Skip to content

Legal

Data Processing Agreement

Last updated: June 2, 2026 · Effective immediately upon use of the platform.

1

Definitions & Interpretation

In this Data Processing Agreement (“DPA”), the following terms shall have the meanings set out below:

  • “Controller” means the entity that determines the purposes and means of the Processing of Personal Data, as defined in the Kenya Data Protection Act, 2019 (“DPA 2019”).
  • “Data Subject” means an identified or identifiable natural person whose Personal Data is processed.
  • “Personal Data” means any information relating to a Data Subject by which that person can be identified, directly or indirectly, including but not limited to name, identification number, location data, online identifier, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
  • “Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, erasure, or destruction.
  • “Processor” means a natural or legal person, public authority, agency, or other body which Processes Personal Data on behalf of the Controller.
  • “Sub-processor” means a third-party Processor engaged by Javen to Process Personal Data on behalf of the Controller.
  • “Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed.
  • “Applicable Law” means the Kenya Data Protection Act, 2019 (No. 24 of 2019), the Data Protection (General) Regulations, 2021, and any other subordinate legislation or guidance issued by the Office of the Data Protection Commissioner (“ODPC”).
2

Parties & Scope

This DPA forms part of the Javen Terms & Conditions and any other agreement governing the use of the Javen platform (“Principal Agreement”) between Javen (“Processor”) and the platform user, whether an individual or an entity (“Controller”). It sets out the rights, obligations, and responsibilities of the parties concerning the Processing of Personal Data in connection with the escrow, trust scoring, dispute resolution, and related services provided by Javen.

This DPA applies exclusively to the Processing of Personal Data for which the Controller is a Data Controller and Javen acts as a Data Processor. Where Javen determines the purposes and means of Processing independently (e.g., for its own platform analytics, fraud detection, or legal compliance), Javen acts as a Controller in its own right, and such Processing is governed by the Javen Privacy Policy rather than this DPA.

3

Controller Obligations

The Controller represents, warrants, and undertakes that:

  • It has obtained all necessary consents and has a lawful basis under Applicable Law for the Processing of Personal Data that it instructs Javen to process.
  • It has provided, and will continue to provide, all required privacy notices to Data Subjects in compliance with Section 29 of the DPA 2019.
  • Its instructions to Javen regarding the Processing of Personal Data comply with Applicable Law.
  • It is responsible for the accuracy, quality, and lawfulness of the Personal Data provided to Javen.
  • It has implemented appropriate technical and organisational measures to protect the rights of Data Subjects.
4

Processor Obligations

Javen shall, as a Data Processor:

  • Process Personal Data only on documented instructions from the Controller, unless required to do otherwise by Applicable Law (in which case Javen shall inform the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest).
  • Ensure that persons authorised to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as appropriate: pseudonymisation and encryption of Personal Data; the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of Processing systems and services; the ability to restore the availability of and access to Personal Data in a timely manner in the event of a physical or technical incident; and a process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures.
  • Not engage another Processor without prior specific or general written authorisation of the Controller. In the case of general written authorisation, Javen shall inform the Controller of any intended changes concerning the addition or replacement of other Processors, thereby affording the Controller the opportunity to object to such changes.
  • Taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising the Data Subject’s rights under Applicable Law.
  • Assist the Controller in ensuring compliance with obligations relating to security of Processing, Data Breach notification, data protection impact assessments, and prior consultation with the ODPC, taking into account the nature of Processing and the information available to Javen.
  • At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services, and delete existing copies unless Applicable Law requires storage.
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
5

Data Processing Details

The subject matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are as follows:

5.1 Subject Matter

Provision of escrow services, J-Score reputation system, dispute resolution, identity verification (KYC/KYB), and related platform services.

5.2 Duration

The duration of Processing shall be the term of the Principal Agreement, plus a retention period of up to six (6) years following termination or expiry, or such longer period as required by Applicable Law, for compliance, audit, and legal defence purposes.

