Privacy policy
PesaRails builds the software that lenders use to originate and manage loans. That puts us in two different roles depending on whose data is involved. This policy explains both, and what you can ask us to do.
Effective 1 August 2026
1. Who we are
PesaRails Africa Ltd ("PesaRails", "we", "us") is a company incorporated in Kenya and based in Nairobi. We build credit infrastructure: an AI credit scoring engine, a WhatsApp loan origination chatbot, a borrower self-service portal, and a core management information system for microfinance institutions, SACCOs and digital lenders.
We are a technology vendor, not a lender. We are not licensed by the Central Bank of Kenya and we do not lend on our own account or decide who receives credit. Those decisions belong to the financial institution you are dealing with.
2. Our two roles, and why the difference matters
Under the Kenya Data Protection Act 2019 (the "DPA"), responsibility for personal data depends on who decides how it is used. We sit on both sides of that line:
- Data controller
- For our own business: visitors to this website, demo and sales enquiries, correspondence with prospective clients, and our own staff and contractors. Here we decide what is collected and why, and this policy governs it in full.
- Data processor
- For borrower and member data that our clients put through the platform. The lender is the controller. They decide what is collected, for what purpose, and how long it is kept. We act on their documented instructions under a written agreement.
If you are a borrower and you want to see, correct or delete your data, the fastest route is to contact the institution that lent to you, because they hold the decision rights. If you cannot reach them, or they do not respond, write to us at info@pesarails.com and we will help. We will route the request to the controller and, where the law requires us to act directly, we will.
3. Data we handle as a controller (this website)
When you request a demo or contact us, the form collects:
- Your name, work email address and phone number
- Your institution, your role there, the institution type and portfolio size
- The system you use today, what you are interested in, and your message
- Your explicit consent to be contacted about your enquiry
That submission is emailed to our sales mailbox. We use it to respond to you and to keep a record of the conversation. We do not sell it, and we do not use it for advertising.
We also briefly hold the IP address of anyone submitting the form, in memory only, to rate limit automated abuse. It is not written to a database and does not survive a restart.
Cookies and tracking
This website sets no cookies. There is no analytics script, no advertising pixel, no tag manager and no third-party tracker on any page. Fonts are served from the site itself rather than a font CDN. Nothing on this site follows you anywhere else.
4. Data we process on behalf of lenders
Depending on which products a lender has enabled and how they configure them, the platform may process:
- Identity and contact data: name, national ID number, phone number, date of birth, and images of identity documents including the front and back of an ID and a selfie used for verification
- Next of kin and guarantor data: names, contact details, and where the lender requires it, their ID images and selfies
- Location data: GPS coordinates captured at the point of application where the borrower consents
- Financial data: M-PESA statements and the individual transactions parsed from them, business details, loan applications, disbursements, balances, repayment history and M-PESA transaction references
- Derived data: credit scores on a 300 to 850 scale, the component scores behind them, the factors that most influenced a score, and fraud and anti-money-laundering signals
- Conversation data: messages exchanged with a lender's WhatsApp chatbot, and activity in the borrower portal
We hold each lender's data in a separate database schema, isolated from every other lender on the platform. We do not pool borrower data across institutions and we do not build a cross-lender profile of you.
5. WhatsApp and Meta
Where a lender uses the WhatsApp chatbot, conversations run on the WhatsApp Business Platform. Messages travel through Meta's infrastructure and are also subject to Meta's own terms and privacy policy. Through that channel we receive your phone number, your WhatsApp profile name, and the content of the messages you send to the lender.
We use that data only to operate the loan conversation on the lender's behalf. We do not use it for advertising, and we do not share it with Meta for advertising. To request deletion of data associated with your WhatsApp or Facebook identity, see our data deletion instructions.
6. Credit scoring and automated decisions
The platform produces a credit score between 300 and 850 from a combination of rules and machine learning, using features derived from M-PESA transaction history, business characteristics, the requested loan, and behavioural indicators. A large language model may be used to turn that result into a plain-language explanation.
The lender sets the thresholds and makes the decision. Scores can be configured to approve automatically, to route to a human reviewer, or to require multiple levels of approval.
