PRIVACY POLICY
Data Controller: Melian Dialogue Limited (the "Company", "we", "us", or "our") Jurisdiction of Incorporation: Republic of Kenya Registered Office: [Insert Registered Office Address, Nairobi, Kenya] Primary Contact Email: info@meliandialogue.com Office of the Data Protection Commissioner (ODPC) Registration No.: [Insert ODPC Registration No.] Effective Date: [Insert Effective Date] Version: 1.0
1. Introduction and Scope
This Privacy Policy (the "Policy") governs the manner in which Melian Dialogue Limited collects, processes, stores, discloses, and otherwise handles Personal Data of natural persons who access, register with, or otherwise use the Melian Dialogue platform, including any associated mobile progressive web applications, application programming interfaces, marketing sites, and related digital properties (collectively, the "Platform").
The Company is registered with the Office of the Data Protection Commissioner of Kenya as a Data Controller pursuant to Section 18 of the Kenya Data Protection Act, 2019 (the "KDPA"). Where applicable, we additionally comply with (i) the European Union General Data Protection Regulation 2016/679 ("GDPR"), (ii) the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act ("CCPA/CPRA"), (iii) the Kenya Consumer Protection Act, 2012, and (iv) the National Payment System Act, 2011 and related regulations of the Central Bank of Kenya ("CBK").
By accessing or using the Platform, the User (as defined below) acknowledges having read, understood, and agreed to this Policy.
2. Definitions
- "Personal Data" has the meaning ascribed to it in Section 2 of the KDPA and Article 4(1) of the GDPR, being any information relating to an identified or identifiable natural person.
- "Sensitive Personal Data" has the meaning ascribed to it in Section 2 of the KDPA and Article 9(1) of the GDPR.
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means.
- "Data Subject" or "User" means the natural person to whom the Personal Data relates.
- "Data Processor" means any third party that processes Personal Data on behalf of the Company.
3. Categories of Personal Data Collected
The Company collects the following categories of Personal Data:
3.1 Identity and Contact Data
Full legal names; preferred display names; residential or postal address (where voluntarily provided); email address; mobile telephone number; national identification particulars where required for regulatory compliance (including but not limited to Kenya National Identity Card number, Kenya Revenue Authority PIN, or passport number for non-resident Users, collected only where mandated by anti-money-laundering ("AML") or Know-Your-Customer ("KYC") obligations under CBK regulations).
3.2 Account and Authentication Data
Encrypted password credentials; multi-factor authentication tokens; single sign-on ("SSO") identifiers issued by federated identity providers (e.g. Google); email verification tokens; password reset tokens; session identifiers.
3.3 Transactional and Financial Data
Subscription tier history; billing cycle records; invoice numbers; last four digits of payment instruments; M-Pesa payer reference; Stripe or Paystack transaction identifiers; virtual trading account balances; simulated trade history; leaderboard positions; payout election records. For the avoidance of doubt, the Company does not collect or retain full primary account numbers ("PANs"), Card Verification Values ("CVV"), M-Pesa PINs, or any equivalent raw payment credential.
3.4 Technical and Device Data
Internet Protocol ("IP") address; anonymised device fingerprints; operating system and version; browser type, version, and configuration; screen resolution; approximate geolocation (city / region granularity) derived from IP; time zone; language preferences; PWA installation status; service worker cache identifiers.
3.5 Usage and Behavioural Data
Pages viewed; features accessed; simulated trades executed; lesson completion telemetry; time-on-page; click paths; A/B test cohort assignments; referrer URLs; UTM campaign parameters.
3.6 Communications Data
Messages exchanged via the in-platform chat widget; support ticket contents; email correspondence sent to the Company; contact-form submissions; feedback surveys.
3.7 Marketing Preferences
Newsletter subscription status; digest opt-in status; SMS marketing opt-in status; referral programme participation records.
4. Legal Bases for Processing
The Company processes Personal Data solely on one or more of the following lawful bases as recognised under Section 30 of the KDPA and Article 6(1) of the GDPR:
4.1 Consent (KDPA s.30(a); GDPR Art.6(1)(a))
Where the User has given clear, affirmative, informed, and specific consent — for example, when opting into marketing communications, accepting non-essential cookies, or authorising Google Sign-In.
