Privacy Policy
Last updated: July 2026
Mobile Sasa is a bulk messaging platform operated by Bitwise Digital Solutions Ltd, a company registered in Kenya ("Mobile Sasa", "we", "us"). This policy explains what personal data we collect, why we collect it, how long we keep it, and the rights you have over it. It applies to our website, the customer portal at account.mobilesasa.com, and our APIs.
We process personal data in accordance with the Kenya Data Protection Act, 2019 and its regulations. Where we decide how and why data is processed (for example, your account details) we act as a data controller. Where we process data on our customers' instructions (for example, the contact lists a business uploads to send messages) we act as a data processor.
1. Information we collect
We collect the following categories of information:
- Account information โ name, email address, phone number, company name, and password (stored only as a salted hash) provided when you register or are invited to a team.
- Billing information โ top-up records and M-Pesa transaction references. We do not receive or store M-Pesa PINs or card details; payments are processed by Safaricom.
- Message content and metadata โ the text of messages you send, sender IDs, recipient numbers, timestamps, and delivery status returned by mobile network operators.
- Contact data you uploadโ names and phone numbers in the contact lists, groups, and files our customers upload. We process this data on the customer's behalf (see section 3).
- Device and connection information โ when you sign in or use the portal we record your IP address, browser type and version, the approximate location derived from your IP address, and your sign-in and session history. See section 2 for how this is used.
- Support communications โ messages you send to our support and sales teams.
2. Account security and abuse prevention
We use device and connection information (IP address, browser characteristics, and sign-in history) to keep accounts safe and the platform trustworthy. Specifically, this data lets us:
- recognise your usual devices and flag sign-ins that look unusual for your account;
- lock accounts after repeated failed sign-in attempts and support two-step verification;
- maintain a session history you can review, and end sessions you don't recognise;
- detect and prevent fraud, spam, and other misuse of the messaging platform;
- rate-limit abusive traffic and investigate security incidents.
This is standard security telemetry โ we do not build advertising profiles, we do not track you across other websites, and we do not sell this information. It is used only for security, fraud prevention, and the integrity of the service, and is visible to a restricted set of platform administrators.
3. Contact data our customers upload
Businesses use Mobile Sasa to message their own customers. When a business uploads contact lists or sends messages, that business is the data controller of its recipients' data and Mobile Sasa processes it only to provide the service โ storing lists, routing messages to mobile network operators, and reporting delivery.
- We do not use customer-uploaded contact data for our own marketing, and we never sell it.
- This includes data uploaded for scheduled messaging โ reminder recipient lists with per-recipient message content, and anniversary contacts with names, phone numbers and significant dates such as birthdays. We process it solely to schedule and deliver the messages the customer configured.
- Customers are responsible for having a lawful basis (such as consent) to message their recipients and for honouring opt-outs.
- Recipients can opt out at any time; opted-out numbers are placed on a blacklist that blocks further messages from the relevant sender.
- If you have received an unwanted message sent through our platform, contact us at [email protected] and we will act on it.
4. How we use your information
- To provide, operate, and improve the service โ including routing messages and reporting delivery.
- To manage your SMS credit balance, process top-ups, and send balance reminders.
- To send transactional communications: verification codes, receipts, and service notifications.
- To keep accounts secure and prevent fraud and platform misuse (section 2).
- To comply with legal obligations, including those under Kenyan communications and data protection law.
- To respond to your support requests.
6. How long we keep data
In line with the storage-limitation principle of the Kenya Data Protection Act, 2019, we keep personal data only for as long as is reasonably necessary for the purpose it was collected โ whether we hold it as a controller or process it on a customer's behalf โ and for any period required by applicable law.
- Account data is kept for as long as your account is active.
- Message records are retained for delivery reporting and billing reconciliation, then removed on a rolling basis.
- Security logs (sign-in history, session records) are kept for a limited period appropriate to security investigation and then removed.
- Reminder and anniversary listsare kept while the customer's schedule exists and are deleted when the customer deletes the reminder, the anniversary group or a contact on it โ and in any case when the account is deleted.
- Deleted accounts โ when an account is deleted, access is revoked immediately and, after a 30-day recovery window, the personal data associated with the account is deleted. Transaction records that Kenyan law requires us to keep (for example, for tax and audit purposes) are retained for the statutory period only.
You may request earlier deletion of your data by contacting [email protected].
8. How we protect data
- Encryption in transit (TLS) for the website, portal, and APIs.
- Passwords stored only as salted bcrypt hashes; API tokens stored hashed.
- Role-based access control โ staff access to customer data is limited by role and logged.
- Account protections: rate limiting, failed-sign-in lockout, session management, and audit trails.
- No system is perfectly secure; if we become aware of a breach affecting your data we will notify you and the Office of the Data Protection Commissioner as required by law.
9. Your rights
Under the Kenya Data Protection Act, 2019 you have the right to:
- be informed about how your data is used;
- access the personal data we hold about you;
- have inaccurate data corrected;
- request deletion of your data;
- object to or restrict certain processing;
- receive your data in a portable format.
To exercise any of these rights, email [email protected]. We respond within the timelines set by the Act. If you are unsatisfied with our response, you may lodge a complaint with the Office of the Data Protection Commissioner (www.odpc.go.ke).
10. Children
The service is intended for businesses and individuals aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email or a prominent notice in the portal at least 14 days before they take effect. The "last updated" date at the top reflects the current version.
12. Contact us
Data protection enquiries: [email protected]
General support: [email protected]
Bitwise Digital Solutions Ltd, IPS Building, 6th Floor, Kimathi Street, Nairobi, Kenya.
See also our Terms of Service.