What we collect,
and what we don't.
Written to be read: every category of data, the reason we hold it, who else touches it, how long it stays, and the regulator in your country if you disagree with any of it.
โก In short
A plain-language summary. The full sections below are what actually applies.
Contents ยท 16 sections
Section 01
Scope and who is responsible
This policy covers getnexus.africa and the GetNexus platform, and takes effect 10 August 2026.
- GetNexus, operated from Nairobi, Kenya, is the data controller for personal data processed on the platform.
- Privacy contact: privacy@getnexus.africa. We answer data requests within 48 hours.
- It applies to workers, clients, visitors, and anyone whose details appear in a job brief.
- It does not cover what a client or worker does with data after it leaves the platform โ for that, they are the controller and their own policy applies.
- Where a client sends us their customers' data as part of a brief, that client is the controller and we process it on their instructions.
Section 02
What we collect
What you give us
- Name, email address and phone number
- Skills, bio, languages, portfolio and work experience
- Government ID documents โ workers only, for verification
- A photo of your face holding that ID โ workers only. We ask for it because an ID photo on its own proves a document exists, not that the person submitting it owns it.
- Country of residence and preferred language
- Mobile money number or bank account for payouts, and the account holder name
- Job briefs, files, messages and work submissions
- Support, dispute and appeal correspondence
What we collect automatically
- IP address, device type and browser, from ordinary web requests
- Country inferred from your IP, to pick a display currency โ the country only, never a precise location
- Pages visited and time on the platform, as aggregate analytics
- Task activity: claims, submissions, approvals, quality scores, earnings
- Message and notification timestamps, and delivery status of emails we send
- Security and fraud signals: sign-in attempts, duplicate-account markers, unusual payout patterns
What we get from others
- Payment and payout providers: transaction status, failure reasons, and their own compliance flags
- Geolocation providers: the country matching an IP address
- Referrals: when someone signs up with your code, we record the link between the two accounts
What we do not collect
- Card numbers or full bank credentials โ payment providers handle those, we never see them
- Precise location, GPS or continuous device tracking
- The content of your communications outside the platform
- Special-category data โ health, religion, politics โ beyond what appears on an ID document you upload for verification
- Facial-recognition data โ a member of our team compares your selfie against your ID by eye. We do not run biometric matching software, and we do not build or store a face template from your photo.
Section 03
Why we use it, and on what basis
To perform our contract with you
- Creating and running your account
- Matching briefs to workers and delivering work to clients
- Collecting client payments and sending worker payouts
- Detecting your country to display local prices
- Sending transactional notices: task assigned, work delivered, payment sent
To meet a legal obligation
- Verifying worker identity before paid work โ which includes comparing the selfie you upload against your ID document to confirm they show the same person
- Anti-money-laundering, sanctions and fraud checks, ours and our providers'
- Keeping financial and tax records for the period the law requires
- Responding to lawful requests from courts, regulators and tax authorities in countries where we operate
For our legitimate interests
- Improving matching, quality scoring and language checks โ using aggregated or de-identified platform data where practical
- Calculating reputation and reliability scores
- Preventing fraud, duplicate accounts, referral abuse and payment circumvention
- Measuring platform performance by region, and deciding which countries and corridors to build next
- Securing the platform and investigating incidents
- Defending legal claims and enforcing our Terms
With your consent
- Non-essential cookies and analytics, where consent is required in your country
- Reminder and marketing email, which you can switch off in Settings at any time
- Showing your work as a portfolio sample, which we ask for case by case
- You can withdraw consent at any time. Doing so does not affect processing that already happened, or anything we do on another basis above.
Where your country's law frames these differently โ POPIA's conditions for lawful processing, or NDPA's lawful bases โ we apply the local framing to your data. The activities above stay the same either way.
Section 04
AI and automated decisions
What AI sees
- Job briefs and work submissions, for matching, quality scoring and language review
- Skills and availability from a worker profile, for matching
- It does not see identity documents, verification selfies, payout details, phone numbers or email addresses
How we handle it
- Our AI provider processes this content to return a result. It is sent for that purpose only, under a commercial agreement that does not permit training their public models on it.
- Quality scores and match decisions influence what work you are offered and whether a submission is returned for revision.
- No decision with legal effect โ payment, suspension, verification โ is made by automated means alone. A person reviews those.
- You may ask for human review of any automated outcome that affects you materially, and we will provide it.
