Legal
Data processing addendum
Last updated 28 August 2026
Draft for review. This document sets out our intended commitments and has not yet been reviewed by counsel. Ask us for the executed version before you rely on it.
Roles
For borrower and staff records held in your system, you are the data controller and Edgecom Websolutions is the data processor. We process that data only on your documented instructions.
Scope
Subject matter: providing loan management software. Duration: the life of the agreement plus the retention window. Data subjects: your borrowers, guarantors, staff and contacts. Categories: identity and contact details, identification numbers, loan and repayment records, and any documents you upload.
Security measures
A separate database per customer with its own least-privilege credentials; encryption of credentials at rest; transport encryption; multi-factor authentication; access narrowed at the query layer by branch and by officer; an append-only audit trail; and per-customer backup.
Sub-processors
We use infrastructure and communications providers to deliver the service. We will maintain a current list and give notice before adding one, so that you have an opportunity to object.
Personal data breaches
We will notify you without undue delay after becoming aware of a breach affecting your data, with the information you need for your own notification obligations under the Data Protection Act 2019.
Return and deletion
On termination we will make an export available and delete your data after the retention window, except where we are required to keep it by law.
Audit
We will provide the information reasonably needed to demonstrate compliance with this addendum, and will respond to security questionnaires.
Questions? Call 0798 358 081 or email hello@microfin.co.ke.