ClariFi Privacy Policy
Kenya-first product. Operated by The Business Clinic Limited. Last updated: 25 August 2026.
1) Controller and Contacts
ClariFi is operated by The Business Clinic Limited (the data controller for platform services described in this policy), subject to the Kenya Data Protection Act, 2019.
BizClinic Africa LLC may provide intercompany technology and support services as a processor where disclosed.
Kenya operations contact: support@bizclinic.africa
Data protection contact: privacy@bizclinic.africa
2) Data We Collect
- Identity data (name, company role, account identifiers).
- Contact data (email, phone number, support correspondence).
- Business and financial figures you input into tools and diagnostics.
- Account data (authentication records, subscription metadata, settings).
- Usage data (device/browser signals, page interactions, diagnostics usage).
- Communications data (support messages, feedback, delivery confirmations).
- Payment reference data (transaction references and billing status; no full card data).
3) How We Use Data
We use data to provide diagnostics, decision support, reports, account management, billing, fraud and abuse prevention, security monitoring, and customer support. Where automated decisioning assists recommendations, you may request a human review or override through support channels.
3A) Lawful basis (Kenya)
Processing is grounded in contract performance, consent (where required — see Consents), legitimate interests that do not override your rights, and legal obligations under the Kenya Data Protection Act, 2019.
4) WhatsApp and Report Delivery Disclosure
If you request WhatsApp delivery, ClariFi may send report notifications or secure links through WhatsApp. WhatsApp is operated by Meta and may process communication metadata under its own terms. Utility WhatsApp messages do not include revenue, balances, scores, or decision recommendations — only opaque references and secure authenticated links.
Where available, secure in-portal download remains the primary report access option.
4A) Meta Lead Ads, Pixel, and Conversions API
ClariFi may use Meta (Facebook/Instagram) Lead Ads for low-friction inquiries (for example a free Financial Decision Check). Meta forms collect only minimal business contact fields — not turnover, profit, loan amounts, or diagnostic answers. Deeper financial information is collected only inside authenticated ClariFi workflows.
With marketing consent, ClariFi may load Meta Pixel and/or send Conversions API events for measurement (PageView, ViewContent, Search, Lead, CompleteRegistration, InitiateCheckout, and Purchase of a verified ClariFi fee). Identifiers such as fbclid, fbc, and fbp may be used for attribution and matching, including hashed email/phone where lawful. You can withdraw marketing consent via Cookie settings; withdrawal stops future non-essential Meta browser requests.
Meta never becomes the system of record for MSME financial data, diagnostics, decision cards, lender-ready evidence, or advisor conclusions. Custom Audiences and paid Meta campaigns remain disabled until ClariFi activation gates and disclosures are approved.
5) Cloud Storage and Sub-processors
ClariFi uses cloud infrastructure and approved service providers to operate the service securely.
- Intuit Inc. (QuickBooks Online / Intuit Developer Platform — accounting data sync when you connect)
- Render (application hosting and managed PostgreSQL)
- Stripe (card payments and subscription billing)
- iPay Africa and Kopo Kopo (Kenya payment rails where enabled)
- Resend (transactional email)
- Meta Platforms / WhatsApp Business Platform (messaging, optional Lead Ads, advertising measurement)
- Cloudflare Turnstile (bot protection on login and forms)
- Hotjar (analytics; loaded only after analytics cookie consent)
- Datadog (optional operational logging)
5a) QuickBooks Online data
When you connect QuickBooks Online, ClariFi requests OAuth authorization to read accounting data (customers, vendors, invoices, bills, payments, chart of accounts, and standard financial reports) and, where you approve write-backs, to create or update selected records in your Intuit company. We use this data to power business health, cashflow, and advisory features inside your ClariFi workspace.
OAuth access and refresh tokens are encrypted at rest (AES-256-GCM). We do not sell QuickBooks data. You may disconnect at any time from Accounting (QuickBooks Online). Choosing "Disconnect and delete my QuickBooks data" revokes tokens at Intuit and deletes locally synced cache, webhook events, sync logs, write-backs, and derived intelligence snapshots for your workspace. If you disconnect without deleting, retained synced data is purged automatically after 30 days.
6) International Transfers
Depending on service operations and customer location, personal data may be processed in Kenya, the United States, and where applicable in the EU/UK.
Transfer safeguards may include contractual protections (for example, SCCs and/or UK IDTA where applicable).
7) Your Rights
You may request access, correction, deletion, portability, objection, and consent withdrawal.
Submit requests to privacy@bizclinic.africa, or use the privacy center deletion instructions. We may verify identity before processing requests. Meta users can also trigger deletion via Meta's data-deletion callback connected to ClariFi.
8) Retention and Security
We retain data only as long as needed for service delivery, legal obligations, dispute handling, and security requirements.
We maintain technical and organizational safeguards; however, no system can guarantee absolute security.
9) Breach Notification
If a reportable personal data breach occurs, ClariFi will notify relevant authorities and affected users in line with applicable law.
10) Children
Services are not intended for children under 18.
11) Complaints
- Kenya Office of the Data Protection Commissioner (ODPC)
- UK Information Commissioner's Office (ICO)
- Relevant EU supervisory authority