4.2 Contractual Necessity (KDPA s.30(b); GDPR Art.6(1)(b))
Processing necessary for the performance of the Terms of Service to which the User is a party, including but not limited to account creation, subscription billing, delivery of the trading simulation engine, and transmission of transactional emails.
4.3 Legal Obligation (KDPA s.30(c); GDPR Art.6(1)(c))
Processing required to comply with legal obligations to which the Company is subject, including AML, KYC, tax reporting to the Kenya Revenue Authority, and reporting to the CBK where applicable.
4.4 Legitimate Interests (KDPA s.30(f); GDPR Art.6(1)(f))
Processing necessary for the legitimate business interests of the Company, including fraud prevention, network and information security, product analytics, service improvement, and the enforcement of the Company's rights — provided such interests are not overridden by the fundamental rights and freedoms of the User.
4.5 Vital Interests and Public Interest
Where processing is necessary to protect the vital interests of a natural person, or to perform a task carried out in the public interest, in each case as recognised under Section 30 of the KDPA.
5. Purposes of Processing
The Company processes Personal Data for the following purposes only:
(a) to authenticate the User and administer their account; (b) to deliver the trading simulation, learning hub, community, copy-trading, and market intelligence features of the Platform; (c) to process subscription payments and issue receipts and invoices; (d) to enforce the Terms of Service, protect against fraud, abuse, and prohibited activities; (e) to comply with legal, regulatory, and audit obligations under Kenyan law; (f) to communicate transactional, security, and service-status notifications; (g) to send marketing communications where consented; (h) to conduct internal research, product analytics, and A/B experimentation; (i) to respond to Data Subject Access Requests and other rights requests.
Personal Data shall not be further processed in a manner incompatible with these purposes.
6. Data Sharing and Third-Party Disclosures
The Company shares Personal Data only with the categories of recipients listed below, in each case pursuant to a written data processing agreement compliant with Section 42 of the KDPA and, where applicable, Article 28 of the GDPR:
6.1 Payment Processors
- Safaricom PLC (M-Pesa Daraja API)
- Stripe, Inc.
- Paystack Payments Limited
Data shared: masked payment references, subscription tier, transaction amount, currency, User email, and mobile number where required for M-Pesa STK push execution.
6.2 Cloud Infrastructure and Hosting Providers
- [Insert Cloud Hosting Provider — e.g., Amazon Web Services (EMEA region) or Google Cloud Platform (europe-west3)]
- Content delivery network provider(s)
- Managed MongoDB service provider
6.3 Communications and Delivery Providers
- Resend, Inc. (transactional email)
- Africa's Talking Limited (SMS delivery)
- [Insert additional providers as applicable]
6.4 Analytics and Product Instrumentation
- Google Analytics (via consent-managed loader)
- [Insert additional analytics processors]
6.5 Regulatory and Governmental Authorities
The Company may disclose Personal Data to the ODPC, CBK, Kenya Revenue Authority, Capital Markets Authority, Financial Reporting Centre, the Judiciary of Kenya, or any competent regulatory or law-enforcement authority, but only pursuant to a validly issued order, subpoena, warrant, or lawful demand under Kenyan or applicable foreign law.
6.6 Professional Advisers and Corporate Transactions
The Company may disclose Personal Data to its auditors, legal counsel, and, in the context of a merger, acquisition, restructuring, or sale of substantially all assets, to any successor entity, subject to equivalent confidentiality and data-protection obligations.
The Company does not sell Personal Data as that term is defined in the CCPA/CPRA.
7. International Data Transfers
Where Personal Data is transferred outside the Republic of Kenya to a jurisdiction that has not been declared to offer adequate protection pursuant to Section 48 of the KDPA, the Company relies on one or more of the following safeguards:
(a) Standard Contractual Clauses ("SCCs") approved by the European Commission (Commission Implementing Decision (EU) 2021/914) or their equivalent adopted by the ODPC; (b) Binding Corporate Rules of the recipient, where such rules have been approved by the competent supervisory authority; (c) Explicit informed consent of the Data Subject, obtained in advance, to the specific transfer; (d) Any derogation permitted under Section 49 of the KDPA or Article 49 of the GDPR.
A copy of the executed SCCs applicable to a specific transfer will be made available on written request to info@meliandialogue.com, subject to redaction of commercially sensitive terms.
