PATO CAPITAL LIMITED
PRIVACY POLICY
Version 2.0 | Effective Date: May 2026 | Last Reviewed: May 2026
Issued under the Kenya Data Protection Act, 2019 and the CBK Digital Credit Providers Regulations, 2022
Pato Capital Limited ("Pato Capital", "PCL", "we", "our", "us") is a company incorporated in Kenya and licensed by the Central Bank of Kenya (CBK) as a Digital Credit Provider. We are registered with the Office of the Data Protection Commissioner (ODPC) as a Data Controller and Data Processor in accordance with the Data Protection Act, 2019 (Cap 411C of the Laws of Kenya).
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you interact with our services, mobile application, USSD channels, website, and any other Pato Capital digital platform (collectively, the "Platform"). It applies to all persons who interact with us, including borrowers, partner organisations, agents, fund administration clients, and website visitors.
Contact information for data matters:
Data Controller: Pato Capital Limited
Physical address: Nairobi, Kenya (PO BOX 51957-00100)
Email: info@patocapital.com
Phone: +254 108 238171
Website: www.patocapital.com
By using our services, you acknowledge that you have read and understood this Privacy Policy. This Policy forms part of our Terms and Conditions of Use.
Our data processing activities are conducted in compliance with the following laws and regulations:
The Data Protection Act, 2019 (Cap 411C) and the Data Protection (General) Regulations, 2021
The CBK Digital Credit Providers Regulations, 2022
The Non-Deposit Taking Credit Providers (NDTCP) Regulations, 2026 (gazetted)
The Electronic Transactions Act, 2017
The Proceeds of Crime and Anti-Money Laundering Act (POCAMLA), 2009
The Prevention of Terrorism Act, 2012
The Credit Reference Bureau Regulations, 2020
We process your personal data on the following legal bases under the Data Protection Act, 2019:
Consent: Where you have given explicit, informed, and freely given consent to a specific processing purpose.
Contract performance: Processing necessary for the performance of your loan agreement.
Legal obligation: Processing required to comply with our obligations under Kenyan law (including KYC, AML/CFT, CRB reporting, and tax obligations).
Legitimate interests: Processing necessary for our legitimate business interests, where these do not override your fundamental rights and freedoms.
Vital interests: In exceptional circumstances, to protect interests that are essential for life.
Pato Capital is committed to the following data protection principles in all its data processing activities:
Principle | What this means for your data |
|---|---|
Lawfulness, Fairness and Transparency | We collect and process your data only on a lawful basis and inform you clearly how your data is used. |
Purpose Limitation | Data collected for credit assessment is not repurposed for incompatible uses without fresh consent. |
Data Minimisation | We collect only the data necessary to deliver the specific service or comply with a legal obligation. |
Accuracy | We take steps to ensure data is accurate and up to date. You can request correction at any time. |
Storage Limitation | Data is retained only as long as necessary for the stated purpose or as required by law. |
Security | Appropriate technical and organisational measures protect your data against unauthorised access, loss, or alteration. |
Accountability | Pato Capital is responsible for compliance with these principles and can demonstrate compliance to the ODPC. |
We collect the following identity data to verify your identity and comply with our KYC obligations under POCAMLA and CBK Regulations:
Full legal name
National Identity Card number, Passport number, Military ID, or Alien ID
Date of birth and gender
Nationality and citizenship
Marital status
Residential address (current and historical)
Photograph or selfie (for biometric matching where applicable)
Tax Identification Number (TIN/KRA PIN) where required
Mobile phone number (M-Pesa registered)
Email address
Physical address
Next of kin or emergency contact (where voluntarily provided)
Bank account details (where applicable for disbursement)
M-Pesa transaction history (with your consent, used for credit scoring)
Income information and payslips (for employer-linked products)
Net disposable income and existing financial obligations
Credit bureau reports from TransUnion, Metropol, and/or Creditinfo
Loan application history with Pato Capital
Repayment history and loan performance data
Invoice data (face value, buyer, due date) for invoice financing products
Pension or annuity statement data for pension-backed products
Insurance policy details and surrender value for insurance-backed products
For employer-linked products (salary advances and check-off loans):
Employer name and HR/payroll contact
Employment status, grade, and date of employment
Gross monthly salary and allowances
Existing payroll deductions and statutory deductions
Net salary available for check-off after Two-Thirds Rule computation
When you use our mobile application, we may collect (subject to your express consent):
Device identifier (IMEI or device ID) and operating system version
Mobile network carrier and signal data
App usage patterns and session duration
SMS data: We access relevant SMS messages solely to identify and summarise M-Pesa transaction confirmations for credit scoring. We do not read personal conversations. This consent can be withdrawn at any time through app settings.
