Privacy Policy
Last updated: June 30, 2026
This Privacy Policy explains how Kairo collects, uses, shares, and protects information when you use any of our products and services: Kairo Personal, Kairo Business, and Kairo Enterprise.
Kairo is a financial intelligence platform operating across three layers: Kairo Personal, Kairo Business, and Kairo Enterprise. Because these three products serve different audiences with different data needs, this Policy is structured so that each section first explains what applies to all users, then breaks out specifics by product where the practices differ. We've marked product-specific subsections clearly so you can navigate directly to what's relevant to you.
By using any Kairo Service, you agree to the collection and use of information in accordance with this Policy. If you do not agree, please do not use our Services.
Who This Policy Covers
1.1 Kairo Personal users
Individuals who create a Kairo wallet to send money, receive money, pay bills, or make purchases through WhatsApp, voice, or chat-based interfaces.
1.2 Kairo Business users
Business owners (sole proprietors, registered companies, and informal businesses) who use Kairo to collect payments, manage a storefront, send invoices, run promotions, or access AI-powered customer support via social media, with optional web dashboard access.
1.3 Kairo Enterprise clients and their end customers
Financial institutions (banks, fintechs, payment processors, and switches) that license Kairo's enterprise software products (Reconcile, Fraud, Support, Flow, Relay, Insight, and Risk). Where Kairo processes data on behalf of an Enterprise client about that client's own customers, Kairo acts as a data processor (or “processor” under NDPA/GDPR terminology) on the institution's instructions, and the institution remains the data controller for its end customers' information. Separate data processing agreements govern this relationship in addition to this Policy.
Information We Collect
We collect information in three ways: information you provide directly, information collected automatically through your use of the Services, and information we receive from third parties (such as identity verification providers, payment networks, and your bank).
2.1 Information collected from all users
- Identity information: full name, date of birth, phone number, and (where applicable) email address
- Account credentials and authentication data.
- Communications you send to Kairo, including WhatsApp messages, voice messages, and chat transcripts.
- Device and technical information: IP address, device identifiers, operating system, app version, and general location data (derived from phone number or IP, not precise GPS unless separately authorized).
- Transaction data: amounts, timestamps, counterparties, payment references, and transaction status.
2.2 Kairo Personal
- Bank Verification Number (BVN) and the identity data returned by BVN verification (full name, date of birth, gender, phone number, and BVN-linked photograph, where provided by the verification provider)
- Wallet balance and full transaction history (sends, receives, bill payments, purchases)
- Recipients and contacts you transact with or save within Kairo
- Voice recordings, when you use voice-based commands (processed to extract transaction intent; see Section 4 for retention and processing detail)
- Images submitted for “snap to pay” functionality (e.g. photographs of account slips or invoices)
- Language preference and the language(s) you communicate in
- Bill payment details (service providers, account numbers for utilities/subscriptions you've linked)
2.3 Kairo Business
- Business name, business category, and (where provided) business registration details
- Storefront content: product listings, prices, images, and descriptions you upload
- Customer lists and contact details you upload or that are generated through transactions (your customers' phone numbers, names, and order history with your business)
- Invoice and payment collection data
- Content of customer service conversations handled by Kairo's AI auto-responder on your behalf
- Business owner's BVN and identity verification data (same as Section 3.2), required to activate a business wallet
2.4 Kairo Enterprise
- Institutional account and integration credentials (API keys, system identifiers).
- Transaction, reconciliation, settlement, and exception data submitted by the institution for processing by Kairo's software.
- Aggregated and pseudonymized behavioral data used to power fraud detection, routing optimization, and risk models, as governed by the applicable data processing agreement.
- Usage and performance data related to the institution's use of Kairo's enterprise products (queries run, API calls, system logs).
How We Use Your Information
We use the information we collect to:
- Create and maintain your wallet or business account, including verifying your identity as required by law.
- Process transactions — sending, receiving, and confirming payments, bill payments, and purchases.
- Understand natural language, voice, and image-based instructions in order to carry out the action you've requested (e.g. interpreting “send 5k to Tunde” as a transfer instruction).
- Detect, investigate, and prevent fraud, unauthorized transactions, and other illegal activity.
- Provide customer support, including AI-powered automated responses for Kairo Business owners' customers.
- Send transaction confirmations, bill reminders, and account-related notifications.
- Improve our Services, including training and refining the AI models that power language understanding, fraud detection, and risk scoring (see Section 4.1 on model training).
- Comply with legal and regulatory obligations, including anti-money laundering (AML), counter-terrorism financing (CTF), and tax reporting requirements.
- With your consent, send promotional messages, product updates, and offers (you can opt out at any time).
AI model training and your data
Kairo uses machine learning models to power conversational understanding, fraud detection, and risk intelligence. Where transaction and behavioral data is used to train or improve these models, we use aggregated and/or pseudonymized data wherever feasible. Voice recordings and message content used to improve language understanding are processed primarily through automated systems; access by human reviewers, where it occurs for quality assurance or model improvement purposes, is limited, logged, and subject to confidentiality obligations. You may object to your data being used for model improvement purposes by contacting us as described in Section 15, though this may limit certain personalization features.