- We may use platform data to improve our own matching and quality models, aggregated or de-identified where practical. We do not publish, sell or expose client-confidential material to other users.
Section 06
Cross-border transfers
GetNexus serves all 54 African countries from Nairobi, Kenya, on infrastructure that is not always in your country. That makes almost every job a cross-border transfer, and this is how we handle it.
Safeguards we apply
- Transfers rely on your consent, contractual necessity, or standard contractual clauses with the receiving provider.
- Where Kenyan law requires it, transfers out of Kenya meet the conditions in the Data Protection Act, 2019 and its transfer regulations.
- POPIA section 72, the NDPA transfer rules, and GDPR Chapter V are applied where a person is protected by them.
- Providers are chosen for their security posture and their willingness to sign data-processing terms, not only on price.
- Where two standards apply to the same data, we apply the stricter one.
Frameworks we align with
- African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention)
- EU / UK GDPR โ where a client or worker is in the EU, EEA or United Kingdom
- Standard contractual clauses or equivalent safeguards for transfers out of your country
If a country requires certain data to stay within its borders and we cannot meet that requirement, we will say so rather than process the data anyway.
Section 07
Country and currency detection
One small feature that deserves its own section, because it involves your IP address.
- When you open the site, your browser calls our own API route, which reads your IP from the request.
- That IP is sent to a geolocation provider โ ipapi.co, with ip-api.com as a fallback โ which returns a two-letter country code. Where our host supplies a country header, we use that instead and skip the lookup.
- We cache the country code against that IP in server memory for 10 minutes to avoid repeat lookups, then it is gone.
- Your IP is not written to our database, not attached to your profile, and not used to track you between visits.
- The country code decides which currency and payment methods to display. Nothing else.
- You can ignore the detected country โ the binding amount for any job is the KES figure, as the Terms explain.
Section 08
Collections, screening and income records
Where you use GetNexus to collect from your own clients and to evidence that income, we handle some data that the rest of the platform does not.
Screening
- We screen users, the clients they name, and transactions against sanctions lists, politically-exposed-person data and fraud signals. This is a legal obligation on us and on our payment providers, so the basis is legal obligation and legitimate interest, not consent โ you cannot opt out of it and still be paid.
- A screening result is a decision record: what was checked, what matched, and what we did. We keep those for as long as financial-crime rules require, which is longer than we keep most things.
- A match does not by itself mean we think you have done anything. It means a payout is held until a person has looked at it.
Your clients' data
- When you raise an invoice you give us your client's name, and usually an email address or phone number. They are not GetNexus users and have not agreed anything with us.
- You are the controller of that data and we process it on your behalf: to deliver the invoice, to collect the payment, and to confirm with them that the invoice is genuine. You are responsible for having a lawful basis to give it to us.
- We use it for nothing else. Your clients are not added to our marketing, not prospected, and not shown to other users.
- If one of your clients asks us to delete their details, we will tell you and act on it, keeping only what the payment and financial-crime rules oblige us to keep.
Income records
- An income summary or proof-of-income document is generated from your own transaction history on request. It exists as a record; producing one does not publish it.
- We do not send these to lenders, bureaux, employers or anyone else. If a third party has one, you gave it to them.
- We are not a credit reference bureau and we do not contribute your data to credit reference agencies.
- Transaction and ledger records behind these are retained for the statutory financial-record period in Kenya and in any country whose rules reach the transaction, which can be several years after you close your account.
Screening and financial-record retention are the two places where a deletion request cannot be met in full. We will delete everything else and tell you precisely what we kept and which rule required it.
Section 09
Your rights
What you can do
- Access โ get a copy of the data we hold about you
- Export โ download your profile, tasks and earnings history from Settings
- Correct โ fix anything inaccurate in your profile, yourself, at any time
- Delete โ close your account and remove your data from Settings, subject to the records we must keep
- Object or restrict โ tell us to stop a particular processing activity, and we will unless we have an overriding legal ground
- Withdraw consent โ switch off reminder email and non-essential cookies whenever you like
- Human review โ ask a person to look at an automated outcome that affects you
- Complain โ to us first, and to your national regulator if we do not resolve it
How to exercise them
- Most of it is self-service in Settings. For anything else, email privacy@getnexus.africa from the address on your account.
- We respond within 48 hours and complete requests within 30 days, or tell you why we need longer.