You have the right, under section 35 of the DPA, to:
- Be told when a decision about you was made by automated means
- Receive the reasons. Where a lender declines an application on the platform, an adverse action notice with specific reason codes is generated for exactly this purpose
- Ask for the decision to be reviewed by a person
- Contest the outcome
Direct these requests to your lender; we will support them in answering.
7. Lawful basis
- Consent: for demo enquiries, for optional data such as GPS location, and for the WhatsApp conversation itself
- Performance of a contract: to deliver the services our clients have engaged us for, and to service a loan you have entered into
- Legal obligation: identity verification, anti-money-laundering monitoring, record retention and regulatory reporting
- Legitimate interests: securing the platform, preventing fraud, and keeping audit records, balanced against your rights
8. Who we share data with
We do not sell personal data. We share it with service providers who help us run the platform, each under contract and only for the purpose described:
- Meta Platforms
- WhatsApp Business Platform message delivery
- Safaricom PLC
- M-PESA disbursement, collection and transaction confirmation
- Africa's Talking and VasPro
- SMS delivery for one-time passcodes and notifications
- OpenAI and Anthropic
- Generating narrative explanations of scoring and fraud outcomes. Content sent for this purpose is not used to train their models under our agreements.
- Hosting and storage providers
- Running the application and storing uploaded documents in encrypted object storage
We also disclose data where the law requires it: to regulators, credit reference bureaus where a lender is required to report, courts, or law enforcement acting under lawful authority.
Transfers outside Kenya
Some of the providers above process data outside Kenya. Where that happens we rely on the safeguards permitted by sections 48 and 49 of the DPA, including contractual protections and transfers necessary for the performance of a contract with you.
9. How long we keep data
As a processor, retention is set by the lender and by Kenyan law. Two things follow from that, and it is important to be plain about the second:
- Demo and sales enquiries we hold as controller are kept for as long as the commercial conversation is live, and then archived.
- Loan and transaction records generally cannot be deleted on request during their statutory retention period. Kenyan anti-money-laundering and financial-records law requires lenders to retain transaction and identity records for a set period, commonly seven years, after the relationship ends. A deletion request does not override that obligation. What we can do is delete data that is not caught by it, and restrict processing of the rest so it is kept only to satisfy the legal requirement.
10. How we protect data
- Encryption in transit, and encryption at rest for stored documents and credentials
- A separate database schema per institution, enforced at the connection level
- Role-based access control with multi-factor authentication for staff accounts
- An append-only audit log of access to and changes in customer records
- Personal data masked in application logs
- Signed, verified webhooks between systems, and secrets held in a managed vault
No system is perfectly secure. If we become aware of a breach that poses a real risk to you, we will notify the Office of the Data Protection Commissioner and affected people as required by section 43 of the DPA.
11. Your rights
Under the DPA you may ask to:
- Be informed of how your data is being used
- Access the personal data we hold about you
- Have inaccurate or incomplete data corrected
- Have data deleted, subject to the retention rules in section 9
- Object to processing, or ask that it be restricted
- Receive your data in a portable format
- Withdraw consent at any time, where consent is the basis we rely on
To exercise any of these, email info@pesarails.com with enough detail for us to find your record. We respond within 30 days. Borrowers should contact their lender first (see section 2).
12. Complaints
If you are not satisfied with how we have handled your data or your request, you can complain to the Office of the Data Protection Commissioner of Kenya at odpc.go.ke. We would rather hear from you first so we can put it right.
13. Children
The platform is not intended for anyone under 18, and lenders using it are contractually required not to onboard minors. If you believe we hold a child's data, tell us and we will delete it.
14. Changes to this policy
We will update this page when our processing changes and revise the effective date at the top. Material changes affecting borrowers are communicated to the lenders who act as their controllers.
15. Contact
Our Data Protection Officer is the point of contact for anything in this policy, including access and deletion requests.
- General enquiries
- info@pesarails.com
- Data Protection Officer
- pesarailslimited@gmail.com
- Registered address
- PesaRails Africa Ltd
TRV Plaza, Muthithi Road
Nairobi 00100, Kenya - Data deletion
- pesarails.com/data-deletion