1. Introduction
Serrari Group Ltd ("we," "our," or "us") is a company incorporated under the laws of the Republic of Kenya. We operate the Serrari Wealth Builder™ platform (the "Platform"), a web-based financial literacy course application designed to empower users with the knowledge and tools necessary to achieve financial transformation.
2. Definitions
For the purposes of this Policy, the following terms shall have the meanings set out below:
- "Consent" means any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which the data subject, through a statement or a clear affirmative action, signifies agreement to the processing of personal data relating to them, as defined under Section 2 of the DPA.
- "Data Controller" means a natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Serrari Group Ltd is the Data Controller for personal data processed through the Platform.
- "Data Processor" means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Data Controller.
- "Data Subject" means an identified or identifiable natural person whose personal data is processed. In the context of this Policy, a Data Subject is any user of the Platform.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined under Section 2 of the DPA. This includes, but is not limited to, a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- "Processing" means any operation or set of operations performed on personal data or sets of personal data, whether by automated means or otherwise, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- "Sensitive Personal Data" means data revealing a natural person's race, health status, ethnic social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details including names of the person's children, parents, spouse or spouses, sex, or the sexual orientation of the data subject, as defined under Section 2 of the DPA.
- "Platform" means the Serrari Wealth Builder™ web-based application, including all features, tools, courses, content, and services provided thereunder.
- "ODPC" means the Office of the Data Protection Commissioner of Kenya, established under Section 5 of the DPA.
3. Scope and Application
This Policy applies to all personal data collected, processed, stored, or transmitted through the Serrari Wealth Builder™ Platform, regardless of the method or device used to access the Platform.
3.1 Persons Covered
This Policy applies to:
- All visitors to the Platform, whether or not they create an account;
- All registered users of the Platform, including free-tier and premium subscribers;
- Users of any feature of the Platform, including but not limited to the 12-stage financial transformation course, net worth tracker, budget tools, investment calculators, vision boards, community circles, Daily Planner, and Calendar Sync;
- Any person who communicates with us through the Platform or related channels (e.g., customer support, email, community forums).
3.2 Services Covered
This Policy covers the following services and features of the Platform:
- Account registration and user profile management;
- The 12-stage financial transformation course and all related course materials;
- Net worth tracking and financial snapshot tools;
- Budget creation and expense management tools;
- Investment calculators and financial planning utilities;
- Vision boards and goal-setting features;
- Community circles and user interaction features;
- Daily Planner, routine alarms, and push/email/in-app notifications;
- Calendar Sync — connecting a Google Calendar or Microsoft Outlook Calendar account to view and manage events alongside your Platform routine (see Section 4.7 and Section 8.6 below);
- Payment processing for premium features and subscriptions;
- Analytics and usage tracking to improve the user experience.
3.3 Territorial Application
This Policy is primarily governed by the laws of the Republic of Kenya. Where the Platform is accessed from jurisdictions outside Kenya, users are advised that their personal data will be processed in accordance with the DPA and the provisions of this Policy.
4. Information We Collect
We collect various categories of personal data to provide, maintain, and improve the Platform. The types of information we collect are described below.
4.1 Account Information
When you register for an account on the Platform, we collect the following information:
- Full name;
- Email address;
- Telephone number (where provided);
- Password (stored in encrypted form);
- Profile preferences and settings.
4.2 Financial Information
The Platform enables you to input and manage financial data for the purpose of financial literacy education and personal financial planning. This data is entered voluntarily by you and may include:
- Assets (e.g., savings, investments, property, and other holdings);
- Liabilities (e.g., loans, debts, credit card balances, and other obligations);
- Income (e.g., salary, business income, rental income, and other sources of revenue);
- Expenses (e.g., recurring bills, discretionary spending, and other outflows);
- Net worth snapshots and historical net worth data;
- Budgets and financial goals;
- Investment portfolio details and projections.
4.3 Payment Information
When you subscribe to premium features or make purchases on the Platform, we collect payment-related information, including:
- Transaction records (amount, date, description, and status);
- Payment method type (e.g., mobile money, debit card, or credit card);
- Billing address (where applicable).
4.4 Usage Data
We automatically collect certain technical and usage information when you access the Platform, including:
- Device information (device type, operating system, browser type and version);
- Internet Protocol (IP) address;
- Pages visited and features used within the Platform;
- Session duration and frequency of access;
- Referring URLs and exit pages;
- Clickstream data and interaction patterns.
