This customer information page forms part of the website publication set. Final regulatory references, statutory timeframes and licence details must be confirmed before formal launch.
1. Who is responsible for your personal data
Kingscross Money Remittance Ltd is the data controller for personal data that it determines how and why to process in connection with its website, customer accounts, branches, agents, money-transfer, foreign-exchange, compliance, support and administration activities.
In some arrangements, another organisation may act as an independent controller or joint controller. In other cases, a service provider may process personal data only on Kingscross’s documented instructions.
Kingscross Money Remittance Ltd
Registered office: Altura, Upper Hill, Ralph Bunche Road, Ground Floor, P.O. Box 1680-00100, Nairobi, Kenya
Privacy email: corporate@kingsxross.com
ODPC registration number: To be inserted when confirmed
2. Scope of this Privacy Notice
This Notice applies when you:
- visit or use the Kingscross website or customer portal;
- register as an individual or business customer;
- request a quote or create a transaction;
- fund, receive, cancel, amend or query a transaction;
- act as a beneficiary, beneficial owner, director or authorised representative;
- apply to become an agent or service provider;
- contact customer support, submit a complaint or report fraud; or
- interact with Kingscross through a branch, agent, email, telephone, SMS or another approved channel.
Separate privacy information may be supplied for employees, job applicants, agents, suppliers or specific products where necessary.
3. Personal data we may collect
3.1 Identity and contact information
- full legal name, former name, title, date of birth, nationality and gender where required;
- national identity, passport, alien identification or other document details;
- photograph, signature and identity-verification results;
- residential, postal, registered and business addresses;
- telephone number, email address and preferred communication method.
3.2 Business and ownership information
- registered name, trading name, registration number and tax number;
- business activity, industry, licences, branches and operating countries;
- directors, shareholders, beneficial owners, controllers and authorised persons;
- constitutional documents, ownership charts, resolutions and mandates;
- financial statements, contracts, invoices and business records.
3.3 Transaction and financial information
- send and receive amounts, currencies, exchange rates, fees and quote references;
- bank account, card, wallet, Paybill, funding and payout information;
- beneficiary names, contact details, account identifiers and relationship to the customer;
- transaction purpose, goods or services involved, invoices and supporting documents;
- payment confirmations, settlement records, refunds, reversals and reconciliation information.
3.4 Source-of-funds and source-of-wealth information
- bank statements, payslips, invoices, contracts, sale agreements and loan records;
- employment, occupation, income, business turnover and expected activity;
- information explaining the origin of a particular payment or overall wealth.
3.5 Compliance and risk information
- customer-risk rating and expected transaction profile;
- sanctions, politically exposed person and adverse-media screening results;
- fraud alerts, transaction-monitoring alerts, case notes and investigation outcomes;
- regulatory reports, lawful requests and information relevant to suspicious activity.
3.6 Technical and security information
- IP address, browser, device type, operating system and session information;
- login, OTP, failed-access, security-event and audit-log information;
- cookie preferences and permitted analytics information;
- approximate location inferred from technical information where lawful and necessary.
3.7 Communications and service information
- emails, telephone notes, correspondence, complaints and support requests;
- customer feedback, survey responses and service preferences;
- records of notices, document requests, confirmations and receipts.
4. Where we obtain personal data
We may receive personal data:
- directly from you;
- from a business, director, authorised representative or beneficial owner;
- from a sender, beneficiary or transaction counterparty;
- from a Kingscross branch, approved agent or customer-support channel;
- from banks, mobile-money operators, card networks and payout partners;
- from identity-verification, sanctions-screening and fraud-prevention providers;
- from public registers, company registries, court records, official publications and lawful databases;
- from regulators, law-enforcement agencies, courts or other competent authorities; and
- from website, device, security and audit systems.
If you provide personal data about another person, you should have authority or another lawful basis to do so and should direct that person to this Notice where appropriate.
5. Why we process personal data
| Purpose | Examples |
|---|---|
| Account opening and management | Registration, identity checks, profile maintenance, login and customer support. |
| Service delivery | Quotes, transfers, FX conversion, payout, settlement, refunds and receipts. |
| Compliance | KYC, beneficial ownership, sanctions screening, AML monitoring and regulatory reporting. |
| Fraud and security | Authentication, device monitoring, scam intervention, investigation and account protection. |
| Legal and dispute management | Complaints, claims, court orders, audits and evidence preservation. |
| Operations and improvement | Reconciliation, reporting, testing, service quality and business continuity. |
| Communication | OTP codes, transaction updates, document requests, notices and service messages. |
| Marketing where permitted | Product information, campaigns and customer research, subject to applicable consent or opt-out rights. |
6. Lawful bases for processing
Depending on the activity, Kingscross may process personal data because:
- processing is necessary to enter into or perform a contract with you;
- processing is necessary to comply with a legal or regulatory obligation;
- processing is necessary for a legitimate interest that is not overridden by your rights;
- you have given valid consent for a specific purpose;
- processing is necessary to establish, exercise or defend a legal claim;
- processing is necessary to protect vital interests; or
- another lawful basis under Kenyan law applies.
