Balance — Kenya Country Annex
Effective date: 19 July 2026 Last updated: 19 July 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Kenyan resident covered by this Annex; the Data Protection Officer designated under the Data Protection Act, 2019 (No. 24 of 2019, the "DPA 2019") Section 24 on the most-protective reading (processing of children's personal data as a matter requiring regular and systematic attention), with business contact ; the designated contact point for the Office of the Data Protection Commissioner (the "ODPC"), the Competition Authority of Kenya / consumer-protection bodies, the Directorate of Criminal Investigations ("DCI"), and Childline Kenya, under their respective intake protocols.
Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the DPA 2019 or the Data Protection (General) Regulations, 2021, the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 (the registration posture is an operational matter tracked in the internal registration checklist per the locked user decision), or the Data Protection (Complaints Handling and Enforcement) Regulations, 2021; (b) any ODPC Guidance Note, determination, or adequacy-style finding materially bearing on Section 33 (children's data), Sections 48-49 (cross-border transfers), or breach notification (Section 43 — 72 hours); (c) any amendment to the Children Act, 2022 (age of majority — 18; best-interests principle) or the Computer Misuse and Cybercrimes Act, 2018 — in particular Section 24 (child pornography); (d) any amendment to the Consumer Protection Act, 2012 or Constitution Article 46 (consumer rights); (e) any decision of the Kenyan superior courts materially bearing on the DPA 2019 or Constitution Article 31 (privacy); (f) any change in Kenya's adequacy postures (no EU adequacy at the Effective date); (g) any change to a sub-processor's Kenya data-handling posture under our sub-processor register; (h) the bringing into force of any post-Effective-date Kenyan regulation governing automated processing or related techniques beyond DPA s 35 (covered by the deliberate-silence carve-out in § 2); (i) any ODPC data-localisation designation under Section 50 (none engaging Balance at the Effective date).
Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — Kenya row).
- Children's Privacy Notice § 14 (Country annexes — Kenya row).
- Child Safety Standards § 13 (Country annexes — Kenya row).
- Terms of Service § 17 (Kenya consumer-protection carve-out under the Consumer Protection Act, 2012).
- Subscription Terms § 18 (Kenya consumer-rights overlay — Consumer Protection Act 2012; Google Play refund policy as the operational floor).
- Data Retention & Deletion Policy § 13 (Kenya — ODPC complaint route).
- our breach-notification runbook § 9 (Kenya breach-notification route under DPA s 43 — 72 hours to the ODPC).
- our international-transfer pack § 6 (DPA ss 48-49 consent + safeguards transfer mechanism).
This Annex is the canonical Kenyan-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Kenyan resident a right that the global Policy does not, this Annex governs; the converse also holds. The two are read together.
This Annex is drafted in English — an official language of Kenya (Constitution Article 7(2)). No translation is statutorily required.
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is Kenya. The DPA 2019 is a national statute; there is no county-level data-protection sub-layer.
We determine country of residence at install/sign-up time by (a) the country the parent self-declares in onboarding, (b) the IP-geolocation read at sign-up (discarded immediately after the residence decision — our internal data-flow map § 2.1), and (c) the Play Store account locale. Reviewable at Settings → Account → Region. Where any signal identifies Kenya, this Annex applies; the most-protective reading controls.
The DPA 2019 has explicit extraterritorial reach at Section 4(b): it applies to a data controller or processor not established or resident in Kenya but processing personal data of data subjects located in Kenya. Balance offers its service to Kenyan residents through Google Play Kenya; the DPA 2019 applies in full.
