Legal

Legal and Privacy Policy

How Convergly protects Customer Data, complies with Kenya's Data Protection Act, and operates as a trusted processor for your association.

Data Protection and Privacy

The following provisions govern how Convergly processes Customer Data as a service provider under applicable Kenyan data protection law.

1

Compliance with Data Protection Act, 2019

Both parties shall comply with all applicable obligations under the Data Protection Act, 2019 (Kenya), the Data Protection (General) Regulations, 2021, and any other applicable data protection legislation.

2

Data Controller / Processor Relationship

For the purposes of this Agreement:

  • The Customer is the Data Controller of Customer Data, responsible for determining the purposes and means of processing of Personal Data.
  • The Provider is the Data Processor, processing Personal Data only on documented instructions from the Customer and solely for the purposes of providing the Service.
3

Infrastructure and Hosting Disclosure

The Provider's primary database and platform infrastructure is hosted on Supabase, a managed cloud database and backend provider. The primary database is located in the West EU (Ireland) region, operating on Amazon Web Services infrastructure in the eu-west-1 zone. All Customer Data is stored within this infrastructure environment. The Provider shall notify the Customer in writing not less than thirty (30) days in advance of any material change to the hosting provider or the geographic location of primary data storage.

The Provider uses the following categories of standard infrastructure sub-processors to deliver the Service:

  • Supabase — primary database hosting and backend services (West EU, Ireland)
  • Vercel — application hosting and content delivery
  • SendGrid (Twilio) — transactional email delivery

The Customer acknowledges and consents to the engagement of the above sub-processors. Where the Provider proposes to engage any additional or replacement sub-processor, it shall notify the Customer in writing not less than fourteen (14) days in advance, and the Customer may object in writing within that period if the proposed sub-processor would result in a material change to the data processing arrangements.

4

Provider's Data Processing Obligations

The Provider shall:

  • Process Customer Data only in accordance with the Customer's instructions and this Agreement;
  • Implement appropriate technical and organisational security measures to protect Customer Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage;
  • Not transfer Customer Data outside Kenya without the Customer's prior written consent and in compliance with the Data Protection Act, 2019. The parties acknowledge that the current hosting location in Ireland constitutes a cross-border data transfer and the Customer's execution of this Agreement constitutes prior written consent for that specific transfer;
  • Notify the Customer without undue delay (and in any event within 72 hours of becoming aware) of any personal data breach affecting Customer Data;
  • Assist the Customer, at the Customer's request and cost, in meeting its obligations to data subjects under the Data Protection Act, 2019 (including access requests and data subject rights);
  • Delete or return all Customer Data upon termination of this Agreement, as instructed by the Customer; and
  • Not engage additional sub-processors beyond those identified in Clause 3 without the Customer's prior written consent.
5

AI Admin Assistant — Data Use Restrictions

The AI Admin Assistant feature operates solely by querying the Customer's own data within the Service to generate responses for authorised users. The Provider warrants that:

The Customer's prior written consent is required before Customer Data may be used for any purpose beyond the provision of the Service.

  • Customer Data shall not be used to train, fine-tune, or improve any artificial intelligence or machine learning model, whether operated by the Provider or any third party;
  • Customer Data shall not be disclosed to any third-party AI service provider for any purpose other than processing the specific query submitted by the Customer's authorised user in real time;
  • Any third-party AI inference provider used to power the AI Admin Assistant shall be bound by equivalent confidentiality and data protection obligations; and
  • The Provider shall notify the Customer in writing of any change to the AI model provider or the AI processing arrangements not less than thirty (30) days before such change takes effect.
6

Customer's Data Obligations

The Customer shall:

  • Ensure it has a lawful basis for processing all Personal Data submitted to the Service;
  • Ensure all data subjects have been informed of, and consented to (where required), the processing of their Personal Data on the platform; and
  • Comply with any privacy notices and policies applicable to its members.
7

Data Retention and Export

Customer Data will be retained for the duration of the active subscription. Upon termination, Customer Data will be available for export for thirty (30) days from the termination date. The Provider shall make Customer Data available for export in the following standard formats: CSV, Microsoft Excel (.xlsx), and PDF, as applicable by data type. After the thirty (30) day export window, Customer Data will be securely deleted from the Provider's systems within a further thirty (30) days, unless longer retention is required by applicable Kenyan law.