Where we rely on legitimate interests, these may include fraud prevention, network and information security, service improvement, record integrity, legal-risk management and efficient administration. We should assess whether the processing is necessary and proportionate.
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing already carried out lawfully and may not prevent processing required under another lawful basis.
7. Sensitive personal data and biometric information
Kingscross may process sensitive personal data only where lawful, necessary and subject to appropriate safeguards. This may include biometric or facial-verification data, property or financial details, family information, health-related transaction evidence, or information revealing other protected characteristics.
Examples include:
- facial comparison used to verify identity;
- medical documents supporting a medical-payment transaction;
- family or relationship information relevant to a beneficiary or source of funds;
- property records supporting source-of-wealth verification.
Access to sensitive information should be restricted to authorised persons and retained only as long as reasonably necessary.
8. KYC, AML, sanctions, fraud and transaction monitoring
As a regulated financial-services business, Kingscross may be required to identify customers, verify beneficial owners, understand transaction purposes, monitor activity and retain compliance records.
We may process and compare information to:
- confirm identity and authority;
- assess whether activity matches the customer’s expected profile;
- detect unusual value, frequency, velocity, geography, funding or beneficiary patterns;
- screen for sanctions, politically exposed persons and adverse information;
- prevent fraud, scams, account takeover and unauthorised transactions;
- investigate alerts and make lawful reports to competent authorities.
We may be legally restricted from telling you whether a report, investigation or particular compliance action has occurred.
9. Who we may share personal data with
We may share personal data, where lawful and necessary, with:
- banks, correspondent institutions and settlement providers;
- mobile-money operators, card networks and payout partners;
- identity-verification, screening, fraud-prevention and compliance providers;
- technology, hosting, cybersecurity, communications and document-storage providers;
- approved agents, branches and customer-support providers;
- auditors, accountants, insurers, lawyers and professional advisers;
- the Central Bank of Kenya, Financial Reporting Centre, Office of the Data Protection Commissioner and other competent authorities;
- courts, tribunals, law-enforcement agencies and government bodies where lawfully required;
- potential purchasers, investors or reorganised entities subject to confidentiality, due diligence and lawful transfer requirements.
We should provide only the information reasonably necessary for the recipient’s purpose and use contractual, technical and organisational safeguards where appropriate.
10. Data processors and service providers
Where a supplier processes personal data on behalf of Kingscross, it should be subject to a written agreement covering confidentiality, security, permitted processing, sub-processors, assistance with rights, breach reporting, deletion or return of data, and audit or assurance rights.
Kingscross should assess providers before appointment and monitor material providers throughout the relationship.
11. International transfers of personal data
Cross-border payments may require personal data to be transferred to or accessed from countries outside Kenya. Recipients may include banks, payment networks, payout partners, technology providers and authorities in the destination or intermediary country.
Before an international transfer, Kingscross should identify a lawful transfer basis and assess the destination, recipient, purpose, categories of data, security and available rights. Safeguards may include:
- the data subject’s valid consent where appropriate;
- transfer necessary to perform a contract or requested transaction;
- adequacy or another recognised legal basis;
- contractual protections;
- encryption, access controls and data minimisation;
- transfer-risk and supplier assessments.
Some foreign authorities may have lawful access powers that differ from those in Kenya.
12. How long we retain personal data
Kingscross should not retain personal data longer than necessary for the purpose for which it was collected, subject to legal, regulatory, accounting, AML, tax, litigation, security and audit requirements.
Retention periods may differ by record type. Relevant factors include:
- the duration of the customer relationship;
- financial-services and AML recordkeeping requirements;
- complaint, dispute and limitation periods;
- fraud, security and regulatory-investigation needs;
- contractual obligations to payment partners;
- whether the data can be anonymised instead of retained in identifiable form.
When retention is no longer justified, data should be securely deleted, destroyed or irreversibly anonymised, unless lawful archival retention applies.
