Contents
1. Parties, definitions and interpretation
“Kebarick”, “we”, “us” or “our” means Kebarick Ventures, provider of Kebarick HR & Payroll. “Customer”, “Organisation”, “you” or “your” means the legal entity registered for or subscribing to the Service. “Authorised User” means a user permitted by the Customer. “Customer Data” means information submitted to or generated within the Customer workspace, including employee, applicant, attendance, payroll and organisational records. “Personal Data”, “Data Controller”, “Data Processor”, “Data Subject” and “Processing” have the meanings applicable under the Kenya Data Protection Act, 2019 and related regulations where applicable.
2. Service, permitted use and licence
Kebarick provides a hosted HR, payroll and workforce-management service that may include employee records, contracts, leave, attendance, rota, payroll calculation, statutory outputs, loans and advances, ESS, recruitment, documents, reports, communications and integrations. Features depend on the subscribed plan, configuration and deployment. Subject to payment and compliance with these Terms, Kebarick grants the Customer a limited, revocable, non-exclusive, non-transferable right to access and use the Service for its internal lawful business purposes during the subscription.
No source-code, ownership or resale right is transferred. The Customer must not sublicense the Service, provide bureau services to third parties without written permission, remove proprietary notices, circumvent subscription limits, or attempt to extract protected source code except to the extent expressly permitted by mandatory law.
3. Organisation registration, authority and account information
- Registration information must be complete, accurate and kept current, including legal/trading name, contact channels, employee estimate, physical address and primary administrator information.
- The registering person warrants that they have authority to register and administer the organisation and to provide the submitted information.
- The Customer is responsible for determining user roles, access rights, separation of duties and timely deactivation of former staff.
- Credentials are personal and must not be shared. The Customer must notify Kebarick promptly of suspected compromise.
- Kebarick may reasonably verify identity, organisation legitimacy, billing details or authority where necessary for security, fraud prevention, legal compliance or support.
4. Free trial, subscriptions, charges and taxes
The advertised trial begins when the workspace is created unless otherwise agreed. Trial duration, plan limits, prices, billing cycle, user charges, discounts and renewal terms are those shown in the Service or an applicable order. The Customer is responsible for applicable taxes and lawful payment. A trial may be limited, changed for abuse prevention, or ended when the trial period expires. Continued access after the trial may require a paid subscription.
Where fees remain overdue, Kebarick may restrict paid functionality or suspend access after any applicable grace period and notice reasonably practicable in the circumstances. Suspension does not transfer ownership of Customer Data. Kebarick may preserve records for lawful recovery, dispute resolution, security and contractual retention.
5. Customer operational responsibilities
The Customer remains the employer and decision-maker. The Service does not appoint, discipline, terminate, classify or pay employees on the Customer’s behalf unless a separate written managed-services agreement expressly says so. The Customer is responsible for employment terms, lawful HR decisions, internal approvals, source documents, data accuracy, workplace policies, employee notices and the legality of instructions entered into the Service.
The Customer must maintain appropriate internal controls, including maker-checker approvals where appropriate, access reviews, payroll sign-off, bank-payment verification, statutory filing verification and independent checks before irreversible transactions.
6. Payroll, tax and statutory responsibility
Kebarick provides configured calculation tools and statutory reports; it is not the Customer’s tax adviser, accountant, legal adviser or statutory filing agent unless separately contracted in writing. The Customer must review each payroll before approval and payment and is responsible for correct salary inputs, employment dates, taxable benefits, employee classifications, exemptions, reliefs, bank instructions and statutory registration numbers.
- Rules may change due to legislation, regulations, court orders, official notices or agency interpretation. Kebarick may update calculation rules, but the Customer must validate payroll and statutory outputs before filing or remittance.
- “Preview”, “calculated”, “processed” or “approved” status does not itself constitute payment, filing, remittance or legal compliance.
- Bank schedules and statutory files must be verified against the receiving bank/agency requirements before use.
- The Customer must promptly report a suspected calculation defect and must not knowingly continue using an incorrect rule.