Upon written request from the Customer made prior to or within the export window, the Provider shall provide reasonable technical cooperation and migration assistance to facilitate the Customer's transition to an alternative provider, at no additional charge for standard data extraction.

8

Backup and Disaster Recovery

The Provider warrants that it maintains automated backup systems and disaster recovery infrastructure adequate to protect and restore Customer Data in the event of system failure or operational disruption. Specifically:

  • Customer Data is backed up on a regular automated basis by Supabase's managed infrastructure, with point-in-time recovery capabilities;
  • Backups are stored within the same geographic region as the primary database (West EU, Ireland);
  • The Provider maintains disaster recovery procedures designed to restore Service availability within commercially reasonable timeframes following a critical system failure; and
  • The Provider shall notify the Customer of any material degradation in its backup or disaster recovery capabilities within seventy-two (72) hours of becoming aware of such degradation.
9

Security Measures

The Provider shall maintain reasonable security measures including, but not limited to:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest;
  • Role-based access controls within the platform;
  • Regular security assessments and vulnerability management;
  • Secure software development lifecycle practices; and
  • Maintenance of access logs recording Provider personnel access to Customer Data environments, which shall be retained for not less than twelve (12) months and made available to the Customer upon reasonable written request.
10

Audit Rights

The Customer shall have the right, upon not less than thirty (30) days' written notice and no more than once per calendar year, to request written confirmation and evidence of the Provider's compliance with its security and data protection obligations under this Agreement. The Provider shall respond to such requests within fifteen (15) business days and shall provide reasonable documentary evidence of its security controls, backup systems, and data processing arrangements. Where the parties agree, such audit rights may be satisfied by the Provider supplying a current third-party security assessment or equivalent compliance attestation.

11

Incident Response Obligations

Upon discovery of a personal data breach or security incident affecting Customer Data, the Provider shall, in addition to the notification obligation in Clause 4:

  • Immediately isolate affected systems to contain the breach and prevent further unauthorised access or data loss;
  • Preserve all forensic evidence relating to the incident and refrain from destroying or altering logs or records without the Customer's prior written consent;
  • Within five (5) business days of initial notification, provide the Customer with a written incident report setting out the nature of the breach, the categories and approximate volume of Customer Data affected, the likely consequences, and the measures taken or proposed to address the breach;
  • Engage qualified security or forensic specialists to investigate the incident where the nature or scale of the breach warrants such engagement;
  • Provide the Customer with ongoing written updates on the progress of investigation and remediation at intervals of not more than five (5) business days until the incident is fully resolved; and
  • Take all reasonable steps to remedy the cause of the breach and prevent recurrence, and provide the Customer with a final written remediation report upon closure of the incident.
12

Payment Processing and Settlement

The following provisions govern payment processing and settlement for payments collected through the Service via the Paystack integration.

12.1 Licensed Payment Processor

The Provider utilises Paystack (operated by Paystack Payments Limited, a company licensed and regulated as a payment service provider under the laws of Nigeria and operating in Kenya in compliance with the Central Bank of Kenya's National Payment System Act, 2011) as the exclusive licensed payment processor for all subscription and transactional payments processed through the Service. CBK identifies Paystack Payments Kenya Limited as the Kenyan licensed entity.

12.2 Fees

Two categories of fee apply to payments processed through the Service:

Paystack Processing Fee: All transaction and processing fees charged by Paystack in connection with payments processed through the Service shall be borne exclusively by the Customer and shall be deducted by Paystack from the gross transaction amount at the point of settlement in accordance with Paystack's standard fee schedule. The Provider shall not add any markup or surcharge on top of Paystack's published processing fees.

Convergly Platform Fee: The Provider shall charge a platform fee of one percent (1%) of each transaction value processed through the Service. This fee is levied by the Provider for the maintenance of the payment infrastructure, technical integration, and security controls that facilitate payment processing on the platform. The Convergly platform fee shall be borne by the payer at the point of transaction and shall be collected automatically at the time of payment processing before settlement of the net amount to the Customer. The Provider shall itemise the Convergly platform fee separately in all reconciliation reports issued under Clause 12.4 so that it is clearly distinguishable from Paystack's processing fees and from the amounts settled to the Customer.

