Legal

Griot Privacy Policy

Effective date: 2 July 2026

This Privacy Policy explains how Griot Data Technologies Limited (“Griot Data”, “we”, “us”) collects, uses, discloses, and protects personal data in connection with the Griot Duka mobile application (“the App”). Griot Data is the data controller for the purposes of the Kenya Data Protection Act, 2019.

1. Scope

This Policy applies to merchants who register for and use the App. It does not apply to third-party services that we reference but do not operate.

2. Data we collect

We collect the following categories of personal data:

3. How we use your data, and legal basis

We use your data to:

4. Market insights

The App is provided free of charge. Griot Data produces aggregated market insights for manufacturers, brands, distributors, and other suppliers.

  1. Insights are derived from sales activity, namely products, quantities, prices, general area, and dates.
  2. Insights are aggregated across multiple shops and are subject to differential-privacy techniques, such that no individual shop, merchant, or person is identifiable.
  3. We do not sell your personal data. We do not sell or disclose your shop’s precise location. Location is used only in aggregated, de-identified form to indicate area-level trends.
  4. Your account data, and your customers’ names and notes, are excluded from Insights. Data extracted from M-Pesa confirmations is used only to match payments to sales and is excluded from Insights.
  5. You may withdraw consent to the use of your data for Insights at any time in the App’s Settings, without affecting your continued use of the App.

5. Disclosure and sharing

We disclose personal data only as follows:

We do not otherwise sell or share your personal data with third parties for their own purposes. The market insights described in Section 4 are aggregated and de-identified and do not constitute personal data.

6. Data security

Personal data is stored on your device as an append-only, cryptographically signed record. Where cloud backup is enabled, records are transmitted to Google Firebase over an encrypted (HTTPS) connection. Your shop name, telephone number, and your customers’ names and notes are encrypted on your device, using Griot Data’s public key, before transmission, and can be decrypted only by Griot Data.

7. International transfers

Cloud infrastructure provided by Google may store data on servers located outside Kenya. Where personal data is transferred outside Kenya, we take steps to ensure an appropriate level of protection as required by the Kenya Data Protection Act, 2019.

8. Data retention

We retain your personal data for as long as your account remains active. Following a valid deletion request, we delete your personal data and cloud backup within thirty (30) days, except where retention is required by law. Insights already produced in aggregated and de-identified form do not identify you and are not affected.

9. Your rights

Under the Kenya Data Protection Act, 2019, you have the right to access, correct, and delete your personal data, to object to or restrict its processing, to data portability, and to withdraw consent. To exercise these rights, contact us using the details in Section 12.

10. Account and data deletion

You may delete your account and associated data at any time:

Deletion removes your account, your on-device records, and your cloud backup, subject to the retention exceptions in Section 8.

11. Children

The App is intended for business use by shop operators and is not directed to children.

12. Changes and contact

We may update this Policy from time to time and will revise the effective date above. Where appropriate, we will notify material changes in the App.

Data controller: Griot Data Technologies Limited, Nairobi, Kenya.

Contact: brackly@griotdata.com