Privacy Policy

Your trust is fundamental to our business. This policy explains how MacraSMS handles personal data.

Last Updated: July 26, 2026

1. Introduction

MacraSMS ("we", "us", "our") is committed to protecting your privacy and ensuring transparency in how we handle personal data. This Privacy Policy applies to all users of our SMS platform, API services, website visitors, and business customers.

We are registered as a Data Controller with the Office of the Data Protection Commissioner (ODPC) under Registration Number [INSERT REG NUMBER]. For users outside Kenya, we also comply with applicable GDPR requirements where relevant.

By using MacraSMS services, you acknowledge that you have read and understood this policy. If you do not agree, please discontinue use immediately.

2. Information We Collect

We collect only the data necessary to provide our services and comply with legal obligations:

2.1 Account & Business Data

  • Business name, registration number, and KRA PIN
  • Contact person name, email address, and phone number
  • Billing information and payment transaction records
  • Sender ID applications and approval documentation

2.2 Technical & Usage Data

  • API keys, IP addresses, and access logs
  • Message metadata (sender, recipient, timestamp, delivery status)
  • Device information and browser type for dashboard access
  • Cookies and session identifiers for authentication

2.3 Message Content

Important: We process message content solely for transmission purposes. We do not store message content longer than necessary for delivery confirmation and dispute resolution (maximum 30 days). Content is encrypted in transit and at rest.

3. How We Use Your Data

Purpose Legal Basis Data Categories
Service Delivery Contract Performance Account, Technical, Message Metadata
Billing & Payments Contract + Legal Obligation Billing, Transaction Records
Security & Fraud Prevention Legitimate Interest Technical, Access Logs, IP Addresses
Regulatory Compliance Legal Obligation All Categories
Service Improvement Legitimate Interest Anonymized Usage Data
Marketing Communications Consent (Opt-In) Email, Phone Number

4. Data Sharing & Third Parties

We never sell personal data. We share data only when necessary:

  • Telecom Carriers: Safaricom, Airtel, Telkom for message delivery (contractual necessity)
  • Payment Processors: M-Pesa, banks, Stripe for billing (contractual necessity)
  • Cloud Infrastructure: Hosted on Kenyan-based servers with ISO 27001 certification
  • Legal Authorities: Only when required by court order or regulatory mandate
  • Service Providers: Email delivery, analytics (under strict DPAs and data processing agreements)

All third parties sign Data Processing Agreements compliant with Section 25 of the Data Protection Act, 2019.

5. Data Retention

Data Type Retention Period Rationale
Account Records Duration of account + 7 years Tax and audit requirements
Message Metadata 90 days Delivery verification and dispute resolution
Message Content 30 days maximum Transmission confirmation only
Access Logs 1 year Security monitoring and incident response
Consent Records Duration of relationship + 3 years Compliance evidence
Deleted Accounts 30 days grace period Recovery window before permanent deletion

6. Your Rights

Under the Data Protection Act, 2019, you have the following rights:

  • Right to Access: Request copies of your personal data we hold
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data (subject to legal retention requirements)
  • Right to Restrict Processing: Limit how we use your data in specific circumstances
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Opt out of processing based on legitimate interest or direct marketing
  • Right to Withdraw Consent: Revoke consent at any time without affecting prior lawful processing

To exercise these rights, contact our Data Protection Officer at dpo@macrasystems.com. We respond within 14 business days.

7. Security Measures

We implement industry-standard safeguards:

  • AES-256 encryption for data at rest
  • TLS 1.3 for all data in transit
  • Role-based access control with multi-factor authentication
  • Quarterly penetration testing and annual security audits
  • Automated anomaly detection and intrusion prevention systems
  • Staff trained annually on data protection and security protocols

In the event of a data breach affecting your rights, we will notify you and the ODPC within 72 hours as required by law.

8. International Transfers

All primary data storage occurs within Kenya. Any cross-border transfers (e.g., for carrier routing) are protected by:

  • Standard Contractual Clauses approved by the ODPC
  • Adequacy decisions where applicable
  • Explicit consent for specific transfers

9. Children's Data

Our services are not intended for individuals under 18. We do not knowingly collect data from minors. If you believe we have inadvertently collected such data, contact us immediately for deletion.

10. Cookies & Tracking

We use essential cookies for authentication and session management. Analytics cookies require your consent via our cookie banner. You can manage preferences through your browser settings or our cookie consent tool.

11. Policy Updates

We may update this policy to reflect legal changes or service improvements. Significant changes will be communicated via email and dashboard notification at least 30 days before implementation. Continued use after updates constitutes acceptance.

Data Protection Officer

For privacy inquiries, data subject requests, or complaints:

Email: dpo@macrasystems.com

Phone: +254 708 138 498

Address: Macra Systems Ltd, Nairobi, Kenya

You also have the right to lodge a complaint with the Office of the Data Protection Commissioner if unsatisfied with our response.