Last updated: May 2026
This policy describes how Geliana Pay collects, uses, and protects your personal data in compliance with the Kenya Data Protection Act, 2019.
Geliana Pay ("we", "us", "our", "the Platform") is committed to protecting your personal data in accordance with the Kenya Data Protection Act, No. 24 of 2019 ("Data Protection Act"), the Data Protection (General) Regulations, 2021, and other applicable data protection laws.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use our Platform. It also explains your rights under the Data Protection Act and how to exercise them.
By using Geliana Pay, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, you should discontinue use of the Platform.
Geliana Pay is the data controller for the purposes of the Data Protection Act. We determine the purposes and means of processing your personal data.
Our Data Protection Officer (DPO) can be contacted at:
Email: dpo@geliana.com
We collect the following categories of personal data:
KYC data is encrypted using AES-256-GCM before storage. Decryption keys are managed separately and only accessible to authorised administrative personnel.
We process your personal data for the following purposes, under these legal bases:
| Purpose | Legal Basis (Data Protection Act) |
|---|---|
| Account creation and management | Contract (Section 25) — necessary to provide our services |
| Identity verification (KYC) | Legal obligation (Section 25) — anti-money laundering compliance |
| Payment processing and settlement | Contract — necessary to execute transactions |
| Fraud prevention and risk management | Legitimate interest (Section 26) — protecting our Platform and users |
| Tax and regulatory compliance | Legal obligation — KRA and CBK requirements |
| Customer support and communication | Contract and legitimate interest |
| Platform improvement and analytics | Legitimate interest — improving our services |
We adhere to the following data protection principles under Section 25 of the Data Protection Act:
Under the Data Protection Act, you have the following rights regarding your personal data:
You have the right to be informed about the collection and use of your personal data — this Privacy Policy fulfils that right.
You have the right to request a copy of the personal data we hold about you. To exercise this right, contact our DPO at dpo@geliana.com.
You have the right to request correction of inaccurate or incomplete data. Profile information can be updated directly in your account settings.
You have the right to request deletion of your personal data, subject to legal retention requirements. See our Data Deletion Policy in our Terms of Service for details. Certain data may be retained for legal or regulatory compliance.
You have the right to request restriction of processing where you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used format and request transmission to another controller where technically feasible.
You have the right to object to processing of your data for direct marketing or processing based on legitimate interests.
You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you.
To exercise any of these rights, contact our Data Protection Officer at dpo@geliana.com. We will respond to your request within the timeframe required by the Data Protection Act (generally 30 days).
We retain personal data only as long as necessary for the purposes described in this policy, subject to the following retention periods:
| Data Category | Retention Period |
|---|---|
| Account and profile data | Until account deletion + 30-day buffer |
| KYC verification data | As required by anti-money laundering regulations (minimum 7 years after account closure) |
| Transaction records | Minimum 7 years for tax and audit compliance |
| Audit logs | Permanently — retained for legal and security purposes |
| Email notification logs | Permanently — retained for audit and compliance purposes |
| Communications (support inquiries) | 3 years after resolution |
We implement appropriate technical and organisational measures to protect your personal data, including:
Despite these measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but will notify you of any data breach affecting your personal data as required by the Data Protection Act.
Your personal data may be transferred to and processed in countries outside Kenya where our service providers operate:
We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses or equivalent data protection agreements with our service providers, as required by Section 31 of the Data Protection Act.
If you believe we have violated your data protection rights, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC):
Office of the Data Protection Commissioner
P.O. Box 19937-00100, Nairobi, Kenya
Email: complaints@odpc.go.ke
Website: www.odpc.go.ke
We encourage you to contact us first at dpo@geliana.com so we can address your concerns before you escalate to the ODPC.
We may update this Privacy Policy from time to time. Material changes will be communicated via email or through the Platform. We encourage you to review this policy periodically.
For questions about this Privacy Policy or our data protection practices:
Data Protection Officer
Email: dpo@geliana.com
General Inquiries
Email: support@geliana.com
Geliana Pay — Payment facilitation for African freelancers and creators.