Privacy Policy
Last updated: 27 August 2026
Xcobean Systems Limited ("Xcobean", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our website, client portal, mobile applications, and related services.
Table of Contents
- 1. Scope of This Policy
- 2. Data Controller
- 3. Data We Collect
- 4. How We Collect Data
- 5. How We Use Your Data
- 6. Legal Basis for Processing
- 7. Cookies and Tracking Technologies
- 8. Third-Party Services and Integrations
- 9. Data Sharing and Disclosure
- 10. Data Storage and Security
- 11. Data Retention
- 12. Your Rights
- 13. International Data Transfers
- 14. Children's Privacy
- 15. Changes to This Policy
- 16. Contact Us
1. Scope of This Policy
This Privacy Policy applies to:
- Our Websites and Platforms: xcobean.co.ke and xcobean.com and all of their subdomains (including api, developers, payments, sign, vault, connect, links, pass, id and ai-gw), xs.ke and its subdomains (our one-time secret service), and notarize.africa
- Client Portal: our WHMCS-based client area for account management, billing, and service provisioning (including Apache CloudStack integration)
- Mobile Applications: the myxcobean and Xcobean ID mobile apps available on Google Play and the Apple App Store
- Communications: emails, live chat (Zoho SalesIQ), WhatsApp Business, Telegram, and phone calls
- Third-Party Integrations: services we use to deliver and improve our products
2. Data Controller
The data controller responsible for your personal data is:
Xcobean Systems Limited
11th Floor, Britam Towers, Nairobi, Kenya
Kigali Innovation City, Kigali, Rwanda
Email: privacy@xcobean.co.ke
Phone: +254 709 488 888 / +254 726 415 131 (Kenya)
Phone: +250 788 931 752 (Rwanda)
3. Data We Collect
3.1 Account Information
When you register for an account or purchase services, we collect:
- Full name, company name, and job title
- Email address and phone number
- Physical/postal address
- KRA PIN (for VAT compliance, where applicable)
- Username and password (hashed)
3.2 Authentication Data
Depending on the method you choose, we may process:
- Email/password credentials (passwords are stored as one-way hashes)
- Social login tokens (Google Sign-In, Apple Sign-In)
- Biometric authentication flags (Face ID, Touch ID, or fingerprint unlock is evaluated entirely by your device; we never receive or store your device's biometric templates). Face data collected during identity verification is described separately in Section 3.7
- FIDO2/WebAuthn passkeys (public key only; private key remains on your device)
- Two-factor authentication (2FA) recovery codes
3.3 Billing and Financial Data
- Invoices and payment history
- Payment method details (M-Pesa phone number, PayPal email, Pesapal transaction references)
- Credit notes and account balances
We do not store full credit/debit card numbers. Payment processing is handled by our third-party payment providers.
3.4 Service and Technical Data
- Cloud resource usage (virtual machines, storage, bandwidth) via Apache CloudStack
- Domain registrations and DNS records
- Support tickets and communications
- Service configuration data
3.5 Device and Usage Data
- IP address and approximate geolocation
- Browser type, version, and operating system
- Device type and screen resolution
- Pages visited, time spent, and referral source
- Mobile app: device model, OS version, app version, unique device identifiers
3.6 Permissions (Mobile Apps)
The myxcobean and Xcobean ID apps may request the following device permissions:
- Camera: for scanning QR codes, scanning your identity document, and taking a selfie during identity verification (see Section 3.7)
- NFC: to read the secure chip inside your passport or national eID during identity verification (Xcobean ID)
- Notifications: to send service alerts and updates
- Biometric: for secure local authentication
Permissions are requested at the point of use and can be revoked through your device settings at any time.
3.7 Identity Verification and Face Data (Xcobean ID)
The Xcobean ID app offers an optional identity verification feature. It reads the secure chip inside your passport or national eID, then performs a short face check to confirm that you are the document's holder. This feature runs only when you choose to start it and only after you have reviewed a consent screen describing what will happen. If you use this feature, we process:
- Document chip data: the details stored on your document's chip: full name, document number, nationality, date of birth, document expiry, the machine-readable zone (MRZ), the chip's digital signatures, and the photograph stored on the chip
- A live selfie photograph: a single, standard two-dimensional photograph taken by the front camera during the face check
- A liveness result: a pass or fail indication that a live person, rather than a photo or a screen, completed the face check
Face data from the TrueDepth camera stays on your device. On iPhones with Face ID hardware, the liveness check uses Apple's TrueDepth camera (through Apple's ARKit face tracking) to confirm a real, three-dimensional face is present and to follow simple prompts such as turning your head and blinking. The depth information, facial geometry, and facial-expression values produced by the TrueDepth camera are processed solely on your device, in memory, for the duration of the check. They are never stored, never written to disk, and never transmitted off the device, and they are discarded the moment the check ends. The only items that leave your device are the standard two-dimensional selfie photograph and the pass or fail result.
