Privacy Policy for NuaSense
Last updated: 4 August 2026
This Privacy Policy describes how NuaSense Limited (“NuaSense”, “we”, “us”, or “our”) collects, uses, processes, stores, and protects information when you access or use the NuaSense application, mobile apps, platform, and related services (collectively, the “Service”).
NuaSense provides an IoT data platform that ingests data from connected agricultural devices, visualises that data through dashboards, generates analytical insights and alerts, and — for customers who enable it — supports the disbursement of farm wages through a licensed payment provider.
This Privacy Policy applies to all users of the Service, including users of our iOS and Android applications.
By using NuaSense, you acknowledge that you have read and understood this Privacy Policy.
1. Roles and scope
Depending on how the Service is used, we may act as:
- a data processor, when we process IoT data on behalf of our customers;
- a data controller, when we process account, identity verification, billing, and platform usage data.
This distinction matters. Customers determine what IoT data is collected and uploaded to NuaSense, and we process that data only according to their instructions and for the purpose of providing the Service. By contrast, when we verify a customer’s identity to meet our obligations under anti-money-laundering law, we decide what is collected and why, and we act as controller.
We are established in Kenya and process personal data in accordance with the Kenya Data Protection Act, 2019, and, where it applies, the EU/UK General Data Protection Regulation.
2. Information we collect
2.1 IoT and operational data
The Service collects and processes data transmitted from IoT devices connected by the user. This may include:
- sensor measurements and telemetry (soil, weather, crop condition);
- device identifiers, gateway identifiers, and metadata;
- system status, logs, and event data;
- timestamps and field locations, where enabled by the user.
The type, volume, and sensitivity of this data depend entirely on the devices and configurations chosen by the customer.
2.2 Account and identity information
When registering for or administering an account, we collect:
- name and contact details;
- email address and login credentials;
- organisation or company affiliation;
- role and access permissions within the platform;
- telephone numbers designated to receive alerts.
2.3 Identity verification data (customer due diligence)
If you apply to use the wage-disbursement functionality, Kenyan anti-money-laundering law requires us to verify who you are before that functionality is enabled. For this purpose we collect:
- your full name as it appears on your identity document;
- your national identity document number or passport number;
- a mobile telephone number, which we verify by one-time passcode;
- for business customers: the registered business name, registration number, a description of the business activity, and a copy of the certificate of registration;
- information about ownership and control of the business, and the expected volume of payments.
We additionally screen the names we collect against international sanctions lists (including the United Nations Consolidated List) and check for politically exposed persons. The results of that screening, and any decision taken on it, form part of your verification record.
Identity document numbers are encrypted before storage and are never displayed in full within the Service.
2.4 Payment data
Where you use the wage-disbursement functionality, we process:
- the names, telephone numbers, and payment amounts of the workers you choose to pay;
- transaction references, statuses, timestamps, and receipts;
- records of the fees applied to each transaction.
Payments themselves are executed by our payment service provider (see section 6). We do not collect or store full payment card details.
2.5 Mobile application data and device permissions
Our mobile applications request the following device permissions. Each is optional, each is requested only at the point it is used, and the Service remains usable if you decline:
| Permission | Why we ask | What leaves your device |
|---|---|---|
| Notifications | To deliver sensor and advisory alerts | A push token identifying the app installation |
| Camera / photo library | To attach a photo when asking about a crop problem, or to upload a business registration certificate | Only the image you select |
| Contacts | To let you add workers to a wage roster without retyping them | Only the contacts you explicitly select |
| Location | To tag the position of a soil sample | Coordinates for the sample you save |
| Face ID / biometrics | To unlock the app without retyping your password | Nothing. Biometric data never leaves your device and is never accessible to us; the device’s secure enclave performs the match and only releases stored credentials locally |
We store a push notification token for each device on which you enable notifications, together with the platform (iOS or Android), so that alerts can be delivered to that device. Tokens are deleted when they become invalid or when you sign out.
2.6 Platform usage and technical information
We automatically collect information related to the operation and security of the Service, including:
- IP address;
- device type, browser, operating system, and application version;
- access logs, error logs, and audit trails;
- interaction and feature usage metrics.
2.7 Messages you send to our assistant
If you use the in-app or WhatsApp assistant, we process the messages you send and the sensor data relevant to answering them. These messages are transmitted to a third-party language model provider to generate a response (see section 6). Do not include information in these messages that you do not wish to have processed in this way.
3. How we use information
We process information for defined and legitimate purposes, including to:
- deliver and operate the NuaSense platform;
- ingest, store, visualise, and analyse IoT data;
- generate insights, alerts, and reports, and deliver them by in-app notification, push notification, SMS, WhatsApp, or email;
- verify the identity of customers who apply for payment functionality, and meet our obligations under anti-money-laundering, counter-terrorist-financing, and sanctions law;
- execute and reconcile wage payments you instruct;
- monitor transactions for indicators of financial crime, as we are required to do by law;
- maintain the security, integrity, and availability of the Service;
- improve performance, reliability, and functionality;
- provide customer support and service communications;
- meet legal, regulatory, and compliance obligations.
We do not use customer IoT data for advertising, and we do not sell personal data.
