PayDesk
PayDesk

Privacy Policy

Last Updated: September 1, 2026

ODPC Registered Data Processor · 628-7798-B0C8

01Our Commitment

PayDesk is operated by G3 Labs in Nairobi, Kenya. Our institutional clients entrust us with sensitive data about children, their families, and school finances. Privacy is not a feature of this platform; it is a condition of it.

This policy explains what we collect, why, how long we keep it, who else touches it, and what you can require us to do. It is written to meet the Kenya Data Protection Act, 2019 and the regulations made under it. G3 Labs Limited, which operates PayDesk, is registered with the Office of the Data Protection Commissioner (ODPC) of Kenya as a Data Processor, registration number 628-7798-B0C8, valid from 9 June 2026 to 9 June 2028.

02Who Controls Your Data

This distinction matters, because it determines who you go to with a request:

Your school is the Controller

For student, parent and staff records, the school decides what is collected and why. PayDesk processes that data only on the school's documented instructions. Requests about a student's record go to the school first.

PayDesk is the Controller

For our own account, subscription, billing and support records, and for the security logs we keep to protect the platform. You can bring those requests directly to us.

03Data We Collect

To provide our school management services, we process these categories of information:

  • Institutional Info

    School name, licence details, and administrative contact information.

  • Academic Records

    Enrolment, class placement, attendance, assessment and grading data.

  • Financial Data

    Invoices, fee structures, M-Pesa transaction references and payment history.

  • Location Data

    Vehicle position during an active school transport run, and boarding events.

  • Contact Data

    Parent and guardian names, phone numbers and email addresses.

  • Security Data

    Sign-in events, IP address, and an audit trail of actions taken in the system.

04Children's Data

Most of the people whose data passes through PayDesk are children. Section 33 of the Data Protection Act, 2019 sets a higher bar for that, and we treat it as the design constraint for the whole platform.

  • A child’s data is processed on the instruction of their school, on the lawful basis the school relies on, and in the child’s best interests.
  • Parents and guardians are linked to their own children only. A guardian can never see another family’s records.
  • We do not profile children for advertising, and we do not sell or share their data for any commercial purpose.
  • Transport location is visible to a linked guardian and authorised school staff during an active run, and is not retained as a long-term movement history.

05How We Use Data

We process data to deliver the service the school has contracted us for, to meet our legal obligations, and to keep the platform secure. Specifically:

  • Issue invoices, reconcile M-Pesa payments and maintain fee balances.
  • Record attendance, assessments and results, and produce report cards.
  • Show a linked guardian where their child’s vehicle is during an active transport run.
  • Send notifications by SMS, email and in-app message to authorised recipients.
  • Produce financial and academic reports for school management.
  • Detect abuse, investigate incidents and maintain the audit trail.

We do not sell personal data, we do not share it with advertisers, and we do not use school or student data to train third-party models.

06Who Else Processes Your Data

We use a small number of sub-processors. Each is bound by contract to process data only on our instructions and to protect it to the standard set out in this policy. A current list of named providers is available to subscribing schools on request.

FunctionPurposeLocation
Mobile money paymentsFee collection and reconciliation via M-PesaKenya
SMS gatewayText message delivery to parents and staffKenya
Cloud hosting and storageRunning the platform and storing its recordsOutside Kenya
Email deliveryTransactional and notification emailOutside Kenya

07Transfers Outside Kenya

Payment and SMS processing happen in Kenya. Some of the infrastructure we rely on, shown in the table above, stores or processes data outside Kenya. Where that happens we rely on the safeguards permitted by sections 48 and 49 of the Data Protection Act, 2019: contractual protections with the provider, encryption in transit and at rest, and a transfer limited to what the service actually requires. We will tell affected schools before adding a sub-processor that materially changes where their data is held.

08How Long We Keep Data

We keep personal data only as long as it is needed for the purpose it was collected for, or as long as Kenyan law requires:

  • Student academic and enrolment records

    For as long as the school subscribes, plus 90 days after termination.

  • Financial and billing records

    Seven years, to meet Kenyan tax and audit obligations.

  • Transport location history

    Rolling 90 days, then deleted.

  • Communication logs (SMS, email, in-app)

    Two years, for delivery-dispute resolution.

  • Security and audit logs

    Two years.

09Your Rights

Under the Data Protection Act, 2019 you have the right to:

  • Be informed of how your personal data is being used.
  • Access the personal data we hold about you.
  • Request correction of data that is inaccurate or incomplete.
  • Request deletion of your personal data where we have no lawful reason to keep it.
  • Object to processing, and to withdraw consent where consent is the basis we rely on.
  • Receive a copy of your data in a portable, machine-readable format.

How to exercise them: if the data is held by your school, ask the school — they are the controller, and PayDesk gives every school a built-in erasure tool that anonymises personal identifiers while retaining the financial facts the law requires them to keep. For data PayDesk controls, or if your school does not respond, contact us directly using the details below. We respond within 30 days.

10Security and Breach Notification

Data is encrypted in transit and at rest. Access is governed by role-based permissions, so staff see only what their role requires, and every consequential action is written to an audit trail. Details of our security posture are on our security page.

If a breach occurs that presents a real risk to the people affected, we will notify the ODPC within 72 hours of becoming aware of it, and notify the affected school without undue delay, as required by section 43 of the Act.

11Data Sovereignty

We believe in institution-owned data. We never sell student or institutional data to third parties, and we do not use your data for advertising. Your school retains full control over its records and can export them at any time, including on termination.

Contact and Complaints

For any privacy question, data-subject request, or to reach our data protection contact:

PayDesk (G3 Labs)

hello@paydesk.live
0748 938 887
Northern Bypass, Nairobi, Kenya

Office of the Data Protection Commissioner

If you are not satisfied with how we have handled your request, you may lodge a complaint with the ODPC at odpc.go.ke.

Changes to This Policy

We update this policy as the platform changes. The date at the top reflects the current version. Where a change materially affects how we handle personal data, we notify subscribing schools before it takes effect.

© 2026 PayDesk - A Product of G3 Labs