KaziKit

Privacy Policy

Version 2.0 — June 2026

This Privacy Policy explains how KaziKit collects, uses, shares, and protects your personal data, and your rights under the Kenya Data Protection Act, 2019 (the “DPA”). By creating an account and using KaziKit, you agree to the practices described here.

1. Who we are

KaziKit (“KaziKit”, “we”, “us”, “our”) is a mobile-first, AI-powered career toolkit for Kenyan job seekers, available at kazikit.co.ke. KaziKit is the data controller responsible for your personal data.

For any privacy matter, contact our Data Protection contact at privacy@kazikit.co.ke.

2. Data we collect

  • Phone number — required to create and secure your account, and to deliver one-time login codes.
  • Work history and career information — the experience, education, skills, and personal story you provide so we can generate your CV and cover letters.
  • Payment records — M-Pesa transaction data (amount, receipt number, timestamp) received from Safaricom when you purchase a plan.
  • Device information and IP address — collected automatically for security, fraud prevention, and to keep your session secure.
  • WhatsApp consent and message delivery records — whether you opted in to WhatsApp alerts, the consent timestamp, and delivery status of messages we send you.

3. Why we collect it

  • Service delivery — generating your CV, cover letters, and other career documents.
  • Payment processing — taking payment for plans via M-Pesa and granting access.
  • Job matching and alert delivery — matching live job listings to your preferences and sending them in-app and on WhatsApp.
  • Fraud prevention and security — protecting your account and our service from abuse and unauthorised access.

4. How long we keep it

  • CV and document text — retained for 12 months from your last activity, then deleted.
  • Payment records — retained for 7 years as required by Kenya Revenue Authority (KRA) tax law.
  • Phone number after account deletion — held for 30 days after deletion to prevent re-registration fraud, then anonymised.

5. Who we share data with

We share the minimum data necessary with trusted processors who help us run KaziKit. Each processes data only on our instructions:

  • Anthropic — provides the Claude AI used to generate your CV and cover letters.
  • Safaricom — processes M-Pesa payments.
  • WhatChimp / Meta — delivers WhatsApp messages.
  • HostPinnacle — delivers SMS one-time login codes.
  • Supabase — hosts our database (data stored in the EU region).

We do not sell your personal data. We only disclose data to third parties where required by law or to protect our legal rights.

6. Your rights under the Kenya DPA 2019

As a data subject, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate or incomplete data (you can also edit your profile in-app).
  • Deletion — delete your account and data using the in-app account deletion feature, subject to the retention periods in Section 4.
  • Data portability — request your data in a portable, machine-readable format.

To exercise any of these rights, contact privacy@kazikit.co.ke. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya.

7. Security

We protect your data with industry-standard measures, including encrypted connections, secure session tokens, and access controls. No system is perfectly secure, but we work continuously to safeguard your information.

8. Contact

Questions about this policy or your data? Email privacy@kazikit.co.ke.

Version 2.0 — June 2026. We may update this policy; material changes will be notified in-app or by message.