- Historical payrolls may be locked for integrity. Re-opening or deletion rights, where provided, are controlled, permissioned and audited; once a payslip is sent, the Service may permanently lock that payroll to preserve issued-record integrity.
7. Data protection roles and lawful processing
For Customer employee/applicant/workforce data, the Customer will ordinarily act as Data Controller and Kebarick as Data Processor acting on documented Customer instructions, except where Kebarick independently determines purposes and means of processing for its own lawful obligations, security, billing, fraud prevention or corporate administration, in which case Kebarick may act as a separate controller for that limited processing.
The Customer warrants that it has a lawful basis, appropriate privacy notices and any required consent or other authority for Personal Data uploaded to the Service. The Customer must apply data minimisation and should not upload information irrelevant to the employment or service purpose.
Special or sensitive categories of information, including health, biometric, disciplinary, identity and bank information, require heightened care. The Customer is responsible for determining whether such processing is necessary, proportionate and lawful.
8. Kebarick processing instructions
Kebarick will process Customer Data to provide, secure, maintain, support and improve the contracted Service; produce Customer-requested HR/payroll outputs; authenticate users; deliver authorised communications; maintain audit records; prevent abuse; and comply with applicable law. Kebarick will not sell Customer employee data or use Customer payroll data for unrelated advertising.
If Kebarick reasonably believes a Customer instruction infringes applicable data-protection law, Kebarick may notify the Customer and suspend the affected instruction pending clarification, where permitted by law.
9. Security, confidentiality and access controls
Each party must protect the other’s confidential information using appropriate organisational and technical safeguards. Kebarick may use tenant isolation, authentication, role-based access, audit trails, encrypted transport, secret management, backups, monitoring and other controls appropriate to the Service. No internet-connected service is absolutely secure and no security measure eliminates all risk.
Customer administrators are responsible for least-privilege access, strong credentials, approved devices where required, prompt revocation, internal confidentiality obligations and preventing unauthorised export or sharing. Downloaded payroll files and payslips become the Customer’s responsibility once delivered to an authorised user or destination.
10. Personal-data breach and security-incident handling
Where an incident involving Customer Personal Data is confirmed, the parties will cooperate in accordance with applicable law and their respective controller/processor roles. Where Kebarick acts as processor, it will notify the Customer without undue delay after becoming aware of a qualifying Personal Data breach and provide information reasonably available to assist the Customer. Kenyan data-protection law may require a processor to notify the controller without delay and, where reasonably practicable, within forty-eight hours; a controller may have a separate notification duty to the Data Commissioner within seventy-two hours where the statutory threshold is met. The Customer remains responsible for determining its legal notification duties unless Kebarick is the relevant controller.
Incident information may include the nature of the breach, affected data/categories, likely consequences, mitigation and contact information, to the extent known. Neither party will issue a public statement naming the other without prior consultation unless legally required.
11. Data-subject requests and privacy rights
Where Kebarick acts as processor, the Customer is responsible for responding to employees/applicants exercising applicable rights. Taking into account the nature of processing, Kebarick will provide reasonable technical assistance through available access, correction, export, restriction or deletion functionality and support where necessary. The Customer must verify requester identity and preserve records where retention is legally required.
12. Cross-border transfers and hosting
Customer Data may be hosted or processed using infrastructure or service providers in Kenya or other jurisdictions, depending on deployment and integration. Where Personal Data is transferred outside Kenya, the parties must use a lawful transfer basis and appropriate safeguards as required by applicable Kenyan data-protection law, including adequacy, appropriate safeguards, necessity or valid consent where applicable. The Customer must not configure an external integration that transfers Personal Data unlawfully.
13. Subprocessors and service providers
Kebarick may use hosting, email, SMS, monitoring, backup, support, payment or other providers to deliver the Service. Kebarick will impose appropriate confidentiality and data-protection obligations where the provider processes Customer Personal Data on Kebarick’s behalf. The Customer authorises such processing subject to applicable law and any enterprise subprocessor terms. Third-party services selected directly by the Customer are governed by the Customer’s relationship with that provider.
