For the purposes of the Kenya Data Protection Act, 2019, the data controller responsible for your personal data collected through DENI – Loan Manager is:
As data controller, Wendy Digital determines the purposes and means of processing your personal data and is accountable for ensuring that processing is lawful, fair, and transparent under the DPA 2019.
DENI collects a minimal, purposeful set of personal data. We do not collect more data than necessary to operate the Service. The categories below cover everything we may hold about you:
| Category | Specific Data Points | Source |
|---|---|---|
| Account Data | Google display name, email address, Google profile photo URL, Firebase User ID (UID) | Google Sign-In via Firebase Authentication |
| Loan Record Data | Loan name, principal amount, interest rate, start date, loan term, lender type, lender name, current balance, notes, payment dates, payment amounts, repayment progress | Manually entered by you in-app |
| Borrower Data | Borrower names and notes you optionally associate with Loan Records | Manually entered by you in-app |
| Premium Billing Data | Phone number (for M-Pesa STK push), IntaSend transaction reference, payment confirmation status (success / failure) | IntaSend checkout |
| Technical & Device Data | Firebase installation ID, app version, Android OS version, device model | Firebase SDK (collected automatically) |
| Crash & Diagnostic Data | Stack traces, app state at time of crash. No Loan Record content is included in crash reports. | Firebase Crashlytics (collected automatically) |
DENI does not access, read, or transmit: your device address book, SMS messages, call history, precise or approximate location, device camera or microphone, photos or media files, your mobile phone number (except optionally at IntaSend checkout), or any data not described in Section 2.
We process your personal data only for specific, explicit, and legitimate purposes:
| Purpose | Data Used |
|---|---|
| User authentication and account management | Google account data (name, email, UID) via Firebase Auth |
| Storing and displaying your Loan Records on-device | All Loan Record data (local SQLCipher database) |
| Calculating amortisation schedules and repayment plans | Loan principal, interest rate, term, and payment history |
| Syncing your Loan Records across your devices | All Loan Record data (Firebase Firestore — optional) |
| Sending on-device payment reminder notifications | Payment due dates derived from Loan Records (processed locally only — no data leaves your device for this purpose) |
| Processing your Premium subscription payment | Phone number and transaction reference (via IntaSend) |
| Verifying and activating your Premium status | IntaSend payment confirmation, Firebase UID |
| App stability monitoring and bug fixing | Crash reports, device and OS version |
| Responding to support or data-rights requests | Account data and any information you include in your message to us |
We do not use your personal data for advertising, behavioural profiling, or any purpose not listed in this table, without obtaining your explicit prior consent.
Under Section 30 of the Kenya Data Protection Act, 2019, we rely on the following legal grounds to process your personal data:
You provide consent when you sign in with Google (account data), enable cloud sync (Loan Record data to Firestore), and initiate a Premium purchase (billing data via IntaSend). You may withdraw consent at any time — see Section 11 for how. Note that withdrawing consent for cloud sync will stop future synchronisation but will not automatically delete data already in Firestore; you must delete your account for that.
Processing is necessary to provide you with the loan tracking, repayment scheduling, and Premium features as agreed under our Terms & Conditions. Without this processing, we cannot deliver the Service.
We process crash reports and technical diagnostics to maintain app stability and security. These legitimate interests are balanced against your rights and do not override them. You may object to processing on this basis by contacting our DPO.
DENI uses Google Firebase as its cloud infrastructure. The following Firebase services are active in the App:
| Firebase Service | Purpose in DENI | Data Transmitted |
|---|---|---|
| Firebase Authentication | Secure user sign-in and session management via Google Sign-In | Google account name, email, UID |
| Firebase Firestore | Optional cloud storage and multi-device sync of Loan Records | All Loan Record data (only when sync is enabled) |
| Firebase Crashlytics | Automated crash and error reporting for app stability | Stack traces, device/OS info — no Loan Record content |
Firebase is operated by Google LLC and data may be processed on Google's global server infrastructure. Google's processing is governed by the Firebase Privacy and Security documentation, which incorporates Standard Contractual Clauses for international data transfers.
Firestore Security Rules: We enforce Firebase Security Rules that restrict each authenticated user to reading and writing only their own Loan Records. No Wendy Digital employee has routine access to your Firestore data; access is logged and audited by Firebase.
DENI Premium payments are processed by IntaSend Limited, a payment service provider licensed to operate in Kenya. The following explains the exact data flow during a Premium purchase:
Given the sensitive nature of personal financial data, Wendy Digital has implemented layered security measures across every point where your data is stored or transmitted:
We do not sell, rent, or trade your personal data to any third party. We share data only in the following limited, necessary circumstances:
| Recipient | Data Shared | Reason & Basis |
|---|---|---|
| Google LLC / Firebase | Account data, Loan Records (if sync enabled), crash logs | Cloud infrastructure and authentication provider. Data processing agreement in place. Basis: contract performance and legitimate interests. |
| IntaSend Limited | Phone number (at checkout), payment confirmation event | Premium subscription payment processing. Data processing agreement in place. Basis: consent and contract performance. |
| Legal & regulatory authorities | As required by law or valid court order | Compliance with the DPA 2019, Computer Misuse and Cybercrimes Act 2018, orders from DCI, DPP, ODPC, or other competent authority. Basis: legal obligation. |
| Business successors | All user data | In the event of a merger, acquisition, or transfer of substantially all assets. You will be notified in advance and given the opportunity to delete your account. Basis: legitimate interests. |
All third-party data processors listed above are bound by contractual data processing agreements to process your data only on our documented instructions, in accordance with the DPA 2019 and applicable international data protection standards.
We retain personal data only for as long as necessary to fulfil the purposes in this Policy, comply with legal obligations, and resolve disputes. The specific retention periods are:
| Data Category | Retention Period | Deletion Trigger |
|---|---|---|
| Google account data (Firebase Auth) | Until account deletion | You delete your account in-app or request deletion from us |
| Loan Records (Firebase Firestore) | Until deleted by you or account deletion | You delete individual records in-app or delete your account |
| Loan Records (local on-device) | Until app uninstall or data clear | You uninstall the App or clear app data in Android settings |
| Premium billing records (IntaSend transaction reference) | 7 years from transaction date | Statutory financial records obligation under Kenyan law |
| Crash and diagnostic logs (Crashlytics) | 90 days (rolling) | Automatic purge per Firebase Crashlytics default retention policy |
| Support correspondence | 3 years from last interaction | Routine data management; earlier deletion available on request |
After the applicable retention period, personal data is securely deleted or irreversibly anonymised. You may request early deletion of your personal data in accordance with your rights under Section 11.
The Kenya Data Protection Act, 2019 grants you the following rights in relation to your personal data. You may exercise any of these rights at any time by contacting our Data Protection Officer at dpo@deniapp.com.
DENI – Loan Manager is designed for use by persons aged 18 years and older. We do not knowingly collect or process personal data from anyone under the age of 18.
If you are a parent or guardian and believe that a minor has registered for DENI or submitted personal data through the App, please contact us immediately at support@deniapp.com. We will promptly delete the minor's account and all associated personal data upon verification.
We may update this Privacy Policy from time to time to reflect changes in the App's features, our data practices, or applicable legal requirements. When we make material changes, we will:
For minor or non-material changes (e.g. clarifications, corrected contact details), we may update the Policy without an in-app notice, but the "Last Revised" date will always reflect the most recent change.
Your continued use of DENI after the effective date of any revised Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you should stop using the App and delete your account before the changes take effect.
If you have any questions about this Privacy Policy, wish to exercise your data rights, or want to raise a concern about how we handle your personal data, please contact our Data Protection Officer: