1. Who We Are
GoatVest Africa Limited (KRA PIN: P052538879F) operates the GoatVest platform at goatvest.africa. We are the data controller for personal data collected through the Platform.
Contact: support@goatvest.africa
2. Data We Collect
Account data: full name, email address, phone number, role (Investor/Farm/Vet).
KYC data: national ID or passport number, selfie photo, business registration documents (Farm Partners).
Financial data: M-Pesa phone number, transaction amounts and references, Bell Credits balance and history, Cash Earnings balance and history. We do not store M-Pesa PIN or card numbers.
Animal and farm data: photos, milk records, health records, breeding records, location coordinates.
Usage data: pages visited, auction activity, bid history, login times, IP address, device type.
Communications: support tickets, platform announcements you read.
3. How We Use Your Data
- To operate your account and provide Platform services.
- To process mobile money deposits and withdrawals via our licensed payment processor.
- To verify your identity (KYC) and comply with AML regulations.
- To calculate and pay GMA milk income.
- To send transactional notifications (bid alerts, payout credits, auction outcomes).
- To detect and prevent fraud and money laundering.
- To comply with legal obligations including POCAMLA and the Data Protection Act 2019.
- To improve the Platform through aggregated, anonymised analytics.
4. Legal Basis for Processing
- Contract performance: processing your transactions, issuing certificates, paying milk income.
- Legal obligation: KYC, AML reporting, 7-year record retention.
- Legitimate interest: fraud prevention, platform security, aggregated analytics.
- Consent: marketing communications (opt-in only).
5. Data Sharing
We share data only with:
- Our licensed mobile money processor: for deposit and withdrawal transaction processing.
- Our SMS notification service provider: for transactional alerts and notifications.
- Our cloud database and infrastructure provider: for data storage and authentication (data processed in accordance with applicable international data transfer safeguards).
- Our web hosting and content delivery provider: for serving the Platform to users.
- Our application monitoring service provider: for error tracking and platform stability (PII and financial data are redacted before sending).
- Financial Reporting Centre (FRC): where legally required by POCAMLA.
- Kenyan law enforcement: where required by court order or statutory duty.
We do not sell personal data. We do not share data with advertisers.
6. Data Retention
| Data type | Retention period |
|---|---|
| Account data | Duration of account + 7 years |
| KYC documents | 7 years from collection |
| Financial records | 7 years from transaction date |
| Health and milk records | Duration of GMA + 3 years |
| Usage logs | 12 months rolling |
7. Your Rights (Data Protection Act 2019)
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request erasure (subject to legal retention requirements).
- Object to processing for marketing purposes.
- Data portability (receive your data in a structured format).
To exercise these rights, email support@goatvest.africa. We will respond within 30 days.
8. Security
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.2+) and at rest.
- Row-level security on all database tables.
- Redaction of PII and financial data in error logs.
- Regular security reviews and backups.
- Admin audit logging for all sensitive operations.
No method of electronic transmission or storage is 100% secure. In the event of a data breach affecting your rights, we will notify you and the Office of the Data Protection Commissioner within 72 hours.
9. Cookies
The Platform uses essential cookies for authentication session management. We do not use third-party advertising cookies. Analytics cookies (provided by third-party web analytics services) are used only if you consent and only when the service is active.
10. Children
The Platform is not directed at persons under 18. We do not knowingly collect data from minors. If you believe a minor has registered, contact us immediately.
11. Changes to This Policy
We will notify you of material changes via the Platform with at least 14 days' notice. The effective date at the top of this page reflects the most recent update.
12. Contact and Complaints
GoatVest Africa Limited
Email: support@goatvest.africa
You have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya at odpc.go.ke.