Summary (not a substitute for reading the full policy)
FundFlow collects only the data necessary to run your organisation's spend approval and reconciliation workflows. We do not sell your data. Financial records are retained for 7 years to satisfy Kenya tax and accounting obligations. You have the right to access, correct, and erase your personal data. Our servers are hosted in the European Union (Google Cloud — europe-west1).
1. Who We Are
ProSysInsights Ltd ("Company", "we", "us", or "our") is a limited company incorporated in Kenya. We operate FundFlow, a cloud-based financial governance and spend automation platform available at fundflow.co.ke and app.fundflow.co.ke.
For the purposes of the Kenya Data Protection Act 2019 (KDPA) and, where applicable, the EU General Data Protection Regulation (GDPR), ProSysInsights Ltd is the Data Controller of the personal data processed through FundFlow.
Data Protection contact: privacy@fundflow.co.ke
Postal address: ProSysInsights Ltd, Nairobi, Kenya
Supervisory authority: Office of the Data Protection Commissioner (ODPC), Kenya
2. Scope of This Policy
This Privacy Policy applies to:
- Visitors to fundflow.co.ke and related sub-domains;
- Users who create an account on, or access, the FundFlow application; and
- Employees, contractors, or representatives of organisations ("Subscribers") whose employer holds a FundFlow subscription.
It does not apply to third-party websites linked from our platform. We are not responsible for those sites' privacy practices.
3. Information We Collect
3.1 Information You Provide
| Category | Examples | Source |
|---|---|---|
| Account data | Full name, work email address, phone number, job title, role within FundFlow (requester, approver, finance, admin) | Registration / Subscriber admin |
| Organisation data | Company name, registered address, billing contact, department names | Subscription setup |
| Financial request data | Request amounts, currencies (KES/USD), item descriptions, cost categories, budget codes, supporting notes | Fund request submissions |
| Receipt & document data | Scanned receipts, invoice images, reconciliation attachments uploaded to support a request | Uploaded by users |
| Approval & audit data | Approval decisions, rejection reasons, approval timestamps, approver identity | Workflow actions |
| Communications | Support emails, demo request forms, in-app messages | Direct communications with us |
3.2 Information Collected Automatically
| Category | Examples |
|---|---|
| Usage data | Pages visited, features used, click events, session duration |
| Technical data | IP address, browser type and version, operating system, device type, time zone |
| Authentication logs | Login timestamps, failed login attempts, password reset requests |
3.3 Data We Do Not Collect
We do not collect: government identification numbers, biometric data, health data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, or sexual orientation. We do not store payment card data — billing is handled directly by our payment processor.
4. Legal Basis for Processing
Under KDPA Section 26 and GDPR Article 6, we rely on the following lawful bases:
| Processing purpose | Lawful basis (KDPA / GDPR) |
|---|---|
| Providing the FundFlow service under a subscription agreement | Performance of a contract (S.26(1)(b) / Art.6(1)(b)) |
| Sending transactional emails (approval notifications, receipts) | Performance of a contract (S.26(1)(b) / Art.6(1)(b)) |
| Maintaining financial audit trails and records | Compliance with a legal obligation — Kenya Companies Act, Income Tax Act (S.26(1)(c) / Art.6(1)(c)) |
| Detecting fraud, security incidents, abuse | Legitimate interests of the Company (S.26(1)(f) / Art.6(1)(f)) |
| Improving the platform through anonymised analytics | Legitimate interests of the Company (S.26(1)(f) / Art.6(1)(f)) |
| Sending marketing communications about new features | Consent (S.26(1)(a) / Art.6(1)(a)) — you may withdraw at any time |
5. How We Use Your Information
We use the data we collect to:
- Create and manage your user account and your organisation's workspace;
- Process, route, and record fund requests through your approval matrix;
- Deliver email notifications required by the workflow (e.g., approval requests, approver decisions, reconciliation prompts);
- Generate reports, CSV exports, and analytics dashboards within the platform;
- Provide customer support and respond to enquiries;
- Monitor platform security, investigate suspicious activity, and enforce our Terms of Service;
- Maintain legally required financial records;
- Improve and develop new FundFlow features using aggregated, anonymised usage data; and
- Send you product updates or feature announcements where you have consented.
We do not use personal data for automated decision-making that produces legal or similarly significant effects without human oversight.
6. Sharing and Disclosure
6.1 Sub-processors and Service Providers
We engage the following data processors who process personal data on our behalf under contractual obligations consistent with this policy:
| Sub-processor | Purpose | Location |
|---|---|---|
| Google LLC (Firebase Auth, Firestore, Firebase Storage, Firebase Hosting) | Authentication, database, file storage, static hosting | EU (europe-west1) / USA |
| Google LLC (Cloud Run) | Application server hosting | EU (europe-west1) |
| Google LLC (Gemini API) | AI-powered features (e.g., smart categorisation) | USA |
| SMTP2GO Pty Ltd | Transactional email delivery | Australia / Global CDN |
We do not sell, rent, or trade personal data to third parties for their own marketing purposes.
6.2 Within Your Organisation
FundFlow is a multi-user platform. Data you enter (fund requests, receipts, approval decisions) is visible to other authorised users within your organisation's workspace according to your organisation's configured role permissions. Organisation administrators control who has access to what within their workspace.
