Privacy Policy

How FortyPOS collects, uses, protects and manages personal data across the website, web platform, mobile applications and support services.

Privacy framework

Effective date: 28 July 2026 · Last updated: 28 July 2026

This policy explains how FortyPOS handles personal data, distinguishes our controller and processor roles, and describes choices and rights available to users. Mandatory rights under applicable law always prevail over this policy.

1. Scope and who we are

FortyPOS is a web and mobile point-of-sale and business-management service provided by FortyHives Innovations Ltd, Crown Plaza, Room 12, Kutus, Kirinyaga County, Kenya. This Privacy Policy applies to the FortyPOS website, web console, mobile applications, support channels and related services.

This policy is intended to provide clear information consistent with the Kenya Data Protection Act, 2019, the Data Protection (General) Regulations and internationally recognised privacy principles. Additional rights may apply under laws such as the EU General Data Protection Regulation, the UK GDPR or other local privacy laws when their territorial requirements are met.

2. Controller and processor roles

Our privacy role depends on the information and the context in which it is processed:

  • FortyPOS as controller: we determine how account registration, subscription, billing, website, security, support and service-usage information is processed.
  • Customer business as controller: the subscribing business determines why and how it records information about its customers, suppliers, staff and transactions in FortyPOS.
  • FortyPOS as processor or service provider: we process business records on the subscribing business’s instructions to host and provide the service.
  • Business responsibility: each subscribing business must provide required notices, establish a lawful basis and configure staff access appropriately for personal data it enters into FortyPOS.

Where required, the parties may agree additional written data-processing terms that take precedence for the relevant processing.

3. Personal data we collect

CategoryExamples
Account and identityName, business name, email address, phone number, username, role, language and account identifiers.
Subscription and billingPlan, payment reference, payment status, invoice and receipt records, billing history and tax-related information.
Business contentProducts, prices, branches, staff roles, customers, suppliers, sales, purchases, expenses, inventory, invoices, statements and reports entered by authorised users.
Support and communicationsQuestions, tickets, WhatsApp, telephone or email communications, feedback and troubleshooting information.
Technical and securityIP address, device, browser, operating system, session, login, audit, error, diagnostic and security-event information.
Website and analyticsConsent choice, referring page, campaign parameters, page engagement and conversion actions when analytics consent is provided.
Connected servicesIdentifiers, status information and records received from integrations or providers authorised by the customer, subject to their terms.

4. Sources of personal data

  • Directly from account holders, administrators, staff users and people who contact us.
  • From the subscribing business when it creates users or enters business records.
  • Automatically from devices, browsers, logs, cookies and similar technologies.
  • From payment providers, app stores or integrated services when required to verify a transaction or provide a requested feature.
  • From authorised representatives, professional advisers, regulators or lawful public authorities where appropriate.

5. Purposes and lawful bases

We process personal data only where there is a valid purpose and lawful basis. The applicable basis depends on the activity and jurisdiction.

PurposeTypical lawful basis
Provide accounts, subscriptions, applications, support and requested functionalityPerformance of a contract or steps requested before entering a contract.
Operate authentication, permissions, audit trails, fraud prevention and service securityContract necessity, legitimate interests and compliance with legal obligations.
Process payments, invoices, receipts, tax records and financial administrationContract necessity and legal obligations.
Maintain, troubleshoot and improve reliability and usabilityLegitimate interests, provided those interests do not override individual rights.
Send essential service, security, billing and policy noticesContract necessity, legal obligations and legitimate interests.
Send optional marketing messagesConsent where required, or legitimate interests where permitted with an effective opt-out.
Use non-essential analyticsConsent through the website consent control.
Respond to legal requests and protect rights, safety and propertyLegal obligations and legitimate interests.

Where processing is based on consent, consent may be withdrawn at any time without affecting processing that was lawful before withdrawal.

6. Sharing and service providers

We do not sell personal data for money. We may disclose only the information reasonably necessary to:

  • Hosting, infrastructure, database, communications, analytics, payment, app-store and customer-support providers that help deliver FortyPOS.
  • Professional advisers, auditors and insurers under confidentiality duties.
  • A buyer, investor or successor in a proposed or completed restructuring, subject to appropriate protections.
  • Courts, regulators, law-enforcement agencies or other parties where disclosure is legally required or necessary to protect rights and safety.
  • A third party connected by a customer or user, where the customer has instructed or authorised the connection.

Service providers are expected to process information only for agreed purposes and to apply appropriate confidentiality and security measures. Details of material provider categories may be requested through the privacy contact below.