14. Data retention, backup, portability and deletion
The Customer determines operational retention periods subject to applicable employment, tax, audit and other legal obligations. Kebarick may maintain operational backups, audit records and security logs for defined recovery/security periods. Deletion from an active screen may not immediately remove data from protected backups. Backups may age out according to the backup cycle rather than be individually edited.
Customers should export records needed for independent business continuity and statutory retention. On termination, Kebarick may provide a reasonable export window subject to plan, technical feasibility, outstanding fees and legal restrictions. Data may then be deleted, anonymised or retained only where required for law, fraud/security, audit or dispute purposes.
15. Devices, APIs and third-party integrations
The Service may integrate with attendance devices, banks, email/SMS providers, payment platforms, recruitment services, statutory systems or APIs. The Customer is responsible for valid credentials, authorised endpoints and third-party terms. Kebarick does not control third-party uptime, policy, data quality or fee changes. An integration failure does not automatically establish a defect in Kebarick.
API credentials and tokens must be treated as secrets. The Customer must not place platform-master credentials in tenant-visible settings. Kebarick may rate-limit, suspend or rotate integration access in response to misuse or security risk.
16. Electronic communications and payslip delivery
The Customer authorises operational electronic communications to registered organisation contacts and, when configured by the Customer, to employee contact addresses. The Customer is responsible for maintaining accurate email/phone addresses and ensuring it has authority to send employment communications. A delivery marked “sent” means the configured provider accepted the message; it does not guarantee reading, inbox placement or control of the recipient’s mailbox.
Payslips are confidential. Customers should use appropriate password protection and verified employee addresses. Once a payslip is sent, the underlying approved payroll may be permanently locked to preserve the integrity of the issued record.
17. Acceptable use
The Customer and Authorised Users must not use the Service to violate law; unlawfully discriminate or harass; conduct unlawful surveillance; process data without authority; upload malware; probe another tenant; bypass authentication; defeat licensing; misrepresent payroll records; falsify attendance; unlawfully intercept communications; or use the Service to facilitate fraud or other unlawful conduct. Kebarick may suspend harmful activity immediately where reasonably necessary to protect users, systems or legal obligations.
18. Intellectual property and feedback
Kebarick owns the Service, software, interfaces, documentation, system architecture, templates and related intellectual property excluding Customer Data and Customer-owned branding. The Customer may use generated outputs for its lawful internal business. If the Customer provides suggestions or feedback, Kebarick may use them to improve the Service without transferring Customer confidential information.
19. Availability, maintenance, support and force majeure
Kebarick aims for reliable availability but does not guarantee uninterrupted service unless a signed SLA states otherwise. Planned maintenance, emergency maintenance, internet failures, infrastructure incidents, third-party outages, government action and events beyond reasonable control may affect operation. Support priority and response commitments depend on the applicable plan or agreement.
20. Warranties and disclaimers
Each party warrants that it has authority to enter into the agreement. Kebarick will provide the Service with reasonable care and skill. Except to the extent prohibited by law, the Service is otherwise provided on an “as available” basis. Kebarick does not warrant that Customer-entered information, Customer decisions, third-party data or every statutory interpretation is correct, or that a third-party service will remain available.
21. Liability allocation and indemnities
Nothing in these Terms excludes liability that cannot lawfully be excluded, including liability where mandatory law requires otherwise. To the maximum extent permitted by law, neither party is liable for indirect, special, incidental or consequential losses, loss of profit, loss of anticipated savings or loss arising solely from the other party’s failure to maintain reasonable internal controls.
Any financial liability cap should be read with the Customer’s applicable order or enterprise agreement. Where no negotiated cap exists, Kebarick’s aggregate contractual liability should not exceed fees paid or payable for the affected Service during the twelve months preceding the event giving rise to the claim, except where such limitation is prohibited by law or the claim concerns fraud, wilful misconduct or another non-excludable category.
The Customer will be responsible for claims, penalties or losses arising from unlawful Customer instructions, unauthorised data supplied by the Customer, Customer employment decisions, Customer failure to review payroll, or Customer misuse, except to the extent caused by Kebarick’s breach. Kebarick remains responsible for its own proven breach subject to applicable law and agreed limitations.