6.3 Legal Disclosures
We may disclose personal data when required by law, court order, or regulatory authority, including to the Kenya Revenue Authority (KRA), the ODPC, or a competent court. Where legally permissible, we will notify you before disclosure.
6.4 Business Transfers
If ProSysInsights Ltd is acquired, merged, or undergoes a change of ownership, personal data held by us may be transferred to the successor entity, subject to the same data protection obligations.
7. International Data Transfers
FundFlow's application servers and primary database are hosted in Google Cloud europe-west1 (Belgium) — within the European Economic Area. Firebase Authentication and some AI features involve processing in the United States through Google LLC's services.
Under KDPA Part V, transfers of personal data outside Kenya require adequate protection. We rely on the following mechanisms:
- Google Cloud / Firebase: Google LLC's Standard Contractual Clauses (SCCs) with the European Commission, supplemented by Google's data processing addendum, provide adequate safeguards for transfers to the EU and USA.
- SMTP2GO: Governed by a data processing agreement incorporating appropriate safeguards for cross-border transfer.
- Google Gemini API: Subject to Google's Cloud Data Processing Addendum.
You may request a copy of the applicable transfer safeguards by contacting privacy@fundflow.co.ke.
8. Data Retention
| Data type | Retention period | Reason |
|---|---|---|
| User account data | Duration of subscription + 12 months after account deletion | Dispute resolution, audit |
| Financial request records (amounts, approvals, reconciliation) | 7 years from the financial year of the transaction | Kenya Income Tax Act / Companies Act record-keeping obligation |
| Receipt and document uploads | 7 years from upload date | Same as above |
| Email communication logs | 12 months | Delivery troubleshooting |
| Authentication and security logs | 90 days | Security incident investigation |
| Anonymised analytics data | Indefinite (not personal data) | Platform improvement |
On expiry of the applicable retention period, data is securely deleted or irreversibly anonymised.
9. Your Rights
Under the Kenya Data Protection Act 2019 (Sections 34–38) and, where applicable, GDPR (Articles 15–22), you have the following rights:
| Right | What it means |
|---|---|
| Access | Request a copy of the personal data we hold about you. |
| Rectification | Request correction of inaccurate or incomplete personal data. |
| Erasure | Request deletion of your personal data where it is no longer necessary, consent is withdrawn, or processing is unlawful — subject to legal retention obligations. |
| Restriction | Request that we limit processing of your data in certain circumstances. |
| Data portability | Receive your personal data in a structured, machine-readable format and transfer it to another controller. |
| Object | Object to processing based on legitimate interests or for direct marketing purposes. |
| Withdraw consent | Withdraw consent at any time where processing relies on consent, without affecting the lawfulness of prior processing. |
| Complaint | Lodge a complaint with the ODPC (Kenya) or, for EEA residents, your local supervisory authority. |
To exercise any of these rights, submit a written request to privacy@fundflow.co.ke. We will respond within 21 days as required by the KDPA. Where requests are complex or numerous, we may extend this by a further 21 days with prior notice. We will not charge a fee for reasonable requests.
Note for Subscriber employees: If you use FundFlow as an employee of a Subscriber organisation, your organisation's administrator controls certain aspects of your data within the platform. For data held in your organisation's workspace, you should first contact your organisation administrator.
10. Security of Personal Data
We implement technical and organisational measures appropriate to the risk of processing, including:
- 256-bit TLS/SSL encryption for all data in transit;
- AES-256 encryption for data at rest in Google Cloud Firestore and Firebase Storage;
- Firebase Authentication with secure, hashed credential storage (Firebase does not expose raw passwords);
- Role-based access controls limiting data access to authorised users and processes;
- Firestore security rules enforcing tenant isolation (one organisation's data is never accessible to another);
- Regular security reviews and dependency audits.
In the event of a personal data breach that is likely to result in risk to the rights and freedoms of individuals, we will notify the ODPC within 72 hours of becoming aware, and affected individuals without undue delay, in accordance with KDPA Section 43 and GDPR Article 33.
11. Cookies and Tracking
The FundFlow marketing website (fundflow.co.ke) uses only technically necessary cookies for session management. It does not use third-party advertising or cross-site tracking cookies.
The FundFlow application (app.fundflow.co.ke) stores authentication tokens in browser local storage to maintain your session. It uses Firebase's IndexedDB-based offline persistence to cache data for offline access. These are not tracking technologies — they are functional requirements of the application.
We do not use cookies to profile you for advertising purposes.
12. Children's Privacy
FundFlow is a business-to-business platform intended for use by adults in an employment or professional capacity. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has provided us with personal data, contact privacy@fundflow.co.ke and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Services we offer. Where changes are material, we will notify Subscriber account administrators by email and post an updated effective date at the top of this page. Continued use of FundFlow after the effective date of a material change constitutes acceptance of the revised policy.
We encourage you to review this page periodically. The version in effect on the date you use FundFlow applies to the data collected on that date.
14. Contact and Complaints
For any questions about this policy or to exercise your data subject rights:
Email: privacy@fundflow.co.ke
General support: support@fundflow.co.ke
Website: fundflow.co.ke
If you are unsatisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC):
Office of the Data Protection Commissioner
www.odpc.go.ke
Email: info@odpc.go.ke
EEA residents may also contact their local EU supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu.