Privacy Policy

Last Updated: October 24, 2025

Effective Date: October 24, 2025


1. INTRODUCTION

1.1 Overview

Pangoni ("we," "us," "our," or "Company") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you access or use our website, mobile application, and related services (collectively, the "Platform").

1.2 Scope

This Privacy Policy applies to all Users of the Platform, including:

  • Property owners and landlords
  • Real estate agents and brokers
  • Property seekers (buyers, renters, tenants)
  • Visitors and browsers
  • Service providers and business partners

1.3 Acceptance

By accessing or using the Platform, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree, you must immediately cease using the Platform.

1.4 Kenya Data Protection Act Compliance

We process personal data in full compliance with the Data Protection Act, 2019 of Kenya and adhere to data protection principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.

1.5 Contact Information

Data Controller: Pangoni
Data Protection Officer Email: dpo@pangoni.com
Legal/Privacy Inquiries: legal@pangoni.com
Physical Address: [Address to be inserted]
Data Protection Registration Number: [To be inserted upon registration with Office of the Data Protection Commissioner]


2. DEFINITIONS

For purposes of this Privacy Policy:

  • "Personal Data" means any information relating to an identified or identifiable natural person
  • "Processing" means any operation performed on personal data, including collection, storage, use, disclosure, or deletion
  • "Data Subject" means the individual to whom personal data relates
  • "Data Controller" means Pangoni, who determines the purposes and means of processing personal data
  • "Data Processor" means any third party that processes personal data on behalf of Pangoni
  • "Consent" means freely given, specific, informed, and unambiguous agreement to processing of personal data
  • "Sensitive Personal Data" means data revealing racial or ethnic origin, health status, genetic data, biometric data, sexual orientation, or any data specifically classified as sensitive under Kenyan law

3. INFORMATION WE COLLECT

3.1 Information You Provide Directly

Account Registration Information:

  • Full name (as per national ID or passport)
  • Email address
  • Phone number (mobile and alternative)
  • Password (encrypted)
  • Date of birth
  • Gender
  • Nationality
  • Physical address
  • Profile photograph (optional)
  • User type (owner, agent, buyer, renter)
  • Professional credentials (for agents: license number, registration body, brokerage name)

Property Listing Information:

  • Property details (type, size, location, features, amenities)
  • Property address and GPS coordinates
  • Property photographs and videos
  • Property ownership documentation (when provided)
  • Pricing information
  • Availability dates
  • Contact preferences
  • Property description and marketing materials

Transaction and Communication Information:

  • Messages sent through the Platform
  • Inquiry details and property viewing requests
  • Saved searches and favorites
  • Comparison lists
  • Reviews and ratings
  • Feedback and survey responses
  • Customer support communications

Identity Verification Information (when required):

  • National ID or passport number
  • Copy of identification documents
  • Tax Identification Number (PIN)
  • Business registration documents
  • Professional licenses and certifications
  • Proof of address documents
  • Bank account or mobile money details (for payment features)

Payment Information (if applicable):

  • Payment method details (credit/debit card, M-Pesa, bank transfer)
  • Billing address
  • Transaction history
  • Invoice information

3.2 Information Collected Automatically

Device and Technical Information:

  • IP address and geographic location
  • Device type, model, and operating system
  • Browser type and version
  • Device identifiers (IMEI, advertising ID)
  • Screen resolution and device settings
  • Mobile network information
  • Time zone and language preferences

Usage and Analytics Data:

  • Pages viewed and time spent on pages
  • Links clicked and features used
  • Search queries and filters applied
  • Listings viewed, saved, or shared
  • Date and time of visits
  • Referring and exit pages
  • Navigation paths through the Platform
  • Interaction with emails and notifications

Location Data:

  • Precise GPS location (with your permission)
  • Approximate location (based on IP address)
  • Location information in property searches
  • Location tags in photographs (if enabled)

Cookies and Tracking Technologies:

  • Session cookies
  • Persistent cookies
  • Web beacons and pixels
  • Local storage
  • Analytics tools data

3.3 Information from Third Parties

Social Media Platforms:

  • Profile information when you sign in via social media (Facebook, Google, LinkedIn)
  • Public profile data
  • Friends list (with permission)
  • Email address associated with social account

Real Estate Agents and Property Owners:

  • Information shared by agents about their clients
  • Property documentation provided by owners
  • Reference information

Third-Party Services:

  • Payment processors (transaction data)
  • Identity verification services (verification results)
  • Credit reference bureaus (with consent, for rental applications)
  • Marketing partners (demographic data)
  • Data aggregators (public records)

Public Sources:

  • Land Registry records (for verification purposes)
  • Professional licensing databases
  • Business registration records
  • Publicly available property information

3.4 Sensitive Personal Data

We generally do not collect sensitive personal data. However, in limited circumstances, we may process:

  • Health or accessibility information (voluntary, for property accessibility matching)
  • Biometric data (for enhanced security features, with explicit consent)

We process sensitive personal data only with your explicit consent or where legally permitted, and we implement enhanced security measures for such data.



5. HOW WE USE YOUR INFORMATION

5.1 Primary Purposes

Platform Services:

  • Create and manage user accounts
  • Facilitate property listings and searches
  • Enable communication between property owners, agents, and seekers
  • Match Users with relevant properties
  • Provide personalized property recommendations
  • Process and display property listings
  • Facilitate property viewings and inquiries

Transaction Processing:

  • Process payments for Platform fees (if applicable)
  • Generate invoices and receipts
  • Maintain transaction records
  • Prevent fraud and unauthorized transactions

Communication:

  • Send service-related notifications
  • Respond to inquiries and support requests
  • Send property alerts matching saved searches
  • Notify about messages and inquiries
  • Send account and security notifications
  • Provide customer support

Personalization:

  • Customize user experience
  • Remember preferences and settings
  • Provide location-based property results
  • Show relevant property recommendations
  • Display recently viewed listings

5.2 Analytics and Improvement

Platform Optimization:

  • Analyze user behavior and engagement
  • Identify and fix technical issues
  • Test new features and functionalities
  • Improve search algorithms
  • Enhance user interface and experience
  • Monitor Platform performance

Business Intelligence:

  • Understand market trends
  • Analyze property demand and pricing
  • Generate statistical reports
  • Conduct research and development
  • Improve business operations

5.3 Marketing and Advertising

Our Marketing (with consent):

  • Send promotional emails and newsletters
  • Inform about new features and services
  • Send special offers and promotions
  • Conduct surveys and request feedback
  • Share property investment opportunities

Targeted Advertising:

  • Display personalized advertisements
  • Retarget Users who visited the Platform
  • Measure advertising effectiveness
  • Share anonymized data with advertising partners

You can opt out of marketing communications through:

  • Unsubscribe links in emails
  • Account settings
  • Contacting dpo@pangoni.com

5.4 Security and Legal Compliance

Platform Security:

  • Detect and prevent fraud
  • Identify suspicious activity
  • Prevent unauthorized access
  • Enforce Terms and Conditions
  • Protect against malicious attacks
  • Verify user identities

Legal Compliance:

  • Comply with anti-money laundering requirements
  • Respond to legal requests and court orders
  • Cooperate with law enforcement
  • Fulfill regulatory obligations
  • Maintain records as required by law
  • Protect legal rights and interests

5.5 Other Purposes

  • Resolve disputes between Users
  • Conduct internal audits
  • Create anonymized, aggregated data for research
  • Develop new products and services
  • Facilitate business transfers or acquisitions

6. HOW WE SHARE YOUR INFORMATION

6.1 Public Information

The following information is publicly visible on the Platform:

  • Property listings and descriptions
  • Property photographs and videos
  • Public portions of user profiles (name, profile picture, user type)
  • Reviews and ratings you post
  • Public messages or forum posts

Important: Do not include sensitive personal information in public listings or profiles.

6.2 Sharing Between Users

We facilitate communication by sharing:

  • Contact information with Users who inquire about your listings (if you're a property owner/agent)
  • Listing owner contact information with Users who make inquiries (if you're a buyer/renter)
  • Messages sent through the Platform

6.3 Service Providers and Business Partners

We share data with trusted third parties who provide services on our behalf:

Technology Services:

  • Cloud hosting providers (AWS, Google Cloud, etc.)
  • Email service providers
  • SMS and push notification services
  • Analytics and monitoring tools
  • Content delivery networks (CDNs)
  • Database management services

Payment Processing:

  • Payment gateways and processors
  • Mobile money providers (M-Pesa, etc.)
  • Banks and financial institutions
  • Payment fraud detection services

Identity Verification:

  • KYC (Know Your Customer) service providers
  • Identity verification platforms
  • Credit reference bureaus (with consent)

Marketing and Advertising:

  • Email marketing platforms
  • Social media advertising platforms
  • Analytics providers
  • Marketing automation tools

Customer Support:

  • Customer service platforms
  • Chatbot and support ticket systems
  • Communication tools

All service providers are contractually obligated to:

  • Process data only as instructed
  • Implement appropriate security measures
  • Maintain data confidentiality
  • Comply with data protection laws
  • Not use data for their own purposes

6.4 Legal and Regulatory Authorities

We may disclose information to:

  • Law enforcement agencies (criminal investigations)
  • Courts and tribunals (court orders, subpoenas)
  • Office of the Data Protection Commissioner
  • Financial Reporting Centre (AML compliance)
  • Kenya Revenue Authority (tax compliance)
  • Other regulatory bodies as legally required

6.5 Business Transfers

If Pangoni is involved in a merger, acquisition, asset sale, or bankruptcy:

  • Your information may be transferred to successor entity
  • You will be notified of any such transfer
  • This Privacy Policy continues to apply unless updated

6.6 Aggregate and Anonymous Data

We may share anonymized, aggregated data that cannot identify you:

  • Market research and industry reports
  • Statistical analysis and trends
  • Academic research
  • Business partners and investors

6.7 With Your Consent

We may share your information for purposes not covered above with your explicit consent.

6.8 We Do Not Sell Personal Data

We do not sell your personal data to third parties for their direct marketing purposes.


7. INTERNATIONAL DATA TRANSFERS

7.1 Transfer Outside Kenya

Some of our service providers and partners are located outside Kenya. When we transfer your personal data internationally, we ensure:

Adequate Protection:

  • Transfer only to countries with adequate data protection laws (as determined by the Office of the Data Protection Commissioner)
  • Use of Standard Contractual Clauses approved by data protection authorities
  • Implementation of additional security measures
  • Binding Corporate Rules for transfers within corporate groups
  • Transfers based on your explicit consent

Primary Transfer Jurisdictions:

  • European Union (GDPR-compliant countries)
  • United Kingdom
  • United States (with appropriate safeguards)
  • Other African countries with adequate protection

7.2 Cloud Storage

Data may be stored on cloud servers located in various jurisdictions. We select providers with:

  • Strong data protection policies
  • Compliance with international standards
  • Appropriate contractual safeguards

7.3 Your Rights Regarding International Transfers

You have the right to:

  • Be informed about international transfers
  • Object to transfers to certain countries
  • Request information about safeguards in place
  • Withdraw consent for transfers (where consent is the legal basis)

8. DATA SECURITY

8.1 Security Measures

We implement comprehensive technical and organizational measures to protect your personal data:

Technical Safeguards:

  • Encryption in transit (TLS/SSL certificates)
  • Encryption at rest for sensitive data
  • Secure password hashing (bcrypt, Argon2)
  • Firewalls and intrusion detection systems
  • Regular security audits and vulnerability assessments
  • Secure coding practices
  • Multi-factor authentication options
  • Automated backup systems
  • Access controls and authentication

Organizational Safeguards:

  • Employee training on data protection
  • Confidentiality agreements with staff and contractors
  • Role-based access controls (least privilege principle)
  • Background checks for employees with data access
  • Data protection impact assessments
  • Incident response and breach notification procedures
  • Regular policy reviews and updates
  • Vendor security assessments

8.2 Data Breach Procedures

In the event of a data breach:

  • We will investigate immediately
  • Contain and remediate the breach
  • Notify the Office of the Data Protection Commissioner within 72 hours (as required by law)
  • Notify affected Data Subjects without undue delay if there's high risk to rights and freedoms
  • Provide information about the breach, affected data, and mitigation steps
  • Document the breach and response

8.3 User Responsibilities

You are responsible for:

  • Maintaining password confidentiality
  • Using strong, unique passwords
  • Enabling two-factor authentication
  • Not sharing account credentials
  • Logging out from shared devices
  • Reporting suspicious activity immediately
  • Keeping contact information updated

8.4 Limitations

Important: While we implement strong security measures, no system is 100% secure. We cannot guarantee absolute security. You acknowledge that you provide information at your own risk.


9. DATA RETENTION

9.1 Retention Principles

We retain personal data only as long as necessary for the purposes outlined in this Privacy Policy, unless longer retention is:

  • Required by law
  • Necessary for legal claims
  • Required by regulatory authorities
  • Necessary for legitimate business purposes

9.2 Retention Periods

Active Accounts:

  • Account information: Duration of account plus 7 years
  • Property listings: Duration of listing plus 3 years
  • Messages and communications: 5 years from last message
  • Transaction records: 7 years (tax and accounting requirements)
  • Support tickets: 5 years from resolution

Closed Accounts:

  • Account information: 90 days after closure (unless legal retention required)
  • Transaction records: 7 years (legal requirement)
  • Legal claims data: Duration of claim plus 6 years

Analytics and Logs:

  • Server logs: 12 months
  • Analytics data: 26 months
  • Cookie data: As specified in cookie settings

Marketing Data:

  • Marketing preferences: Until withdrawal of consent plus 3 years
  • Marketing analytics: 26 months

9.3 Deletion Procedures

At the end of retention periods:

  • Data is securely deleted or anonymized
  • Backups containing deleted data are purged within 90 days
  • Third-party processors are instructed to delete data
  • Physical records are securely destroyed

9.4 Exceptions to Deletion

We may retain data longer when:

  • Required by law (tax records: 7 years)
  • Necessary for ongoing legal proceedings
  • Required for defending legal claims (statute of limitations period)
  • Needed for fraud prevention or security
  • Properly anonymized for research

10. YOUR DATA PROTECTION RIGHTS

Under the Kenya Data Protection Act, 2019, you have the following rights:

10.1 Right of Access (Right to Information)

You have the right to:

  • Confirm whether we process your personal data
  • Access your personal data
  • Obtain a copy of your personal data
  • Receive information about processing purposes, categories, recipients, and retention periods

How to Exercise: Email dpo@pangoni.com with subject "Data Access Request"

Response Time: Within 30 days

Fee: Generally free (may charge reasonable fee for excessive requests)

10.2 Right to Rectification (Correction)

You have the right to:

  • Correct inaccurate personal data
  • Complete incomplete personal data
  • Update outdated information

How to Exercise: Update through account settings, or email dpo@pangoni.com

Response Time: Without undue delay

10.3 Right to Erasure (Right to be Forgotten)

You have the right to request deletion of your personal data when:

  • Data is no longer necessary for original purpose
  • You withdraw consent (where consent is legal basis)
  • You object to processing and there are no overriding legitimate grounds
  • Data has been unlawfully processed
  • Legal obligation requires deletion
  • Data was collected from a minor without proper consent

Exceptions: We may refuse deletion if retention is necessary for:

  • Legal obligations
  • Legal claims (establishment, exercise, or defense)
  • Public interest purposes
  • Archiving in public interest

How to Exercise: Email dpo@pangoni.com or request account deletion through Platform

Response Time: Within 30 days

10.4 Right to Restriction of Processing

You have the right to restrict processing when:

  • You contest data accuracy (restriction during verification)
  • Processing is unlawful but you oppose deletion
  • We no longer need the data but you need it for legal claims
  • You object to processing (restriction pending verification of grounds)

How to Exercise: Email dpo@pangoni.com

Response Time: Within 30 days

10.5 Right to Data Portability

You have the right to:

  • Receive your personal data in structured, commonly used, machine-readable format
  • Transmit data to another controller
  • Have data transmitted directly to another controller (where technically feasible)

Applies When:

  • Processing is based on consent or contract
  • Processing is carried out by automated means

How to Exercise: Email dpo@pangoni.com with subject "Data Portability Request"

Response Time: Within 30 days

Format: JSON, CSV, or XML

10.6 Right to Object

You have the right to object to processing based on:

  • Legitimate interests (including profiling)
  • Direct marketing (absolute right)
  • Scientific or historical research
  • Statistical purposes

How to Exercise:

  • Marketing opt-out: Use unsubscribe link or account settings
  • Other objections: Email dpo@pangoni.com

Response Time: Immediate for marketing; 30 days for other objections

10.7 Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal effects or similarly significantly affect you.

Exceptions: Automated decisions are allowed when:

  • Necessary for contract performance
  • Authorized by law with suitable safeguards
  • Based on your explicit consent

How to Exercise: Email dpo@pangoni.com if you believe you're subject to automated decision-making

10.8 Right to Withdraw Consent

Where processing is based on consent, you have the right to:

  • Withdraw consent at any time
  • Withdraw without affecting lawfulness of processing before withdrawal
  • Withdraw as easily as giving consent

How to Exercise: Account settings for most preferences, or email dpo@pangoni.com

10.9 Right to Lodge a Complaint

You have the right to lodge a complaint with the supervisory authority:

Office of the Data Protection Commissioner (ODPC)
Website: www.odpc.go.ke
Email: complaints@odpc.go.ke
Phone: +254 (020) 2346000
Address: Kalamu House, 2nd Floor, Grevillea Grove, Off Brookside Drive, Westlands, Nairobi

You may also seek judicial remedy through Kenyan courts.

10.10 Right to Compensation

You have the right to compensation for material or non-material damage suffered as a result of data protection violations.

10.11 Exercising Your Rights

Verification: We may require identity verification before fulfilling requests to prevent unauthorized access.

Required Information:

  • Full name
  • Email address associated with account
  • Account username (if applicable)
  • Description of request
  • Verification documents (copy of ID)

No Charge: Generally free, but we may charge a reasonable fee for:

  • Manifestly unfounded or excessive requests
  • Additional copies of the same information

Response Time: Within 30 days (may extend by 2 months for complex requests with notice)

Refusal: We will explain if we cannot fulfill your request and inform you of your right to complain to ODPC.


11. COOKIES AND TRACKING TECHNOLOGIES

11.1 What Are Cookies?

Cookies are small text files stored on your device that help us provide and improve our services. We also use similar technologies such as pixels, web beacons, and local storage.

11.2 Types of Cookies We Use

Essential Cookies (Strictly Necessary):

  • Session management and authentication
  • Security and fraud prevention
  • Load balancing

These cookies are necessary for Platform functionality and cannot be disabled.

Functional Cookies:

  • Remember user preferences and settings
  • Store language preferences
  • Remember saved searches and favorites
  • Remember map zoom and location

Analytics and Performance Cookies:

  • Google Analytics (traffic and usage patterns)
  • Hotjar or similar (user behavior analysis)
  • Error tracking and debugging
  • Performance monitoring
  • A/B testing and feature experiments

Advertising and Marketing Cookies:

  • Facebook Pixel
  • Google Ads conversion tracking
  • Retargeting and remarketing
  • Personalized advertisements
  • Campaign effectiveness measurement

11.3 Third-Party Cookies

We use third-party services that set cookies:

  • Google Analytics: Analytics and reporting
  • Facebook: Social media integration and advertising
  • Advertising Networks: Ad serving and targeting
  • Payment Processors: Transaction security

Each third party has its own privacy policy governing cookie use.

11.4 Cookie Management

Browser Controls:

You can control cookies through browser settings:

  • Block all cookies
  • Accept only first-party cookies
  • Delete existing cookies
  • Receive notifications before cookies are set

Note: Blocking essential cookies may prevent Platform functionality.

Opt-Out Tools:

  • Google Analytics Opt-out: https://tools.google.com/dlpage/gaoptout
  • Network Advertising Initiative: http://optout.networkadvertising.org
  • Digital Advertising Alliance: http://optout.aboutads.info

Our Cookie Settings:

Manage cookie preferences through our cookie consent banner or account settings.

11.5 Do Not Track

Some browsers include "Do Not Track" (DNT) signals. We currently do not respond to DNT signals as there is no industry standard for compliance.

11.6 Mobile App Tracking

Our mobile app may use:

  • Device advertising IDs
  • Mobile analytics SDKs
  • Push notification tokens
  • App usage analytics

You can control mobile tracking through device settings:

  • iOS: Settings > Privacy > Advertising > Limit Ad Tracking
  • Android: Settings > Google > Ads > Opt out of Ads Personalization

11.7 Cookie Lifespan

  • Session cookies: Deleted when you close browser
  • Persistent cookies: Remain for set duration (typically 1-24 months)
  • See specific cookie durations in cookie settings

12. CHILDREN'S PRIVACY

12.1 Age Restriction

The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children under 18.

12.2 Parental Responsibility

If you are a parent or guardian and believe your child has provided personal data to us:

  • Contact us immediately at dpo@pangoni.com
  • We will delete the information promptly
  • We will terminate any associated account

12.3 Verification

We may request age verification during account registration. Providing false age information violates our Terms and Conditions.

12.4 Educational Use

If educational institutions wish to use the Platform for training purposes with students under 18:

  • Prior written approval is required
  • Parental consent must be obtained
  • Special data protection measures will apply
  • Contact legal@pangoni.com for arrangements

13. MARKETING COMMUNICATIONS

13.1 Types of Communications

With your consent, we may send:

  • Promotional emails about Platform features
  • Property investment opportunities
  • Special offers and discounts
  • Newsletter and market updates
  • Survey and feedback requests
  • Event invitations

13.2 Opt-In and Consent

We obtain explicit consent before sending marketing communications. By checking the marketing opt-in box during registration or later in account settings, you consent to receive marketing communications.

13.3 Opt-Out Methods

You can opt out of marketing communications:

  • Click "Unsubscribe" link in any email
  • Update preferences in account settings
  • Email dpo@pangoni.com with "Unsubscribe" in subject
  • Reply "STOP" to marketing SMS

Note: Opting out of marketing does not affect:

  • Transactional emails (account notifications, security alerts)
  • Service-related communications
  • Legal notices

13.4 Third-Party Marketing

We do not share your personal data with third parties for their direct marketing purposes without your explicit consent.


14. THIRD-PARTY LINKS AND SERVICES

14.1 External Links

The Platform may contain links to external websites, applications, or services operated by third parties. This Privacy Policy does not apply to third-party sites.

14.2 Third-Party Privacy Practices

We are not responsible for:

  • Privacy practices of third-party sites
  • Content on external websites
  • Data collection by third parties
  • Security of third-party services

14.3 Social Media Integration

If you use social media features (share buttons, login):

  • Your social media provider may collect information
  • Social media platform privacy policies apply
  • We may receive information from social platforms per your settings

14.4 Recommendation

Review privacy policies of any third-party sites or services you access through our Platform.


15. CALIFORNIA AND INTERNATIONAL USERS

15.1 California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to opt-out of sale of personal information
  • Right to deletion
  • Right to non-discrimination for exercising privacy rights

We do not sell personal information.

Contact dpo@pangoni.com for California-specific requests.

15.2 European Union (GDPR)

If you are an EU resident and access our Platform, GDPR may apply. You have rights similar to those under the Kenya Data Protection Act.

EU Representative (if required): [To be designated if GDPR applies]

15.3 Other Jurisdictions

We comply with applicable data protection laws in jurisdictions where we operate or have Users. If you have jurisdiction-specific rights, contact dpo@pangoni.com.


16. CHANGES TO THIS PRIVACY POLICY

16.1 Right to Modify

We reserve the right to modify this Privacy Policy at any time to reflect:

  • Changes in our practices
  • Legal or regulatory requirements
  • New features or services
  • User feedback
  • Business needs

16.2 Notification of Changes

We will notify you of material changes through:

  • Email to your registered address
  • Prominent notice on the Platform
  • In-app notification
  • Updated "Last Updated" date at the top of this policy

16.3 Continued Use

Your continued use of the Platform after changes constitutes acceptance of the modified Privacy Policy. If you do not agree with changes, you must cease using the Platform and may request account deletion.

16.4 Review Responsibility

You are responsible for reviewing this Privacy Policy periodically. Material changes become effective 30 days after notification unless you object.