13. How we protect personal data
Kingscross should apply technical and organisational measures appropriate to the nature, volume and risk of the data. These may include:
- role-based access and least-privilege controls;
- multi-factor authentication and strong password controls;
- encryption in transit and at rest where appropriate;
- secure software development, vulnerability testing and patching;
- network monitoring, logging and incident detection;
- maker-checker approvals and segregation of duties;
- secure backups, recovery and business-continuity arrangements;
- employee screening, training and confidentiality obligations;
- supplier due diligence and contract controls;
- secure deletion and physical document protection.
No system can guarantee absolute security. Customers should protect their own devices, passwords, OTP codes, email accounts and telephone numbers and report suspected compromise immediately.
14. Profiling, automated monitoring and decisions
Kingscross may use rules, risk scores and automated tools to support identity verification, fraud prevention, sanctions screening, transaction monitoring, customer-risk assessment and service security.
Automated tools may flag a transaction for further review, request additional information, delay processing or support a decision. Where a decision produces a significant effect and is made solely by automated means, Kingscross should apply the protections required by law, including human review where applicable.
You may request information about significant automated processing and may have the right to challenge or seek review of certain decisions, subject to legal and compliance restrictions.
15. Service messages and marketing
Kingscross may send necessary service communications without marketing consent, including OTP codes, security alerts, transaction updates, document requests, regulatory notices and service-interruption information.
Marketing communications should be sent only where permitted. You may opt out using the unsubscribe method provided or by contacting Kingscross. Opting out of marketing does not stop essential service messages.
Kingscross should not sell personal data to third parties for their independent marketing.
16. Cookies and similar technologies
The website may use necessary cookies or browser storage for authentication, security, preferences and transaction continuity. Optional analytics or marketing technologies should be controlled through the Cookie Notice and preference tool.
17. Your data-protection rights
Subject to the Data Protection Act, applicable regulations and lawful exemptions, you may have the right to:
- be informed about how your personal data is used;
- access personal data held about you;
- request correction of inaccurate or misleading data;
- request deletion where there is no lawful reason to retain the data;
- object to certain processing;
- request restriction of processing;
- receive certain personal data in a portable format;
- withdraw consent where processing relies on consent;
- challenge certain solely automated decisions;
- complain to the Office of the Data Protection Commissioner.
Some rights are not absolute. For example, Kingscross may need to retain data to comply with AML, financial-services, tax, court, fraud-prevention or regulatory obligations.
How to make a rights request
You should contact the final published privacy address and describe the request. Kingscross may ask for proof of identity or authority before disclosing or changing information.
Kingscross should respond within the period required by applicable law and should explain any refusal, restriction or lawful extension.
18. Children’s personal data
Kingscross services are not intended for children acting independently unless a product is lawfully designed and approved for that purpose.
Where information about a child is required for a lawful transaction, Kingscross should verify the authority of the parent, guardian or authorised person and apply enhanced protection appropriate to the child’s best interests.
19. Accuracy and customer responsibility
You should provide accurate and current information and promptly notify Kingscross of changes. We may request updated documents periodically or when risk, regulation, transaction activity or account information changes.
20. Personal data breaches
Kingscross should maintain procedures to identify, contain, assess, investigate, document and remediate personal data breaches.
Where required by law, Kingscross should notify the Office of the Data Protection Commissioner and affected individuals within the applicable period, taking account of the nature of the breach and risk to rights and freedoms.
If you suspect unauthorised access, disclosure or loss of your data, contact Kingscross immediately through the final published security or privacy channel.
21. Questions, complaints and regulatory contact
Questions or privacy complaints should first be sent to Kingscross through the final published privacy contact. We should record, investigate and respond appropriately.
You also have the right to complain to the Office of the Data Protection Commissioner in Kenya. The Office’s current contact details should be linked or reproduced after final website review.
22. Changes to this Privacy Notice
Kingscross may update this Notice to reflect changes in law, regulation, products, technology, partners or processing activities. Material changes should be communicated through the website, customer account, email, SMS or another appropriate channel.
The version and effective date displayed at the top identify the applicable notice.
23. Contact details to be completed before launch
| Privacy contact | Kingscross Money Remittance Ltd |
| corporate@kingsxross.com | |
| Registered office | Altura, Upper Hill, Ralph Bunche Road, Ground Floor, P.O. Box 1680-00100, Nairobi, Kenya |
| ODPC registration number | To be confirmed |
| Security incident channel | To be confirmed |
Contact
Email: corporate@kingsxross.com
Registered office: Altura, Upper Hill, Ralph Bunche Road, Ground Floor, P.O. Box 1680-00100, Nairobi, Kenya
