Legal · Privacy

Privacy Policy

Version 1.0Effective: 1 June 2026
This policy applies to mandu360.com, the Mandu platform, and all associated services.
This Privacy Policy explains how Mandu collects, uses, stores, and protects your personal data. It applies to all users of the Mandu website, platform, and services. Please read it carefully.
1 Who We Are

The Mandu platform is jointly owned and operated by Mandu Goodz, a business entity registered under the laws of the Republic of Kenya, and EMMMW LLC, a limited liability company organized under the laws of the United States of America (together, “Mandu”, “we”, “us”, or “our”). Both entities are jointly responsible for the collection and use of personal data as described in this Policy.

This Privacy Policy applies to all personal data collected through: (a) the Mandu website at mandu360.com and all subdomains; (b) the Mandu platform and tenant environments; (c) the Partner Program and Partner Dashboard; (d) our support channels; and (e) any communications between you and Mandu.

2 Legal Framework

Mandu is committed to processing personal data in compliance with all applicable data protection laws, including:

Where multiple frameworks apply, Mandu will apply the standard that provides the greatest level of protection to you.

3 Personal Data We Collect
3.1 Data You Provide Directly

We collect personal data that you voluntarily provide when you:

3.2 Data Generated Through Your Use of the Service

When you use the Mandu platform, we automatically collect:

3.3 Customer Data (Data You Submit About Others)

In the course of using the platform for your business, you may upload or process personal data relating to your own customers, employees, or suppliers (“Customer Data”). This data is processed by Mandu on your behalf as a data processor, in accordance with your instructions and our Customer Terms of Service. You remain the data controller for such data and are responsible for your own compliance obligations.

3.4 Data From Third Parties

We may receive personal data about you from: (a) Partners who refer you through our Partner Program; (b) payment processors providing transaction confirmation; and (c) publicly available sources used to verify business information.

3.5 Sensitive Data

Mandu does not intentionally collect sensitive personal data (such as health data, biometric data, or data on racial or ethnic origin) through the platform. Please do not submit such data unless specifically requested for a compliance feature.

4 How We Use Your Personal Data
4.1 To Provide and Operate the Service
4.2 To Manage the Partner Program
4.3 To Improve and Develop the Service
4.4 For Marketing

We may send marketing emails about Mandu features and offers only where you have opted in or where permitted by applicable law. You may opt out at any time by clicking “Unsubscribe” in any marketing email or by contacting support@mandu360.com.

4.5 For Legal and Compliance Purposes
4.6 Legal Bases for Processing (GDPR/KDPA)

Where the GDPR or KDPA applies, we process your personal data on the following legal bases: Performance of a contract (providing the Service); Legitimate interests (analytics, fraud prevention, security); Legal obligation (where required by law); and Consent (for marketing and non-essential cookies).

5 Who We Share Your Data With
5.1 Service Providers and Sub-processors

We share personal data with carefully selected third-party service providers who assist us in operating the Service, bound by data processing agreements. Categories include:

Specific providers may change over time. Current sub-processors are available upon written request.

5.2 Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you prior to such a transfer as required by applicable law.

5.3 Legal Requirements

We may disclose personal data where required by applicable law, court order, or governmental request. We will notify you where legally permitted.

5.4 What We Do Not Do
Mandu does not: (a) sell your personal data to third parties; (b) share your personal data for third parties’ own marketing purposes; or (c) use your Customer Data for any purpose other than providing and maintaining the Service.
6 International Data Transfers

Mandu operates globally and your personal data may be transferred to and processed in countries other than your country of residence, including Kenya and the United States. These countries may have data protection laws that differ from those in your jurisdiction.

Where we transfer personal data from the EEA or UK, we implement appropriate safeguards including Standard Contractual Clauses approved by the European Commission or UK ICO, and adequacy decisions where applicable. For transfers from Kenya, we comply with the KDPA cross-border transfer requirements.

7 How Long We Keep Your Data
8 Your Rights
8.1 Rights Under Applicable Law

Depending on your location and applicable law, you may have the following rights:

🔍 Access

Request a copy of the personal data we hold about you.

✏️ Rectification

Request correction of inaccurate or incomplete data.

🗑️ Erasure

Request deletion of your personal data, subject to legal requirements.

⚙️ Restriction

Request that we limit processing in certain circumstances.

📤 Portability

Receive your data in a structured, machine-readable format.

✋ Object

Object to processing based on legitimate interests or for direct marketing.

🔒 Withdraw Consent

Withdraw consent at any time where processing is consent-based.

🤖 Automated Decisions

Not be subject to decisions based solely on automated processing.

8.2 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights including: (a) the right to know what personal information is collected, used, shared, or sold; (b) the right to delete personal information; (c) the right to opt-out of the sale or sharing of personal information (Mandu does not sell personal information); (d) the right to non-discrimination for exercising privacy rights; and (e) the right to correct inaccurate personal information.

8.3 How to Exercise Your Rights

Contact us at support@mandu360.com with the subject line “Privacy Rights Request”, providing sufficient information to identify yourself and the right you wish to exercise. We will respond within thirty (30) days. We may request proof of identity before processing your request.

8.4 Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with applicable law, you may lodge a complaint with the relevant supervisory authority. In Kenya: the Office of the Data Protection Commissioner (ODPC) at odpc.go.ke. In the EU: your local Data Protection Authority. In the UK: the Information Commissioner’s Office (ICO) at ico.org.uk.

9 Cookies and Tracking Technologies
9.1 What Are Cookies

Cookies are small text files placed on your device when you visit a website. We also use similar technologies including pixel tags and local storage. We refer to all such technologies collectively as “cookies”.

9.2 Types of Cookies We Use
9.3 Cookie Management

You can manage cookies through your browser settings. Disabling certain cookies may affect the functionality of the Mandu website and platform. Where consent is required for cookies, we will request it via a cookie consent mechanism.

10 Data Security

Mandu implements commercially reasonable technical, administrative, and physical security measures to protect your personal data, including encryption of data in transit and at rest, access controls, regular security assessments, logical isolation of Tenant Environments, and staff training on data protection.

No method of electronic transmission or storage is 100% secure. In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you in accordance with applicable law.

11 Children’s Privacy

The Mandu Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected personal data from a child, please contact us immediately at support@mandu360.com and we will take steps to delete such data promptly.

12 Links to Third-Party Websites and Services

The Mandu website and platform may contain links to third-party websites, services, and integrations. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services before providing them with your personal data. Mandu is not responsible for the privacy practices or content of third-party websites.

13 Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be posted at mandu360.com/privacy with a revised “Effective Date”. For material changes that significantly affect how we process your personal data, we will provide not less than thirty (30) days’ advance notice by email or via a prominent notice within the Service.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the effective date of any update constitutes your acceptance of the revised Policy.

14 Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data:

Mandu Privacy Team

📧 Email: support@mandu360.com — Subject: “Privacy Policy Enquiry”
🌐 Website: mandu360.com
🏢 Mandu Goodz — Nairobi, Republic of Kenya
🏢 EMMMW LLC — United States of America
Regulatory Contacts:
Kenya ODPC: odpc.go.ke  ·  EU: Your local Data Protection Authority  ·  UK ICO: ico.org.uk