Privacy Policy
Last Updated: September 1, 2026
ODPC Registered Data Processor · 628-7798-B0C8
01Our Commitment
PayDesk is operated by G3 Labs in Nairobi, Kenya. Our institutional clients entrust us with sensitive data about children, their families, and school finances. Privacy is not a feature of this platform; it is a condition of it.
This policy explains what we collect, why, how long we keep it, who else touches it, and what you can require us to do. It is written to meet the Kenya Data Protection Act, 2019 and the regulations made under it. G3 Labs Limited, which operates PayDesk, is registered with the Office of the Data Protection Commissioner (ODPC) of Kenya as a Data Processor, registration number 628-7798-B0C8, valid from 9 June 2026 to 9 June 2028.
02Who Controls Your Data
This distinction matters, because it determines who you go to with a request:
Your school is the Controller
For student, parent and staff records, the school decides what is collected and why. PayDesk processes that data only on the school's documented instructions. Requests about a student's record go to the school first.
PayDesk is the Controller
For our own account, subscription, billing and support records, and for the security logs we keep to protect the platform. You can bring those requests directly to us.
03Data We Collect
To provide our school management services, we process these categories of information:
Institutional Info
School name, licence details, and administrative contact information.
Academic Records
Enrolment, class placement, attendance, assessment and grading data.
Financial Data
Invoices, fee structures, M-Pesa transaction references and payment history.
Location Data
Vehicle position during an active school transport run, and boarding events.
Contact Data
Parent and guardian names, phone numbers and email addresses.
Security Data
Sign-in events, IP address, and an audit trail of actions taken in the system.
04Children's Data
Most of the people whose data passes through PayDesk are children. Section 33 of the Data Protection Act, 2019 sets a higher bar for that, and we treat it as the design constraint for the whole platform.
- A child’s data is processed on the instruction of their school, on the lawful basis the school relies on, and in the child’s best interests.
- Parents and guardians are linked to their own children only. A guardian can never see another family’s records.
- We do not profile children for advertising, and we do not sell or share their data for any commercial purpose.
- Transport location is visible to a linked guardian and authorised school staff during an active run, and is not retained as a long-term movement history.
05How We Use Data
We process data to deliver the service the school has contracted us for, to meet our legal obligations, and to keep the platform secure. Specifically:
- Issue invoices, reconcile M-Pesa payments and maintain fee balances.
- Record attendance, assessments and results, and produce report cards.
- Show a linked guardian where their child’s vehicle is during an active transport run.
- Send notifications by SMS, email and in-app message to authorised recipients.
- Produce financial and academic reports for school management.
- Detect abuse, investigate incidents and maintain the audit trail.
We do not sell personal data, we do not share it with advertisers, and we do not use school or student data to train third-party models.
06Who Else Processes Your Data
We use a small number of sub-processors. Each is bound by contract to process data only on our instructions and to protect it to the standard set out in this policy. A current list of named providers is available to subscribing schools on request.
| Function | Purpose | Location |
|---|---|---|
| Mobile money payments | Fee collection and reconciliation via M-Pesa | Kenya |
| SMS gateway | Text message delivery to parents and staff | Kenya |
| Cloud hosting and storage | Running the platform and storing its records | Outside Kenya |
| Email delivery | Transactional and notification email | Outside Kenya |
07Transfers Outside Kenya
Payment and SMS processing happen in Kenya. Some of the infrastructure we rely on, shown in the table above, stores or processes data outside Kenya. Where that happens we rely on the safeguards permitted by sections 48 and 49 of the Data Protection Act, 2019: contractual protections with the provider, encryption in transit and at rest, and a transfer limited to what the service actually requires. We will tell affected schools before adding a sub-processor that materially changes where their data is held.
08How Long We Keep Data
We keep personal data only as long as it is needed for the purpose it was collected for, or as long as Kenyan law requires:
Student academic and enrolment records
For as long as the school subscribes, plus 90 days after termination.
Financial and billing records
Seven years, to meet Kenyan tax and audit obligations.
Transport location history
Rolling 90 days, then deleted.
Communication logs (SMS, email, in-app)
Two years, for delivery-dispute resolution.
Security and audit logs
Two years.
09Your Rights
Under the Data Protection Act, 2019 you have the right to:
- Be informed of how your personal data is being used.
- Access the personal data we hold about you.
- Request correction of data that is inaccurate or incomplete.
- Request deletion of your personal data where we have no lawful reason to keep it.
- Object to processing, and to withdraw consent where consent is the basis we rely on.
- Receive a copy of your data in a portable, machine-readable format.
How to exercise them: if the data is held by your school, ask the school — they are the controller, and PayDesk gives every school a built-in erasure tool that anonymises personal identifiers while retaining the financial facts the law requires them to keep. For data PayDesk controls, or if your school does not respond, contact us directly using the details below. We respond within 30 days.
10Security and Breach Notification
Data is encrypted in transit and at rest. Access is governed by role-based permissions, so staff see only what their role requires, and every consequential action is written to an audit trail. Details of our security posture are on our security page.
If a breach occurs that presents a real risk to the people affected, we will notify the ODPC within 72 hours of becoming aware of it, and notify the affected school without undue delay, as required by section 43 of the Act.
11Data Sovereignty
We believe in institution-owned data. We never sell student or institutional data to third parties, and we do not use your data for advertising. Your school retains full control over its records and can export them at any time, including on termination.
Contact and Complaints
For any privacy question, data-subject request, or to reach our data protection contact:
PayDesk (G3 Labs)
hello@paydesk.live
0748 938 887
Northern Bypass, Nairobi, Kenya
Office of the Data Protection Commissioner
If you are not satisfied with how we have handled your request, you may lodge a complaint with the ODPC at odpc.go.ke.
Changes to This Policy
We update this policy as the platform changes. The date at the top reflects the current version. Where a change materially affects how we handle personal data, we notify subscribing schools before it takes effect.