Pangisha
Legal centreTermsPrivacy

Data Processing Addendum

How we process customer data.

This DPA applies when a Customer uses Pangisha to manage tenant, building, rent, invoice, payment, notice or portfolio records.

Effective date: 18 June 2026. This DPA forms part of the Pangisha Terms for Customers who upload or manage personal data through the service.

1. Roles

The Customer is the data controller for Customer Data when the Customer decides why and how that data is used. Pangisha is the data processor for that Customer Data and processes it to provide, secure and support the service. Pangisha may be an independent controller for its own account, billing, security, diagnostics and business records.

2. Processing Instructions

Pangisha will process Customer Data only on documented Customer instructions, including these Terms, the Customer's settings, support requests and lawful use of features, unless the law requires something else. If an instruction appears unlawful, Pangisha will tell the Customer unless the law prevents us from doing so.

3. Subject Matter and Categories

ItemDescription
PurposeProvide property management, tenant records, rent tracking, payment status, notices, invoices, subscription administration, reports and support.
Data subjectsCustomers, admins, landlords, property managers, tenants, occupants, guarantors or emergency contacts where entered by a Customer, and support contacts.
Data categoriesNames, email, phone, ID number, unit number, building name, rent amount, balance, payment references, messages, notices, invoice records, logs and account metadata.
DurationFor the subscription term and the retention period described in the Data Retention and Deletion Policy, unless law or a written agreement requires otherwise.

4. Confidentiality and Security

Pangisha will limit access to Customer Data to people and providers who need it to run the service and are bound by confidentiality duties. Pangisha will maintain practical security measures, including access controls, password hashing, provider secret storage, session controls, logging, backup controls and secure development practices.

5. Sub-processors

The Customer allows Pangisha to use sub-processors needed to run the service, such as hosting, security, email, payment, messaging, analytics, storage and support providers. Current categories include Cloudflare hosting/security, email delivery providers, M-Pesa service providers, Paystack, WhatsApp or messaging relay providers where enabled, and professional support providers.

Pangisha remains responsible for sub-processors under this DPA and will require them to protect Customer Data under written obligations suited to the work they perform.

6. Data Subject Requests

If Pangisha receives a data subject request about Customer Data, we may direct the request to the Customer and provide reasonable help. The Customer remains responsible for deciding how to respond when it is the controller.

7. Personal Data Breaches

Pangisha will notify the affected Customer without undue delay after becoming aware of a personal data breach involving Customer Data. We will share the information reasonably needed for the Customer to assess notification duties and reduce harm. Customers are responsible for regulator and data subject notifications where they are the controller, with Pangisha's reasonable help.

8. International Transfers

Where Customer Data is transferred outside Kenya, Pangisha will use lawful transfer routes such as appropriate contractual safeguards, service-delivery necessity, consent where applicable, or other protections recognised by law.

9. Return and Deletion

When a subscription ends, Pangisha will allow reasonable export or return of Customer Data where technically available. Pangisha may then delete, anonymise or archive data under the Data Retention and Deletion Policy, except where law, disputes, accounting or security duties require us to keep it longer.

10. Audit and Information

Pangisha will provide reasonable information to show compliance with this DPA. Formal audits must be requested in writing, limited to once per year unless required by a regulator or incident, carried out during business hours, and handled under confidentiality and operational security limits.

Pangisha by G&G MarketingLegal centre