5.3 Nature & Purpose

Processing is carried out for the following purposes: facilitation of escrow transactions between buyers and sellers; calculation and maintenance of J-Score trust and reputation metrics; identity verification (KYC) for compliance with anti-money laundering and counter-terrorism financing obligations; Know Your Business (KYB) verification for platform accounts; dispute resolution and mediation; communication of transaction updates; fraud detection and prevention; compliance with legal and regulatory obligations; platform analytics and service improvement; and provision of customer support.

5.4 Types of Personal Data

The following categories of Personal Data may be processed: full name; username; email address; phone number (M-Pesa/Airtel Money); postal or physical address; government-issued identification numbers (National ID, Passport, KRA PIN, Business Registration Number); date of birth; gender; transaction history and escrow activity; J-Score and trust metrics; dispute and mediation records; device and browser information; IP address; location data; communication content (chat messages, dispute evidence); payment information (M-Pesa transaction IDs, bank account details for payouts); and KYC/KYB documentation (images of identity documents, business certificates, utility bills).

5.5 Categories of Data Subjects

Buyers and sellers using the Javen platform; platform account owners and their team members; mediators and dispute resolution participants; and any individual whose Personal Data is provided to Javen in connection with a transaction or platform service.

6

Data Subject Rights

The Controller is responsible for responding to requests from Data Subjects exercising their rights under the DPA 2019, including rights of access, rectification, erasure (“right to be forgotten”), restriction of Processing, data portability, and objection. Javen shall assist the Controller in fulfilling these obligations by:

  • Providing the Controller with self-service tools to access, rectify, or delete Personal Data through the platform dashboard.
  • Responding to any request received directly from a Data Subject by referring the Data Subject to the Controller and, where appropriate, cooperating with the Controller to address the request.
  • Implementing technical measures to facilitate the Controller’s compliance with Data Subject requests, including the ability to export and delete account data.
  • Complying with any legally binding request for disclosure of Personal Data from the ODPC, law enforcement, or other governmental authority, in accordance with Section 45 of the DPA 2019.

Javen shall notify the Controller promptly (and in any event within 48 hours) if it receives a request from a Data Subject in respect of their Personal Data, and shall not respond to such request without the Controller’s prior written authorisation, except where required by Applicable Law.

7

Sub-processing

The Controller provides general written authorisation to Javen to engage Sub-processors to Process Personal Data on behalf of the Controller. Javen currently engages the following Sub-processors:

  • Safaricom PLC (M-Pesa): Payment processing, B2C disbursements, and mobile money services. Data processed includes phone numbers, transaction IDs, and amounts. Safaricom is a data Controller in its own right with respect to M-Pesa services.
  • Airtel Money: Alternative mobile money payment processing. Data processed includes phone numbers and transaction identifiers.
  • Cloud Infrastructure Providers: Cloud hosting, storage, and database services. Data may be stored on servers located in the following regions: Kenya, European Union, and United States. Current providers include Hetzner and AWS.
  • Email Service Providers: Transactional email delivery for notifications, verification, and support communications.
  • SMS Providers: Delivery of SMS notifications and one-time passwords (OTPs).

Javen shall notify the Controller of any intended changes to Sub-processors at least 14 days before engagement, including by updating the list on its website. The Controller may object to a new Sub-processor within 7 days of notification. If the objection cannot be resolved within a further 14 days, either party may terminate the affected service without penalty.

Javen shall impose, by way of a written contract, the same data protection obligations on each Sub-processor as are imposed on Javen under this DPA, and shall remain fully liable to the Controller for any failure by a Sub-processor to fulfil its data protection obligations.

8

International Data Transfers

The Controller acknowledges that the Processing of Personal Data under this DPA may involve the transfer of Personal Data to countries outside Kenya. Where such transfers occur, Javen shall ensure that appropriate safeguards are in place in compliance with Section 48 of the DPA 2019 and the Data Protection (Transfers of Personal Data to Third Countries) Regulations, 2021.