22. Audit logs, approvals and evidentiary records
The Service may record sign-ins, approvals, changes, payroll transitions, exports, communications, administrative actions and other audit events. Customers must not tamper with audit records. Electronic records may be used to investigate access, resolve disputes and demonstrate workflow history, subject to applicable evidentiary law. Audit logs do not replace the Customer’s statutory books and records.
23. Suspension, termination and exit
Kebarick may suspend access for material security threats, unlawful use, repeated policy violations or persistent non-payment, with notice where reasonable. Either party may terminate in accordance with the applicable subscription or signed agreement. Termination does not extinguish accrued payment obligations, confidentiality, intellectual-property, data-protection, audit, liability or dispute provisions intended to survive.
24. Changes to the Service, statutory rules and these Terms
Kebarick may improve features, interfaces and security controls. Material contractual changes will be versioned and presented to an authorised administrator or otherwise notified electronically. A new Terms version may require renewed acceptance. Statutory calculation rules may be updated separately when law or official guidance changes.
25. Governing law, complaints and disputes
Unless a signed agreement states otherwise, these Terms are governed by the laws of Kenya. The parties should first attempt good-faith resolution through authorised representatives. Nothing prevents a Data Subject or party from exercising rights before the Office of the Data Protection Commissioner (ODPC), a court, regulator or other competent body where the law provides such a right.
26. General provisions
- Entire agreement: these Terms, applicable subscription/order, Data Processing Terms and signed enterprise documents form the agreement.
- Precedence: a signed agreement expressly addressing a conflicting term prevails for that Customer.
- Severability: an invalid provision will be limited or severed to the minimum extent necessary without invalidating the remainder.
- No waiver: failure to enforce a right immediately is not a waiver.
- Assignment: neither party may assign the agreement contrary to law or an applicable signed agreement; Kebarick may assign in connection with a genuine corporate reorganisation or transfer of the Service subject to continuing obligations.
- Notices: legal, billing, security and operational notices may be sent electronically to registered organisation contacts and displayed in the Service.
- Headings: headings are for convenience and do not limit interpretation.
Schedule A — Data Processing Terms
A1. Subject matter and duration
Processing covers the Customer Data necessary to provide the subscribed HR/payroll Service for the subscription term plus lawful backup, security and exit-retention periods.
A2. Nature and purpose
Collection, recording, organisation, storage, retrieval, consultation, calculation, reporting, communication, export, backup, support and deletion required for employee administration, attendance, leave, payroll, ESS, recruitment and related Customer instructions.
A3. Categories of Data Subjects
Employees, former employees, applicants, contractors, consultants, interns, volunteers, next of kin/emergency contacts, authorised Customer users and other individuals whose information the Customer lawfully enters.
A4. Types of Personal Data
Names, contact information, identifiers, employment data, salary/payroll information, statutory numbers, bank/payment information, attendance, leave, performance, disciplinary, recruitment, documents, emergency contacts, device identifiers and, where lawfully required, health/biometric or other sensitive information.
A5. Processor commitments
- Process Personal Data only on documented Customer instructions except where law requires otherwise.
- Ensure authorised personnel are bound by confidentiality.
- Implement appropriate technical and organisational security measures.
- Assist the Customer, reasonably and proportionately, with Data Subject rights, breach response, security obligations and lawful regulator enquiries.
- Use subprocessors subject to appropriate data-protection obligations.
- Return/export or delete data on termination in accordance with the Service, retention policy and law.
- Maintain information reasonably necessary to demonstrate compliance with these processing commitments.
A6. Customer controller commitments
- Issue lawful instructions and maintain an appropriate legal basis and notices.
- Minimise data and restrict access to personnel with a need to know.
- Respond to Data Subject requests and regulator correspondence as controller.
- Configure retention, user access and external integrations lawfully.
- Not instruct Kebarick to conceal, falsify or unlawfully alter employment/payroll records.