Privacy Policy

Last updated: August 2026

KaziPeople is an HR platform that helps organizations manage their people. This policy explains what personal data we handle, how we use it, and the rights available to you.

1. Introduction & Scope

This Privacy Policy describes how KaziPeople ("we", "us") collects, uses, and protects personal data when you use our platform, websites, and related services. It applies to account holders, administrators, and the employees whose data is managed in a KaziPeople workspace.

2. Our Role: Controller and Processor

For data about account holders and administrators (e.g. sign-up, billing, and usage data), KaziPeople acts as the data controller. For employee/HR data that a customer uploads about its workforce, the customer (the employer) is the controller and KaziPeople acts as a processor, handling that data only on the customer's instructions to provide the Service. If you are an employee, please direct privacy requests to your employer in the first instance.

3. Information We Collect

  • Account data: name, work email, company name, role, and billing details of administrators.
  • Employee & HR data: records customers add about their people: names, contact details, job titles, departments, leave requests and balances, documents, and related HR information.
  • Usage & device data: log data, IP address, browser/device type, and how the Service is used, for security and improvement.
  • Cookies: essential cookies to keep you signed in and remember preferences (see Section 10).

4. How We Use Information

  • To provide, operate, and support the Service;
  • To authenticate users and keep accounts secure;
  • To process billing for paid plans;
  • To communicate with you about your account, updates, and support;
  • To monitor, maintain, and improve the Service;
  • To comply with legal obligations and enforce our terms.

5. Legal Bases for Processing

Where applicable data-protection law requires a legal basis, we rely on: performance of our contract with you; our legitimate interests in operating and securing the Service; your consent (where requested); and compliance with legal obligations. We process personal data in line with the Tanzania Personal Data Protection Act, 2022, and other applicable laws, including the GDPR where it applies.

6. How We Share Information

We do not sell personal data. We share it only:

  • With sub-processors who help us run the Service (e.g. cloud hosting, email delivery), under contracts that require appropriate safeguards;
  • Within your own organization's workspace, according to the roles and permissions you configure;
  • Where required by law, regulation, or valid legal process, or to protect rights and safety.

7. Data Retention

We retain account data for as long as your account is active and as needed to provide the Service. Employee data is retained according to the customer's instructions. After an account is terminated, we make data available for export for a reasonable period and then delete or anonymize it, unless we are required to keep it for legal or compliance reasons.

8. Security

We use technical and organizational measures designed to protect personal data, including encryption in transit, access controls, role-based permissions, and tenant isolation. No method of transmission or storage is perfectly secure, but we work to protect your information and to respond promptly to any incident.

9. International Data Transfers

Your data may be processed in locations where we or our sub-processors operate. Where data is transferred across borders, we take steps to ensure an appropriate level of protection consistent with applicable law.

10. Your Rights & Cookies

Depending on your location, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Account holders can exercise these by contacting us; employees should contact their employer (the controller of their HR data), who can act within the platform on their behalf. We use only essential and preference cookies needed to operate the Service and remember settings such as your theme and language. We do not use them for third-party advertising.

11. Children's Privacy

The Service is intended for use by organizations and their workforce and is not directed at children under 18. We do not knowingly collect personal data from children.

12. Google User Data (Calendar Integration)

If you choose to connect your Google Calendar, KaziPeople requests a single Google permission — the granular Google Calendar events scope (https://www.googleapis.com/auth/calendar.events.owned), which lets an application see, create, change and delete events on calendars you own — and uses it only as described below. Connecting is optional, is done per employee, and requires your employer to enable the integration first.

  • What we access: we create, update, and delete calendar events that KaziPeople manages on your own calendar — for example an all-day "Out of Office" entry for leave you have had approved, or a meeting you schedule through the platform. We do not read, list, download, or store the contents of your other calendar events.
  • What we store: an encrypted Google refresh token so the sync can continue without asking you to sign in again, and the identifiers of the events we created so we can keep them up to date or remove them. We do not store the contents of your calendar.
  • How we use it: solely to reflect your approved leave and platform-scheduled meetings on your calendar. We do not use Google user data for advertising. Google user data is never shared with, transferred to, or made accessible to any artificial-intelligence or machine-learning provider, and is never used to create, train, or improve any AI or machine-learning model, whether ours or a third party's. The integration is write-only: KaziPeople does not read or retrieve the contents of your Google Calendar, so no Google user data enters the platform's AI features (including the Dana assistant).
  • Sharing: we do not sell Google user data and do not share it with third parties, except sub-processors that host the Service under contracts requiring appropriate safeguards.
  • Revoking access: you can disconnect at any time from your My Calendar page in the app, or from your Google Account's third-party access settings (https://myaccount.google.com/permissions). When you disconnect, we delete the stored token.
  • Limited Use: KaziPeople's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (for example, by email or in-app). The "Last updated" date above reflects the latest revision.

Contact Us

For privacy questions or to exercise your rights, contact our privacy team at privacy@kazipeople.com.

See also our Terms of Service.