- We may ask you to confirm your identity before releasing or deleting data โ that check protects you, not us.
- There is no charge, unless a request is repetitive or excessive, in which case we will tell you before doing anything.
- A request does not pause work in progress or a payout you are owed.
Where to complain in your country
You can go to your national regulator directly โ you do not need our permission, and you do not have to come to us first.
Country reference
๐ฐ๐ช Kenya ยท KES
- Law:
- Data Protection Act, 2019
- Regulator:
- Office of the Data Protection Commissioner (ODPC)
- Payouts:
- M-Pesa, Airtel Money
๐น๐ฟ Tanzania ยท TZS
- Law:
- Personal Data Protection Act, 2022
- Regulator:
- Personal Data Protection Commission
- Payouts:
- Manual payout โ reviewed by our team
๐บ๐ฌ Uganda ยท UGX
- Law:
- Data Protection and Privacy Act, 2019
- Regulator:
- Personal Data Protection Office (PDPO)
- Payouts:
- Manual payout โ reviewed by our team
๐ท๐ผ Rwanda ยท RWF
- Law:
- Law No. 058/2021 on personal data
- Regulator:
- National Cyber Security Authority (NCSA)
- Payouts:
- Manual payout โ reviewed by our team
๐ช๐น Ethiopia ยท ETB
- Law:
- Personal Data Protection Proclamation (2024)
- Regulator:
- Ethiopian Communications Authority
- Payouts:
- Manual payout โ reviewed by our team
๐ณ๐ฌ Nigeria ยท NGN
- Law:
- Nigeria Data Protection Act, 2023
- Regulator:
- Nigeria Data Protection Commission (NDPC)
- Payouts:
- Manual payout โ reviewed by our team
๐ฌ๐ญ Ghana ยท GHS
- Law:
- Data Protection Act, 2012 (Act 843)
- Regulator:
- Data Protection Commission
- Payouts:
- Manual payout โ reviewed by our team
๐ฟ๐ฆ South Africa ยท ZAR
- Law:
- POPIA, 2013
- Regulator:
- Information Regulator (South Africa)
- Payouts:
- Manual payout โ reviewed by our team
๐ธ๐ณ Senegal ยท XOF
- Law:
- Loi nยฐ 2008-12 sur les donnรฉes personnelles
- Regulator:
- Commission de protection des donnรฉes personnelles (CDP)
- Payouts:
- Manual payout โ reviewed by our team
๐จ๐ฎ Cรดte d'Ivoire ยท XOF
- Law:
- Loi nยฐ 2013-450 sur les donnรฉes personnelles
- Regulator:
- ARTCI
- Payouts:
- Manual payout โ reviewed by our team
๐ฒ๐ฆ Morocco ยท MAD
- Law:
- Loi nยฐ 09-08 sur les donnรฉes personnelles
- Regulator:
- CNDP
- Payouts:
- Manual payout โ reviewed by our team
๐ช๐ฌ Egypt ยท EGP
- Law:
- Personal Data Protection Law No. 151 of 2020
- Regulator:
- Egyptian Data Protection Centre
- Payouts:
- Manual payout โ reviewed by our team
| Country | Data-protection law | Where to complain | Payouts today |
|---|---|---|---|
| ๐ฐ๐ช KenyaKES | Data Protection Act, 2019 | Office of the Data Protection Commissioner (ODPC) | M-Pesa, Airtel Money |
| ๐น๐ฟ TanzaniaTZS | Personal Data Protection Act, 2022 | Personal Data Protection Commission | Manual payout โ reviewed by our team |
| ๐บ๐ฌ UgandaUGX | Data Protection and Privacy Act, 2019 | Personal Data Protection Office (PDPO) | Manual payout โ reviewed by our team |
| ๐ท๐ผ RwandaRWF | Law No. 058/2021 on personal data | National Cyber Security Authority (NCSA) | Manual payout โ reviewed by our team |
| ๐ช๐น EthiopiaETB | Personal Data Protection Proclamation (2024) | Ethiopian Communications Authority | Manual payout โ reviewed by our team |
| ๐ณ๐ฌ NigeriaNGN | Nigeria Data Protection Act, 2023 | Nigeria Data Protection Commission (NDPC) | Manual payout โ reviewed by our team |
| ๐ฌ๐ญ GhanaGHS | Data Protection Act, 2012 (Act 843) | Data Protection Commission | Manual payout โ reviewed by our team |
| ๐ฟ๐ฆ South AfricaZAR | POPIA, 2013 | Information Regulator (South Africa) | Manual payout โ reviewed by our team |
| ๐ธ๐ณ SenegalXOF | Loi nยฐ 2008-12 sur les donnรฉes personnelles | Commission de protection des donnรฉes personnelles (CDP) | Manual payout โ reviewed by our team |
| ๐จ๐ฎ Cรดte d'IvoireXOF | Loi nยฐ 2013-450 sur les donnรฉes personnelles | ARTCI | Manual payout โ reviewed by our team |
| ๐ฒ๐ฆ MoroccoMAD | Loi nยฐ 09-08 sur les donnรฉes personnelles | CNDP | Manual payout โ reviewed by our team |
| ๐ช๐ฌ EgyptEGP | Personal Data Protection Law No. 151 of 2020 | Egyptian Data Protection Centre | Manual payout โ reviewed by our team |
Countries not listed are still served. Where we have no local payout corridor yet, work is paid manually by our team in an agreed currency, and the data-protection standard we apply is the strictest of Kenyan law, your national law, and GDPR.
