Skip to main content

Privacy Policy

  1. Introduction
    1. Koro (a brand of Zenka Digital Limited) is a digital credit provider specialized in consumer lending. With Koro App you can use our Services and apply for a consumer loan.
    2. Koro App greatly simplifies the process of obtaining a loan by allowing you to borrow loan amounts according to the internal credit policy that you qualify for, within the allowed limits. Koro App is making it by using your data as contained in your device and Koro’s App algorithms to identify you, verify your identity, assess your creditworthiness, credit risk, create a credit score for you and to comply with applicable laws, regulations, and rules, such as those relating to KYC (know-your-customer) and anti-money laundering requirements, also to analyze your behavior and to detect and prevent fraud and other illegal uses of our services.
    3. This Policy explains what personal information we collect, how the data is shared, and you can inform us to not share certain information with certain third parties.
    4. Please read the following Policy. If you have any questions, feel free to contact us in accordance with the Policy procedures.
  2. Consent
    Please be informed that, by downloading the Koro App, you hereby give the following consent:
    I consent to the collection and processing of my personal information for legitimate business purposes, included but not limited to determining my credit score and providing a loan.
    I hereby certify that all the provided information is true and correct to the best of my knowledge, and that I will immediately notify Koro of any inaccuracies in the data provided.
    At the same time I authorize Koro to verify and investigate the above statements and provided information. For this purpose, I consent to the processing of any personal information and records relating to me that might be obtained from third parties, including government agencies, employer, credit bureaus, business associates and other entities you may deem proper and sufficient in the conduct of the proper verification process.
    By giving your consent and downloading the Koro app, you allow Koro to collect and process personal data in accordance with Consent, under Section 30(1)(a) of the Act as a legal basis for processing and collecting your personal data. Further on, your data may be processed, considering multiple legal basis, such as – consent, performance of the contract, the legitimate interest of the company, fulfillment of legal obligation etc.
  3. Definitions
    1. Compliance Obligations means Koro’s legal obligation in particular imposed by the local and international law, internal policies or procedures;
    2. Consumer means any natural person with its resident at territory of Republic of Kenya to which Koro provides its products or services;
    3. Consumer Information means Consumer Personal Data, confidential information, tax information, information concerning the Consumer, Consumer’s transactions, use of Koro’s products and services and history relation with Koro;
    4. Mobile Money Services Providers means a mobile network operator that has been duly authorized by the Central Bank of Kenya under applicable laws to offer mobile money services in Kenya;
    5. Personal Data means any information concerning the individual who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic etc. whether recorder in a material form or not;
    6. Policy means this Privacy Policy of Koro (that is a brand of Zenka Digital Limited);
    7. Sensitive Consumer Personal Data means data revealing the natural person’s race, health status, ethnic social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details including names of the person’s children, parents, spouse or spouses, sex or the sexual orientation;
    8. Services means services offered by Koro in particular via Koro App during the relation established between Koro and the Customer;
    9. System means Koro’s electronic communications and payments software and, mobile and USSD applications enabling you to communicate with Koro for purposes of the Services;
    10. Terms and Conditions means loan terms and conditions used by Koro to conclude the loan agreement with the Consumer;
    11. Koro- means a brand of Zenka Digital Limited with its registered seat in Nairobi, Kenya, the register number PVT-EYU82X2;
    12. Koro App- means Koro’s mobile application available on our site or hosted on the Google Play Store.
    13. Sun Finance Group means capital group which Koro is part of.
  4. Consumer Information that we collect
    1. Your privacy and personal information are of utmost concern to us. We consider your privacy to be very important and would never share your personal information without your explicit consent and in any unlawful manner.
    2. We use your personal data to provide our Services, improve the quality of Services and products offered, send notifications, offers and promotional materials, protect our rights and interests as well as the rights and interests of third parties, and comply with generally applicable laws.
    3. We may collect, use, store and share Consumer Information different kinds of personal data about you which we have grouped together as follows:
      1. Identity Data includes first name, last name, maiden name, photograph, username or similar identifier, marital status, title, date of birth, gender, identity document type, number, and age.
      2. Contact Data includes billing address, delivery address, email address and telephone numbers.
      3. Financial Data includes bank account, payment card details and codes or other banking information.
      4. Transaction Data includes details about payments to and from you and details of transactions.
      5. Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
      6. Profile Data includes your username and password, transaction history, your interests, preferences, feedback and survey responses, name, family details, age, profiling information such as level of education, bank account status, income brackets, credit information etc. collected by Koro and their agents on behalf of Koro.
      7. Usage Data includes details of your use of any of our Apps or your visits to any of Our Sites including, but not limited to, traffic data and other communication data, whether this is required for our own purposes or otherwise and the resources that you access.
      8. Marketing and Communications includes Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
    4. Consumer Information will be requested directly by Koro or they may be collected from you directly, from the person acting on your behalf, from other relevant sources including non-public and publicly available information and they may be combined or generated with other information available to Koro or any Koro’s members Group.
    5. To use our services, you must be at least 18 years of age. We have incorporated appropriate technical mechanisms for age verification upon registration on Koro App, therefore we do not in any way process, collect or store in our systems any personal data related to the child. A child by Kenyan law is anyone below the age of 18 years as defined in the Children Act No. 8 of 2001 and as such the age of consent is 18 years.
    6. Please be informed that we may collect the following Consumer Information via our getaway https://endpoint.koro.co.ke:
      1. information received directly from you;
      2. provided by filling our registration forms which are integral part of using our Services via Koro App;
      3. provided during corresponding with us by chat, e-mail, phone, sms, ussd messages;
      4. provided when you enter a competition, promotion, surveys and reporting any technical issues related to the Koro App or our Services;
      5. participate in discussion groups, when you use social media as facebook, Instagram,
      6. communicate with us using the above-mentioned methods with any other reason than mentioned above;
      7. including but not limited to your name, surname, address, e-mail address, phone number, mobile phone number, your ID data, password, financial or credit information, personal description or photography, employer name and address, date of birth, sex, marital status, employment status, work phone number, monthly income and expenses, content of your sms saved on your mobile, bank account number, transactions on bank accounts, description, signature, localization, contact list and any other information you would provide to us.
    7. Information that we are collecting in regard to you and used devices:
      1. concerning the technical details of the device through which you have opened our website or for which our Koro App has been downloaded, including information of the kind of the devices (IMEI or serial number) that you use to connect with our website or Koro App, data from internet service providers, IP address and we have also data about your login to your personal profile created in Koro (which is equal to the mobile phone number), information about SIM card used in your device, mobile network information, operation system used by your device, the type of used browser, device location and time zone settings;
      2. information stored on your device concerning contact list, call logs, SMS logs;
      3. information of your use of Koro’s App or your visits on our website including location data or weblogs.
      4. localizations of your device. Please be advised that we can use GPS technology or other location services to determine your localization while using Koro App. We have to be sure that you are using Koro App from the territory of Kenya and at the same it will allow us to prevent eventual frauds or improper use of our Services and to fulfill obligations arising from the anti-money laundering regulation.
      5. information obtained from third parties. Koro cooperates with the external partners including but not limited to the credit reference bureaus, mobile network providers and collection agencies. We put our efforts to limit the number of such partners to the necessary minimum.
      6. Koro’s unique application numbers which are generated during installation or uninstallation of our Koro App.
    8. Please be informed that we may from time to time send you push/sms notifications or we can call on your mobile number, or send you e-mail (if any) concerning marketing messages or other information related to our Services or transactions. You have the right to opt-out from receiving this type of notification at any time by any means specially by sending an SMS to the number: +254207650878 or an e-mail to dpo@koro.co.ke with the message: stop.
    9. If you use the Services, you consent (and to our affiliates’ and licensees’) to the transmission, collection, sharing, disclosure, retention, maintenance, processing, and use of your data for credit scoring services or to improve our Services or your experience while using the Koro App. The processing of your data will be done in accordance with this Policy, the provisions of Terms and Conditions, the Data Protection Act, Our Data Protection Policy and any other applicable laws and regulations governing the protection of personal data.
    10. Moreover we gather some information automatically when you visit our website or you download the Koro App via our gateway https://endpoint.koro.co.ke Please take into account that these kind of data are mostly collected by cookie files and tracking of navigation signals, they also include internet protocol (IP) address, browser type, internet service provider, referring and exit pages, operating system, clickstreams data, data and time stamp. Please note that we can also combine the collected data to other information that we already obtained in particular to provide analyses, security, content generation and marketing.
