Dates
Last updated: [date of publication]. Effective from: [date].
1. Who we are
Veniate is the affiliate programme of [Denri Africa Limited] (“Denri Africa”, “we”, “us”), a company registered in Kenya with its principal office at [registered address]. Denri Africa operates the online store at denriafricastores.com and Denri Africa retail stores, and is the data controller for the personal data described in this policy.
Questions about this policy or your data: partners@denriafrica.co.ke, or write to [postal address]. [Data Protection Officer / privacy contact name, if designated.]
This policy covers people who apply to or take part in the Veniate programme (“partners”), visitors to the partner portal, and — in a limited way described in Section 4 — customers whose purchases are attributed to a partner. It does not replace the denriafricastores.com store privacy policy, which continues to govern shopping on the store.
2. Personal data we collect
2.1 Data you give us
| When | What |
|---|---|
| Application | Full name, email address, M-Pesa phone number, social media platform(s) and handle(s), stated audience size, your promotion plan, and the version of the programme terms you accepted. |
| Identity verification (before first payout) | Kenyan national ID number and KRA PIN. We do not collect or store ID photographs or document scans. |
| Profile | Changes to the above, email-notification and leaderboard preferences. |
| Support | The content of tickets and messages you send us, and any files you attach. |
| Campaign participation | Which campaigns you join and any campaign-specific codes issued to you. |
2.2 Data we generate or observe
| Category | Details |
|---|---|
| Account and programme data | Your promo code, partner status, tier, join date, and the identifiers our systems assign to you in our store and point-of-sale platforms. |
| Share-link clicks | Timestamp, campaign and channel, the referring page, browser user-agent string, and a one-way hash of the visitor’s IP address. We do not store the IP address itself and cannot reverse the hash. |
| Sales and commissions | Attributed orders (with order numbers partly masked), order dates and values, eligible subtotals, commission amounts and status, adjustments, and refund or cancellation events. |
| Payouts | Withdrawal requests, payout amounts, M-Pesa transaction receipts, transaction charges, and failure reasons. |
| Integrity signals | Automated flags for suspected self-referral, coupon-site leakage or unusual redemption velocity, and the outcome of any review. |
| Sign-in and security | Sign-in timestamps, one-time-code delivery records, and session cookies. |
| Audit log | A record of actions taken on your account by you or by Denri Africa staff, for accountability. |
| Portal analytics | If enabled, Google Analytics 4 collects aggregated usage of the portal (pages viewed, device type, approximate location). No analytics cookie is set unless the tag is active. |
2.3 Data about customers
When an order is attributed to a partner, we receive the order from our store or point-of-sale system. To detect self-referral we compare the customer’s email address and phone number on the order against the partner’s own registered details. The comparison result is stored as a flag; the customer’s contact details are not shown to partners and are not used for any other purpose within Veniate.
3. Why we use your data and our legal basis
| Purpose | Legal basis (DPA 2019, s.30) |
|---|---|
| Reviewing your application and deciding whether to admit you | Steps at your request prior to entering a contract |
| Running your account: issuing codes, tracking clicks and sales, calculating commission, running campaigns | Performance of our contract with you (the programme terms) |
| Verifying your identity before payouts and paying you via M-Pesa | Performance of contract; legal obligation (anti-fraud, tax record-keeping) |
| Keeping tax and accounting records | Legal obligation |
| Detecting and preventing fraud, self-referral and terms breaches | Legitimate interests (protecting the programme and other partners); performance of contract |
| Sending programme emails: approval, sales, payouts, terms changes | Performance of contract |
| Optional notifications and the public leaderboard | Your consent — you can withdraw it in your profile at any time |
| Support and dispute handling | Performance of contract; legitimate interests |
| Portal analytics and error monitoring | Legitimate interests (keeping the portal working and improving it) |
We do not sell personal data, and we do not use your data for automated decisions that have legal or similarly significant effects on you without human review. Integrity flags are reviewed by a person before any commission is cancelled or an account suspended.
6. How long we keep data
| Data | Retention |
|---|---|
| Declined applications | [12] months from decision, then deleted |
| Account, sales, commission and payout records | Life of your account plus [7] years, to satisfy tax and accounting law |
| National ID number and KRA PIN | Life of your account plus the period required for tax records, then deleted |
| Share-link click logs (hashed IP, user agent) | [12] months, then aggregated or deleted |
| Support tickets and attachments | [24] months after closure, then deleted |
| Audit log | [7] years |
| Sign-in and security logs | [90] days |
When you close your account, we first settle any payable balance, then delete or anonymise data that we are not required to keep.
7. How we protect data
We use encryption in transit and at rest, role-based access so staff only see what their job requires, short-lived signed links for any support attachments, hashing of IP addresses at the point of collection, masking of order numbers shown to partners, and an audit log of administrative actions. We deliberately do not collect ID document images, which limits the impact of any incident. If a breach is likely to cause real risk to you, we will notify the ODPC within 72 hours and inform you without undue delay, as the Act requires.
8. Your rights
Under the Data Protection Act you have the right to:
- be told how your data is used (this policy);
- access a copy of the personal data we hold about you;
- have inaccurate or incomplete data corrected — most details can be edited in your profile;
- object to processing, or ask us to restrict it, in certain circumstances;
- ask for deletion of data we are not legally required to keep;
- withdraw consent for optional processing (leaderboard, optional notifications) at any time;
- receive your data in a portable, machine-readable format;
- not be subject to purely automated decisions with significant effects.
To exercise any right, email partners@denriafrica.co.ke from your registered address. We respond within the time limits set by the Act (generally within [7 / 30] days) and may ask you to confirm your identity first. If you are not satisfied, you may complain to the Office of the Data Protection Commissioner (odpc.go.ke).
9. International transfers
Some of our service providers store or process data outside Kenya, including in the United States and the European Union. Where this happens we rely on the transfer being necessary to perform our contract with you and/or on contractual safeguards with the provider that meet the requirements of sections 48–49 of the Act. [List each provider’s hosting region once confirmed.]
10. Children
The programme is open to adults only. We do not knowingly collect data from anyone under 18, and we will close any account we discover belongs to a minor.
11. Changes to this policy
We may update this policy as the programme develops — for example if we introduce tax withholding, expand beyond Kenya, or add a new identity-verification provider. Material changes will be emailed to partners at least [14] days before they take effect, and the “last updated” date above will change.
12. Contact
[Denri Africa Limited] · [registered address] · partners@denriafrica.co.ke · denriafricastores.com