17. DATA PROTECTION OFFICER

17.1 DPO Responsibilities

Our Data Protection Officer is responsible for:

  • Monitoring compliance with data protection laws
  • Advising on data protection impact assessments
  • Cooperating with the Office of the Data Protection Commissioner
  • Acting as contact point for data subjects and authorities
  • Reviewing data protection policies and practices

17.2 Contacting the DPO

Data Protection Officer
Email: dpo@pangoni.com
Subject Line: [Indicate nature of inquiry - Access Request, Complaint, General Inquiry]
Response Time: Within 7 business days for acknowledgment; within 30 days for full response

17.3 What to Include in Communications

  • Your full name and contact information
  • Description of your inquiry or request
  • Account information (username or email)
  • Specific data or processing activities concerned
  • Desired outcome or action requested

18. SPECIFIC PRIVACY NOTICES

18.1 Property Owners and Agents

If you list properties:

  • Your contact information will be shared with interested Users
  • Property listings are publicly visible
  • You may receive inquiries and messages
  • Do not include sensitive personal information in listings
  • Images may be indexed by search engines
  • Reviews and ratings may be posted about your properties or service

18.2 Property Seekers

If you search for properties:

  • Your search criteria may be used to send relevant listings
  • Agents and owners can see your inquiry messages
  • Your profile may be visible to listing owners when you inquire
  • Saved searches and favorites are stored in your account

18.3 Real Estate Agents

If you are a registered agent:

  • Your professional credentials may be verified
  • Your license information may be displayed publicly
  • Client testimonials and reviews may be published
  • Your agency affiliation may be displayed

18.4 WhatsApp Integration

If we integrate with WhatsApp:

  • Your phone number must be valid
  • WhatsApp terms and privacy policy apply
  • Messages are subject to WhatsApp's encryption
  • We process metadata about WhatsApp interactions

18.5 Mobile Money (M-Pesa) Integration

If we process payments via mobile money:

  • Your mobile money number is collected
  • Transaction details are recorded
  • Mobile money provider terms apply
  • We do not store sensitive payment credentials

19. CONTACT US

19.1 Privacy Inquiries

For any privacy-related questions, concerns, or requests:

General Privacy Inquiries:
Email: privacy@pangoni.com

Data Protection Officer:
Email: dpo@pangoni.com

Legal Department:
Email: legal@pangoni.com

Physical Address:
[Company address to be inserted]
Nairobi, Kenya

Phone:
[Phone number to be inserted]

Response Time:
Acknowledgment: Within 7 business days
Full response: Within 30 days
Complex requests: Up to 90 days with notice

19.2 Required Information

When contacting us, please include:

  • Full name
  • Account email address or username
  • Detailed description of inquiry or request
  • Any relevant documentation
  • Preferred method of response

19.3 Identity Verification

To protect your privacy, we may require identity verification before:

  • Providing personal data
  • Making changes to your account
  • Processing deletion requests
  • Fulfilling access requests

Acceptable verification documents:

  • Government-issued ID (copy)
  • Passport
  • Driving license

20. ACKNOWLEDGMENT AND CONSENT

By using the Pangoni Platform, you acknowledge that:

  1. You have read and understood this Privacy Policy in its entirety
  2. You understand how we collect, use, disclose, and protect your personal data
  3. You consent to the processing of your personal data as described herein
  4. You understand your rights under the Kenya Data Protection Act, 2019
  5. You agree to receive necessary service communications
  6. You understand that you can withdraw consent at any time
  7. You will review this Privacy Policy periodically for updates
  8. You are responsible for maintaining the security of your account
  9. You will not provide false or misleading information
  10. You understand the public nature of property listings

For marketing communications, you provide separate opt-in consent during registration or through account settings.


LAST UPDATED: October 24, 2025

EFFECTIVE DATE: October 24, 2025

© 2025 Pangoni. All Rights Reserved.

DATA PROTECTION REGISTRATION: [To be inserted upon registration with ODPC]

END OF PRIVACY POLICY

Landlord or real estate pro?

List properties, manage tenants, and track payments — all in one place with Pangoni.


...

Start building today!

A complete and customizable solution to building the website of your dreams.

Account
About
Company
Library