    11. We are also using analytics tools and software to develop and analyze the use of our Koro App and our services. We may use from time-to-time support of analytics companies and grant them access to anonymous individual data to analyze and present the best solutions from user experience perspective how the offered Services are used.
    12. Please be informed that we use a tool that allows us to make automatic decisions. Making decisions in an automated way is the ability to make decisions using technological tools without human involvement. We use the above technology to reduce the risk of making a mistake, lowering the risk of non-payment of a loan, and most importantly, it allows a credit decision to be made in a shorter period.
    13. Decisions that are not fully automatic are those that may include the actions of our employees. For instance, before we grant you a loan, we will investigate your creditworthiness and, in some cases, we may perform additional phone verification, which takes place before making a credit decision.
    14. When you uninstall Koro App, you can also withdraw your consents from accessing your Consumer Information in the future. However please note that we may keep and share stored Consumer Information even after when you uninstalled Koro App for as long as necessary for the fulfillment of the purposes for which the Consumer Information was received, as per our data retention policies or for the legitimate data controller purposes, exercise or defense of legal claims, statistics or as permitted by law.
    15. Please also be informed that we can record our telephone conversations for training purposes, in connection with processing complaints, for evidentiary purposes, and to verify customer service transactions.
  5. Purposes of data collection
    Koro collects Consumer Information including but not limited for the following purposes:

    Purpose/Activity Type of data Lawful basis for processing including basis of legitimate interest
    To register you as a new customer (a) Identity
    (b) Contact
    Performance of a contract with you
    To process and deliver services including:
    (a) Manage payments, fees and charges
    (b) Collect and recover money owed to us
    (a) Identity
    (b) Contact
    (c) Financial
    (d) Transaction
    (e) Marketing and Communications
    (a) Performance of a contract with you
    (b) Necessary for our legitimate interests (to recover debts due to us)
    To manage our relationship with you which will include:
    (a) Notifying you about changes to our terms or privacy policy
    (b) Asking you to leave a review or take a survey
    (a) Identity
    (b) Contact
    (c) Profile
    (d) Marketing and Communications
    (a) Performance of a contract with you
    (b) Necessary to comply with a legal obligation
    (c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)
    To enable you to partake in a prize draw, competition or complete a survey (a) Identity
    (b) Contact
    (c) Profile
    (d) Usage
    (e) Marketing and Communications
    (a) Performance of a contract with you
    (b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)
    To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) (a) Identity
    (b) Contact
    (c) Technical
    (a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganization or group restructuring exercise)
    (b) Necessary to comply with a legal obligation
    To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you (a) Identity
    (b) Contact
    (c) Profile
    (d) Usage
    (e) Marketing and Communications
    (f) Technical
    Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)
    To use data analytics to improve our website, products/services, marketing, customer relationships and experiences (a) Technical
    (b) Usage
    Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
    To make suggestions and recommendations to you about goods or services that may be of interest to you (a) Identity
    (b) Contact
    (c) Technical
    (d) Usage
    (e) Profile
    (f) Marketing and Communications
    Necessary for our legitimate interests (to develop our products/services and grow our business)
    a. To provide a safe and secure environment in all Koro premises through use of CCTV surveillance
    b. Use of Koro’s WIFI by customers while within Koro’s premises
    Identity
    Contact
    Profile
    Technical
    Your consent

    Necessary for our legitimate interests (to ensure safety within our premises)

    a. Analyzing job application documents Identity
    Contact
    Profile
    Your consent

    Necessary for our legitimate interests (for running our business)

    a. To deliver content and advertisements to you
    b. To make recommendations to you about goods or services which may interest you
    c. To send you marketing notices, service updates, and promotional offers
    d. To measure and analyze the effectiveness of the advertising we serve you
    e. To monitor trends so we can improve the services offered to you
    Identity
    Contact
    Device
    Content
    Profile
    Usage
    Marketing and Communications
    Location
    Consent

    Necessary for our legitimate interests (to develop our products/Services and grow our business)

    a. To comply with applicable laws, regulations, and rules, such as those relating to “know-your-customer” and anti-money laundering requirements
    b. To detect and prevent fraud and other illegal uses of our Services
    c. To exchange information with any local or international law enforcement or competent regulatory or governmental agencies to assist in the prevention, detection, investigation or prosecution of criminal activities or fraud
    Identity
    Contact
    Device
    Content
    Profile
    Usage
    Marketing and Communications
    Location
    Financial
    Necessary for our legitimate interests (for running our business)
  6. Sharing, transfer and disclosing Consumer Information
    1. You will find here information concerning the sharing data process.
    2. The information collected by us shall be used for the purposes indicated at Clause 5 of the Policy.
    3. We may share Consumer Information with a limited number of our partners for research and development. We may also provide anonymous Consumer Information for our external partners for the purposes of compiling statistics relating to our user base, loan portfolio, and analysis.
    4. When you use our Koro App and Services you agree that we may as it is necessary and appropriate share, transfer and disclose Consumer Information to the following recipients, with whom Koro has accordingly concluded data sharing agreements:
      1. External Debt Collection Agencies: Gilchery Limited, Acorns Limited, Collection Africa Limited, Ideon Limited, AFS Holdings, Metropol Limited, Fast Dial Business Solutions Limited, Finley International Limited, etc.
      2. Credit reference bureaus: TransUnion, Metropol, Credit Info etc.
      3. to members of Sun Finance Group for internal administrative purposes or for services necessary to make a credit decision, sub-contractors, service providers or agents of Koro,
      4. any credit reference bureaus or agencies and any financial institutions in order to obtain information concerning credit references,
      5. to persons acting on your behalf, payment recipients, beneficiaries, account nominees, intermediary, stock exchanges,
      6. to any third party to whom we provide introductions or referrals;
      7. to third party services providers which has concluded relevant contract with Koro that support us in our business operations in particular in marketing, identification of your identity, fraud prevention, anti-money laundering and transaction processing, specialized in analytical tools or providers of information search services, hosting and website development, risk assessment, debt recovery and customer service. We will share the data only when it is necessary to appropriate perform our legal obligations and the proper performance of the Services;
      8. government official’s, law enforcement or other third parties, but only in relation to a formal request, court order or a similar legal procedure or when we assume that the disclosure is necessary to comply with the law, prevent physical arms, financial losses, report suspected illegal activity or to investigate violations of our Services;
      9. or any other legally permissible purposes.
    5. By using our Services you hereby agree and authorize us to:
      1. verify any information provided by you to us against the information held by the Mobile Money Services Providers in relation to your mobile money account pursuant to the agreement between you and the relevant Mobile Money Services Provider for the provision of its products and services and the mobile money services.
      2. verify the Consumer Information with the Mobile Money Services Providers and using of the Consumer Information to the extent necessary in the opinion of Koro;
      3. contact you at any time to verify your details, ask for further information or clarification necessary to perform the proper KYC proceeding,
      4. to obtain and procure your Consumer Information from your respective Mobile Money Services Provider (or any other authority or person) and you further agree and consent to the disclosure, sharing and provision to us of such Consumer Information by the Mobile Money Services Provider (or other authority or person),
      5. obtain and procure your credit information from the Credit Reference Bureaus and you further agree and consent to the disclosure, sharing and provision of such Consumer Information by the Credit Reference Bureaus,
      6. to disclose, respond, advise, exchange and communicate the details or information pertaining to your Account or use of the Services to persons including but not limited to: (1) third parties involved in the administration of your Account, underwriting of insurance policies, updating of databases or provision of user support, (2) Koro’s service providers, subsidiaries or holding company for reasonable commercial, administrative, support, risk purposes relating to the Service.
      7. collect, transmit, move, store, process and access your Consumer Information and relevant information across cloud computing platforms and the servers of Koro, its subsidiaries, affiliates, service providers and associated entities wheresoever the said cloud computing platforms and servers may be located whether it be within the Republic of Kenya or without its borders for all purposes relating to the application, maintenance and operation of your account and profile in Koro App and System.
    6. We can transfer your personal data:
      1. at any time when we are legally obliged to do; in particular we may disclose information about using our services and your visit to our websites and using Koro App in order to ensure compliance with the law, when we can have reasonable suspicion that these disclosure is necessary to protect our rights, protect your safety or the safety of others, prevent and detecting fraud or responding to requests from state institutions;
      2. when it is in connection with the personal identification, detection and prevention of fraud and protection against fraud and to reduce credit risk and prevention of money laundering activities and the financing of terrorist activities;
      3. for credit reference bureaus and credit intermediaries, competent national authorities and non-governmental organizations, as well as other third parties to provide a full assessment of your creditworthiness;
      4. when executing a direct debit or other payment due under the loan agreement you have entered into with you; then we may share your personal data with external suppliers providing payment processing services;
      5. in the event of non-performance or improper performance of your obligations arising from concluded loan agreement, we may transfer data regarding your overdue liabilities to debt collection companies, credit reference bureaus and companies providing legal services.
      6. we may submit your personal data to the analysts and service providers who provide web browser services, who help us improve and optimize our application and/or website.
      7. during selling all or part of our business or transferring our receivables to a third party.
    7. Your personal data will be processed, stored, and transferred to third parties by the channels indicated in this Policy, in the agreements between you and Koro, and in the consents granted by you.
    8. We may search your data, information about you, your creditworthiness, your financial situation including your incomes and your debts, information about your employment, in credit references bureaus, publicly available sources, other suppliers providing such information.
    9. We may associate any category of information with any other category of information and will treat the combined information as Consumer Information in accordance with this Policy for as long as it is combined.
    10. You agree that Koro shall not be liable for any loss or damage arising from or incidental to our use, collection, processing and sharing of information relating to you, and any action we have taken in relation to this section.
  7. Consumer obligations and rightsUnder certain circumstances, you have rights under data protection laws in relation to your personal data. You have the right to:
    1. Request access to your personal data (commonly known as a “data subject access request”) in a timely manner. This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
    2. Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
    3. Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
    4. Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object to where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which overrides your rights and freedoms.
    5. Request restriction oof your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:
      1. if you want us to establish the data’s accuracy;
      2. where our use of the data is unlawful but you do not want us to erase it;
      3. where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or
      4. you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
    6. Request the transfer of your personal data to you or to a third party. We will provide you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
    7. Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
    8. You also have the right to ask us not to continue to process your personal data for marketing purposes.
    9. You can exercise any of these rights at any time by contacting our DPO via the address provided above.
    10. You agree to inform us promptly, and in any event, within 30 days, via e-mail: dpo@koro.co.ke or by texting to our customer care Infoline: +254 20 7650878 if there are any changes to your data supplied to us from time to time, and to respond promptly to any request from us.
    11. Please note that when you fail to provide promptly Consumer Information that are necessary to use our Koro App or Services or you withhold or withdraw any consents that are necessary to process, transfer or disclose your Consumer Information in accordance to the Clause 5, or we may have suspicions regarding any illegal use of Koro App or our Services or any fraud or any financial crime we may be unable to continue our Services and we reserve the right to terminate our relationship with you. We can also take actions that are necessary in accordance with our internal policies and Compliance Obligations. Moreover, we can block, transfer or close your accounts where it is permitted under the law.
  8. Data Controller
    1. Koro is the controller of your data. We respect your privacy and ensure protection of your personal data and the processing of your personal data in accordance with the law.
    2. The data that we collect from you may be transferred to, and stored at, a destination outside Kenya. Thus, by submitting your Consumer Information you agree to this transfer, storing or processing of data.
  9. Data Security
    1. All information you provide to us is stored on our secure servers. Where we have given you (or where you have chosen) a password that enables you to access certain parts of our application, you are responsible for keeping this password confidential. We ask you not to share this password with anyone.
    2. Once we have received your information, we will use strict procedures and security features to try to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way.
    3. We will collect and store personal data on your Device using application data caches and browser web storage and other technology.
    4. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator when we are legally required to do so.
  10. Retention
    1. To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, the need to comply with our internal policy and the applicable legal, regulatory, tax, accounting or other requirements.
    2. In adherence to the law, we must keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for certain periods after they cease being customers.
    3. Details of retention periods for different aspects of your personal data are available in our retention policy, which you can request by contacting us.
    4. In some circumstances, you can ask us to delete your data: see your legal rights under clause 7 on Consumer rights for further information.
    5. In some circumstances we will anonymize your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
    6. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
  11. Contact
    1. Please be advised that regarding the privacy point of contact or this Policy you shall write an e-mail to: dpo@koro.co.ke or you can call or text our Infoline: +254 20 7650878 (cost of the text or call is in line with your operator’s tariff).
  12. Sublicense regulation
    1. Subject to this Policy and Terms and Conditions and in consideration of you agreeing to abide by them, we grant you a non-transferable, non-exclusive sublicence to use the Koro App on your equipment. We reserve all other rights, including but not limited to intellectual property rights, that relate to the Koro App and any other Services that we provide. Except as expressly set out in these Policy and Terms and Conditions or as permitted by any applicable law, you agree:
      1. to ensure that you are the only person using the Koro App on your equipment and to notify Koro as soon as you become aware of any unauthorized use of the Koro App by any person;
      2. not to rent, lease, sub-license, loan, translate, merge, adapt, vary or modify the Koro App;
      3. not to make alterations to, or modifications of, the whole or any part of the Koro App, or permit the Koro App or any part of it to be combined with, or become incorporated in, any other programs;
      4. not to disassemble, decompile, reverse-engineer or create derivative works based on the whole or any part of the Koro App or attempt to do any such thing; and
      5. to comply with all technology control, data or export laws and regulations that apply to the technology used or supported by the Koro App or any Service (the “Technology”).
    2. You must:
      1. not use the Koro App or any Service in any unlawful manner, for any unlawful purpose, or in any manner inconsistent with these Policy and Terms and Conditions, or act fraudulently or maliciously, for example, by hacking into or inserting malicious programs or code, including viruses, or harmful data, into the Koro App, any Service or any operating system;
      2. not infringe our intellectual property rights or those of any third party in relation to your use of the Koro App or any Service (to the extent that such use is not licensed by these Policy and Terms and Conditions);
      3. not transmit any material that is defamatory, offensive or otherwise objectionable in relation to your use of the Koro App or any Service;
      4. not use the Koro App or any Service in a way that could damage, disable, overburden, impair or compromise the System or interfere with other users; and
      5. not collect or harvest any information or data from any Service or the System or our Systems or attempt to decipher any transmissions to or from the servers running any Service.
    3. Intellectual property rights:
      1. You acknowledge that rights in the Koro App are sublicensed (not sold) to you, and that you have no rights in, or to, the Koro App or the Technology whatsoever other than the right to use each of them in accordance with the terms of these Policy and Terms and Conditions.
      2. You acknowledge that you have no right to have access to the Koro App in source-code form.
    4. You acknowledge that the Koro App has not been developed to meet your individual or unique requirements, and that it is therefore your responsibility to ensure that the facilities and functions of the Koro App as described meet your requirements.
    5. We only supply the Koro App for domestic and private use. You agree not to use Koro App or Services for any commercial, business or resale purposes, and we have no liability to you for any loss of profit, loss of business, business interruption, loss of data or loss of business opportunity.
    6. We will not be liable for any losses or damage suffered by you because of or in connection with:
      1. any defect or fault in the Koro App or any Service resulting from you having altered or modified the Koro App,
      2. any defect or fault in the Koro App resulting from you having used the Koro App in breach of the terms of this Policy and Terms and Conditions;
      3. your breach of any of the license restrictions or the acceptable use restrictions,
      4. failure, malfunction, interruption or unavailability of the System, your equipment, the network, or a mobile money System,
      5. any fraudulent or illegal use of the Services, the system and/or your equipment.
  13. Final provisions
    1. We may update our Policy from time to time. Whenever we make a change, we will post the updated Policy at our website or Koro App when you next start the Koro App. We encourage you to check our Policy periodically. The new terms may be displayed on-screen, and you may be required to read and accept them to continue your use of the App or the services.
    2. This Privacy policy was last updated on 8th March 2024.
  14. Loans’ Rates and Fees
    1. Koro issues loans that range between KES 500 to KES 30000 for terms that range between 1 days to 61 days. Interest varies from 12% to 29% of the loan principal. Late payment of loans attracts late payment interest of 1% of the loan principal. Koro terms and conditions apply.
    2. Effective APR: varies between 146% and 352,8%.
    3. Important: All interests and fees that may be charged by Koro are not compounded nor accrue from day to day. Borrowers only pay back the loan principal and the fixed loan interest if the loan is paid on or before the due date; and if the loan is paid after the due date, loan principal, the fixed loan interest, and the late payment interest, only. There are no hidden fees or interest or charges.
  15. Data subject access request
    1. You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we could refuse to comply with your request where we have a legal basis.
    2. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
    3. We endeavor to respond to all legitimate requests within a reasonable time. Occasionally it could take us longer if your request is particularly complex or you
      have made several requests. In this case, we will notify you and keep you updated.