Phone contacts: We may request access to contacts solely to enable you to select a contact when initiating a transaction. We do not upload or store your full contact list on our servers.
Camera access: To capture photographs for identity verification only.
Storage access: To enable document upload for loan applications.
We may collect approximate location data (based on network or GPS) to support fraud detection, identity verification, and regulatory compliance. Precise location data is collected only where you have expressly granted location permission in your device settings. You may disable this at any time.
For groups using our Fund Administration service (chamas, SACCOs, employer funds):
Group name, registration certificate, and constitution
Names, ID numbers, and contact details of group officials (chairperson, treasurer, secretary)
Group membership lists and contribution records
Group financial statements and bank account details
Individual member loan applications and repayment records
We may receive data about you from the following third-party sources:
Credit Reference Bureaus (TransUnion, Metropol, Creditinfo via Peleza or equivalent aggregator)
IPRS and the National Registration Bureau (for identity verification)
Your employer (payroll data for employer-linked products)
Invoice payer or buyer organisations (invoice verification for supply chain financing)
Pension or annuity administrators (for pension-backed products)
Insurance companies (for insurance-backed products and policy verification)
M-Pesa/Safaricom (transaction confirmation data, through Daraja API)
Fraud detection and AML screening services (including PEP/sanctions screening via Dow Jones or equivalent)
Government departments and regulatory agencies as legally required
We use your personal data for the following purposes, each on the legal basis indicated:
Purpose | Data Used | Legal Basis |
|---|---|---|
Identity verification and KYC | Identity, contact, biometric data | Legal obligation; Consent |
Credit scoring and loan assessment | Financial, M-Pesa, CRB, employment, device data | Contract; Consent |
Loan disbursement and account management | Identity, contact, M-Pesa number, bank details | Contract |
Repayment tracking and collections | Loan, payment, contact, employment data | Contract; Legal obligation |
CRB reporting (positive and negative) | Loan history and repayment data | Legal obligation |
AML/CFT screening and suspicious transaction reporting | Identity, transaction, PEP/sanctions data | Legal obligation |
Tax reporting (WHT, excise duty) to KRA | Identity, TIN, loan and interest data | Legal obligation |
Customer support and complaint resolution | Contact, loan, and communication history | Contract; Legal obligation |
Fraud detection and security monitoring | Device, location, transaction, and behavioural data | Legitimate interest; Legal obligation |
Platform improvement and analytics | Anonymised usage data | Legitimate interest |
Regulatory reporting to CBK, ODPC, FRC | Loan book, CRB, AML, and financial data | Legal obligation |
Marketing of Pato Capital's own products (opt-in only) | Contact data and product usage history | Consent |
AI and Automated Decision-Making: Pato Capital uses an automated credit scoring model to assess loan applications. In accordance with Regulation 57 of the NDTCP Regulations, 2026, all automated decisions are subject to human oversight by a Credit Officer. You have the right to request a human review of any automated decision and to receive a plain-language explanation of the top factors influencing the decision (top 5 score drivers). We do not use your protected attributes (race, religion, political opinion, ethnic origin, or disability) in credit assessment.
Pato Capital does not sell your personal data. We share your data only in the following circumstances and with the safeguards described:
Central Bank of Kenya (CBK): Monthly loan book returns, NPL reports, product change notifications, and any information required by CBK inspection or inquiry.
Financial Reporting Centre (FRC): Suspicious Transaction Reports (STRs) filed within the timeframes required by POCAMLA, 2009.
Office of the Data Protection Commissioner (ODPC): Annual compliance reports, data breach notifications (within 72 hours of discovery), and data subject access responses.
Kenya Revenue Authority (KRA): Withholding tax remittances, excise duty, and any other tax reporting required by law.
Courts and law enforcement agencies: In response to valid court orders, subpoenas, or lawful demands.
Credit Reference Bureaus (CRBs): Positive and negative credit data submitted monthly and on an event-driven basis as required by CRB Regulations.
Our technology partner (core lending platform, loan origination, and management system provider): accesses data under a Data Processing Agreement (DPA) and is bound by equivalent data protection standards.
M-Pesa/Safaricom (Daraja API): For loan disbursement (B2C), repayment collection (STK Push, Paybill), and transaction status queries.
CRB aggregator (Peleza or equivalent): For CRB bureau queries and data submission.
IPRS verification provider: For National ID and biometric verification.
PEP/Sanctions screening provider: For AML watchlist screening (e.g., Dow Jones Risk & Compliance or equivalent).
SMS gateway and communication provider: For loan notifications, payment reminders, and OTP delivery.
Cyber insurance provider: As required for insurance coverage of data security incidents.
Legal counsel and debt collection agents: For enforcement and recovery purposes, limited to data necessary for that purpose.
Employer Aggregators: Where your loan is employer-linked, your employer receives aggregate portfolio data (total outstanding, collection rates) and the minimum individual data necessary to process payroll check-off deductions. Your employer does not receive your full credit profile or CRB data.
Invoice Buyers/Payers: For invoice financing, the buyer organisation receives only confirmation of invoice assignment and payment instructions.
Pension Administrators: For pension-backed loans, the administrator receives only the deduction instruction and loan reference.
Insurance Companies: For insurance-backed loans, the insurer receives the irrevocable assignment documentation and, on default, settlement instructions.
Fund Administration Clients: Group officials receive aggregated portfolio data for their group's members. Individual member data is shared with group administrators only to the extent necessary and with the member's consent.
Pato Capital's creditors (lenders of capital to Pato Capital) receive only portfolio-level aggregated data (total deployed, PAR30 metrics, returns). They do not receive individual borrower data, names, or personal information. This boundary is maintained throughout all phases of operations.
Where we seek to share your data for any purpose not covered above, we will obtain your separate, explicit, and freely given consent before doing so, including specifying the purpose, recipient, and duration of the sharing.
All personal data collected by Pato Capital is stored and processed in Kenya or within the East African Community (EAC) region, in data centres that comply with the data residency requirements of the Data Protection Act, 2019. We do not routinely transfer personal data outside Kenya.
In the event that any transfer of personal data outside Kenya becomes necessary, we will ensure compliance with Section 49 of the Data Protection Act, 2019, including:
Transferring only to jurisdictions with equivalent data protection laws.
Implementing appropriate safeguards (such as Standard Contractual Clauses or binding corporate rules).
Notifying the ODPC as required.
Obtaining your explicit consent to the transfer where required.
We retain your personal data for the periods set out below, after which data is securely deleted, anonymised, or archived in a form that no longer identifies you:
Data Category | Retention Period | Legal Basis for Retention |
|---|---|---|
Identity and KYC records | 7 years after account closure or final loan repayment | POCAMLA; CRB Regulations; Tax |
Loan agreements and transaction records | 7 years after the last transaction | CBK Regulations; Tax; Limitation Act |
Repayment and CRB data | 7 years after repayment or closure | CRB Regulations |
AML/STR records and investigation notes | 7 years after the report date | POCAMLA, 2009 |
Credit scoring decisions and model outputs | 7 years (for audit and regulatory review) | NDTCP Reg 57; CBK audit requirements |
Complaints and dispute records | 7 years after final resolution | NDTCP Reg 38; Limitation Act |
Marketing consent records | While consent is active; deleted on revocation | Data Protection Act, 2019 |
M-Pesa statement copies (SMS read data) | 90 days post-consent; deleted on withdrawal | Consent; Data minimisation |
Audit logs (system access and changes) | 7 years (immutable, encrypted) | FRC; CBK; NDTCP |
Declined application data | 1 year after decline date | Legitimate interest; regulatory |
As a data subject, you have the following rights under the Data Protection Act, 2019. You may exercise any of these rights by contacting us at info@patocapital.com or through the in-app privacy settings:
You have the right to request confirmation of whether we process your personal data and to receive a copy of that data. We will respond within 21 days. The first request is free; reasonable fees may apply for repeat requests.
