Legal

Privacy policy

How we collect, use and protect personal data when you use JMSURF SMS. Last updated 30 September 2026.

Who we are

JMSURF SMS is operated by JMSURF Technologies in Nairobi, Kenya. We act as a data controller for account information and as a data processor for the contact lists and messages our customers upload, in line with the Kenya Data Protection Act, 2019.

What we collect

  • Account details: name, company, email address, phone number, industry, website and KRA PIN when provided.
  • Customer content: contacts, groups, custom fields, message text, templates and replies you receive.
  • Transaction data: top-up amounts, M-Pesa receipts, card payment references and invoices. We do not store card numbers.
  • Technical data: sign-in activity, IP addresses for security and audit logs, and API usage.

How we use it

  • To deliver your messages through licensed carriers and report their status.
  • To process payments, issue invoices and keep your wallet accurate.
  • To secure accounts, prevent fraud and abuse, and meet legal obligations.
  • To support you and tell you about important service changes.

Your customers' data

You remain responsible for having a lawful basis to message your contacts and for honouring opt-outs. We automatically block numbers that reply STOP to your messages. We never sell or use your contact lists for our own marketing.

Sharing

We share data only with service providers needed to run the platform — SMS carriers and aggregators, payment processors, and cloud hosting — under contractual safeguards, or where required by law.

Retention and security

We keep account and transaction records for as long as your account is active and as required by tax law. Data is encrypted in transit, access is role-restricted, sensitive actions are audited and two-factor sign-in is available to every user.

Your rights

You may request access to, correction of or deletion of your personal data, or object to processing, by emailing jmsurftech@gmail.com. You may also lodge a complaint with the Office of the Data Protection Commissioner.