privacy.

This policy is issued in compliance with the Data Protection Act, No. 24 of 2019, and the Data Protection (General) Regulations, 2021.

who we are.

Duara is a mobile application that helps groups — chamas, family investment clubs, estate associations, and savings circles — coordinate their shared finances, governance, and communication.

Duara is built and operated by Pluribus Tech Limited, based in Kenya. Our mission is to provide secure, resilient infrastructure for community-led financial growth.

When we say "Duara," "we," "us," or "our" in this policy, we mean Pluribus Tech Limited, the team behind the app. When we say "you," we mean you as an individual user. When we say "your group," we mean the savings circle or community you belong to on Duara. We take your privacy seriously.

our principles.

Everything in this policy is built around the core principles set out in Kenya's Data Protection Act:

01.

Lawfulness, fairness and transparency — we tell you what we do with your data and why.

02.

Purpose limitation — we only use your data for the purposes described in this policy.

03.

Data minimisation — we only collect what we actually need to run Duara.

04.

Accuracy — we keep your data accurate and let you correct it at any time.

05.

Storage limitation — we don't keep your data longer than necessary (see Data Retention below).

06.

Integrity and confidentiality — we protect your data with the security measures described below.

07.

Accountability — we take responsibility for demonstrating our compliance with these principles.

data collection.

personal identification

When you register, we collect your phone number, email and name. This is essential to authenticate your identity and facilitate trust within your private circles.

financial data

We track group contributions, withdrawals, and balances. This data is only visible to authorized members of your specific group. This includes contribution amounts, loan requests, loan repayments, withdrawal requests, fine records, and pool balances.

group content

Chat messages, votes, proposals, meeting agendas, and any documents your group generates — constitutions, loan agreements, financial reports, meeting minutes — are stored securely and visible only within your group. Financial reports are only visible to the user that created them.

device & usage data

We collect device type, operating system version, and a unique device identifier for push notification delivery. We also collect usage data — which features you use, when you use them, and how often — to help us improve the app.

what we do not collect

We do not collect your M-Pesa PIN, bank account credentials, or any payment authentication secrets. We do not run advertising on Duara and we do not build advertising profiles on our users. We do not sell your data to third parties.

if you don't provide this data

Some data is required for Duara to function — without it, we cannot deliver the corresponding part of the service:

01.

Phone number, email and name at registration — without these, we cannot create or verify your account.

02.

Financial data tied to a specific action (a contribution, loan request, or fine payment) — without it, that transaction cannot be recorded in your group's official records.

03.

Device information — this is optional; declining device permissions only means you won't receive push notifications, and doesn't affect any other feature.

how we use it.

We use your data only to deliver and improve the service you signed up for. We do not use your data to serve you advertisements. We do not use your data to train AI models. For each purpose below, we rely on a specific legal basis recognised under the Data Protection Act.

Purpose Data used Legal basis
Creating and managing your accountName, phone number, emailPerformance of a contract
Delivering group chat and financial coordinationMessages, votes, transaction recordsPerformance of a contract
Sending you group notificationsDevice push token, group activityPerformance of a contract
Generating tamper-proof group documentsAll group financial and governance recordsPerformance of a contract
Processing Duara Records subscriptionsPayment details, account identityPerformance of a contract; legal obligation (financial record-keeping)
Improving and debugging the appUsage data, device informationLegitimate interest
Complying with applicable lawAny data required by Kenyan lawLegal obligation

governance.

We believe in "privacy by design." Your data is not our product.

Your data is stored on Supabase infrastructure with servers located in secure, access-controlled data centres. All data in transit is encrypted using TLS. Sensitive records are stored encrypted at rest. Group financial documents generated by Duara are cryptographically hashed at the time of creation — this hash serves as a tamper-proof fingerprint, allowing any party to verify a document has not been altered, directly in the app.

encryption

All data transmissions are secured with TLS (Transport Layer Security). Sensitive records are stored encrypted at rest.

zero-access

Only authorized users can access data in the system, by utilizing our Role Based Security system.

cryptographic proof

Documents generated by Duara are hashed at creation. Any alteration is mathematically detectable.

no data selling

We do not grant third parties access to your personal data except as strictly described in this policy. Ever.

data sharing.

within your group

The nature of Duara is that your group members can see shared financial records, votes, documents and governance decisions that belong to the group. Your name, contributions, and group activity are visible to other members of the same group. You agree to this when you join a group.

service providers

We use a small number of trusted third-party services — Supabase (database and file storage), Firebase / Google FCM (push notification delivery), and payment processors (for Duara Records subscription billing). These providers access only the data necessary to perform their specific function, are bound by written data processing agreements, and are contractually prohibited from using your data for their own purposes.

legal requirements

We may disclose your information if required to do so by a court order, government authority, or applicable Kenyan law. We will notify you of such a request where legally permitted to do so.

