Data Processing Addendum
How we process customer data.
This DPA applies when a Customer uses Pangisha to manage tenant, building, rent, invoice, payment, notice or portfolio records.
Effective date: 18 June 2026. This DPA forms part of the Pangisha Terms for Customers who upload or manage personal data through the service.
1. Roles
The Customer is the data controller for Customer Data when the Customer decides why and how that data is used. Pangisha is the data processor for that Customer Data and processes it to provide, secure and support the service. Pangisha may be an independent controller for its own account, billing, security, diagnostics and business records.
2. Processing Instructions
Pangisha will process Customer Data only on documented Customer instructions, including these Terms, the Customer's settings, support requests and lawful use of features, unless the law requires something else. If an instruction appears unlawful, Pangisha will tell the Customer unless the law prevents us from doing so.
3. Subject Matter and Categories
| Item | Description |
|---|---|
| Purpose | Provide property management, tenant records, rent tracking, payment status, notices, invoices, subscription administration, reports and support. |
| Data subjects | Customers, admins, landlords, property managers, tenants, occupants, guarantors or emergency contacts where entered by a Customer, and support contacts. |
| Data categories | Names, email, phone, ID number, unit number, building name, rent amount, balance, payment references, messages, notices, invoice records, logs and account metadata. |
| Duration | For the subscription term and the retention period described in the Data Retention and Deletion Policy, unless law or a written agreement requires otherwise. |
4. Confidentiality and Security
Pangisha will limit access to Customer Data to people and providers who need it to run the service and are bound by confidentiality duties. Pangisha will maintain practical security measures, including access controls, password hashing, provider secret storage, session controls, logging, backup controls and secure development practices.
5. Sub-processors
The Customer allows Pangisha to use sub-processors needed to run the service, such as hosting, security, email, payment, messaging, analytics, storage and support providers. Current categories include Cloudflare hosting/security, email delivery providers, M-Pesa service providers, Paystack, WhatsApp or messaging relay providers where enabled, and professional support providers.
Pangisha remains responsible for sub-processors under this DPA and will require them to protect Customer Data under written obligations suited to the work they perform.
6. Data Subject Requests
If Pangisha receives a data subject request about Customer Data, we may direct the request to the Customer and provide reasonable help. The Customer remains responsible for deciding how to respond when it is the controller.
7. Personal Data Breaches
Pangisha will notify the affected Customer without undue delay after becoming aware of a personal data breach involving Customer Data. We will share the information reasonably needed for the Customer to assess notification duties and reduce harm. Customers are responsible for regulator and data subject notifications where they are the controller, with Pangisha's reasonable help.
8. International Transfers
Where Customer Data is transferred outside Kenya, Pangisha will use lawful transfer routes such as appropriate contractual safeguards, service-delivery necessity, consent where applicable, or other protections recognised by law.
9. Return and Deletion
When a subscription ends, Pangisha will allow reasonable export or return of Customer Data where technically available. Pangisha may then delete, anonymise or archive data under the Data Retention and Deletion Policy, except where law, disputes, accounting or security duties require us to keep it longer.
10. Audit and Information
Pangisha will provide reasonable information to show compliance with this DPA. Formal audits must be requested in writing, limited to once per year unless required by a regulator or incident, carried out during business hours, and handled under confidentiality and operational security limits.