4.5 Cookies and Tracking Technologies
We use cookies, localStorage, and similar tracking technologies to collect and store information about your interactions with the Platform. This includes:
- Session cookies to maintain your authenticated session;
- Persistent cookies to remember your preferences and settings;
- localStorage on your device to store financial data, course progress, and user preferences for offline access and performance optimization;
- Third-party analytics cookies to understand aggregate usage patterns (e.g., Google Analytics or similar services).
For more information about our use of cookies, please refer to Section 13 of this Policy.
4.6 Communications Data
When you interact with us or other users through the Platform, we may collect:
- Customer support tickets and correspondence;
- Feedback, reviews, and survey responses;
- Posts, comments, and contributions made within community circles and discussion forums;
- Email communications sent to or received from us.
4.7 Google Calendar and Other Connected Calendar Data
Where you choose to connect a Google Calendar or Microsoft Outlook Calendar account to the Platform's Daily Planner and Calendar Sync feature, we access and store the following information from that connected account, solely to display and sync your calendar alongside your Platform routine:
- Event titles, descriptions, locations, and start and end times;
- Attendee names, email addresses, and response status (accepted, declined, or tentative);
- Whether you are the organizer of a given event;
- Any video-conferencing link generated for or attached to an event you sync through the Platform;
- The connected account's own display email address, so you can tell which calendar an event came from.
We do not access your email, contacts, files, or any other data from your connected Google or Microsoft account beyond what is listed above. This data is encrypted at rest, and is permanently deleted from our systems immediately when you disconnect the calendar integration. See Section 8.6 below for how we use and limit our handling of this specific category of data.
5. Legal Basis for Processing
In accordance with Section 30 of the Kenya Data Protection Act, 2019, we process your personal data only where we have a lawful basis to do so. The legal bases upon which we rely are as follows:
5.1 Consent
Where you have given clear, informed, and unambiguous consent to the processing of your personal data for one or more specific purposes. You provide consent when you create an account, input financial data, subscribe to communications, connect a Google or Microsoft calendar, or opt in to optional features. You may withdraw your consent at any time, and we will cease processing based on consent upon receipt of such withdrawal, without affecting the lawfulness of processing carried out prior to withdrawal.
5.2 Performance of a Contract
Processing that is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This includes processing necessary to provide the Platform's services, process payments, and deliver course content.
5.3 Legal Obligation
Processing that is necessary for compliance with a legal obligation to which we are subject under Kenyan law or any other applicable legislation. This includes maintaining records for tax purposes (including Value Added Tax and Digital Service Tax), responding to lawful requests from regulatory authorities, and complying with court orders.
5.4 Legitimate Interests
Processing that is necessary for the purposes of the legitimate interests pursued by us or a third party, provided that such interests are not overridden by your fundamental rights and freedoms. Our legitimate interests include:
- Improving and optimizing the Platform's functionality and user experience;
- Detecting, preventing, and addressing fraud, security breaches, and technical issues;
- Conducting internal analytics and research to develop new features and services;
- Ensuring the security and integrity of our systems and data.
6. How We Use Your Information
We use the personal data we collect for the following purposes:
6.1 Service Delivery
- To create and manage your user account;
- To provide access to the 12-stage financial transformation course and all Platform features;
- To process and record financial data you input for use in budgeting, net worth tracking, and investment calculators;
- To display and sync connected calendar events alongside your Daily Planner routine, and to fire the alarms and reminders you configure;
- To process payments for premium features and subscriptions.
6.2 Personalization
- To customize the Platform's content and features to your preferences and financial profile;
- To provide personalized course recommendations and progress tracking;
- To display relevant financial insights and calculations.
6.3 Analytics and Improvement
- To analyze usage patterns and trends to improve the Platform's design, functionality, and content;
- To conduct research and development for new features and tools;
- To measure the effectiveness of our educational content.
6.4 Communications
- To send you service-related notifications (e.g., account verification, password resets, payment confirmations, planner alarms);
- To send marketing communications where you have opted in (e.g., newsletters, product updates, promotional offers);
- To respond to your inquiries, support tickets, and feedback.
6.5 Security
- To detect, investigate, and prevent fraudulent, unauthorized, or illegal activity;
- To protect the rights, property, and safety of Serrari Group Ltd, our users, and the public;
- To enforce our Terms of Service and other agreements.
6.6 Legal Compliance
- To comply with applicable laws, regulations, and legal processes;
- To respond to lawful requests from government authorities and regulatory bodies;
- To maintain records required by tax (including VAT and Digital Service Tax), financial, and other regulatory obligations.
7. Data Storage and Security
We take the security of your personal data seriously and implement appropriate technical and organizational measures to protect it against unauthorized access, alteration, disclosure, or destruction.
