1. Introduction
MacraSMS ("we", "us", "our") is committed to protecting your privacy and ensuring transparency in how we handle personal data. This Privacy Policy applies to all users of our SMS platform, API services, website visitors, and business customers.
We are registered as a Data Controller with the Office of the Data Protection Commissioner (ODPC) under Registration Number [INSERT REG NUMBER]. For users outside Kenya, we also comply with applicable GDPR requirements where relevant.
By using MacraSMS services, you acknowledge that you have read and understood this policy. If you do not agree, please discontinue use immediately.
2. Information We Collect
We collect only the data necessary to provide our services and comply with legal obligations:
2.1 Account & Business Data
- Business name, registration number, and KRA PIN
- Contact person name, email address, and phone number
- Billing information and payment transaction records
- Sender ID applications and approval documentation
2.2 Technical & Usage Data
- API keys, IP addresses, and access logs
- Message metadata (sender, recipient, timestamp, delivery status)
- Device information and browser type for dashboard access
- Cookies and session identifiers for authentication
2.3 Message Content
Important: We process message content solely for transmission purposes. We do not store message content longer than necessary for delivery confirmation and dispute resolution (maximum 30 days). Content is encrypted in transit and at rest.
3. How We Use Your Data
| Purpose | Legal Basis | Data Categories |
|---|---|---|
| Service Delivery | Contract Performance | Account, Technical, Message Metadata |
| Billing & Payments | Contract + Legal Obligation | Billing, Transaction Records |
| Security & Fraud Prevention | Legitimate Interest | Technical, Access Logs, IP Addresses |
| Regulatory Compliance | Legal Obligation | All Categories |
| Service Improvement | Legitimate Interest | Anonymized Usage Data |
| Marketing Communications | Consent (Opt-In) | Email, Phone Number |
4. Data Sharing & Third Parties
We never sell personal data. We share data only when necessary:
- Telecom Carriers: Safaricom, Airtel, Telkom for message delivery (contractual necessity)
- Payment Processors: M-Pesa, banks, Stripe for billing (contractual necessity)
- Cloud Infrastructure: Hosted on Kenyan-based servers with ISO 27001 certification
- Legal Authorities: Only when required by court order or regulatory mandate
- Service Providers: Email delivery, analytics (under strict DPAs and data processing agreements)
All third parties sign Data Processing Agreements compliant with Section 25 of the Data Protection Act, 2019.
5. Data Retention
| Data Type | Retention Period | Rationale |
|---|---|---|
| Account Records | Duration of account + 7 years | Tax and audit requirements |
| Message Metadata | 90 days | Delivery verification and dispute resolution |
| Message Content | 30 days maximum | Transmission confirmation only |
| Access Logs | 1 year | Security monitoring and incident response |
| Consent Records | Duration of relationship + 3 years | Compliance evidence |
| Deleted Accounts | 30 days grace period | Recovery window before permanent deletion |
6. Your Rights
Under the Data Protection Act, 2019, you have the following rights:
- Right to Access: Request copies of your personal data we hold
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data (subject to legal retention requirements)
- Right to Restrict Processing: Limit how we use your data in specific circumstances
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Opt out of processing based on legitimate interest or direct marketing
- Right to Withdraw Consent: Revoke consent at any time without affecting prior lawful processing
To exercise these rights, contact our Data Protection Officer at dpo@macrasystems.com. We respond within 14 business days.
7. Security Measures
We implement industry-standard safeguards:
- AES-256 encryption for data at rest
- TLS 1.3 for all data in transit
- Role-based access control with multi-factor authentication
- Quarterly penetration testing and annual security audits
- Automated anomaly detection and intrusion prevention systems
- Staff trained annually on data protection and security protocols
In the event of a data breach affecting your rights, we will notify you and the ODPC within 72 hours as required by law.
8. International Transfers
All primary data storage occurs within Kenya. Any cross-border transfers (e.g., for carrier routing) are protected by:
- Standard Contractual Clauses approved by the ODPC
- Adequacy decisions where applicable
- Explicit consent for specific transfers
9. Children's Data
Our services are not intended for individuals under 18. We do not knowingly collect data from minors. If you believe we have inadvertently collected such data, contact us immediately for deletion.
10. Cookies & Tracking
We use essential cookies for authentication and session management. Analytics cookies require your consent via our cookie banner. You can manage preferences through your browser settings or our cookie consent tool.
11. Policy Updates
We may update this policy to reflect legal changes or service improvements. Significant changes will be communicated via email and dashboard notification at least 30 days before implementation. Continued use after updates constitutes acceptance.
Data Protection Officer
For privacy inquiries, data subject requests, or complaints:
Email: dpo@macrasystems.com
Phone: +254 708 138 498
Address: Macra Systems Ltd, Nairobi, Kenya
You also have the right to lodge a complaint with the Office of the Data Protection Commissioner if unsatisfied with our response.