Purpose. Your selfie is used for exactly one purpose: a one-to-one comparison against the photograph on your own identity document, to confirm you are the document's holder. We do not use face data to identify you among other people, we do not build or contribute to any facial-recognition database, and we do not use face data for advertising, analytics, profiling, or any other purpose.
Sharing. Face data is never shared with, sold to, or disclosed to any third party. The face comparison and liveness analysis are performed entirely on Xcobean's own systems, running on infrastructure we operate on Google Cloud Platform. No third-party facial-recognition or biometric service is involved. Google acts solely as our hosting infrastructure provider and has no access to this data for its own purposes.
Storage and retention. Your selfie is processed transiently for the comparison and is not retained once the check completes. The verified document details and the photograph from your document's chip are stored encrypted (AES-256-GCM, with keys held separately from the database) for as long as the verification remains active on your account. The face comparison produces a numeric similarity score, which we retain as part of the verification record.
Deletion. You can delete your identity verification, including the stored document details and document photograph, at any time from your Xcobean account page at id.xcobean.com (Account, then Remove identity verification), or by emailing privacy@xcobean.co.ke. Deletion takes effect immediately.
4. How We Collect Data
- Directly from you: when you register, place orders, submit tickets, fill in forms, or communicate with us
- Automatically: through cookies, analytics, and server logs when you use our website or apps
- From third parties: payment providers (transaction confirmations), social login providers (basic profile data), and public registries (WHOIS, company registries)
5. How We Use Your Data
We use your personal data to:
- Provision, manage, and support the services you purchase
- Process payments and issue invoices
- Communicate with you about your account, services, and support requests
- Send service notifications, maintenance alerts, and security advisories
- Send marketing communications (only with your consent; you can opt out at any time)
- Analyse website and app usage to improve our products and user experience
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations, including tax and regulatory requirements
- Enforce our Terms of Service and Acceptable Use Policy
6. Legal Basis for Processing
Under the Kenya Data Protection Act 2019 and, where applicable, the EU General Data Protection Regulation (GDPR), we process your data on the following bases:
- Contractual necessity: to perform our obligations under your service agreement
- Legitimate interests: to improve our services, prevent fraud, and maintain security
- Legal obligation: to comply with tax, accounting, and regulatory requirements
- Consent: for marketing communications and non-essential cookies (which you can withdraw at any time)
7. Cookies and Tracking Technologies
Our website uses the following categories of cookies:
| Category | Purpose | Examples |
|---|---|---|
| Strictly Necessary | Session management, authentication, CSRF protection | Laravel session, XSRF-TOKEN |
| Functional | Remember preferences (theme, language) | theme-mode |
| Analytics | Understand site usage and performance | Google Analytics (GA4), Zoho PageSense |
| Marketing | Personalise content, measure campaign effectiveness | Zoho Marketing Automation |
| Live Chat | Enable real-time support | Zoho SalesIQ |
You can manage cookie preferences through your browser settings. Note that disabling strictly necessary cookies may affect the functionality of our website.
8. Third-Party Services and Integrations
We use the following third-party services, each of which has its own privacy policy:
8.1 Service Delivery
- WHMCS: client management, billing, and support ticketing
- Apache CloudStack: cloud infrastructure orchestration
8.2 Zoho Suite
- Zoho SalesIQ: live chat and visitor tracking
- Zoho PageSense: website analytics and A/B testing
- Zoho Marketing Automation: email marketing and lead nurturing
- Zoho Books: accounting and invoicing
- Zoho Desk: customer support management
- Zoho Sign: electronic document signing
- Zoho Assist: remote support sessions (initiated with your consent)
- Zoho Survey: customer satisfaction surveys
- Zoho Bookings: appointment scheduling
8.3 Google Services
- Google Analytics (GA4): website traffic analysis
- Google Workspace: email and collaboration (for internal operations)
- Google Sign-In / OAuth: social login for the mobile app
8.4 Payment Processors
- Xcobean Pay: our own payment aggregation platform, and the method most customers use. We handle the transaction record, settlement and reconciliation, and the payment itself is carried by one of the providers below depending on how you choose to pay
- M-Pesa (Safaricom): mobile money payments, including STK push, paybill and till
- Paystack: card and bank payment processing
- DPO Group: card and mobile money processing
- Pesapal: card and mobile money payments
- PayPal: international payments
- Bank transfer: where you pay us directly by bank transfer, your bank and ours process the payment. We receive the reference and remittance details
8.5 Communications
- WhatsApp Business API: customer messaging
- Telegram Bot: notifications and support
- Firebase Cloud Messaging: push notifications for the mobile app
8.6 Authentication
- Apple Sign-In: social login for iOS
- Google Sign-In: social login
- Firebase Authentication: mobile app user management
8.7 Infrastructure and Network
- Cloudflare: content delivery, DNS, DDoS mitigation, web application firewall and bot protection (Turnstile). Cloudflare sits in front of our websites and therefore processes the IP address and request metadata of every visitor
- Google Cloud Platform: hosting for this website, our API platform and our identity verification service
- Vultr: hosting for certain services
- Zabbix and Grafana: service monitoring and availability reporting
- Meilisearch: site and knowledge base search
- n8n: internal workflow automation
8.8 Artificial Intelligence Services
Some features send text to AI providers to generate a response. This includes our website assistant, our WhatsApp assistant and certain support and reporting tools in the client portal. We do not send payment details, passwords or identity verification data to these providers, and our agreements with them do not permit your data to be used to train their models. You can always reach a human instead by emailing info@xcobean.co.ke.