7. International data transfers

FortyPOS and its service providers may process information in countries other than the country in which the user is located. Where a transfer is restricted by applicable law, we will use a legally recognised transfer basis and appropriate safeguards, such as adequacy decisions, contractual protections, approved transfer clauses, consent where valid, or another permitted mechanism.

No transfer mechanism eliminates every risk. We assess the nature of the information, destination, provider and available safeguards when determining an appropriate approach.

8. Retention and deletion

We retain personal data only for as long as reasonably necessary for the relevant purpose, contract, security need or legal obligation. Retention depends on the record type, account status, dispute risk and statutory requirements.

Record typeRetention approach
Active account and business contentRetained while the account is active and as needed to provide the service.
Billing, tax and financial recordsRetained for the period required by accounting, tax, audit and legal obligations.
Support and security recordsRetained as needed to resolve issues, investigate misuse, maintain auditability and protect legal rights.
Marketing preferencesRetained as needed to respect opt-in or opt-out choices.
Analytics and technical dataRetained according to configured service settings and then deleted, aggregated or anonymised where appropriate.
Closed accountsDeleted, anonymised or restricted after applicable operational and legal retention periods, unless longer retention is required for a claim, investigation or legal duty.

Businesses should export records required for accounting, tax or operational purposes before expiry, cancellation or deletion. Backup copies may persist for a limited period until overwritten in the ordinary backup cycle.

9. Security and personal-data breaches

We use reasonable administrative, technical and organisational measures designed to protect personal data, including access controls, role permissions, authentication, logging, change management, infrastructure protections and incident-response procedures appropriate to the service and risk.

No online system is completely secure. Users must protect credentials, maintain secure devices, review staff permissions and notify us promptly of suspected unauthorised access. Where a personal-data breach triggers a legal notification duty, we will notify the relevant authority and affected individuals as required by applicable law.

10. Your privacy rights

Depending on applicable law and our role, individuals may have rights to:

  • Be informed about the collection and use of personal data.
  • Request access to personal data and obtain a copy where applicable.
  • Request correction of inaccurate or incomplete information.
  • Request deletion or erasure where the legal conditions are met.
  • Request restriction of processing or object to certain processing.
  • Withdraw consent where consent is the lawful basis.
  • Receive certain information in a portable format where the right applies.
  • Object to direct marketing at any time.
  • Complain to the Office of the Data Protection Commissioner in Kenya or another competent supervisory authority.

When FortyPOS acts only as a processor for a subscribing business, requests concerning that business’s records should normally be directed to the business first. We will assist the business as required. We may verify identity, request clarification and refuse or charge for requests only where permitted by law, such as requests that are manifestly unfounded or excessive.

11. Cookies, local storage and analytics

The website uses essential browser storage for security, session operation, language or display preferences and consent choices. Non-essential Google Analytics measurement is activated only after a visitor selects “Allow analytics”. Advertising storage, advertising user data and advertising personalisation are disabled in the current configuration.

Analytics helps us understand pages visited, content engagement, campaign attribution and actions such as trial, pricing, contact and download interactions. We do not intentionally send names, email addresses, phone numbers, free-text messages or other form-field content to Google Analytics.

Visitors may decline analytics through the consent prompt. They may also clear the site’s cookies or local storage through browser settings to reset stored preferences. Browser controls may affect site functionality.

12. Marketing communications

We may send product information, updates or offers where permitted by law. Marketing messages will identify FortyPOS or FortyHives Innovations Ltd and provide a reasonable method to opt out. Opting out of marketing does not stop essential account, security, billing or service communications.

13. Automated decision-making

FortyPOS does not currently use personal data to make solely automated decisions that produce legal or similarly significant effects on individual users. If this changes, we will provide the information and safeguards required by applicable law.

14. Children

FortyPOS is designed for businesses and authorised business users and is not intended for children to create independent accounts. A business that records information relating to a child must have an appropriate lawful basis and apply any additional protections required by law.

15. Changes to this policy

We may update this Privacy Policy to reflect service, provider, security, business or legal changes. Material changes will be communicated through the website, application, email or another appropriate channel. The updated effective date will appear at the top of the policy.

16. Contact, rights requests and complaints

Privacy requests and questions may be sent to support@fortypos.com, by telephone at +254 718 505 072, or through the account deletion request page. Include enough information to identify the account and the right being exercised, but do not send passwords or unnecessary sensitive information.

If a concern is not resolved, a person may lodge a complaint with the Office of the Data Protection Commissioner in Kenya or another competent authority in their jurisdiction. This right is not affected by contacting us first.

Related documents: Terms of Service and Refund Policy.

LTR RTL