Privacy Policy

Effective Date: [21/01/2025]

 

[ZEROX TECHNOLOGY COMPANY LIMITED] ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information, as well as your rights regarding that information.

 

By using our services, you agree to the terms of this Privacy Policy. If you do not agree with any part of this policy, please discontinue using our application immediately.

 

1. Information We Collect

We may collect the following categories of information:

 

1.1 Information You Provide

Personal identification information (e.g., name, gender, ID number, address, email, phone number, ID card photo, selfie, work information, postal code, emergency contact information, E-wallet account, educational background ).

 

1.2 Information Collected Automatically

Device information: Device model, operating system version, operating system name, operating system language, unique device identifiers (e.g., IDFA), camera permission, photo library permission, screen width and height .

Log data: IP address, access times, features used, and pages viewed.

Location information: With your consent, we may collect your geographic location.

 

1.3 Information from Third Parties

Credit information provided by credit assessment agencies or partners.

 

2. How We Use Your Information

We use the information we collect for the following purposes:

 

To evaluate and process your loan application.

To provide, maintain, and improve our services.

To comply with legal and regulatory requirements (e.g., anti-money laundering checks).

To prevent fraud and unauthorized activities.

To offer personalized services and recommendations.

To communicate with you, including sending notifications and updates.

To transfer to your receiving account.

 

3. Sharing and Disclosure of Information

We may share your information under the following circumstances:

 

With Service Providers: Third-party partners who assist with services such as payment processing, credit assessment, or data storage.

Legal Requirements: When required by law, court order, or governmental authority.

Business Transactions: In the event of a merger, acquisition, or asset sale, your information may be transferred as part of the transaction.

 

4. Data Protection

We are committed to protecting your personal information and employ comprehensive measures to ensure its security. These measures include, but are not limited to:

1.Encryption
  1. All sensitive data is encrypted during transmission and at rest using industry-standard encryption protocols (e.g., HTTPS).
  2. This ensures your information is protected from unauthorized access during communication and while stored in our systems.

 

2. Access Control

  1. Personal data is accessible only to authorized personnel who require access to perform their duties.
  2. Role-based access controls (RBAC) are implemented to limit data access to a "need-to-know" basis.

3. System Security

  1. Regular security assessments, including vulnerability scanning and penetration testing, are conducted to identify and mitigate potential risks.

4. Data Minimization and Retention

  1. We only collect and retain the minimum amount of personal data necessary for the purposes outlined in this policy.
  2. Data is securely deleted or anonymized when it is no longer needed, unless retention is required by applicable laws.

5.Monitoring and Incident Response

  1. Systems are continuously monitored for suspicious activities or potential breaches.
  2. A dedicated incident response team is in place to address and resolve any security incidents promptly.

6.Employee Training

  1. All employees undergo regular training on data protection, privacy policies, and security best practices to ensure compliance with industry standards.

Your Responsibility
While we implement robust security measures, no system is entirely foolproof. We encourage you to take steps to protect your personal information, such as keeping your login credentials secure and using strong, unique passwords for your accounts.

 

5. Data Storage and Retention

We retain your information as long as necessary to fulfill contractual obligations or comply with legal requirements.

When information is no longer needed, we securely delete or anonymize it.

 

6.Collection and Use of Emergency Contact Information

When using our services, we may request you to provide information about an emergency contact. The collection and use of this information are strictly limited to the following purposes:

We are committed to the following principles:

User Responsibility :
Before providing emergency contact information, you must ensure that you have obtained the explicit consent of the individual and informed them about the purposes for which their information will be used.

 

7.Collection and Use of E-wallet Account Information

We use the E-wallet account solely for the purpose of disbursing funds to customers. Your E-wallet account information will be used exclusively for the following:

User Responsibility

You are responsible for protecting your E-wallet account information, avoiding disclosure, and promptly notifying us of any unusual activity.

 

8.Camera Permission

To provide certain features of our services, we may request access to your device's camera. The camera permission will be used solely for the following purposes:

User Control

9.Image Information Collection

As part of our services, we may collect image information that you provide. The collection of image information is limited to the following purposes:

Third-Party Sharing

Your image information will not be shared with third parties unless required by law or explicitly authorized by you.

User Responsibility

You are responsible for ensuring the accuracy and authenticity of the images you provide. Providing false or misleading images may result in delays or denial of services.

 

10.Location Information Collection

To enhance our services and provide you with better user experiences, we may collect your device's location information. The collection of location information is limited to the following purposes:

Third-Party Sharing

Your location information will not be shared with third parties unless required by law or explicitly authorized by you.

User Control

 

11.Collection of Mobile Phone Numbers and Email Addresses

We collect your mobile phone number and email address solely for the purpose of verifying your identity. This information is used for account management, security verification, and necessary communication with you.

 

12.Account Deactivation

You have the option to deactivate your account. You can do so by selecting the "Cancel Account" option in the "More" menu located in the top left corner, or by contacting us via customer service phone or email. If you choose to contact us via email, please ensure that you provide your name, phone number, and KTP information in the email so that we can verify your identity.

After submitting your account deactivation request, we will conduct a manual review. If your account meets the deactivation criteria, we will process your request within 15 business days. Once the deactivation is complete, all information associated with your account will be deleted or anonymized, unless otherwise required by applicable laws. Please note that after deactivation, you will no longer be able to access services provided through this account.

 

13. Cookies and Tracking Technologies

We may use cookies and similar technologies to collect information for analytics, advertising, or personalization. You can manage or disable cookies through your device settings, but this may affect some functionality.

 

14. Children's Privacy

Our services are not intended for individuals under the age of 18. If we become aware that we have collected information from a minor without parental or guardian consent, we will delete it promptly.

 

15. Changes to This Privacy Policy

We may update this Privacy Policy periodically. Any changes will be posted on this page, and the effective date will be updated accordingly. Please review this page regularly for the latest information.

 

16. Your Rights

Depending on applicable laws, you may have the following rights:

 

Access your personal data and request a copy.

Request corrections, deletion, or restriction of your personal data.

Withdraw your consent to data processing (without affecting the legality of prior processing).

File a complaint with a regulatory authority.

To exercise your rights, please contact us using the details provided below.

 

17. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

Working time: 8am-5pm(Monday - Saturday)

Company Name: ZEROX TECHNOLOGY COMPANY LIMITED

Address: Enterprise Road, Road B Plot Number One Stroke One Seven Six, Nairobi

Email: help@apesa.co.ke

Phone Number: +254 207903583

Website: https://www.apesa.co.ke/