2. Statutory framework — what applies
| Instrument | What it does | Balance's posture |
|---|---|---|
| Constitution of Kenya, 2010 — Article 31 (privacy) + Article 46 (consumer rights) + Article 53 (children — best interests paramount) | The constitutional layer. | Constitutional anchor. §§ 3, 5, 6 below. |
| DPA 2019 | The principal statute. s 4(b) extraterritorial reach; s 25 principles (lawfulness/minimisation/purpose/accuracy/storage limitation/integrity + the s 25(g) transfer-out limitation); s 26 data-subject rights; s 28-29 collection + notice duties; s 30 lawful bases (consent; contract; legal obligation; vital interest; public interest; legitimate interests); s 31 DPIA duty for high-risk processing; s 33 — children's data: a data controller shall not process personal data relating to a child unless consent is given by the child's parent or guardian and the processing is in such a manner that protects and advances the rights and best interests of the child (with age-verification and consent mechanisms incorporated); s 35 automated decision-making rights; ss 37 commercial-use restrictions; ss 41-42 security safeguards; s 43 breach notification — ODPC within 72 hours where there is a real risk of harm, and communication to the data subject; ss 48-49 cross-border transfers — proof of appropriate safeguards or adequacy (s 48), or consent of the data subject, plus the s 49 conditions (necessity limbs); s 50 localisation power (no designation engaging Balance); ss 56 et seq. complaints + enforcement (penalties up to KES 5 million or 1% of turnover). | The principal statute. Applies in full via s 4(b). Treatment throughout. |
| Data Protection Regulations, 2021 (General; Registration; Complaints/Enforcement) | Operationalise notice content, consent mechanics (incl. parental consent verification), registration thresholds (registration posture tracked internally), complaint procedure. | Applies. §§ 3, 5, 7 below. |
| Children Act, 2022 | A child is a person under 18; best-interests principle (s 8); parental responsibility. | Applies. §§ 5, 16 below. |
| Computer Misuse and Cybercrimes Act, 2018 | Cybercrime offences — s 24 child pornography (production/distribution/possession via computer systems); procedural powers (preservation, production orders). | Applies. §§ 13, 14 below. |
| Consumer Protection Act, 2012 | Consumer rights: disclosure, unfair practices, remote/internet agreements (Part VII — disclosure + cancellation rights for internet agreements), unconscionable representations. | Applies. § 16 below. |
| EU adequacy / Convention 108 / Budapest | No EU adequacy; Kenya is not a party to Convention 108/108+; Kenya has been invited to accede to the Budapest Convention (accession pending at the Effective date); the AU Malabo Convention (in force 8 June 2023) — Kenya signature/ratification posture tracked. | Context-setting facts. § 13 below. |
(Any prospective Kenyan regulation governing automated processing, algorithmic decisions, or related techniques beyond DPA s 35 — including any AI code of practice and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence is deliberate.)
3. Supervisory authorities
3.1 ODPC
| Field | Value |
|---|---|
| Name | Office of the Data Protection Commissioner (ODPC) |
| Address | CA Centre, Waiyaki Way, Nairobi, Kenya |
| Website / complaint channel | https://www.odpc.go.ke/ — online complaint portal; info@odpc.go.ke |
| Breach-notification channel | ODPC breach-notification form per DPA s 43 — 72 hours |
A Kenyan resident may complain to the ODPC (Complaints Handling Regulations 2021) at any time. We accept all enquiries at (named individual: , DPO) and respond within the § 6 timelines. Appeals from ODPC determinations lie to the High Court.
3.2 Other regulatory bodies
| Body | Subject matter | Channel |
|---|---|---|
| Competition Authority of Kenya / Kenya Consumers protection bodies | Consumer Protection Act 2012 | https://www.cak.go.ke/ |
| DCI — Directorate of Criminal Investigations (Anti-Human Trafficking and Child Protection Unit) | CSAE investigation | https://www.dci.go.ke/ — emergency 999/112 |
| Childline Kenya | 24/7 national child helpline (with the Department of Children's Services) | dial 116 (toll-free) — https://childlinekenya.co.ke/ |
| Department of Children's Services | Child protection (Children Act 2022) | Per county |
3.3 The DPO
DPA s 24 makes DPO designation obligatory where processing requires regular and systematic monitoring at scale or involves special categories; on the most-protective reading (children's data), Balance designates , Director, BabaYaga Program, TOO — , published here, in the global Privacy Policy § 1, and at balance.babayagaprogram.com. Registration with the ODPC is an operational matter tracked internally per the locked user decision; no local representative is engaged.
4. Lawful bases — DPA s 30 + s 33
- Parent account data: s 30(1)(b)(i) contract performance + s 30(1)(a) consent obtained at sign-up.
- Kid profile + device data: s 33 parental/guardian consent, given by design through the parent-first onboarding, with processing conducted in a manner that protects and advances the rights and best interests of the child (§ 5); the DPIA (s 31) is recorded in our Data Protection Impact Assessment.
- Security, fraud-prevention, legal compliance: s 30(1)(b)(ii) legal obligation + s 30(1)(b)(vii) legitimate interests with balancing.
- No sensitive personal data (s 44-46) of Kenyan residents is processed in its own right. No advertising, profiling, or sale — monitoring/limits/tasks are performed at the parent's direction, strictly for the safety, well-being and parental supervision of the child, never for any commercial purpose (also the s 37 commercial-use restriction posture).
5. Children's rights overlay — DPA s 33
- The parent/guardian always consents; the kid never self-registers. The s 33(1)(a) parental consent is satisfied by construction — the kid profile exists only inside the authenticated parent account and the pairing act is the parent's. The s 33(2) mechanism duty (age verification + consent incorporation) is met by the parent-declared, parent-managed kid age and the identity-verified consenting adult.
- Best interests advanced, not merely protected: Balance exists to give the parent supervision tools — the DPIA records how each feature serves the child's safety and well-being (Constitution Art 53(2); Children Act s 8).
- The parent exercises the kid's s 26 rights in-app or by email.
- Plain language toward the kid on kid-facing screens.
- No commercial exploitation of children's data — ever.
6. DPA s 26 rights catalogue
Honoured at and in-app (the parent exercises the kid's rights):
- s 26(a) — to be informed of the use of personal data: this bundle + the sign-up notice (ss 28-29).
- s 26(b) — access: in-app JSON export at Settings → Family → [kid name] → "Export this kid's data" + plain-language summary.
- s 26(c) — objection to processing of all or part of the data.
- s 26(d) — correction of false or misleading data: Settings → Account → Edit.
- s 26(e) — deletion of false or misleading data; plus the s 40 erasure/rectification regime and the consent-withdrawal cascade: Settings → "Delete my account" / "Delete this kid"; Delete-account page; cascade per Data Retention & Deletion Policy § 7.
- s 34 — portability (structured, commonly-used, machine-readable — the JSON export).
- s 35 — automated decisions: Balance takes none producing legal/significant effects; the earned-time ledger is deterministic and parent-reviewable.
Timeline: acknowledgement within one business day; substantive response within the Regulations' windows and in any event within 30 days, Balance's self-imposed ceiling. English or Kiswahili accepted (we translate on receipt), free of charge.
7. Children's data — consent mechanics and minimisation
- Parent creates the account with a verified email (+ Google Play payment instrument where subscribed), then affirmatively creates the kid profile and pairs the kid's device — the s 33 parental consent, evidenced and logged, via a consent screen itemising categories, purposes (safety and parental supervision only), recipients, retention, and rights.
- Data minimisation (s 25(c)): only what the supervision service needs; proof media is E2EE to the parent's devices — Balance holds ciphertext only (§ 13).
- Kid data is never used for advertising, never profiled, never sold.
8. International data transfers from Kenya — DPA ss 48-49
Balance transfers Kenyan residents' personal data to the United States (hosting) with controller access from Kazakhstan, relying on:
- s 48(a) proof of appropriate safeguards — written DPAs with every sub-processor imposing security and confidentiality controls (our international-transfer pack § 6), reinforced by the E2EE proof-media measure; and
- s 48(b) the data subject's consent — the parent's transfer-disclosure consent at sign-up (naming the destinations), given after being informed of the possible absence of adequate safeguards determinations; and
- the s 49 necessity limbs (contract performance) for contract-necessary flows.
No sensitive personal data of Kenyan residents is transferred (the s 49(2) strict regime is not engaged in its own right; children's data receives the sensitive-grade handling voluntarily). No s 50 localisation designation engages Balance. § 18 covers any ODPC safeguards/adequacy development.
9. Data residency for Kenyan residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region (E2EE ciphertext only). |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Kenyan resident's data held in Kenya? | No. The ss 48-49 mechanisms in § 8 ground the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO), with administrative access under written processor DPAs. |
| Is there a Kenyan establishment? | No. Registration posture tracked internally. |
No s 50 data-localisation designation applies to parental-control services at the Effective date.
10. Sub-processors touching Kenyan-resident data
| Sub-processor | Role | Location | Kenya transfer basis |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (US); relationship per our internal vendor-handling plan | Hosts the FastAPI backend + MongoDB cluster | United States | DPA s 48(a) safeguards (DPA on file) + s 48(b) consent; E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | E2EE proof-media ciphertext + daily 30-day-rolling backups | United States (us multi-region) |
s 48 safeguards + consent via Google Cloud DPA; ciphertext-only. |
| Google LLC — Firebase Cloud Messaging | Push notifications | United States | s 48 safeguards + consent; push body free of sensitive content (M3). |
| Google LLC — Google Sign-In | Parent Google authentication (when used) | United States | s 48 safeguards + consent via Google DPA. |
| Google LLC — Google Play Billing | Subscription purchases | United States / Kenya (Google Play) | Google Play Developer Distribution Agreement + s 48 consent. |
| Resend, Inc. (San Francisco, CA, USA) | Transactional email | United States | s 48 safeguards + consent (DPA on file). |
Full list: our sub-processor register.