7.1 Local Storage on User's Device
Certain data, including financial information, course progress, and user preferences, may be stored locally on your device using the browser's localStorage mechanism. This data remains on your device and is accessible only through the Platform in your browser. While localStorage data is not transmitted to our servers by default, it is subject to the security of your device and browser. We recommend that you:
- Use a secure and up-to-date browser;
- Protect your device with a strong password or biometric authentication;
- Avoid accessing the Platform on shared or public devices;
- Clear your browser data if you suspect unauthorized access.
7.2 Server-Side Storage
Personal data that is transmitted to and stored on our servers is protected using industry-standard security measures, including:
- Encryption of data in transit using Transport Layer Security (TLS/SSL);
- Encryption of sensitive data at rest using AES-256 or equivalent encryption standards — including calendar event details, attendee data, and OAuth tokens for connected calendar accounts;
- Access controls and role-based permissions to limit access to personal data on a need-to-know basis;
- Regular security audits and vulnerability assessments;
- Intrusion detection and prevention systems;
- Secure backup and disaster recovery procedures.
7.3 Employee and Contractor Access
Access to personal data is restricted to authorized employees, contractors, and agents of Serrari Group Ltd who require such access to perform their duties. All such persons are bound by contractual confidentiality obligations and are subject to disciplinary action for any breach.
7.4 Data Breach Notification
In accordance with Section 43 of the Kenya Data Protection Act, 2019, in the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, we shall:
- Notify the Office of the Data Protection Commissioner (ODPC) within seventy-two (72) hours of becoming aware of the breach;
- Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms;
- Document the breach, its effects, and the remedial actions taken;
- Cooperate with the ODPC in any investigation or inquiry relating to the breach.
Notification to affected data subjects will include a description of the nature of the breach, the likely consequences, the measures taken to address it, and recommendations for steps the data subject can take to protect themselves.
8. Data Sharing and Disclosure
We do not sell, trade, or rent your personal data to third parties. We may share your personal data only in the following limited circumstances:
8.1 Third-Party Service Providers
We engage trusted third-party service providers to assist us in operating the Platform and delivering our services. These service providers may have access to your personal data solely to perform specific tasks on our behalf and are contractually obligated to protect your data in accordance with this Policy and applicable law. Categories of service providers include:
- Payment processors (for processing subscription payments and transactions);
- Cloud hosting and infrastructure providers (for storing and serving Platform data);
- Analytics providers (for understanding usage patterns and improving the Platform);
- Email and communication service providers (for sending transactional and marketing emails, and planner alarm notifications);
- Customer support tools and platforms.
8.2 Legal Requirements
We may disclose your personal data where required to do so by law or in response to valid legal process, including:
- Court orders, subpoenas, or other compulsory legal process;
- Requests from law enforcement or regulatory authorities acting within their lawful authority;
- To protect the rights, property, or safety of Serrari Group Ltd, our users, or the public.
8.3 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or other corporate transaction involving Serrari Group Ltd, your personal data may be transferred as part of the transaction. In such event, we will ensure that the recipient entity is bound by obligations at least as protective as those set out in this Policy, and we will notify you of any such transfer.
8.4 With Your Consent
We may share your personal data with third parties where you have provided your explicit, informed consent to such sharing. You may withdraw your consent at any time.
8.5 No Sale of Personal Data
We do not sell your personal data. We have not sold personal data in the preceding twelve (12) months and do not intend to do so. Your financial information, account data, and usage data are never sold, licensed, or otherwise made available to third parties for their own commercial purposes.
8.6 Google API Services and Limited Use Compliance
Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, calendar data obtained through the Google Calendar API or Microsoft Graph Calendar API (see Section 4.7):
- Is used solely to power the Daily Planner and Calendar Sync feature described in Section 4.7 — nothing else;
- Is never used for advertising purposes of any kind, including any advertising displayed elsewhere on Serrari Group's websites or properties. Calendar data is never shared with, or made available to, our advertising or analytics providers;
- Is never sold, licensed, or transferred to any third party other than the service providers strictly necessary to operate the Calendar Sync feature (our encrypted cloud hosting provider);
- Is never used to train generalized artificial intelligence or machine learning models;
- Is permanently and immediately deleted from our systems when you disconnect the calendar integration.
9. International Data Transfers
The Platform is primarily operated from Kenya. However, some of the third-party service providers we use may process or store personal data in jurisdictions outside Kenya.