You have the right to request correction of inaccurate or incomplete personal data. We will update records and, where required, notify relevant third parties (including CRBs) of corrections.
You may request deletion of your personal data where it is no longer necessary for the purpose collected, or where consent is withdrawn and no other legal basis applies. Note that we cannot delete data we are legally required to retain (such as KYC records under POCAMLA or CRB data under CRB Regulations). We will inform you of any limitations on erasure.
You have the right to object to processing based on legitimate interests, including direct marketing. Where you object to direct marketing, we will stop processing for that purpose immediately. Where you object to other processing on legitimate interests grounds, we will assess whether our interests override your rights and respond within 21 days.
You may request restriction of processing in certain circumstances, such as while the accuracy of data is being contested or where processing is unlawful but you prefer restriction to erasure.
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
In accordance with Regulation 57 of the NDTCP Regulations, 2026, you have the right to: request a human review of any automated credit decision; receive an explanation of the main factors (top 5 drivers) that influenced the decision; and contest any automated decision that significantly affects your credit access.
Where processing is based on consent, you may withdraw that consent at any time by adjusting your app settings or contacting us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal or your obligations under existing Loan Agreements.
If you believe we have violated your data rights, you may lodge a complaint with the Office of the Data Protection Commissioner. Contact: Office of the Data Protection Commissioner, Nairobi, Kenya. Website: www.odpc.go.ke. Email: info@odpc.go.ke.
Pato Capital implements the following technical and organisational security measures to protect your personal data:
Encryption at rest: AES-256 encryption for all personal and financial data stored in our systems.
Encryption in transit: TLS 1.3 for all API communications between systems and users.
Role-Based Access Control (RBAC): Data is accessible only to authorised staff on a need-to-know basis.
Multi-Factor Authentication (MFA): Required for all privileged system access.
Audit logging: All data access, modification, and export events are logged with user ID, timestamp, and IP address. Logs are immutable and retained for 7 years.
Column-level encryption: Sensitive fields (National ID numbers, payment details) use additional encryption with keys rotated quarterly.
Password management: Passwords are hashed using Argon2 and are never stored in plain text.
Penetration testing: Pato Capital conducts periodic security assessments and penetration tests by independent third parties.
Data centre controls: All data is hosted in Kenya or EAC-region data centres with physical access controls.
Cyber insurance: Pato Capital maintains appropriate cyber insurance coverage.
Business continuity: Recovery Point Objective (RPO) of 4 hours and Recovery Time Objective (RTO) of 2 hours.
Data breach response: In the event of a personal data breach, Pato Capital will notify the ODPC within 72 hours of discovery and notify affected individuals within 7 days where the breach is likely to result in a risk to their rights and freedoms.
Our website (www.patocapital.com) and mobile application may use the following tracking technologies:
Session cookies are used to maintain your login session and application state. These are essential for the Platform to function and cannot be disabled. Preference cookies remember your language and display settings. Analytics cookies (where your consent is obtained) help us understand how users interact with our Platform to improve the user experience. You may manage cookie preferences through your browser settings, noting that disabling essential cookies may impair Platform functionality.
Where you have provided consent, we may use analytics tools to analyse usage patterns within the mobile application. All analytics data is anonymised or pseudonymised before use in reporting. We do not permit third-party advertisers to place tracking technologies on our Platform or in our application.
Our website currently does not respond to browser Do-Not-Track (DNT) signals, as there is no universal standard for these signals in Kenya. We will update this position if a standard is established and legally required.