8. Data Retention
Personal Data shall be retained only for so long as is necessary for the purpose for which it was collected, or as required by applicable law:
- Account and profile data: for the duration of the account and for seven (7) years following account closure, in line with retention obligations under the Kenya Companies Act, 2015 and the Tax Procedures Act, 2015.
- Transactional and payment data: seven (7) years from the date of the transaction.
- Authentication logs, security event logs, and IP address logs: eighteen (18) months.
- Marketing consent records: until consent is withdrawn plus twelve (12) months.
- Support ticket and chat records: three (3) years from case closure.
Upon expiry of the applicable retention period, Personal Data shall be securely deleted or irreversibly anonymised.
9. Data Subject Rights
Users have the following rights under Part V of the KDPA and Chapter III of the GDPR:
9.1 Right of Access
The right to obtain confirmation as to whether Personal Data concerning the User is being processed and, where so, a copy of such data and information about the processing.
9.2 Right to Rectification
The right to have inaccurate Personal Data corrected without undue delay and to have incomplete data completed.
9.3 Right to Erasure ("Right to be Forgotten")
The right to have Personal Data erased where the data is no longer necessary for the purposes for which it was collected, where consent is withdrawn, or where processing was unlawful. This right is subject to legal and regulatory retention obligations.
9.4 Right to Restrict Processing
The right to obtain a temporary restriction on processing pending verification of the accuracy of the data or the legitimacy of the processing.
9.5 Right to Data Portability
The right to receive the Personal Data provided to the Company in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
9.6 Right to Object
The right to object at any time to processing based on legitimate interests, including profiling, and to object to processing for direct marketing purposes.
9.7 Right to Withdraw Consent
Where processing is based on consent, the User may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
9.8 Right to Lodge a Complaint
The User has the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya (odpc.go.ke), or with the supervisory authority of their habitual residence within the European Economic Area, or with the California Privacy Protection Agency (cppa.ca.gov) where applicable.
9.9 Exercising Rights — Operational Instructions
All rights requests must be directed to info@meliandialogue.com with:
(a) the subject line "Data Subject Rights Request — [Type of Request]"; (b) the User's registered email address; (c) sufficient information to verify the User's identity (which may include a request for further authentication in accordance with Section 34 of the KDPA); (d) a clear statement of the right being exercised and the scope of the request.
The Company shall respond to a valid request without undue delay and in any event within thirty (30) calendar days of receipt of a verified request, as required by Section 26 of the KDPA. Where the request is complex or numerous, this period may be extended by up to two (2) further months, with prior notification to the User.
10. Security of Processing
The Company implements technical and organisational measures appropriate to the risk, in accordance with Section 41 of the KDPA and Article 32 of the GDPR, including without limitation: encryption in transit (TLS 1.2 or higher); encryption at rest for sensitive fields; hashed password storage using industry-standard adaptive algorithms; role-based access control; principle of least privilege; audit logging; regular security assessments; secure software development lifecycle practices; and incident-response procedures.
11. Data Breach Notification
In the event of a Personal Data breach likely to result in a risk to the rights and freedoms of Data Subjects, the Company shall notify the ODPC within seventy-two (72) hours of becoming aware of the breach, in accordance with Section 43 of the KDPA. Where the breach is likely to result in a high risk, affected Data Subjects shall be notified without undue delay.
12. Children
The Platform is not directed to persons under the age of eighteen (18). The Company does not knowingly collect Personal Data from minors. Where the Company becomes aware that such data has been collected, it shall delete the data forthwith.
13. Automated Decision-Making
The Platform does not subject Users to solely automated decisions producing legal or similarly significant effects, save for automated fraud-scoring of transactions and automated feature-gating based on subscription tier, in each case with human review available upon written request.
14. Changes to this Policy
The Company reserves the right to amend this Policy from time to time. Material changes will be notified to Users by email and by prominent notice on the Platform not less than fourteen (14) days prior to taking effect.
15. Contact and Data Protection Officer
Data Protection Officer / Contact Person: [Insert Name and Title] Email: info@meliandialogue.com Postal Address: [Insert Registered Office Address, Nairobi, Kenya]
This Privacy Policy is issued in the English language, which shall be the controlling language for all interpretation purposes.