For the avoidance of doubt, this Agreement and the payment processing arrangements set out in this Schedule apply solely to payments collected through the Service via the Paystack integration. Payments made by the Customer's members or any other party directly to the Customer by cheque, bank transfer, cash, or any other method outside the Service are entirely outside the scope of this Agreement. The Provider has no entitlement, interest, visibility, or involvement in such payments, and no fees, charges, reconciliation obligations, or settlement requirements under this Agreement shall apply to them.

12.3 Settlement Timelines

All funds collected through the Service on behalf of the Customer shall settle directly into the Customer's designated bank account within three (3) business days of the transaction being confirmed and cleared by Paystack, unless a shorter settlement period is agreed in writing between the parties. The Provider shall ensure that the Customer's settlement account details are correctly registered with Paystack and shall not redirect, hold, commingle, or otherwise delay the settlement of funds beyond the agreed period without the Customer's prior written consent. Where settlement is delayed beyond the agreed period for any reason within the Provider's control, the Provider shall notify the Customer in writing within twenty-four (24) hours of becoming aware of the delay and shall take all reasonable steps to expedite settlement.

12.4 Reconciliation

The Provider maintains a real-time reconciliation dashboard accessible to the Customer's authorised administrators within the Service at all times. The dashboard displays, for each transaction processed through the Service: the gross amount collected, the Convergly platform fee deducted, Paystack processing fees deducted, the net amount settled to the Customer, the date and reference number of each settlement transfer, and the status of any transactions held, reversed, or flagged. The Customer may access this dashboard at any time without the need to request a separate report.

Where the Customer requires clarification on any individual transaction appearing in the dashboard, the Customer may raise a query through the Provider's support channels and the Provider shall respond within five (5) business days.

12.5 Refunds

Refunds of payments made through Paystack shall be processed only upon the Customer's written authorisation. The Provider shall not issue refunds unilaterally without the Customer's prior written consent, except where required by applicable Kenyan law or by Paystack's mandatory operating rules. Where a refund is authorised, it shall be processed within five (5) business days of authorisation and the Provider shall update the reconciliation records accordingly. Refund amounts shall be sourced from the Provider's operational funds and shall not cause a reduction in the settlement amounts otherwise due to the Customer unless the Customer expressly directs otherwise in writing.

12.6 Chargebacks

In the event that a chargeback is initiated against any transaction processed through the Service, the Provider shall notify the Customer in writing within forty-eight (48) hours of receiving notice of the chargeback from Paystack. The Provider shall, with the Customer's cooperation and written approval, contest the chargeback where there are reasonable grounds to do so. Responsibility for chargeback losses shall be allocated as follows: where the chargeback arises from a technical error, fraud, or negligence on the part of the Provider or Paystack, the Provider shall bear the full financial loss. Where the chargeback arises from a dispute initiated by a member of the Customer or a customer in respect of a service or product delivered by the Customer, the Customer shall bear the financial loss. Where liability is disputed between the parties, the matter shall be escalated in accordance with the dispute resolution procedure in Section 14 of this Agreement.

12.7 Responsibility for Losses

The Provider shall be responsible for any loss of funds arising from: unauthorised access to the Paystack integration, misconfiguration of settlement account details, failure to notify the Customer of settlement delays within the required period, or any act or omission of the Provider or its personnel in the administration of the payment processing arrangement. The Customer shall be responsible for any loss arising from incorrect settlement account details provided by the Customer, or from the Customer's own instructions that result in misdirected payments. Neither party shall be liable for losses caused solely by Paystack system failures beyond their respective control, provided that the affected party has taken all reasonable steps to mitigate such losses and has notified the other party promptly.

12.8 Change of Processor

The Provider shall not replace or supplement Paystack with an alternative payment processor without the Customer's prior written consent. Where a change of processor is proposed, the Provider shall provide the Customer with not less than sixty (60) days' written notice, together with details of the proposed replacement processor's licensing status, fee structure, and settlement terms.

Questions about this policy?

Contact us at info@convergly.app for data protection enquiries.

Back to home