Such safeguards may include: (a) the existence of an adequacy decision by the ODPC with respect to the recipient country; (b) the use of Standard Contractual Clauses (“SCCs”) approved by the ODPC or equivalent regulatory authority; (c) binding corporate rules (“BCRs”) approved by the ODPC; or (d) the Data Subject’s explicit consent after being informed of the possible risks of such transfers.

The Controller may request a copy of the relevant safeguards at any time by contacting Javen. Javen shall provide such copies (redacted as necessary to protect confidential information) within a reasonable time frame.

9

Security Measures

Javen shall implement and maintain appropriate technical and organisational security measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, but are not limited to:

  • Encryption of Personal Data in transit using TLS 1.2+ and at rest using AES-256.
  • Pseudonymisation and anonymisation of Personal Data where practicable for analytics and reporting.
  • Role-based access controls with least-privilege principles, multi-factor authentication for administrative access, and regular access reviews.
  • Regular security assessments, penetration testing, and vulnerability scanning by qualified third parties at least annually.
  • Staff training on data protection and information security upon onboarding and annually thereafter.
  • Written incident response plan covering Data Breach detection, containment, investigation, notification, and remediation.
  • Physical security controls at data centre facilities including access controls, surveillance, and environmental protections.
  • Automated backup procedures with encrypted off-site storage and regular restoration testing.
  • Data minimisation and retention policies ensuring Personal Data is not kept longer than necessary.
  • Vendor risk assessment and due diligence for all Sub-processors and third-party service providers.

Javen regularly reviews and updates its security measures to reflect technological developments and evolving threats. Upon the Controller’s reasonable request (not more than once per calendar year), Javen shall provide a summary of its SOC 2, ISO 27001, or equivalent certification or audit report, subject to confidentiality obligations.

10

Data Breach Notification

Javen shall notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of a Data Breach affecting Personal Data processed on behalf of the Controller. The notification shall include, to the extent available:

  • A description of the nature of the Data Breach including, where possible, the categories and approximate number of Data Subjects and Personal Data records concerned.
  • The name and contact details of Javen’s data protection officer or other contact point from whom more information can be obtained.
  • A description of the likely consequences of the Data Breach.
  • A description of the measures taken or proposed to be taken by Javen to address the Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

Javen shall cooperate fully with the Controller in investigating the Data Breach and in notifying the ODPC and affected Data Subjects, as required by Sections 43 and 44 of the DPA 2019. Javen shall document all Data Breaches, including the facts, effects, and remedial actions taken, and shall make that documentation available to the Controller and the ODPC upon request.

11

Data Protection Impact Assessment & Prior Consultation

Javen shall assist the Controller in conducting Data Protection Impact Assessments (“DPIAs”) where the Controller determines that Processing is likely to result in a high risk to the rights and freedoms of Data Subjects, as required by Section 41 of the DPA 2019. Such assistance shall include:

  • Describing the Processing operations and the purposes of Processing.
  • Assessing the necessity and proportionality of the Processing operations.
  • Assessing the risks to the rights and freedoms of Data Subjects.
  • Identifying measures to address the identified risks, including safeguards, security measures, and mechanisms to ensure the protection of Personal Data.

Where a DPIA indicates that the Processing would result in a high risk that cannot be mitigated, and where the ODPC requires prior consultation under Section 42 of the DPA 2019, Javen shall assist the Controller in consulting the ODPC prior to the commencement of Processing.

12

Audit Rights

Upon the Controller’s reasonable request (not more than once per calendar year, unless a Data Breach or material non-compliance has occurred), Javen shall make available to the Controller all information necessary to demonstrate compliance with this DPA. The Controller, or an independent third-party auditor appointed by the Controller (subject to Javen’s reasonable approval, not to be unreasonably withheld), may conduct an audit of Javen’s data processing activities, including on-site inspections, provided that:

  • The Controller provides at least 30 days’ prior written notice.
  • The audit is conducted during Javen’s normal business hours and does not unreasonably interfere with Javen’s operations.
  • The Controller and any third-party auditor enter into a confidentiality agreement acceptable to Javen.
  • The Controller bears all costs of the audit, including Javen’s reasonable costs for providing access and support.
  • The scope of the audit is limited to matters directly relevant to compliance with this DPA and Applicable Law.