In accordance with Section 48 of the Kenya Data Protection Act, 2019, we will only transfer personal data to a country or territory outside Kenya where:
- The recipient country or territory has been determined by the ODPC to have adequate data protection safeguards;
- Appropriate safeguards have been put in place, including binding data processing agreements that incorporate standard contractual clauses approved by the ODPC;
- The data subject has given explicit, informed consent to the transfer after being informed of the possible risks;
- The transfer is necessary for the performance of a contract between the data subject and the Data Controller, or for pre-contractual measures taken at the data subject's request;
- The transfer is necessary for important reasons of public interest recognized under Kenyan law.
We ensure that all international data transfers are conducted in compliance with the DPA and that appropriate technical and organizational safeguards are in place to protect the confidentiality, integrity, and availability of the transferred data.
10. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required or permitted by applicable law. The specific retention periods for different categories of data are as follows:
10.1 Account Deletion
You may request deletion of your account at any time by contacting us at info@serrarigroup.com. Upon receipt of a valid account deletion request, we will:
- Delete or anonymize your personal data within thirty (30) days, except where retention is required by law;
- Remove your financial data from our active systems;
- Inform you of any data that must be retained for legal or regulatory purposes and the applicable retention period;
- Provide confirmation of deletion upon completion.
Please note that data stored in localStorage on your device is not controlled by us and must be deleted by you through your browser settings.
10.2 Connected Calendar Data
Calendar data obtained through a connected Google or Microsoft account is deleted immediately and permanently upon disconnection, independent of your overall account deletion timeline described above. Disconnecting a calendar also revokes the Platform's stored access token for that account where the provider supports revocation.
11. Your Rights
Under Part IV of the Kenya Data Protection Act, 2019, you have the following rights in relation to your personal data. We are committed to facilitating the exercise of these rights promptly and transparently.
11.1 Right to Be Informed (Section 26)
You have the right to be informed about the collection and use of your personal data. This Policy, together with any supplementary notices, serves to fulfil this obligation. You are entitled to know the identity of the Data Controller, the purposes of processing, the legal basis for processing, the categories of data collected, and any recipients of the data.
11.2 Right of Access (Section 26(b))
You have the right to request access to your personal data held by us. Upon a verified request, we will provide you with a copy of your personal data, the purposes for which it is being processed, the categories of data concerned, and any recipients to whom the data has been or will be disclosed. We will respond to access requests within thirty (30) days.
11.3 Right to Rectification (Section 26(c))
You have the right to request the correction of inaccurate personal data and the completion of incomplete personal data. You may update certain information directly through your account settings on the Platform, or you may contact us to request corrections.
11.4 Right to Deletion / Erasure (Section 26(d))
You have the right to request the deletion or erasure of your personal data where it is no longer necessary for the purpose for which it was collected, where you have withdrawn consent, where the data has been unlawfully processed, or where deletion is required by law. This right is subject to exceptions where retention is required for legal or regulatory compliance.
11.5 Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where the processing is unlawful but you do not wish the data to be deleted, or where you have objected to processing pending verification of our legitimate grounds.
11.6 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another data controller without hindrance, where the processing is based on consent or a contract and is carried out by automated means.
11.7 Right to Object to Processing (Section 26(e))
You have the right to object to the processing of your personal data where such processing is based on our legitimate interests. Upon receiving such an objection, we will cease processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defense of legal claims.
11.8 Right Not to Be Subject to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. The Platform does not currently engage in solely automated decision-making that produces legal or similarly significant effects.
11.9 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal. You may withdraw consent by adjusting your account settings, unsubscribing from communications, disconnecting a connected calendar account, or contacting us directly.
11.10 How to Exercise Your Rights
To exercise any of the rights described above, you may:
- Email us at info@serrarigroup.com with the subject line "Data Subject Rights Request";
- Use the account settings and privacy controls available on the Platform;
- Contact our Data Protection Officer using the details provided in Section 15 of this Policy.
We will respond to all valid requests within thirty (30) days. We may require verification of your identity before processing a request to ensure the security of your personal data.
12. Children's Privacy
The Serrari Wealth Builder™ Platform is not directed at, and is not intended for use by, persons under the age of eighteen (18) years. We do not knowingly collect personal data from children under the age of 18.
If we become aware that we have collected personal data from a child under the age of 18 without verifiable parental or guardian consent, we will take immediate steps to delete such data from our records. If you are a parent or guardian and believe that your child has provided personal data to us, please contact us at info@serrarigroup.com so that we can take appropriate action.
In the event that we introduce features specifically designed for users under 18 in the future, we will implement appropriate age verification mechanisms and obtain verifiable parental or guardian consent prior to collecting any personal data from such users, in accordance with applicable law.
13. Cookies and Tracking Technologies
This section provides detailed information about the cookies and tracking technologies used on the Platform.