4. Legal bases for processing
Where applicable, we rely on one or more of the following:
- performance of a contract — to provide the Service you have signed up for;
- compliance with a legal obligation — in particular identity verification, sanctions screening, transaction monitoring, and record retention under Kenyan anti-money-laundering law;
- legitimate interests — operating, securing, and improving the Service;
- consent — for device permissions, optional notification channels, and where consent is otherwise required. Consent may be withdrawn at any time, without affecting processing already carried out.
Where processing is required by law, we cannot offer the affected functionality without it. If you decline identity verification, you may continue to use the monitoring and advisory features; only the payment functionality will remain unavailable.
5. Data ownership and customer control
Customers retain full ownership of and responsibility for the IoT data they provide to the Service.
NuaSense does not claim ownership over customer data and does not access it except:
- to provide the requested functionality;
- to maintain system reliability and security;
- as required by law.
Customers may access, export, or delete their data through the Service or by contacting us, subject to the retention obligations described in section 8.
6. Data sharing, payment provider, and subprocessors
We do not sell personal data or IoT data. We share information only as set out below.
6.1 Payment service provider
Wage payments are executed by SasaPay, a payment service provider licensed and regulated by the Central Bank of Kenya. Funds are held and moved by the licensed provider, not by NuaSense.
To execute a payment we transmit to SasaPay the information necessary to complete it — including recipient telephone numbers, amounts, and transaction references — and receive back transaction statuses and receipts. SasaPay processes this data as an independent controller for the purposes of its own regulatory, licensing, and record-keeping obligations, and its own privacy terms apply to that processing.
Our own identity verification is carried out in addition to, and independently of, any checks performed by our payment provider.
6.2 Subprocessors
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Account database and authentication | EU |
| DigitalOcean | Application, data, and time-series hosting | EU |
| Hostinger | Web application hosting | EU |
| Africa’s Talking | SMS delivery | Kenya |
| Meta Platforms | WhatsApp message delivery | EU / US |
| Google (Firebase) | Push notification delivery to Android devices | EU / US |
| Apple | Push notification delivery to iOS devices | EU / US |
| Amazon Web Services (SES) | Email delivery | EU |
| DeepSeek | Language model powering the in-app assistant | Outside the EEA |
We may also share information with professional advisers under confidentiality obligations, and with authorities where required by law or legal process. All subprocessors are bound by contractual data protection obligations consistent with this Privacy Policy.
Where a report is required under anti-money-laundering law, we may be legally prohibited from informing you that it has been made.
7. Data security
We implement technical and organisational safeguards, including:
- access controls and authentication mechanisms;
- encryption in transit, and encryption at rest for identity document numbers;
- monitoring, logging, and audit trails;
- role-based access and least-privilege principles;
- restriction of identity verification records to authorised compliance personnel only.
While we take security seriously, no system can be guaranteed to be completely secure.
8. Data retention
We retain data only for as long as necessary to provide the Service, comply with legal and regulatory requirements, and resolve disputes.
Specifically:
- IoT and operational data — for the duration of the customer relationship, and thereafter according to the customer’s configuration;
- Account data — for the duration of the account, and a short period thereafter for security and audit purposes;
- Identity verification and payment records — retained for seven (7) years after the end of the business relationship or the date of the transaction, as required by Kenyan anti-money-laundering law.
This means that if you delete your account, we must still retain your verification and transaction records for the statutory period. During that period the records are kept in restricted, access-controlled storage and are not used for any purpose other than compliance.
9. Account deletion
You can delete your account at any time from within the Service, under Settings → Account → Delete account, or by writing to the address in section 13.
Deleting your account removes your login, your profile, your device tokens, your notification settings, and your access to the Service. Where we are legally required to retain identity verification and payment records, those records are retained as described in section 8 and are not used for any other purpose.
10. International data transfers
The Service processes data in multiple jurisdictions, including outside Kenya and outside the European Economic Area. Where we transfer personal data internationally, we apply appropriate safeguards — such as standard contractual clauses or an equivalent mechanism — to ensure a level of protection consistent with applicable data protection law.
11. Children
The Service is intended for use by businesses and adult professional users. It is not directed at children, and we do not knowingly collect personal data from children.
12. Your rights
Depending on your jurisdiction, you have the right to:
- be informed about how your data is used;
- access the personal data we hold about you;
- correct or update inaccurate information;
- request deletion or restriction of processing;
- object to certain processing activities;
- receive a copy of your data in a portable format;
- withdraw consent where processing is based on consent;
- lodge a complaint with a supervisory authority. In Kenya this is the Office of the Data Protection Commissioner (ODPC).
Some of these rights are limited where we are under a legal duty to retain information, in particular for anti-money-laundering purposes.
Requests can be submitted using the contact details below. We will respond within the period required by applicable law.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by other appropriate means. Continued use of NuaSense after changes take effect constitutes acceptance of the updated policy.
14. Contact
For questions, requests, or concerns regarding privacy or data protection:
NuaSense Limited
Email: [email protected]
For matters relating to anti-money-laundering compliance, address correspondence to the Money Laundering Reporting Officer at the same address.