OneApp Privacy & Data Policy
At OneApp, your privacy and trust matter. This policy explains how and when your identification (KYC) information may be shared if you choose to use financial or investment products through OneApp.
What OneApp Is (and Is Not)
- OneApp is a technology platform, not a bank or investment firm.
- We do not hold your money or make financial decisions.
- Regulated banks, payment providers, and investment institutions provide all financial products.
When Is Your KYC Shared?
Your KYC information is shared only if you choose to use a specific product (for example, a savings account, loan, or investment).
- ❌ We never share your KYC automatically or by default.
- ❌ No silent background sharing.
What Happens When You Opt In
When you select a bank or investment product in OneApp:
- We clearly show:
- What information will be shared.
- Which licensed institution it will be shared with.
- Why the information is required.
- You confirm your consent using secure authentication (such as biometrics or PIN).
- Only the required information is securely sent to the selected institution.
Business Verification & KYB
For our business users, we conduct Know Your Business (KYB) checks to ensure platform integrity and regulatory compliance.
- Veriff Business Integration: We use Veriff to verify the legitimacy of your business and its representatives.
- M-Pesa Verification: We collect and verify your till or paybill numbers against records to ensure ownership.
- Secure Document Handling: Business documents (Certificate of Incorporation, KRA PIN, CR12, etc.) are stored in encrypted vaults and accessed only for verification and compliance audits.
AI & Wunna Analytics Consent (Optional)
To provide you with personalized financial insights and "Wunna" personas, OneApp offers an optional analytics service.
- Strictly Opt-In: We never analyze your transaction history for AI insights without your explicit, separate consent.
- Private "Memory Vault": If you opt in, your transaction data is stored in a secure, private vault that only YOU and the AI agent acting on your behalf can access.
- No Global Training: Your financial data is never used to train public AI models. It remains isolated to your personal context.
- Revocable: You can turn off AI analytics at any time, which will delete your generated personas and insights.
Your Rights
You have the right to:
- Know exactly what data is shared and with whom.
- Refuse or withdraw consent for future sharing.
- Access products only after required regulatory checks.
Compliance & Regulatory
OneApp operates in full compliance with the **Data Protection Act (2019)** of Kenya. We are registered with the Office of the Data Protection Commissioner (ODPC).
