Loading...
Legal
How Lakisa Assetlink Finance collects, uses, shares and protects your personal information, and your rights under the Data Protection Act, 2019.
Last updated: 2 September 2026
Before this page goes live
This is a professionally-structured first draft generated from how Lakisa Assetlink Finance operates. It must be reviewed by an advocate admitted in Kenya before Lakisa Assetlink Finance relies on it. Replace every placeholder:
[Registered company name — e.g. Lakisa Assetlink Finance Limited][Company registration number][ODPC registration number][Data Protection Officer — name & email, e.g. dpo@lakisa.co.ke][Retention periods for loan, shop, sell-your-item and enquiry records][Confirm which service providers process data outside Kenya and the safeguards used][If analytics or marketing tools are added later, update the Cookies section and add a consent banner]Lakisa Assetlink Finance is the trading name of [Registered company name — e.g. Lakisa Assetlink Finance Limited], a company registered in Kenya (registration number [Company registration number]), with its registered office at Fedha Estate, Embakasi, Nairobi, Kenya.
For the personal data described in this policy, Lakisa Assetlink Finance is the data controller under the Data Protection Act, No. 24 of 2019 (Kenya) (the “DPA”). We are registered with the Office of the Data Protection Commissioner (“ODPC”) under [ODPC registration number].
Our Data Protection Officer can be reached at [Data Protection Officer — name & email, e.g. dpo@lakisa.co.ke].
This policy explains what personal data we collect, why, how we use and share it, how long we keep it, and the rights you have.
We do not knowingly collect personal data from anyone under 18 years of age.
We use your personal data for the purposes below. Next to each is our lawful basis under section 30 of the DPA.
Our loan decisions are not made solely by automated means — a member of our team reviews every application.
Some of our service providers may process data outside Kenya. Where that happens we take the steps the DPA requires — for example confirming the destination offers adequate protection, putting appropriate contractual safeguards in place, or relying on your consent — so your data stays protected. Confirm which providers process data outside Kenya and the safeguards used.
We keep personal data only for as long as we need it for the purpose we collected it, then delete or anonymise it.
We use technical and organisational measures appropriate to the risk: access limited to staff who need it, secure premises for stored collateral, encryption of data in transit, and confidentiality obligations on our team and service providers.
No system is completely secure. If a breach affects your rights and freedoms, we will notify you and the ODPC as the DPA requires.
You have the right to:
To exercise any of these rights, contact us using the details in “How to contact us” below. We will respond within the time the DPA allows and may need to verify your identity first. Some rights have limits — for example, we may keep data we are legally required to retain.
We may update this policy from time to time. The “Last updated” date at the top shows when it last changed, and we will highlight significant changes on this page. Please check back periodically.
Questions? Contact us or email info@lakisa.co.ke.