are therefore sensitive personal data under Kenyan law. Much of what SinglbasePM holds, including who occupies which property, on what terms, with which household members, falls into that category. Identity documents and biometric data are also sensitive, but we no longer hold either: identity verification is performed by a specialist processor and only its verdict is returned to us.
What this means:
- We process this data on the instructions of the customer who controls it, and we apply access controls that restrict it to users within that customer's own organisation.
- Customers must have a valid lawful basis, and must give the Tenant the privacy notice required by regulation 4 of the General Regulations, before entering this data.
- We do not use sensitive personal data for any purpose of our own. We do not use it to build profiles, we do not use it for marketing, and we do not sell or share it for commercial purposes.
- We hold no identity-document images and no biometric data. Identity verification is performed by Didit, which captures and retains that material in the European Union; SinglbasePM receives only the outcome. Removing that data from our systems entirely is a stronger control than restricting access to it.
We have not yet completed a Data Protection Impact Assessment under section 31 of the Act. We consider one appropriate for this processing and it is in progress; we will not claim otherwise in the meantime.
5. Lawful Basis for Processing
Where we act as Data Controller, we rely on the following lawful bases under section 30 of the Data Protection Act, 2019:
| Processing Activity | Lawful Basis |
|---|---|
| Account registration and platform access | Contract performance |
| Tenant app accounts and authentication | Contract performance |
| Processing subscription payments and renewals | Contract performance |
| Issuing invoices and keeping tax records | Legal obligation |
| Security monitoring, fraud prevention, and abuse control | Legitimate interests |
| Transactional notifications (receipts, renewal and payment alerts) | Contract performance |
| Marketing communications | Consent (opt-in) |
| Non-essential cookies and stored preferences | Consent |
| Platform stability and feature improvement | Legitimate interests |
| Responding to lawful requests from a competent authority | Legal obligation |
Where we act as Data Processor, the lawful basis is determined by the customer who controls the data, not by us.
6. How We Use Personal Data
- To provide, maintain, secure, and improve the Service.
- To process subscription payments, manage renewals, issue refunds, and send billing notices through Paystack.
- Where a customer has enabled the integration, to initiate rent collection through M-Pesa or to reconcile payments through NCBA.
- To issue invoices and meet our own tax record-keeping obligations.
- To detect and prevent fraud, abuse, and unauthorised access.
- To respond to support requests.
- To comply with applicable Kenyan law, including the Data Protection Act, 2019 and the Computer Misuse and Cybercrimes Act, 2018.
- Marketing: we send marketing communications only with your prior consent, and every one carries a clearly visible unsubscribe link. You can also opt out at any time by emailing legal@singlbase.com. Transactional messages (payment confirmations, renewal reminders, invoices, and security alerts) are not marketing and continue while you hold an account.
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significant effects. We do not carry out profiling, and we do not use personal data to train machine-learning models.
8. Transfers Outside Kenya
Some of the providers above are located outside Kenya, so personal data leaves the country. We want to be exact about this rather than reassuring: your data is not stored in Kenya. The platform database and all files are hosted on a server in France, and encrypted backups are held in Cloudflare R2 storage restricted to the European Union. Email is delivered from the United States, and push notifications through United States infrastructure. SMS and the payment providers listed as Kenyan process in Kenya.
Section 48 of the Data Protection Act, 2019 and regulations 40 to 47 of the General Regulations allow such transfers where appropriate safeguards exist. The safeguards we currently rely on are the published data-processing terms and security commitments of each provider, accepted as part of our contract with them, together with the access controls and encryption in transit described in section 9.
We state plainly what we have not yet done: we have not executed bespoke data-transfer agreements with these providers, and we do not yet maintain the transfer register described in regulation 41. Both are in progress. We would rather record that here than claim a standard we have not met.
9. Security and Breach Notification
We take appropriate technical and organisational measures to protect personal data. We describe only measures that are actually in place:
- All traffic between your device and the Service is encrypted in transit using current TLS.
- Row-level security in the database, so records are readable only within the organisation that owns them.
- Role-based access control, so users see only what their role permits.
- Multi-factor authentication, available to every user account regardless of role.
- Trusted-device tokens are signed and verified server-side, and stored so that browser scripts cannot read them.
- Lease files are held in non-public storage scoped to the owning organisation. Identity-document images are not stored by us at all.
- Credentials for third-party integrations are held encrypted, separately from application data.
- Bot protection on sign-in, sign-up, and password reset.
- Backups are encrypted with AES-256 before they leave our infrastructure, so our backup storage provider never holds readable copies. Backups run hourly and are restore-tested weekly.
- Electronic lease signing runs on software we host ourselves, so lease documents and signatures are not sent to a third-party e-signature service.
No system is completely secure and we do not claim that yours is. We cannot and do not guarantee that personal data will never be accessed without authorisation.
Breach notification. Where a personal data breach poses a real risk of harm, we will notify the Data Commissioner without delay and within 72 hours of becoming aware of it, as section 43 of the Act requires, explaining any delay if we cannot meet that window. We will notify affected data subjects within a reasonably practicable period where the breach is likely to result in real risk to their rights. Where we act as Data Processor, we will notify the customer who controls the data so that they can meet their own obligation.
10. Data Retention
Regulation 19 of the General Regulations requires a retention schedule that is periodically audited. The following is our retention policy. Some of it is enforced automatically today and some is applied on review rather than by an automated job, so we describe it as our policy rather than claim it happens without human involvement:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account and profile data | Account lifetime + 30 days | Final export window |
| Organisation data (properties, tenants, leases) | Account lifetime + 30 days | Final export window |
| Identity-document images and biometric data | Not held by SinglbasePM. Retained by Didit under the retention period configured for our account, and deletable on request | We removed this data from our systems rather than set a retention period for it |
| Invoices and accounting records | 7 years from creation | Companies Act 2015, s.630 (accounting records must be preserved for not less than seven years) |
| Tax records | 5 years minimum, kept 7 | Tax Procedures Act 2015, s.23 requires 5 years; we keep 7 so a single period covers the longer accounting obligation above |
| Payment transaction history | 7 years | Part of the accounting record |
| Saved payment method reference | Active subscription + 30 days | Deactivated with Paystack on expiry |
| Security telemetry in audit records (IP address, device/browser string) | 90 days | Erased from the audit record after 90 days; the record of what happened is kept, the identifiers of where you were are not |
| Audit records (what changed, by whom, when) | 7 years | Accounting record under Companies Act 2015, s.630 |
| Support correspondence (email) | 3 years | Dispute resolution. Held in our email system, not in the Service, where there is no in-product messaging or ticketing |
| Demo accounts and all their contents | Purged on expiry of the demo period | See section 12 |
At the end of the applicable period, data is deleted or anonymised. Anonymised data is no longer personal data and falls outside the Act. Backups are on their own rotation, so deleted data can persist in an encrypted backup for a short period after deletion from the live system.
A note on audit records. Our audit trail is tamper-evident: each entry is cryptographically linked to the one before it, so a record cannot be altered or removed without detection. That is what makes it worth keeping. It also means we cannot delete individual entries at 90 days without destroying the property that makes the trail trustworthy. Instead, we erase the personal identifiers inside them, meaning your IP address and device description, while keeping the record of what happened. We consider this a better outcome for you than either option alone: the accountability record survives, and the data that could locate you does not.
11. Your Rights Under the Data Protection Act, 2019
To exercise any right, email legal@singlbase.com with your name, your account email, and what you are asking for. The deadlines below are those set by the Data Protection (General) Regulations, 2021, and we work to them.
| Right | What It Means | Our Deadline |
|---|---|---|
| Access | Obtain a copy of your personal data and information about how it is processed. | 7 days (reg 9) |
| Rectification | Have inaccurate or incomplete data corrected. | 14 days (reg 10) |
| Erasure | Have data deleted where it is no longer necessary or consent is withdrawn, subject to retention we are legally required to keep. | 14 days (reg 12) |
| Portability | Receive your data in a structured, machine-readable format, or have it ported to another provider. | 30 days (reg 11) |
| Restriction | Limit how we use your data while a dispute about it is resolved. | 14 days (reg 7) |
| Objection | Object to processing based on legitimate interests. For direct marketing the right is absolute and we will stop. | 14 days (reg 8) |
| Withdraw consent | Withdraw consent at any time. This does not affect processing already carried out. | Immediate |
| Be informed | Know how your data is used before it is collected, as set out in this policy. | Ongoing |
We respond free of charge, other than a reasonable fee for porting data where regulation 11 permits it. Where a request is manifestly unfounded or excessive we may charge a reasonable fee or decline, giving written reasons.
If you are a Tenant: for anything in your tenancy record, such as your lease or your rent history, your landlord or property manager is the Data Controller, and the request is theirs to decide. Send it to us anyway if you do not know who to ask; we will forward it to them and tell you that we have. For your tenant app account itself, ask us and we will act on it directly.
12. Children's Data
The Service is not directed at children under 18 and we do not knowingly collect their personal data for our own purposes. Customers may record the names of household members, including children, in a tenancy record; that data is under the customer's control and section 33 of the Act places the consent obligation on them. If you believe we hold a child's data without a proper basis, contact legal@singlbase.com and we will act on it.
13. The Demo Environment
We run a separate demo environment so people can try SinglbasePM before committing. It is a distinct installation with its own database, and demo data is never mixed with production data.
- Do not enter real personal data in the demo. Do not enter a real tenant's name, phone number, national ID, or identity document. Use invented details. This is a condition of use under our Terms of Service.
- Demo accounts are temporary. When the demo period expires, the account and everything in it is purged. There is no export and no recovery.
- Payment integrations run against provider sandboxes: M-Pesa amounts are capped at KSh 1 and reversed, and no emails or SMS are delivered to real recipients. Where we switch a demo account to live mode for a supervised evaluation, the Service shows a persistent LIVE MODE warning.
- The demo is provided as is, with no service level commitment and no guarantee of availability.
This policy applies to the demo in full. If you do enter real personal data despite the above, it is real personal data and our obligations under the Act apply to it, which is precisely why we ask you not to.
14. Complaints and Contact
To exercise a right, raise a privacy concern, or make a complaint, contact us:
- Privacy and legal: legal@singlbase.com
- Billing: billing@singlbase.com
- Company: Singlbase Technologies Limited, company number PVT-2LAIMDM
- Registered office: Kamulu, 00100, Nairobi, Kenya
We have not appointed a Data Protection Officer. Section 24 of the Act makes that optional, and we would rather tell you than imply a role that does not exist. Privacy matters are handled by the contact above.
If you are not satisfied with our response, you may complain to the Office of the Data Protection Commissioner, under the Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021:
- Website: www.odpc.go.ke
- Complaints and breach reporting: odpc.go.ke/report-a-data-breach
15. Changes to This Policy
We may update this policy to reflect changes in our practices or in the law. For material changes we will update the "Last updated" date, email registered account owners at least 14 days before the change takes effect, and show a notice in the Service. Where a change requires fresh consent we will ask for it rather than infer it from continued use.