11. Breach notification — DPA s 43
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| ODPC | Personal data accessed or acquired by an unauthorised person, where there is a real risk of harm to the data subject. | Within 72 hours of becoming aware. | ODPC breach form, filed by the DPO or Kenyan counsel on instruction. |
| Affected data subjects | The same breach. | Without undue delay (in writing, with sufficient information for protective measures), unless identity cannot be established. | Direct email to the affected parent; in-app banner; public incident page fallback. |
| CSAE-specific | An incident with a CSAE component. | Per § 14 + runbook M1. | DCI + Childline 116 + (where applicable) NCMEC. |
Internal SLA: our breach-notification runbook § 5.4 + § 9.
12. Cookies, spam, and electronic direct marketing
Kenya has no standalone cookies statute; identifiers are personal data under the DPA. The Balance app deploys strictly-necessary storage only (authentication tokens; device-pairing key wrap; earned-time cache), covered by the sign-up consent. The public site uses no analytics, advertising cookies, trackers, or fingerprinting. DPA s 37 restricts use of personal data for commercial purposes without consent — Balance sends no electronic direct marketing to Kenyan residents; only transactional email. Advertising directed at children: never.
13. Lawful-access requests and the encryption posture
Kenyan authorities may seek data via court orders and Computer Misuse and Cybercrimes Act 2018 preservation/production orders, National Police Service investigative powers, and international channels (MLAT / reciprocity; Budapest accession pending). Posture:
- Proof media is end-to-end encrypted (fresh per-file key, XChaCha20-Poly1305, wrapped to parent-device X25519 keys; ciphertext-only upload). No master key, no backdoor.
- Response protocol: (1) acknowledge within one business day; (2) engage Kenyan counsel to assess validity; (3) preserve relevant ciphertext; (4) inform the authority plaintext is unavailable from us; (5) cooperate in identifying the lawful route to the key-holding parent.
- No bulk plaintext interception assistance; no server-side content scanning. CSAE cooperation runs via § 14 regardless.
Full encryption posture: our encryption-posture record.
14. CSAE reporting routes — Kenya
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day. - Childline Kenya 116 — 24/7 toll-free national child helpline (with the Department of Children's Services): dial 116;
https://childlinekenya.co.ke/. - DCI — Anti-Human Trafficking and Child Protection Unit:
https://www.dci.go.ke/; emergency 999/112. - National Police Service — nearest police station / gender desks.
- Department of Children's Services — county children's officers (Children Act 2022 reporting route).
- NCMEC CyberTipline (
https://report.cybertip.org/) — provider-side discoveries route to NCMEC, which relays to Kenyan law enforcement.
Full routing table: Child Safety Standards § 8.5.
15. Complaint routes (summary)
| Authority | Subject matter | Channel |
|---|---|---|
| ODPC | DPA 2019 | https://www.odpc.go.ke/ — complaint portal |
| Consumer-protection bodies (CAK; Kenya Bureau of Standards for services) | Consumer Protection Act 2012 | https://www.cak.go.ke/ |
| DCI / Police | Criminal (incl. CSAE) | 999/112 |
| High Court | Constitutional (Art 31) + appeals from the ODPC + civil damages | Per jurisdiction |
A Kenyan resident may always first raise the matter at ; prior contact is not a precondition to any authority route.
16. Consumer rights — the Consumer Protection Act 2012 overlay
- Disclosure for internet agreements (Part VII): the prescribed pre-contract disclosures (supplier, price, terms, cancellation) are implemented in Subscription Terms § 5; a copy of the agreement is deliverable (the Subscription Terms + receipt email).
- Cancellation: Part VII grants internet-agreement cancellation rights where disclosure/copy duties are breached — Balance meets the duties and additionally honours the Google Play refund policy as the operational floor plus its voluntary refund posture (Subscription Terms § 8).
- Unfair practices / unconscionable representations: prohibited; the Terms of Service are drafted accordingly, preserving Constitution Art 46 consumer rights.
- Contracting capacity: age of majority 18 (Children Act 2022); the subscribing parent must be an adult; the kid never contracts with Balance.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — DPA ss 48-49 safeguards + consent on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
- Every change to a substantive row in §§ 2-16 bumps the frontmatter and triggers re-publication.
- Any ODPC guidance on s 33 children's data, ss 48-49 transfers, or a s 50 localisation designation triggers an off-cycle rewrite of §§ 5, 8, 9.
- Any registration-regulations enforcement development triggers the internal-checklist workstream (public-doc posture unchanged per the locked user decision).
- A material Consumer Protection Act change triggers an off-cycle update to § 16.
- A material change to a sub-processor's posture triggers an off-cycle update to §§ 8, 10.
- The annual review is by 9 June. The Privacy Officer signs off; the Designated Child Safety Officer co-signs any change to §§ 5, 7, 11, 13, 14.
End of Kenya Country Annex.