Section 10
Security and breaches
How we protect data
- Encrypted in transit with TLS, and at rest by our database provider
- Verification documents in private storage, not publicly addressable, deleted on schedule
- Row-level access rules in the database, so one account cannot read another's data
- Admin access limited to a named list, checked in code and in the database
- Payout credentials held by licensed providers, not by us
- Regular review of dependencies, access and permissions
If something goes wrong
- We investigate, contain, and record what happened.
- Where a breach is likely to risk your rights, we notify you and the relevant regulator within the time your law requires โ 72 hours under KDPA and GDPR, and the equivalent under POPIA and NDPA.
- We tell you what happened, what data was involved, and what to do about it. We do not wait for certainty on every detail before warning you.
No platform is perfectly secure, and we do not claim to be. Use a strong, unique password, keep your email account secure, and tell us immediately if you think someone else has access to your account.
Section 12
How long we keep it
- Account and profile data โ while your account is open
- Verification documents, including your selfie โ deleted 30 days after verification completes
- Task, submission and earnings records โ 7 years, for tax and financial compliance
- Payment and payout records โ as long as financial law in the relevant country requires
- Support, dispute and appeal correspondence โ 3 years after the matter closes
- Deleted accounts โ removed within 30 days, other than records under a legal hold or needed for tax and fraud prevention
- Fraud and abuse markers โ kept as long as needed to stop a banned account returning
- Aggregated, de-identified analytics โ kept indefinitely, because it is no longer personal data
- Server-side country cache โ 10 minutes
Section 13
Children
- GetNexus is for adults. You must be 18 or over to hold an account.
- We do not knowingly collect data from children. If we find an account belongs to someone under 18, we close it and delete the data.
- If you believe a child has given us data, email privacy@getnexus.africa and we will remove it.
- A brief that includes data about children is the client's responsibility to have lawful grounds for, and must be flagged to us before upload.
Section 14
Communications and opt-outs
- Transactional email โ task assigned, work delivered, payment sent, security alerts. These are part of the service and cannot be switched off while your account is open.
- Reminder email โ deadline and pending-action nudges. Switch these off in Settings.
- Product and marketing email โ only where you have opted in, and every message carries an unsubscribe link.
- WhatsApp โ used only where you have given us the number for notifications, and Meta's own terms govern that channel.
- We do not sell or rent your address to anyone else's mailing list.
Section 15
Changes to this policy
- We update this policy as the platform changes and as new countries come online.
- Material changes are notified by email and in-app before they take effect.
- The version number and date at the top of this page tell you which version applies.
- Where a change needs your consent, we will ask for it rather than assume it.
Section 16
Contact and complaints
- Privacy and data requests: privacy@getnexus.africa
- Legal notices: legal@getnexus.africa
- WhatsApp: +254 753 538 594
- Response time: 48 hours, with requests completed inside 30 days
- For a deletion request, email us from the address on your account and say what you want removed
- Operated from Nairobi, Kenya, serving all 54 African countries
- Unhappy with our answer? Go to the regulator listed for your country above. We would rather fix it first, but that route is yours either way.
Something here unclear?
Data requests, deletion, exports, or a question about a section. We answer within 48 hours and complete requests inside 30 days.