- Anthropic (Claude): assistant, support and content generation
- Google (Gemini): assistant and content generation
- OpenAI and xAI: assistant and content generation
- Our own AI gateway: some models run on infrastructure we operate ourselves, in which case no third party receives your text
8.9 Email Delivery
- ZeptoMail, Postmark, Resend, Amazon SES and Mailgun: delivery of transactional email such as invoices, service notifications and password resets. These providers process recipient email addresses and message content
- Microsoft 365 and Google Workspace: business email and collaboration
8.10 Electronic Signature
- DocuSeal and LibreSign: electronic signature services we operate on our own infrastructure
- Zoho Sign and Dropbox Sign: third-party electronic signature services, which process the name, email address, IP address and signature of each signatory
8.11 Communications and Telephony
- 3CX and our SIP carriers: voice telephony, call routing and, where you are notified, call recording
- Slack: internal alerting
9. Data Sharing and Disclosure
We do not sell your personal data. We may share data with:
- Service providers: third parties who process data on our behalf (as listed in Section 8), bound by data processing agreements
- Payment processors: to facilitate transactions you initiate
- Regulatory authorities: where required by Kenyan law (e.g., Kenya Revenue Authority, Office of the Data Protection Commissioner)
- Law enforcement: where legally compelled by a valid court order
- Business transfers: in the event of a merger, acquisition, or asset sale, with prior notice to affected users
10. Data Storage and Security
Where your data is stored depends on which service you use. We do not operate a single location, so rather than claim otherwise, here is the actual picture:
- Kenya: data held in our own Kenyan data centre and colocation facilities, including services we provide from local infrastructure
- Switzerland (Zurich): this website and our identity verification service, on infrastructure we operate in Google Cloud Platform's europe-west6 region
- United Kingdom (London): certain hosted and cloud services
- United States: certain third-party platforms we use to deliver and support our services
- Zoho's regional data centres: data held in the Zoho applications we use for customer relationship management, support, email and marketing
The safeguards described in Section 13 apply to any transfer outside Kenya. If your organisation requires data to remain in a particular country, tell us before you sign and we will confirm in writing where your data will sit for your specific service. We would rather agree that up front than have you assume it.
In all locations we implement appropriate technical and organisational measures, including:
- Encryption in transit (TLS 1.2+) and at rest
- Firewalls, intrusion detection, and DDoS mitigation
- Role-based access controls and multi-factor authentication for staff
- Regular security audits and vulnerability assessments
- Encrypted backups with tested restoration procedures
11. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 2 years after closure |
| Billing and invoicing records | 7 years (Kenya tax law requirement) |
| Support tickets | Duration of account + 1 year |
| Website analytics | 26 months (GA4 default) |
| Server and access logs | 90 days |
| Marketing consent records | Duration of consent + 3 years |
| Identity verification record (document details and document photograph, encrypted) | Until you delete the verification or close your account |
| Identity verification selfie | Not retained; processed transiently during the check only |
| TrueDepth face data (depth information, facial geometry, expression values) | Never collected by our servers; processed on your device only and discarded when the check ends |
12. Your Rights
Under the Kenya Data Protection Act 2019 (and the GDPR for EU/EEA residents), you have the right to:
- Access: request a copy of the personal data we hold about you
- Rectification: request correction of inaccurate or incomplete data
- Erasure: request deletion of your personal data (subject to legal retention obligations)
- Data portability: receive your data in a structured, machine-readable format
- Restriction: request that we limit the processing of your data
- Objection: object to processing based on legitimate interests or direct marketing
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing
To exercise any of these rights, contact us at privacy@xcobean.co.ke. We will respond within 30 days.
You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC), Kenya.
13. International Data Transfers
Some of our third-party service providers (e.g., Google, PayPal, Firebase) may process data outside Kenya. Where this occurs, we ensure that appropriate safeguards are in place, including:
- Standard contractual clauses
- Adequacy decisions by the ODPC
- Binding corporate rules of the service provider
14. Children's Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us at privacy@xcobean.co.ke and we will promptly delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page with a revised "Last updated" date
- Sending an email notification for significant changes
- Displaying a prominent notice on our website or client portal
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Xcobean Systems Limited
11th Floor, Britam Towers, Nairobi, Kenya
Kigali Innovation City, Kigali, Rwanda
Privacy inquiries: privacy@xcobean.co.ke
General inquiries: info@xcobean.co.ke
Phone: +254 709 488 888 / +254 726 415 131 (Kenya)
Phone: +250 788 931 752 (Rwanda)
Website: xcobean.co.ke
How Xcobean ID handles your data
Xcobean ID (id.xcobean.com) is the single sign-on service operated by Xcobean Systems Limited, Nairobi, Kenya. It lets you use one account across Xcobean products and across the applications of organisations that connect to it. This supplement adds the detail specific to sign-in, on top of the Privacy Policy above, under the Kenya Data Protection Act, 2019.
What Xcobean ID collects
- Account details you provide: name, and any of email, phone number, or password.
- National ID or passport data: optional; only if you choose to add or verify it for a product that requires identity verification (see section 3.7 of the Privacy Policy).
- Voiceprint (biometric): optional; only if you choose to set up Voice ID as a sign-in factor. This is an encrypted mathematical model of your voice, not a recording of you. The short audio clip you record is used only to compute that model and is then discarded; we do not keep the audio.
- Second-factor enrolments: the phone number, authenticator, passkey, security key, Xcobean tag or device you register for two-step verification, and the signals needed to check them (for example device attestation results).
- Social and federated sign-in identifiers if you sign in with a provider such as Google, Microsoft, Apple, LinkedIn, GitHub, Zoho or PayPal, or through your organisation's own directory: your provider account id, email, name and profile photo.
- Login metadata: timestamps, IP address, browser and device details, and the product or application you signed in to, kept for security and audit.
- Same-room sound check: while you approve a sign-in on your phone, the sign-in page may play a short high-pitched sound your phone can hear, so Xcobean ID can check the phone is in the same room as the screen. Nothing is recorded or uploaded from the page; it only plays a code, and you can mute it on the page.
- Typing rhythm (behavioural biometric): optional; only if you switch it on under Preferences. We keep the gaps between your keystrokes when you type your password, never what you typed, to notice an unfamiliar rhythm. Switching it off deletes the learnt rhythm.
Why Xcobean ID uses it
Solely to authenticate you, protect your account and enable single sign-on to the product or application you choose to access. Lawful bases: your consent and the performance of our service to you. Your voiceprint, if you set one up, is used only to confirm it is you at sign-in or before a sensitive action.
Voice ID (biometric data)
Under the Data Protection Act, 2019 a voiceprint is sensitive personal data, so we process it only with your explicit, opt-in consent, which you give when you set up Voice ID and can withdraw at any time. We store only the encrypted voiceprint model, never the audio. Your voiceprint stays within Xcobean ID: it is never shared with the products or applications you sign in to.
What is shared when you sign in
When you sign in to a Xcobean product or a connected application, we share a minimal identity token (your stable account id, and the name, email, phone or verified identity attributes the application is entitled to) with that application only, so it can recognise you. A third-party application shows you exactly what it will receive and asks for your consent first, which you can withdraw under Connected apps in your account. This token never contains your password, your second factors, your voiceprint or your saved payment details. We do not sell your data or share it for advertising.
Retention and security
We keep your identity record while your account is active. Passwords are hashed; the voiceprint is encrypted at rest and the enrolment audio is discarded once the model is computed; connections are encrypted in transit. Login metadata is retained for the security and audit periods set out in section 11 of the Privacy Policy. You can request deletion at any time, and you can remove Voice ID or any other second factor on its own without closing your account.
Your rights and contact
Under the Data Protection Act, 2019 you may access, correct or delete your data, withdraw consent, and lodge a complaint with the Office of the Data Protection Commissioner. Contact privacy@xcobean.co.ke.
Xcobean ID supplement last updated: 8 September 2026.