Legal Basis for Processing
Depending on your location and applicable law (including the Nigeria Data Protection Act 2023 and, where relevant, the EU General Data Protection Regulation), we rely on the following legal bases to process your information:
- Contractual necessity:
- Processing needed to create your wallet, execute transactions, and deliver the Services you've requested
- Legal obligation:
- BVN/KYC verification, AML/CTF screening, tax and regulatory reporting required by CBN, NDPA, and other applicable regulators
- Legitimate interest:
- Fraud prevention, service improvement, and security monitoring, balanced against your rights and freedoms
- Consent:
- Marketing communications, optional features (e.g. voice processing where separately consented), and any processing not covered by the bases above
BVN, KYC & Identity Verification
This section addresses the collection and use of your Bank Verification Number (BVN) specifically, given its sensitivity and the questions it commonly raises.
- We collect your BVN solely to verify your identity, as required by the Central Bank of Nigeria's Know Your Customer (KYC) regulations and the Nigeria Data Protection Act for the provision of financial wallet services.
- Your BVN is used to confirm your full name, date of birth, and other identity attributes directly with NIBSS or an authorized verification provider.
- We do not use your BVN to access your bank account balance, view your transaction history at other banks, or move money out of any external bank account.
- Your BVN is encrypted in storage and in transit, and access to it within Kairo is restricted to systems and personnel directly involved in identity verification and regulatory compliance.
- We retain BVN-derived identity data for as long as your account is active and for 5 years after account closure.
- Identity verification (including BVN, and where applicable, NIN — National Identification Number) is also required to activate a Kairo Business wallet for the business owner.
Data Storage, Security & Retention
Security measures
- Encryption of sensitive data (including BVN and identity data) both at rest and in transit.
- Role-based access controls limiting employee access to personal data on a need-to-know basis.
- Regular security testing, monitoring, and audit logging of access to sensitive systems.
- Multi-factor authentication for internal systems handling financial and identity data.
- Fraud monitoring systems (Kairo Fraud) that operate across all three products to detect anomalous activity in real time.
Data retention
We retain personal information for as long as necessary to provide the Services, comply with legal obligations (including financial recordkeeping and AML requirements), resolve disputes, and enforce our agreements. Specific retention periods:
- Identity verification data (BVN-derived):
- Duration of account + 5 years after account closure.
- Transaction records
- Minimum 5 years from transaction date, per standard financial recordkeeping requirements.
- WhatsApp/chat conversation logs:
- Duration of account + 5 years for support and dispute resolution.
- Voice recordings:
- 5 years from the date of recording.
- Marketing consent and preferences:
- Until you withdraw consent or close your account
Where you close your Kairo account, we will delete or anonymize your personal information within a reasonable period, except where retention is required by law (such as financial transaction records) or necessary for the resolution of disputes or legal claims.
Your Rights
Subject to applicable law (including the Nigeria Data Protection Act 2023 and, where applicable, GDPR), you have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Request deletion of your information, subject to our legal and regulatory retention obligations
- Object to or restrict certain processing, including processing for marketing or AI model improvement purposes
- Request a copy of your data in a portable, machine-readable format
- Withdraw consent at any time, where processing is based on consent (this will not affect the lawfulness of processing carried out before withdrawal)
- Lodge a complaint with the Nigeria Data Protection Commission (NDPC) or other applicable supervisory authority
To exercise any of these rights, contact us using the details in Section 15. We will respond within the timeframe required by applicable law (generally within 30 days, though this may be extended in certain circumstances with notice to you).
WhatsApp & Third-Party Channels
Kairo Personal and Kairo Business operate primarily through WhatsApp, using the WhatsApp Business API operated by Meta. This section explains how that affects your data.
- Messages you send to Kairo through WhatsApp are transmitted via Meta's infrastructure as part of the WhatsApp Business Platform. Meta's own privacy policy governs its handling of message transport and metadata; this Kairo Privacy Policy governs how Kairo itself processes the content and outcome of those conversations.
- Voice notes, text messages, and images you send to Kairo via WhatsApp are processed by Kairo's systems to interpret and act on your requests, as described in Section 4.
- Where Kairo is also accessible via Telegram, voice channels, or a web/app dashboard, equivalent protections described in this Policy apply, adapted to the technical characteristics of each channel.
- We encourage you to review WhatsApp's own privacy policy and terms of service, available at whatsapp.com, to understand Meta's role in message transport.
Children's Privacy
Kairo's Services are intended for individuals who are at least 18 years old, or who meet the minimum age for entering binding financial agreements and obtaining a BVN under applicable Nigerian law. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected information from a person under the applicable minimum age, we will take steps to delete that information promptly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will notify you of material changes through the Services (e.g., a WhatsApp message or in-app notification) or by other reasonable means, and will update the “Last updated” date at the top of this Policy. We encourage you to review this Policy periodically.
Contact Us & Grievance Redressal
If you have questions, concerns, or requests regarding this Privacy Policy or how your information is handled, please contact:
Kairo Data Protection Officer
Email: privacy@usekairo.co
Address: 4b Babatope Bejide Street, Lekki Phase 1, Lagos.
If you are not satisfied with our response, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC), or the applicable data protection authority in your jurisdiction.