How we collect, use, and protect your personal information
Last updated: December 5, 2025 | Effective: December 5, 2025
Sunny Payments Limited ("Sunny Payments," "we," "us," or "our") is a licensed Payment Service Provider regulated by the Central Bank of Kenya (CBK) under the National Payment System Act, 2011. We are committed to protecting your privacy and ensuring the security of your personal and financial information in compliance with the Kenya Data Protection Act 2019, the General Data Protection Regulation (GDPR), and the Payment Card Industry Data Security Standard (PCI DSS).
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our payment processing services, website, mobile applications, and APIs.
We process your personal data for the following purposes:
To process transactions, verify payment details, and complete money transfers
To comply with Know Your Customer (KYC) and Anti-Money Laundering (AML) requirements
To detect, prevent, and investigate fraudulent transactions and security threats
To meet CBK, GDPR, PCI DSS, and other applicable regulatory requirements
To respond to inquiries, resolve disputes, and provide technical assistance
To analyze usage patterns and enhance our products and services
Under the Kenya Data Protection Act 2019 and GDPR, we process your data based on:
We may share your information with:
We never sell your personal information to third parties.
We implement industry-leading security measures to protect your data:
Highest level of payment card security compliance
All sensitive data encrypted at rest and in transit
Card numbers replaced with secure tokens
Enhanced account protection for all users
Continuous security surveillance and threat detection
Annual penetration testing and security audits
We retain your personal data for as long as necessary to provide our services and comply with legal obligations:
Under the Kenya Data Protection Act 2019 and GDPR, you have the following rights:
To exercise these rights, contact our Data Protection Officer at privacy@sunnypay.com
Your data may be transferred to and processed in countries outside Kenya, including for cloud hosting and payment network processing. We ensure adequate safeguards are in place, including:
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will promptly delete it.
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or prominent notice on our website. Continued use of our services after changes constitutes acceptance of the updated policy.
For privacy-related inquiries or to exercise your rights:
Data Protection Officer: Sunny Payments Limited
Email: privacy@sunnypay.com
Address: Westlands, Nairobi, Kenya
Phone: +254 700 000 000
You may also lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at www.odpc.go.ke