Legal

Privacy policy

How Nuvana Business handles personal data on this website and in the business software services we provide.

Last updated: 6 August 2026

Nuvana HQ operates Nuvana Business from Nairobi, Kenya. If you have a separate signed agreement with us, that agreement may include additional privacy and data-processing terms for your business.

Who this policy applies to

This policy applies to people who visit the Nuvana Business website, contact us by email, phone, or WhatsApp, request a demo, use a Nuvana Business account, or whose personal data is processed through a Nuvana Business customer account.

For website visitors, sales leads, administrators, and our direct business contacts, Nuvana HQ is normally the data controller. For point-of-sale, inventory, payment, customer, staff, branch, invoice, and reporting data entered into Nuvana Business by a customer, that customer is normally the data controller and Nuvana HQ acts as a data processor.

Personal data we collect

We collect only the data needed to operate the website, respond to enquiries, provide the software, support customers, secure accounts, process integrations, and keep records required for business, tax, accounting, compliance, and dispute-resolution purposes.

  • Contact data: name, business name, email address, phone number, WhatsApp contact, and the contents of messages you send to us.
  • Account data: user names, work contact details, roles, permissions, branch access, authentication events, support requests, and audit logs.
  • Business operating data: products, branches, stock movements, sales, returns, invoices, staff actions, payment status, customer details captured by a merchant, and other records a customer chooses to store in the platform.
  • Integration data: M-Pesa transaction references, phone numbers used for payment, payment status, Daraja integration details, eTIMS invoice details, KRA-related invoice metadata, and technical logs needed to keep those integrations working.
  • Website analytics data, where you consent: page path, page URL, page title, referrer, browser and device information, language, viewport size, session and visitor identifiers, clicks, scroll depth, and engagement timing.

How we use personal data

We use personal data to provide Nuvana Business, configure customer accounts, process support requests, keep the website useful, secure the service, monitor reliability, improve product decisions, issue invoices, reconcile payments, maintain records, and comply with applicable law.

Depending on the context, we rely on performance of a contract, steps taken before entering into a contract, compliance with legal obligations, legitimate business interests, consent, or a customer instruction when we process personal data on behalf of that customer.

How we share personal data

We do not sell personal data. We share personal data only when needed to run the service, complete an integration, follow a customer instruction, comply with law, protect the platform, or work with professional advisers.

  • Customer-authorized users, such as owners, managers, accountants, and branch administrators who have permission to access the relevant account data.
  • Payment and integration providers, including Safaricom and M-Pesa services where a customer enables M-Pesa features.
  • Tax and invoicing systems, including KRA eTIMS routes where a customer enables eTIMS-related functionality.
  • Infrastructure, database, hosting, email, support, security, analytics, and monitoring providers that help us operate the website and software.
  • Regulators, courts, law enforcement, professional advisers, or counterparties where disclosure is required by law or needed to protect legal rights.

Security and storage

We use administrative, technical, and organisational safeguards designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These safeguards include role-based access, account controls, logging, secure hosting practices, and limited internal access based on business need.

No online service can guarantee absolute security. Customers are responsible for keeping their own account credentials secure, assigning user permissions carefully, and promptly telling us if they suspect unauthorized access.

Retention

We keep personal data only for as long as needed for the purposes described in this policy, unless a longer period is required or permitted by law. Website analytics identifiers are retained only after consent and may be reset by clearing browser storage and cookies.

Customer operating records are usually retained for the term of the customer relationship and for a reasonable period afterwards for backup, audit, tax, accounting, legal, and dispute-resolution purposes. Kenyan tax record-keeping rules can require relevant business records to be retained for at least five years from the end of the reporting period.

Your rights

Subject to applicable law and our role in the processing, you may request information about how your personal data is used, access your personal data, ask for inaccurate or misleading data to be corrected or deleted, object to processing, withdraw consent where processing is based on consent, or ask for data portability where the law provides that right.

If your data is held inside a customer account, we may need to direct your request to the customer that controls that account. You may also raise concerns with Kenya's Office of the Data Protection Commissioner.

International providers

Some infrastructure, communication, support, or security providers may process data outside Kenya. Where that happens, we use providers and contractual arrangements intended to protect the data to a standard appropriate for the type of processing involved.

Contact us

For privacy questions, data requests, or security concerns, contact Nuvana Business at [email protected] or call 0745020416. We may need to verify your identity and your relationship to the relevant business account before acting on a request.

Legal and regulatory context

This policy is written with Kenya's Data Protection Act, 2019 and ODPC guidance in mind, including the distinction between data controllers and data processors and the rights available to data subjects.