We do not sell your data.

cross-border transfers.

Our infrastructure provider, Supabase, may store and process your data on servers located outside Kenya, including in Ireland. Where your data is transferred outside Kenya, we only do so where:

01.

the destination country or organisation has data protection safeguards essentially equivalent to those required under Kenyan law, or appropriate contractual safeguards are in place with our provider; and

02.

the transfer is necessary to deliver the service you signed up for.

Where sensitive personal data is involved, we will additionally seek your express consent before any such transfer. You can contact us at any time for more detail on the safeguards that apply to your specific data.

data retention.

We retain your personal data for as long as your account is active. If you delete your account, we will delete your personal profile data within 30 days.

Group financial records that involve your activity may be retained for a longer period as part of the group's audit trail, which other members have a legitimate interest in preserving.

Cryptographic hash records for generated documents are retained indefinitely as they contain no personal information — they are fingerprints, not content.

breach notification.

If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it, as required by law. Where the breach poses a significant risk to you personally, we will also notify you directly and share steps you can take to protect yourself.

your rights.

Under the Data Protection Act, you have the following rights over your data. Unless noted otherwise, you can exercise any of them by contacting us using the details in "Contact Us" below.

01.

Right to be informed — clear information about how we collect, use, and protect your data — that's what this policy is for. Always available in the app and on our website · Ongoing

02.

Right of access — ask for confirmation of what personal data we hold about you and a copy of it. Contact us · 7 days

03.

Right to rectification — ask us to correct inaccurate or incomplete data in your profile. Contact us with details · 14 days

04.

Right to erasure — ask us to "be forgotten." We'll scrub your personal identifiers, though group transaction logs may persist to maintain treasury integrity. Contact us · 14 days

05.

Right to restriction — ask us to pause processing of your data while a dispute about its accuracy or lawfulness is resolved. Contact us specifying the grounds · 14 days

06.

Right to data portability — receive your personal data in a structured, commonly used format to transfer elsewhere. Contact us specifying the format · 30 days

07.

Right to object — object to processing that isn't required to deliver the service, including any direct marketing. Contact us, or use the unsubscribe link on marketing messages · 7 days for marketing, 14 days otherwise

08.

Rights around automated decision-making — request human review of any decision made about you based solely on automated processing. (We don't currently use automated decision-making — see below.) Contact us · Promptly

You may also withdraw consent to any non-essential processing at any time, without affecting the lawfulness of processing carried out before withdrawal.

automated decisions.

We do not currently use your personal data to make decisions about you based solely on automated processing that would produce legal or similarly significant effects — for example, loan requests on Duara are decided by your group's own members through voting, not by an algorithm. If this changes in future, we will update this policy, notify you, and give you a way to request human review of any such decision.

complaints.

If you're unhappy with how we've handled your personal data, contact us first at the details below and we'll investigate and respond within 14 days.

If you remain dissatisfied with our response — or you'd prefer to go directly to the regulator — you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC):

01.

Online — www.odpc.go.ke or odpc.go.ke/file-a-complaint

02.

Email — complaint@odpc.go.ke

03.

Address — Britam Towers, 12th Floor, Hospital Road, Upper Hill, Nairobi, Kenya

children.

Duara is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has created an account, please contact us and we will delete the account promptly.

changes.

We may update this policy from time to time as the app evolves. When we make material changes, we will notify you in the app and update the "Last updated" date at the top of this page. Continued use of Duara after a change takes effect constitutes your acceptance of the revised policy.

Last updated: July 2026  ·  Effective date: July 2026

questions?

For any questions about this policy, or to exercise any of the rights described above, contact Pluribus Tech Limited. We aim to acknowledge all privacy-related enquiries within 2 business days.

Nairobi, Kenya