Who we are
AgroDash Limited ("AgroDash", "we", "us") is a Kenyan-incorporated agricultural marketplace operator. For privacy questions, contact our Data Protection Officer at info@agro-dash.org or +254 113 823 499.
We act as the data controller for the personal data of users who sign up directly with us. Where we process data on behalf of a partner institution under a written agreement, the partner is the controller and we act as the data processor.
1. Categories of data we handle
We collect only what is necessary to operate the marketplace, settle payments, and meet our regulatory obligations.
- Account & identity — name, email, phone number, authentication credentials (stored in a non-recoverable form), and demographic basics.
- KYC & KYB — government-issued identification, tax registration, business-incorporation evidence where applicable, beneficial-ownership disclosures, sector licences, and a recent photo.
- Location & farm data — county and sub-county of operation, farm boundaries, and crop information you choose to record.
- Financial — payout instrument details (bank or mobile money), transaction history, escrow ledger entries, invoices, and receipts. Card payment details are never stored on our infrastructure — they are entered directly into our payment partner's secure form, and we receive only a tokenised reference and the masked PAN.
- Marketplace activity — listings, orders, ratings, reviews, dispute filings, and delivery confirmations.
- Compliance & quality — certification documents, lab and inspection results, audit findings.
- Device & usage — IP address, browser, device type, and how you interact with the platform. Used for security and abuse prevention.
- Communications — messages you send through our support channels and notification preferences.
2. Why we handle it (lawful bases)
Under section 30 of the Data Protection Act, every processing activity has a named lawful basis. Ours are:
- Performance of a contract — fulfilling your orders, holding funds in escrow, releasing payouts, issuing receipts, processing refunds.
- Compliance with a legal obligation — anti-money-laundering checks, sanctions screening, suspicious-transaction reporting where the law requires it, tax-record retention, and agricultural-traceability obligations.
- Legitimate interests — fraud prevention, marketplace abuse detection, platform security, and aggregated, de-identified analytics.
- Consent — for marketing emails, SMS broadcasts, and any optional third-party data sharing. You can withdraw consent at any time without affecting the lawfulness of processing before the withdrawal.
- Public interest / vital interest — food-safety incidents that require notifying competent regulators.
3. Categories of recipients
We do not sell personal data. We share it only with the categories of recipient listed below, only for the purpose stated, and only under a written agreement that obliges them to handle it lawfully.
- Payment processors and settlement banks — to authorise, settle, and refund transactions; reconcile our books; and operate our escrow account.
- Communications providers — to deliver transactional email, SMS, and in-app notifications you initiate or that the platform is contractually obliged to send.
- Cloud-infrastructure providers — to host the platform's servers, database, and file storage. They operate the infrastructure under standard data-processing terms; they do not access your data for their own purposes.
- Compliance and verification partners — to validate identity documents, tax registration, sector-specific licences, and to screen against internationally recognised sanctions lists. Limited to the data needed for the specific check.
- Law-enforcement and regulatory bodies — where compelled by court order or required by law (anti-money-laundering authorities, tax authorities, sector regulators).
- Certified auditors and certification bodies — when you apply for a certification, the granted auditor sees a scoped, time-bound view of the records that prove your compliance.
- Insurance partners — when you hold a policy with a partner carrier, the carrier receives the policy and claim data needed to underwrite and settle claims.
- Financial institutions you transact with — when you apply for finance through the platform, the institution receives the trade and KYC data it needs to assess and document the facility.
- Successors — in the event of a merger, acquisition, or asset sale, your data may transfer to the successor entity, subject to this policy or an equally protective successor.
The specific list of partners we work with at any given time is available on request.
4. Cross-border transfers
Where personal data leaves Kenya, we rely on one of the conditions in section 48 of the Data Protection Act: an adequacy finding by the Office of the Data Protection Commissioner, contractual safeguards equivalent to those in the Act, or your explicit consent for a specific transfer. Our primary infrastructure is hosted within Africa where feasible.
5. How long we keep it
- Account & KYC — for the life of your account, plus seven (7) years after closure to meet anti-money-laundering, tax, and audit-defensibility requirements.
- Transaction records — at least seven (7) years from the date of the transaction.
- Compliance audit records — at least ten (10) years for certified-trade evidence (where regulations such as the EU Deforestation Regulation apply).
- Marketing data — until you withdraw consent or two (2) years after your last interaction, whichever is sooner.
- Device logs — short-lived; longer only if needed for an active investigation.
When the retention period ends, we delete or anonymise the data so it can no longer be linked back to you.
6. Your rights
Under sections 26–35 of the Data Protection Act, you have the right to:
- Be informed of the use to which your personal data is to be put.
- Access your data and request a copy.
- Object to the processing of all or part of your data.
- Correct false or misleading data.
- Have data deleted that is false, misleading, or unlawfully obtained — or that we no longer have a basis to keep.
- Restrict processing in certain circumstances.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, where consent is the basis we rely on.
- Lodge a complaint with the Office of the Data Protection Commissioner.
To exercise any of these rights, email info@agro-dash.org with the subject line "Privacy Request" and the right you wish to exercise. We will respond within the timelines set by the Act. We may need to verify your identity before acting — this protects your data from being released to someone else.
7. How we protect it
We apply organisational and technical safeguards proportionate to the risk and sensitivity of the data:
- Encryption of personal data in transit and at rest, using current industry standards.
- Authentication credentials stored in a non-recoverable form.
- Card payment data is captured only inside our payment partner's secure environment and never reaches our systems.
- Role-based access controls; staff access to user data is restricted to what their role requires and logged.
- An append-only audit trail of privileged actions.
- A written incident-response plan; in the event of a breach affecting your personal data, we will notify you and the Office of the Data Protection Commissioner within the timelines required by the Act.
No system is perfectly secure. If you believe your account has been compromised, contact us immediately at info@agro-dash.org.
8. Children
AgroDash is not intended for use by anyone under 18. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it.
9. Cookies & similar technologies
We use a small set of cookies and similar technologies that are necessary to keep you signed in, prevent cross-site request forgery, and understand platform usage in aggregate. We do not use third-party advertising trackers. You can clear cookies in your browser at any time — the only consequence is that you will be signed out and need to sign in again.
10. Changes to this policy
We update this policy when our practices change. The "Last updated" date at the top reflects the most recent revision. For material changes we will email registered users and post a banner on the platform at least 14 days before the change takes effect.
11. Contact
Data Protection Officer
AgroDash Limited
Thika, Kenya
Email: info@agro-dash.org
Phone: +254 113 823 499 · +254 743 351 000
If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya.