1. Purpose and scope
This notice explains how Kapolly handles personal data when a person visits Kapolly.com, creates an account, completes identity checks, funds an account, trades, contacts support, submits a complaint, or otherwise uses Kapolly services.
Kapolly is designed to operate country by country. Privacy rights and legal duties may therefore differ by location. Where local law gives a person stronger rights than this notice, the stronger local protection applies.
2. Who is responsible for your data
For purposes of this notice, “Kapolly”, “we”, “us” and “our” mean Kapolly Ltd. Kapolly Ltd is responsible for the personal data it processes in providing the services described in this notice, subject to any additional country-specific notice required by law.
Privacy questions and data rights requests may be sent to ta@africacyberai.org. You may also complain to the data protection authority that has jurisdiction over your complaint. In Kenya, this is the Office of the Data Protection Commissioner.
3. Personal data we may collect
| Category | Examples |
|---|---|
| Account and contact data | Name, email address, phone number, date of birth, country of residence, citizenship, account identifiers and communication preferences. |
| Identity and compliance data | Government identification details, document images, selfie or photograph where required, address, source of funds information, sanctions and politically exposed person screening results, KYC review history and risk classifications. |
| Trading and financial data | Deposits, withdrawals, balances, orders, cancellations, fills, positions, fees, settlements, payment references, transaction status and reconciliation information. |
| Device and security data | IP address, device and browser information, session identifiers, login history, approximate location, security events, anti abuse signals and account linking indicators. |
| Market integrity data | Trading patterns, order activity, linked account indicators, market restrictions, insider or source conflict flags, investigation records and enforcement history. |
| Support and communications | Support tickets, complaints, correspondence, documents supplied to us, call or message records where recording is lawful and disclosed. |
| Website and analytics data | Pages viewed, navigation events, search activity, referral information, cookie identifiers and service performance data. |
4. How we obtain personal data
We receive data directly from you, automatically from your use of the platform, from payment and identity providers, from public or licensed compliance sources, from regulators or law enforcement where lawful, and from other persons where necessary to investigate fraud, market abuse or account security.
If an external sign-in provider is enabled, Kapolly receives only the identity information authorised for that sign-in. Kapolly keeps its own account, trading and compliance records.
5. Why we use personal data
- Create and administer accounts and authenticate users.
- Determine country, age, KYC and product eligibility.
- Process deposits and withdrawals and reconcile payment rail activity.
- Accept, match, record and settle orders and positions.
- Operate market rules, determine outcomes and maintain an auditable settlement record.
- Detect fraud, sanctions exposure, account abuse, manipulation, insider activity and other market integrity risks.
- Protect users, the platform and third parties from security threats.
- Provide support, handle complaints and resolve trade queries.
- Comply with legal, regulatory, tax, accounting, audit and record keeping obligations.
- Improve service reliability, usability, market education and product design.
- Send service notices and, where permitted, marketing communications that a user can control.
6. Legal grounds for processing
Depending on the law that applies, Kapolly may process personal data because it is necessary to perform a contract with you, comply with a legal or regulatory obligation, pursue a legitimate interest that does not override your rights, protect vital or public interests, establish or defend legal claims, or because you have given valid consent.
Where we rely on consent, you may withdraw it for future processing. Withdrawal does not make prior lawful processing invalid and may mean that a feature cannot continue where the data is necessary to provide that feature.
7. Special or sensitive information
Identity documents, biometric style images, financial information, political exposure indicators and other regulated categories may receive enhanced protection. Kapolly will collect such data only where it is required for a lawful purpose and will restrict access to personnel with an authorised need.
8. Who we may share data with
| Recipient type | Purpose |
|---|---|
| Infrastructure and security providers | Hosting, content delivery, storage, security, logging and service resilience. |
| Identity providers | Authentication and sign-in where an external identity provider is enabled. |
| Payment providers and financial institutions | Payment initiation, collection, payout, reconciliation and related banking or safeguarding services where enabled. |
| Compliance and verification providers | Identity, sanctions, politically exposed person, fraud and source of funds checks where approved for the relevant jurisdiction. |
| Professional advisers and auditors | Legal, compliance, tax, accounting, security, assurance and dispute support. |
| Regulators, courts and public authorities | Where disclosure is required, authorised or reasonably necessary under applicable law. |
| Corporate transaction counterparties | If Kapolly is reorganised, financed, sold or combined, subject to confidentiality and applicable data protection requirements. |
9. International transfers
Kapolly may use infrastructure or service providers located outside the country where a user lives. We will not treat a user’s acceptance of ordinary platform terms as a substitute for any transfer safeguard required by law.
For data transferred from Kenya, Kapolly will document and rely on a permitted transfer basis, such as appropriate safeguards, an adequacy decision, legal necessity or valid consent where the law permits that basis. Sensitive data will receive any additional protection required by law.
10. Retention
Kapolly keeps personal data only for as long as reasonably necessary for the purpose for which it was collected and for any additional period required by law, regulation, audit, dispute preservation, fraud prevention or market integrity obligations.
Kapolly keeps records only for as long as reasonably necessary for the purpose for which they were collected and for any additional period required by law, regulation, audit, dispute preservation, fraud prevention or market integrity obligations. When retention is no longer justified, data is securely deleted, anonymised or placed beyond ordinary operational use, subject to lawful archive requirements.
11. Security
- Encryption in transit and appropriate encryption at rest.
- Role based access and least privilege for identity and KYC documents.
- Strong authentication and session controls for staff and higher risk actions.
- Audit logging for account restrictions, KYC decisions, market operations and financial events.
- Separation of trading, financial ledger, operational records and analytics domains.
- Secure backups, incident response, vulnerability management and recovery testing.
12. Cookies and similar technologies
Kapolly may use strictly necessary cookies and similar technologies for authentication, security, preferences and platform operation. Analytics or marketing technologies will be used only in accordance with the consent and notice requirements that apply in the user’s country.
Users may be able to control optional cookies through a consent tool or browser settings. Blocking essential cookies may prevent account or security functions from working.
13. Your privacy rights
- Ask whether Kapolly holds personal data about you and obtain access where applicable.
- Ask us to correct inaccurate or incomplete information.
- Request deletion where the law provides that right and no overriding retention duty applies.
- Object to or restrict certain processing.
- Withdraw consent where consent is the legal basis.
- Request portability where applicable.
- Ask for information about significant automated processing and challenge a decision where applicable.
- Complain to the relevant data protection authority.
14. Automated assistance and human decisions
Kapolly may use automated tools to help detect anomalies, extract information from documents or support staff review. Where a decision requires human or independent review under Kapolly policy or applicable law, the automated tool does not replace that review.
15. Children and age restricted access
Kapolly is not intended for children. Live trading will be available only to persons who meet the minimum legal age and eligibility requirements configured for their country. If we learn that personal data was collected from a person who is not eligible to hold an account, we may restrict the account and take appropriate deletion or preservation steps required by law.
16. Changes to this notice
We may update this notice when our services, providers, laws or regulatory obligations change. Material changes will be dated and, where required, notified before they take effect. We will request fresh consent where law requires consent for a new purpose.
Kapolly Ltd is responsible for the personal data it processes in providing Kapolly services. Privacy questions and data rights requests may be sent to ta@africacyberai.org.