Legal & Compliance

Privacy Policy

How AutoNet Networks collects, uses, stores, and protects your personal data — in line with the Kenya Data Protection Act, 2019.

Last updated: 01 January 2025 Jurisdiction: Republic of Kenya Data Protection Act, 2019

This Privacy Policy explains how AutoNet Networks ("we", "us", "our") collects, uses, shares, and protects personal data when you use our platform, website, dashboards, captive portals, mobile services, and APIs (collectively, the "Service").

We are committed to processing personal data lawfully, fairly, and transparently in accordance with the Kenya Data Protection Act, 2019 and, where applicable, the EU General Data Protection Regulation (GDPR).

Plain-language summary: We collect the minimum data needed to run the Service — your account details, payment references, device identifiers, and usage logs. We never sell your data, and we never store M-PESA PINs. You can ask to see, correct, or delete your data at any time by emailing support@autonet.co.ke.

1. Who We Are

AutoNet Networks is a software platform operator based in Nairobi, Kenya. We provide tools for ISPs and hotspot operators to manage WiFi access, process M-PESA payments, deliver vouchers, and monitor usage.

For the purposes of the Data Protection Act, 2019, AutoNet Networks acts as a data processor for the End User data that Operators collect through the Platform, and as a data controller for data relating to Operators' accounts and our own business operations.

2. Data We Collect

Depending on how you use the Service, we may collect:

  • Account data: name, email, phone number, business name, physical address;
  • Payment data: M-PESA transaction references, amounts, and timestamps (we never store M-PESA PINs);
  • Device data: MAC address, IP address, device fingerprint, browser user-agent;
  • Usage data: hotspot/PPPoE session logs, connection times, data consumed, and package activation history;
  • Support data: messages, tickets, and correspondence you send to us.

3. How We Collect Data

  • Directly from you when you register, top up, or contact support;
  • Automatically through the captive portal, router, and API when devices connect;
  • From payment gateways and Safaricom M-PESA as transaction confirmations;
  • From cookies and similar technologies on our website.

4. Why We Use Your Data

We process personal data for the following purposes:

  • To create and manage your account and provide the Service;
  • To authenticate hotspot and PPPoE sessions and enable auto-reconnect;
  • To process and confirm M-PESA payments;
  • To send transactional SMS (voucher delivery, session expiry, service notices);
  • To detect fraud, abuse, and security incidents;
  • To comply with legal, tax, and regulatory obligations;
  • To improve the Service through aggregated, anonymised analytics.

5. Legal Basis for Processing

Under the Data Protection Act, 2019, we rely on:

  • Contract: processing needed to provide the Service you signed up for;
  • Legal obligation: retention and disclosure required by Kenyan law;
  • Legitimate interests: fraud prevention, network security, service improvement;
  • Consent: for optional marketing communications, where you have opted in;
  • Vital interests: where processing is necessary to protect life or safety.

6. Data Sharing

We share personal data only with:

  • Safaricom / payment gateways to process M-PESA transactions;
  • SMS providers to deliver voucher and session notifications;
  • Cloud hosting providers that host our infrastructure under contract;
  • Regulators or law enforcement when legally required and properly served;
  • The Operator whose network you are using — they are the data controller of your End User record.

We never sell your personal data to third parties.

7. Data Retention

  • Account data: kept for as long as your account is active, then deleted or anonymised within 90 days;
  • Payment / transaction records: kept for 7 years to comply with Kenyan tax and financial regulations;
  • Session / usage logs: kept for up to 12 months for security and dispute resolution;
  • Support tickets: kept for 24 months from last contact.

When retention periods end, data is securely deleted or irreversibly anonymised.

8. Data Security

We implement reasonable technical and organisational measures to protect personal data, including:

  • Encryption of data in transit (TLS) and at rest where appropriate;
  • Role-based access controls and least-privilege principles;
  • Secure credential storage (hashed passwords, no plain-text secrets);
  • Regular backups and monitoring of our infrastructure;
  • Vendor due diligence for third-party processors.

However, no system can be guaranteed to be 100% secure. If we become aware of a personal data breach affecting you, we will notify you and the Office of the Data Protection Commissioner (ODPC) as required by law.

9. Cookies & Tracking

Our website uses essential cookies to keep you logged in, remember session state, and protect against cross-site request forgery. We may also use privacy-respecting analytics to understand aggregate usage.

We do not use third-party advertising cookies. You can block or delete cookies in your browser settings, but essential cookies are required for the Service to function.

10. Your Rights

Under the Data Protection Act, 2019, you have the right to:

  • Be informed about how your data is used;
  • Access a copy of the personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request deletion of your data, subject to legal retention obligations;
  • Object to or restrict certain processing;
  • Request data portability in a structured, machine-readable format;
  • Withdraw consent at any time where processing is based on consent;
  • Lodge a complaint with the ODPC.

To exercise any of these rights, email support@autonet.co.ke. We will respond within 30 days.

11. International Transfers

Some of our service providers (hosting, SMS, payments) may process data outside Kenya. Where this happens, we ensure that appropriate safeguards are in place such as standard contractual clauses or transfers to jurisdictions recognised as providing adequate protection by the ODPC.

12. Children's Data

The Service is intended for Operators who are at least 18 years old. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified by email or through the dashboard at least fourteen (14) days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

14. Our Contacts

For privacy-related enquiries, complaints, or to exercise your rights, contact us on:

15. Complaints to the ODPC

If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya.

By using AutoNet Networks, you acknowledge that you have read and understood this Privacy Policy. For any questions, contact support@autonet.co.ke.