13.1 What Are Cookies?
Cookies are small text files placed on your device by a website or application. They are widely used to make websites work more efficiently, to provide information to the owners of the site, and to enable certain features and functionality.
13.2 Types of Cookies We Use
Strictly Necessary Cookies: These cookies are essential for the Platform to function correctly. They enable core functionality such as user authentication, session management, and security features. These cookies cannot be disabled without impairing the Platform's operation.
Functional Cookies: These cookies allow the Platform to remember choices you make (such as your preferred language, currency, or display settings) and provide enhanced, personalized features.
Analytics Cookies: These cookies collect information about how you use the Platform, such as which pages you visit most often and whether you encounter error messages. This information is used to improve the Platform's performance and user experience. We may use third-party analytics services, such as Google Analytics, for this purpose.
localStorage: The Platform uses the browser's localStorage feature to store financial data, course progress, and user preferences directly on your device. This enables faster load times and offline access to certain features. Data stored in localStorage is not automatically transmitted to our servers.
13.3 Managing Your Cookie Preferences
You can manage or delete cookies through your browser settings. Most browsers allow you to:
- View the cookies stored on your device;
- Delete individual cookies or all cookies;
- Block cookies from specific or all websites;
- Set preferences for certain types of cookies.
Please note that disabling or deleting certain cookies may affect the functionality of the Platform. Clearing your browser's localStorage will result in the loss of locally stored financial data and course progress.
14. Changes to This Policy
We reserve the right to update or modify this Policy from time to time to reflect changes in our data processing practices, legal requirements, or the features and functionality of the Platform.
When we make material changes to this Policy, we will:
- Update the "Effective Date" at the top of this Policy;
- Publish the revised Policy on the Platform;
- Notify you of material changes through a prominent notice on the Platform or by email to the address associated with your account;
- Where required by law, seek your consent to the revised Policy before continuing to process your data under the new terms.
Your continued use of the Platform after the effective date of any revised Policy constitutes your acceptance of the updated terms. We encourage you to review this Policy periodically to stay informed about how we protect your personal data.
15. Data Protection Officer
In accordance with the requirements of the Kenya Data Protection Act, 2019, Serrari Group Ltd has designated a Data Protection Officer ("DPO") who is responsible for overseeing our data protection strategy, ensuring compliance with the DPA, and serving as the primary point of contact for data protection matters.
You may contact the Data Protection Officer using the following details:
- Email: info@serrarigroup.com (subject line: "Data Protection Officer");
- Address: No. 3 Ridgeways Palms, Ridgeways Lane, P.O. Box 73188-00200, Nairobi, Kenya;
- Telephone: +254 713 600 713.
The DPO is authorised to respond to enquiries regarding the processing of personal data, data subject rights requests, data breach notifications, and any other matters relating to this Policy.
16. Complaints and Disputes
16.1 Internal Complaint Process
If you have a concern or complaint about how we handle your personal data, we encourage you to first contact us directly so that we can attempt to resolve the matter. You may submit a complaint by emailing info@serrarigroup.com with the subject line "Privacy Complaint".
Upon receipt of a complaint, we will acknowledge it within seven (7) business days and endeavour to provide a substantive response within thirty (30) days. Our response will include an explanation of our findings and any corrective actions taken or proposed.
16.2 Right to Lodge a Complaint with the ODPC
If you are not satisfied with our response to your complaint, or if you believe that we have violated your data protection rights, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya.
- Office of the Data Protection Commissioner (ODPC), Kenya
- Website: www.odpc.go.ke
- Email: info@odpc.go.ke (or enquiries@odpc.go.ke)
- Telephone: 020 780 1800, 0796 954 269, or 0752 896 867
- Address: Britam Tower, 12th & 13th Floor, Hospital Road, Upper Hill, P.O. Box 30920-00100 GPO, Nairobi, Kenya
- Complaints may also be filed directly through the ODPC's e-services portal on their website.
16.3 Dispute Resolution
Any disputes arising out of or in connection with this Policy that cannot be resolved through the internal complaint process or through the ODPC shall be subject to the exclusive jurisdiction of the courts of the Republic of Kenya. The parties agree to attempt mediation before initiating formal legal proceedings.
17. Contact Us
If you have any questions, comments, or concerns about this Policy or our data protection practices, please contact us at:
- Serrari Group Ltd
- Email: info@serrarigroup.com
- Address: No. 3 Ridgeways Palms, Ridgeways Lane, P.O. Box 73188-00200, Nairobi, Kenya
- Telephone: +254 713 600 713
For data protection enquiries specifically, please use the subject line "Data Protection Enquiry" to ensure your message is routed to the appropriate team.