If an independent third-party auditor is used, Javen reserves the right to object to any auditor that is, in Javen’s reasonable opinion, a competitor of Javen or otherwise not suitably qualified or independent. Javen may satisfy its obligations under this clause by providing a copy of a current SOC 2 Type II report, ISO 27001 certificate, or equivalent independent audit report, subject to confidentiality obligations.

13

Records of Processing Activities

Each party shall maintain a written record of all categories of Processing activities carried out on behalf of the Controller, as required by Section 38 of the DPA 2019 and Regulation 20 of the Data Protection (General) Regulations, 2021. Such records shall contain:

  • The name and contact details of the party and, where applicable, its representative and data protection officer.
  • The purposes of the Processing.
  • A description of the categories of Data Subjects and categories of Personal Data.
  • The categories of recipients to whom Personal Data has been or will be disclosed, including recipients in third countries or international organisations.
  • Where applicable, transfers of Personal Data to a third country and the documentation of suitable safeguards.
  • A general description of the technical and organisational security measures implemented.
  • The expected retention periods for each category of Personal Data.

Each party shall make its records available to the ODPC upon request.

14

Liability & Indemnification

Each party shall be liable to the other for any damage caused by Processing that is carried out in breach of this DPA or Applicable Law. The liability of Javen shall be limited as set out in the Limitation of Liability section of the Javen Terms & Conditions, provided that nothing in this DPA limits or excludes the liability of either party for:

  • Death or personal injury caused by its negligence.
  • Fraud or fraudulent misrepresentation.
  • Breach of its obligations under Sections 41 (data protection principles), 42 (data subject rights), or 43 (security) of the DPA 2019.
  • Any liability that cannot be excluded or limited by Applicable Law.

The Controller agrees to indemnify and hold harmless Javen from and against any and all claims, liabilities, damages, losses, costs, and expenses arising out of or relating to the Controller’s breach of its obligations under this DPA or Applicable Law, including where such breach results in a claim against Javen by a Data Subject, the ODPC, or any other regulatory authority.

15

Term & Termination

This DPA shall commence on the date the Controller accepts the DPA (by clicking to accept, registering a platform account, or otherwise indicating acceptance) and shall continue in full force and effect until the termination or expiry of the Principal Agreement.

Upon termination of the Principal Agreement, Javen shall, at the Controller’s instruction, delete or return all Personal Data processed under this DPA within 30 days, except where Javen is required by Applicable Law to retain some or all of the Personal Data. If return or deletion is not feasible (e.g., where Personal Data is stored in backup archives), Javen shall continue to protect such Personal Data in accordance with this DPA until deletion is possible.

The obligations of confidentiality, audit, records retention, and liability shall survive termination of this DPA.

16

Governing Law & Dispute Resolution

This DPA is governed by the laws of the Republic of Kenya. Any dispute arising out of or in connection with this DPA shall first be referred to the Office of the Data Protection Commissioner for mediation or alternative dispute resolution, in accordance with Section 55 of the DPA 2019. If the dispute is not resolved within 60 days of referral, either party may submit the dispute to the exclusive jurisdiction of the courts of Kenya.

17

Contact & Data Protection Officer

Javen has appointed a Data Protection Officer (“DPO”) who can be contacted regarding all matters relating to the Processing of Personal Data and the exercise of rights under Applicable Law. The DPO may be reached at:

Data Protection Officer

Javen Technologies

P.O. Box 12345-00100

Nairobi, Kenya

Email: dpo@javen.co.ke

Or via our Contact page.

Data Subjects who wish to make a complaint about the Processing of their Personal Data should contact the Javen DPO in the first instance. Data Subjects have the right to lodge a complaint with the Office of the Data Protection Commissioner at any time. The ODPC can be reached at:

Office of the Data Protection Commissioner

P.O. Box 50681-00200

Nairobi, Kenya

Website: www.odpc.go.ke

Email: complaints@odpc.go.ke