This distinction is the whole basis of the policy.
(a) Your business records — you are the controller, we are the processor. The jobs, clients, drivers, invoices and financial figures you enter belong to you. You decide what to collect and why. We store and process them on your instructions only, to run the service for you. We do not use them for anything else.
(b) Your account with us — we are the controller. Your company name, contact details, subscription, payments and support messages. We control these because we need them to run our business.
| Data | Why | Kept for |
|---|---|---|
| Your business records (jobs, clients, drivers, invoices, money) | To provide the service | While your account is active, then 90 days after closure, then deleted |
| Account and contact details | To identify you, support you, bill you | Account life + 7 years (tax) |
| Payment records | Legal and accounting obligation | 7 years |
| Support messages | To answer you | 24 months |
| Security and audit logs | Security, and to investigate incidents | 12 months |
| Technical logs (IP address, browser, error traces) | Keeping the service running and secure | 90 days |
We never sell your data, never use it for advertising, and never use your business records to train AI models.
Tanzania's Personal Data Protection Act 2022 treats financial data as sensitive personal data, which generally requires prior written consent.
Managix necessarily holds financial information about your clients and drivers. Two consequences:
Two different providers do two different jobs, and this policy states both:
| What | Provider | Where |
|---|---|---|
| Your business records — database, documents, backups | Supabase | Ireland, European Union |
| The application itself (code only, no records) | Cloudflare Pages | Served from the nearest edge location |
| Payment processing | Paystack (a Stripe company) | We never receive or store your full card number |
There is no hosting region in Africa for our database provider. Your records therefore leave the country, which is exactly what this section is about.
For Kenyan customers, cross-border transfer is permitted where appropriate safeguards exist under the Data Protection Act 2019. For Tanzanian customers, transfers abroad require a permit from the Personal Data Protection Commission together with appropriate safeguards.
Only these, and only as far as needed:
Every one of these is bound by contract to protect your data. We do not share your data with anyone else unless the law compels us, and we will tell you if that happens unless we are forbidden to.
Breach notification: if a breach affects your data, we will notify you and the relevant regulator as the law requires, and within 72 hours of becoming aware wherever that is possible.
You may ask us to see, correct, export, or delete the personal data we hold about you, and to restrict or object to certain processing. Write to [email protected]; we respond within 30 days.
Where we act as processor for your customers' data: if one of your clients or drivers exercises a right, they should come to you — you are their controller. We will help you respond.
You can export everything at any time. When you close your account, we delete your business records after 90 days, except anything we must legally retain (such as invoices for tax).
We will tell you before we make a material change, and never reduce your protection retrospectively.
555DIRECT LIMITED — [email protected]
Data Protection Officer: Islam Bayusuf, [email protected]
Kenya: Office of the Data Protection Commissioner · odpc.go.ke
Tanzania: Personal Data Protection Commission