Privacy notice
How KISE SACCO Society Ltd collects, uses, shares and protects your personal information.
This notice should be read together with the SACCO by-laws and any product terms.
1. Who we are
KISE SACCO Society Ltd (“the SACCO”, “we”) is a savings and credit co-operative with its head office at Head Office, KISE, Nairobi (P.O. Box 48413-00100, Nairobi). We are the data controller for the personal data described in this notice and process it in accordance with the Data Protection Act, 2019 of Kenya and its regulations.
2. The information we collect
- Identity and contact details — name, national ID or passport number, KRA PIN, date of birth, gender, photograph, phone numbers, email and postal/physical address.
- Membership and financial information — employment and income details, savings, share capital, loans, guarantees, transactions, M-Pesa payment references and dividends.
- Next of kin and beneficiaries — details you give us about the people you nominate.
- Security and technical data — sign-in times, IP address, browser/device details, security events and an audit trail of actions on your account.
- Communications — enquiries, support tickets and records of messages we send you.
3. Why we use it
- To assess and manage your membership, accounts, loans and guarantees (performance of our contract with you).
- To meet legal and regulatory obligations, including co-operative, tax, anti-money-laundering and SACCO regulatory requirements.
- To protect members and the SACCO against fraud and unauthorised access (legitimate interests).
- To send you service messages such as OTPs, transaction and security alerts, and — only where you agree — newsletters.
4. Who we share it with
We never sell personal data. We share it only where necessary with: payment and messaging partners (for example Safaricom M-Pesa and our SMS provider) to process transactions and deliver messages; auditors, regulators and government agencies where the law requires; credit reference bureaus where permitted; and professional advisers bound by confidentiality.
5. How we protect it
Personal data is stored on secured systems with encrypted connections, role-based access, two-factor authentication for staff, automatic session time-outs, encryption of sensitive credentials, private storage of identity documents and a tamper-evident audit trail. Staff access only what their role requires.
6. How long we keep it
We keep membership and financial records for as long as you are a member and afterwards for the periods required by law and for resolving any claims. Operational logs are retained for shorter periods.
7. Your rights
Under the Data Protection Act, 2019 you may ask to be informed about how your data is used, access it, correct or delete inaccurate or unnecessary data, object to certain processing and, where applicable, request data portability. Some rights are limited where we must keep records by law.
To exercise your rights or ask a question, contact us at Kisesacco@kise.ac.ke or visit our office. If you are not satisfied with our response, you may complain to the Office of the Data Protection Commissioner.
8. Cookies
Our website and portal use a small number of essential cookies to keep you signed in securely and to remember your display preference. We do not use advertising or tracking cookies.
9. Changes
We may update this notice from time to time. The latest version is always available on this page.