Privacy Policy

Privacy Policy

Last Updated: January 1, 2025

1. Introduction

SmartHR Kenya ("we", "our", or "us") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our HR management platform. This policy is in compliance with the Kenya Data Protection Act, 2019.

2. Information We Collect

We collect information that you provide directly to us when you register an account, create an employee profile, process payroll, or use any feature of our platform. This includes:

  • Personal identification information (name, email address, phone number, national ID number)
  • Employment information (job title, department, employment dates, salary details)
  • Financial information (bank account details, M-Pesa numbers, KRA PIN, NSSF and SHIF numbers)
  • Location data (GPS coordinates for attendance tracking, with your consent)
  • Device information (IP address, browser type, device identifiers)
  • Usage data (features accessed, pages viewed, actions taken within the platform)

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our HR management services
  • Process payroll and calculate statutory deductions (PAYE, NSSF, SHIF, Housing Levy)
  • Track attendance and manage leave requests
  • Send notifications via email, SMS, or WhatsApp as configured by your employer
  • Generate reports and analytics for authorized HR personnel
  • Process subscription payments and manage billing
  • Respond to your inquiries and provide customer support
  • Comply with legal obligations under Kenyan law

4. Data Sharing and Disclosure

We do not sell your personal data. We may share your information only in the following circumstances:

  • With your employer (tenant) who has authorized access to employee data within their organization
  • With statutory bodies (KRA, NSSF, SHIF/SHA) as required for payroll compliance
  • With payment processors (M-Pesa, card payment providers) to process transactions
  • With communication service providers (SMS, email, WhatsApp) to deliver notifications
  • When required by law, court order, or governmental authority

5. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including encryption of sensitive data at rest and in transit, access controls, audit logging, and regular security assessments.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. Payroll and statutory records are retained for the minimum period required by Kenyan tax and employment law (currently 7 years). You may request deletion of your data subject to legal retention requirements.

7. Your Rights

Under the Kenya Data Protection Act, 2019, you have the right to:

  • Access your personal data held by us
  • Request correction of inaccurate data
  • Request deletion of your data (subject to legal retention requirements)
  • Object to processing of your data
  • Data portability (receive your data in a structured format)
  • Withdraw consent at any time

8. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:

Email: privacy@smarthr.co.ke
Phone: +254 731 664 845
Address: Nairobi, Kenya