At Neer Technologies Ltd ("Neer", "we", "us", or "our"), we take your privacy and the security of your business data seriously. This Privacy Policy outlines our practices regarding the collection, use, disclosure, and protection of information when you access our Point of Sale (POS), ERP software, and associated web platforms.
This policy has been designed to align with the stringent requirements of the Kenya Data Protection Act, 2019 and global best practices.
1. Information We Collect
To provide you with a reliable and fully operational POS system, we collect information across three main categories:
A. Information You Provide to Us
- Account Data: Business name, individual name, email address, physical location, and phone number required to create and secure your account.
- Financial & Compliance Data: KRA PINs, VAT details, and business registration numbers necessary for setting up KRA eTIMS integrations.
- Customer Data: Phone numbers, names, and purchase histories of your customers that you manually input to operate your loyalty programs and CRM.
B. Information We Collect Automatically
- Transaction Data: Details of sales processed through our platform, including items sold, amounts, payment methods, and timestamps.
- Device & Usage Data: IP addresses, browser types, device identifiers, and login timestamps to monitor platform security and performance.
C. Information from Third Parties
- Payment Processors: We receive confirmation data from Safaricom (Daraja API) and Payhero Kenya when an M-Pesa STK Push, PayBill, or Till Number transaction is completed to reconcile your accounts.
2. How We Use Your Information
We do not use your data for advertising purposes. Your information is used strictly to operate and improve the Neer platform:
- To provide, maintain, and support your daily POS operations.
- To automate and securely process payments via M-Pesa and card terminals.
- To automatically generate and submit required fiscal receipts to the Kenya Revenue Authority (KRA) via eTIMS on your behalf.
- To monitor for fraudulent activity, unauthorized access attempts, and ensure network security.
- To send critical operational emails, such as password resets, subscription renewals, and system downtime alerts.
3. Data Sharing & Third-Party Services
We never sell or rent your personal or business information to third-party marketers. We only share information with trusted third parties when absolutely necessary to operate our service:
- Government Authorities: We transmit invoice and sales data to the Kenya Revenue Authority (KRA) exclusively to fulfill your eTIMS compliance mandates.
- Financial Integrations: We exchange necessary transaction tokens with Safaricom to facilitate M-Pesa payments.
- Infrastructure Providers: We use secure, enterprise-grade cloud hosting providers to store your data securely. These providers are bound by strict confidentiality and data processing agreements.
4. Data Retention
We retain your personal and business data only for as long as your account is active or as needed to provide our services. However, in compliance with Kenyan tax laws and the Tax Procedures Act, specific financial and transaction records (such as fiscal receipts) may be securely retained for a minimum of five (5) years, even if you close your account.
5. Cookies & Tracking Technologies
Neer uses essential cookies and similar tracking technologies to keep you logged into your POS dashboard securely across sessions. We also use minimal analytics tracking to understand how our software is performing and where we can improve the user experience. You can manage your cookie preferences through your browser settings.
6. Data Security Measures
Securing your data is our highest priority. We deploy rigorous technical and organizational measures:
- Encryption: All data in transit is secured using TLS 1.3, and sensitive database information is encrypted at rest using AES-256 standards.
- Access Control: We enforce strict Role-Based Access Control (RBAC). Neer support staff cannot access your raw sales data without your explicit, temporary authorization.
- Backups: Your business data is backed up daily across geographically distributed, secure servers to prevent data loss.
7. Your Privacy Rights
Under the Kenya Data Protection Act, 2019, you retain full control over your personal data. You have the right to:
- Access & Portability: Request a full, machine-readable export of all your business data at any time.
- Correction: Instantly update or rectify any inaccurate information from your account settings.
- Erasure: Request the permanent deletion of your account and personal data, subject to the legal financial retention requirements mentioned in Section 4.
- Objection: Lodge a formal complaint with the Office of the Data Protection Commissioner (ODPC) if you believe your rights have been violated.
8. Changes to this Policy
We may update this Privacy Policy periodically to reflect changes in our technology or legal obligations. We will notify all active account holders via email or a prominent dashboard alert at least 14 days before material changes take effect.