This notice explains how Sieve handles personal data: as a processor of the customer data our clients send us, and as a controller of the data of people who use our website and dashboard.
Data we process for our clients
Institutions using Sieve send us events about their customers: identifiers, contact details they choose to include, device and location signals, and transaction details. We process this data only on the client’s documented instructions, to provide fraud prevention, transaction monitoring and sanctions screening. Our clients remain the controllers and are responsible for their lawful basis and customer notices.
- Names, phone numbers, emails, national IDs and dates of birth are encrypted at rest.
- Payout accounts, devices and identifiers used for linking are stored as keyed hashes.
- We do not sell personal data or use client data to train AI models.
- The optional fraud network shares only keyed hashes of confirmed-fraud identifiers, and only for institutions that opt in.
Data we control
When you contact us or use the dashboard we process your name, work email, institution, role and the content of your messages, plus technical logs (IP address, browser, actions taken) needed to secure the service. We use this to respond to you, operate your account, keep the service secure and meet legal obligations.
We count visits to our website ourselves, without cookies. We keep the page, the referring site, campaign tags, country, and device type. We don’t keep your IP address, and we can’t follow you from one day to the next. If your browser sends Do Not Track or Global Privacy Control, we don’t count you at all.
We send guides and product news only if you ask for them or have a Sieve account. Every such email has a one-click unsubscribe.
Retention
Client event, decision, screening and audit records are kept for seven years to support clients’ record-keeping obligations, unless a client’s agreement specifies otherwise. Sales enquiries are kept for up to two years.
International transfers
Institutions can choose where their data is hosted, including in Kenya. Where data is transferred outside the country of collection, we apply the safeguards required by the Data Protection Act 2019 and the client’s agreement.
Your rights
Under the Data Protection Act 2019 you may request access to, correction of or deletion of your personal data, and object to certain processing. If you are a customer of an institution that uses Sieve, contact that institution first; we will support it in responding. For data we control, email [email protected]. You may also complain to the Office of the Data Protection Commissioner.
Questions about this document? Email [email protected] or talk to our team.