Legal
Privacy Policy
Effective date: 1 March 2025 · Operated by LeadAfrik Agricultural Solutions
1. Who we are
Agrisoko is an agricultural marketplace platform operated by LeadAfrik Agricultural Solutions (“we”, “us”, “our”), a company incorporated in Kenya. We are the data controller for personal data collected through the Agrisoko website and mobile application.
We are registered with the Office of the Data Protection Commissioner (ODPC) in accordance with the Kenya Data Protection Act, 2019.
2. What personal data we collect
We collect personal data in several ways:
Account registration
- Full name
- Email address and/or Kenyan phone number
- Password (stored as a one-way cryptographic hash — never in plain text)
- County and approximate location
- Profile photo (optional)
- Role (buyer, seller, service provider)
Identity verification (optional)
- Government-issued ID (national ID, passport)
- Selfie photo submitted alongside the ID
- Verification status (verified / unverified)
ID documents are stored securely and reviewed only by authorised Agrisoko staff. They are never shared with other users.
Marketplace activity
- Listings you create (title, description, price, photos, location)
- Orders and transactions you participate in
- Messages exchanged with other users through our platform
- Buyer requests and saved listings
- Boost payment records (M-Pesa payer phone and amount)
Technical data
- IP address and device information
- Browser type and operating system
- Pages viewed and actions taken on the platform
- Session tokens (stored in encrypted cookies)
3. How we use your data
We use your personal data to:
- Create and maintain your account
- Enable you to post listings and connect with buyers or sellers
- Verify your identity and display trust signals to other users
- Process orders and facilitate transactions
- Send transactional notifications (OTP codes, order updates, listing status)
- Send platform announcements and marketing emails (you may opt out at any time)
- Detect fraud, enforce our policies, and moderate listings
- Improve platform performance, features, and user experience
- Comply with our legal obligations under Kenyan law
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.
4. Legal basis for processing (Kenya DPA 2019)
Under the Kenya Data Protection Act, 2019, we rely on the following bases:
- Consent — where you have given clear consent (e.g., marketing emails, optional ID verification)
- Contract performance — where processing is necessary to deliver services you have requested
- Legal obligation — where processing is required to comply with Kenyan law
- Legitimate interests — where we have a legitimate interest not overridden by your rights (e.g., fraud prevention, platform security)
6. How long we keep your data
- Account data — retained for the duration of your account and up to 2 years after deletion
- Transaction and order records — retained for 7 years in accordance with Kenyan commercial and tax law
- ID documents — retained only during the verification review period, then deleted unless required for a legal claim
- Messages — retained while your account is active; you may request deletion
7. Security
We implement reasonable technical and organisational measures to protect your data, including:
- HTTPS encryption for all data in transit
- Encrypted password storage (bcrypt)
- Role-based access controls for staff
- Regular security reviews
No method of transmission over the internet is 100% secure. If you believe your account has been compromised, contact us at info@leadafrik.com.
8. Your rights
Under the Kenya Data Protection Act, 2019, you have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Deletion (erasure) — request deletion of your personal data where there is no overriding legitimate reason to retain it
- Object — object to processing in certain circumstances
- Restriction — request that we restrict processing in certain circumstances
- Data portability — request transfer of your data in a structured, machine-readable format
- Withdraw consent — withdraw consent at any time where processing is based on consent
Contact us at info@leadafrik.com. We will respond within 21 days as required by the Act.
10. Minors
Agrisoko is not intended for use by persons under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has created an account, please contact us and we will promptly delete the account and associated data.
11. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify registered users of material changes by email or through a platform notification. The effective date at the top of this page reflects the most recent revision.
12. Contact & complaints
For privacy-related questions, requests, or concerns:
LeadAfrik Agricultural Solutions (Agrisoko)
Email: info@leadafrik.com
If you are not satisfied with our response, you may lodge a complaint with the Office of the Data Protection Commissioner (ODPC), the Kenyan supervisory authority for data protection.
