Legal

Privacy Policy

Effective date: 13 July 2026 · Last updated: 13 July 2026

1. Who we are

Zuka ("Zuka", "we", "us", "our") is a talent development platform run by Tunga in Nairobi, Kenya. You can use it through our website at zuka.ac and through the Zuka mobile apps for Android and iOS. Together we call these the "Service".

We are the data controller for the personal data described in this policy. This policy explains what personal data we collect, why we collect it, how we use and share it and the rights you have over it. It is written to follow the Kenya Data Protection Act, 2019 and its regulations, the EU/UK General Data Protection Regulation (GDPR) where it applies, the Google Play Developer Policies (including the User Data policy) and the Apple App Store guidelines.

You can reach us at any time about this policy or your data at hi@tunga.co or +254 733 466 233.

2. Personal data we collect

We collect these types of personal data:

  • Account information. Your name, email address, phone number, password details and profile photo when you create an account or join a Zuka program.
  • Program and profile data. Information you or your program staff add to the Service. This includes your portfolio, projects, performance records, career interests, mentorship notes, community posts and messages sent within the Service.
  • Payment data. If you pay through M-Pesa, we process your M-Pesa phone number, transaction reference and amount. Safaricom's M-Pesa service processes the payment. We never receive or store card numbers or M-Pesa PINs.
  • Communications. Questions you send us, for example through the contact form, and messages you exchange with our AI coach. AI coach conversations are processed to generate responses and improve the feature.
  • Device and usage data. Device type, operating system, app version, IP address, approximate location worked out from your IP, log data, crash reports and push notification tokens.
  • Cookies and similar technologies. We use strictly necessary cookies to keep you signed in and remember your preferences. See section 9.

We collect this data directly from you and from your device when you use the Service. If you joined through a partner program, we also collect it from the organisation that enrolled you.

3. Why we process your data and our legal bases

Under the Kenya Data Protection Act, 2019 and Article 6 of the GDPR, we process personal data:

  • To carry out our contract with you. We create and manage your account, run your program experience (projects, performance, portfolio, mentorship, community and events), process payments and provide support.
  • With your consent. We send push notifications and marketing messages, and run any optional features that ask for permission. You can withdraw consent at any time. This does not affect processing that happened before you withdrew it.
  • For our legitimate interests. We keep the Service secure, prevent fraud and abuse, measure and improve how the Service works and send service updates. We balance these interests against your rights.
  • To meet legal obligations. This includes tax, accounting and lawful requests from Kenyan or other competent authorities.

We do not sell your personal data. We do not use it for third-party advertising.

4. How we share your data

We share personal data only with:

  • Service providers (data processors). Google LLC provides our hosting and backend systems. These are Google Cloud Platform and Firebase, which cover sign-in, database, storage, cloud functions, push notifications through Firebase Cloud Messaging and Vertex AI for the AI coach. Safaricom PLC processes M-Pesa payments. These providers act on our instructions under data processing agreements.
  • Your program. If you take part through a partner organisation or employer, program staff and mentors can see the program data relevant to their role. For example, your performance records and portfolio.
  • Authorities and successors. We share data with authorities when the law requires it or when we need to protect our legal rights. If Zuka is ever merged, bought or sold, this policy will continue to apply to your data.

5. International transfers

Our infrastructure providers store data on servers that may sit outside Kenya, including in the United States and the European Union. When personal data leaves Kenya, we follow sections 48 and 49 of the Data Protection Act, 2019. This means we make sure the recipient protects the data properly. Where the GDPR applies, transfers outside the EEA and UK rely on safeguards such as the European Commission's Standard Contractual Clauses. For Google, they also rely on its certification under the EU-US Data Privacy Framework.

6. How long we keep your data

We keep personal data for as long as your account is active and as needed to provide the Service. After your account closes, we delete or anonymise your data within 90 days. We keep some data longer only when the law requires it, to resolve disputes or to enforce our agreements. For example, Kenyan law requires us to keep financial records of M-Pesa transactions for up to 7 years.

7. Your rights

Under the Kenya Data Protection Act, 2019 (sections 26 and 34 to 40) and, where it applies, the GDPR (Articles 15 to 22), you have the right to:

  • be told how your data is used
  • get a copy of the personal data we hold about you
  • have wrong or incomplete data corrected
  • have your data deleted (right to erasure), subject to legal retention rules
  • object to or limit processing, including for direct marketing
  • receive your data in a portable, machine-readable format
  • withdraw consent at any time where processing is based on consent
  • not be subject to a decision based only on automated processing that significantly affects you

To use any of these rights, email hi@tunga.co or call +254 733 466 233. We will reply within the time the law requires, normally within 30 days. We will not charge a fee unless a request is clearly unfounded or excessive.

You can also complain to the Office of the Data Protection Commissioner (ODPC), Kenya at www.odpc.go.ke. If you are in the EEA or the UK, you can complain to your local supervisory authority.

8. Account and data deletion

You can ask us to delete your Zuka account and the personal data linked to it at any time. Email hi@tunga.co from the email address on your account, with the subject "Delete my account". We will verify the request, delete your account and erase or anonymise your personal data within 90 days. We keep only the records the law requires us to keep (see section 6). This deletion route covers data collected through the Zuka mobile apps as well as the website, as Google Play's account deletion policy requires.

9. Cookies

The website uses strictly necessary cookies and similar technologies, such as local storage. They keep you signed in, protect against cross-site request forgery and remember interface preferences. We do not use advertising or cross-site tracking cookies. You can clear or block cookies in your browser settings, but signed-in parts of the Service may stop working without them.

10. Security

We protect your data with technical and organisational measures that fit the risk, as section 41 of the Data Protection Act, 2019 and Article 32 of the GDPR require. These include encryption of data in transit (TLS) and at rest, role-based access controls so staff and mentors only see data relevant to their role, security rules on every database collection and audit logging. No system is perfectly secure. If we learn of a breach affecting your data, we will notify the ODPC and affected users as the law requires.

11. Children

The Service is designed for people aged 18 and over. Younger participants can join only through a partner program, with the consent of a parent or guardian as section 33 of the Data Protection Act, 2019 requires. We do not knowingly collect personal data from children under 13. If you believe a child has given us personal data without proper consent, contact us and we will delete it.

12. Mobile apps and platform policies

The Zuka Android app follows the Google Play User Data policy. The data it collects and shares is listed in the app's Data safety section on Google Play and matches this policy. Data travels over encrypted connections, and account deletion works as described in section 8. The app asks for permissions only where a feature needs them. For example, notification permission for push notifications, and camera or photo access if you choose to upload a profile photo or portfolio media. It never uses them in the background for other purposes. The iOS app follows Apple's App Store privacy requirements, including App Privacy labels.

13. Changes to this policy

We may update this policy from time to time. If we make major changes, we will tell you through the Service or by email before they take effect. We will also update the "last updated" date above. If you keep using the Service after changes take effect, the updated policy applies.

14. Contact us

For any question, request or complaint about this policy or your personal data: