Kebarick Ventures

Kebarick HR & Payroll Terms of Service

Version 2026-09-03 · Terms of Service, Data Processing Terms, Acceptable Use and Payroll Responsibility Framework.

Binding agreement. By registering an organisation, clicking acceptance, using an organisation workspace after an authorised administrator has accepted, or otherwise using the service under an agreed order, the Customer accepts these Terms on behalf of the organisation. The person accepting confirms authority to bind that organisation. If you do not have such authority, do not accept these Terms.
Legal review note. This is a comprehensive operational SaaS contract drafted for Kebarick HR & Payroll and Kenya-facing use. It is not a substitute for advice from qualified Kenyan counsel. Kebarick should obtain legal review before relying on it as its final negotiated public instrument, particularly for enterprise liability caps, cross-border processing, sector-specific records and regulated customers.

Contents

1. Parties, definitions and interpretation

“Kebarick”, “we”, “us” or “our” means Kebarick Ventures, provider of Kebarick HR & Payroll. “Customer”, “Organisation”, “you” or “your” means the legal entity registered for or subscribing to the Service. “Authorised User” means a user permitted by the Customer. “Customer Data” means information submitted to or generated within the Customer workspace, including employee, applicant, attendance, payroll and organisational records. “Personal Data”, “Data Controller”, “Data Processor”, “Data Subject” and “Processing” have the meanings applicable under the Kenya Data Protection Act, 2019 and related regulations where applicable.

2. Service, permitted use and licence

Kebarick provides a hosted HR, payroll and workforce-management service that may include employee records, contracts, leave, attendance, rota, payroll calculation, statutory outputs, loans and advances, ESS, recruitment, documents, reports, communications and integrations. Features depend on the subscribed plan, configuration and deployment. Subject to payment and compliance with these Terms, Kebarick grants the Customer a limited, revocable, non-exclusive, non-transferable right to access and use the Service for its internal lawful business purposes during the subscription.

No source-code, ownership or resale right is transferred. The Customer must not sublicense the Service, provide bureau services to third parties without written permission, remove proprietary notices, circumvent subscription limits, or attempt to extract protected source code except to the extent expressly permitted by mandatory law.

3. Organisation registration, authority and account information

4. Free trial, subscriptions, charges and taxes

The advertised trial begins when the workspace is created unless otherwise agreed. Trial duration, plan limits, prices, billing cycle, user charges, discounts and renewal terms are those shown in the Service or an applicable order. The Customer is responsible for applicable taxes and lawful payment. A trial may be limited, changed for abuse prevention, or ended when the trial period expires. Continued access after the trial may require a paid subscription.

Where fees remain overdue, Kebarick may restrict paid functionality or suspend access after any applicable grace period and notice reasonably practicable in the circumstances. Suspension does not transfer ownership of Customer Data. Kebarick may preserve records for lawful recovery, dispute resolution, security and contractual retention.

5. Customer operational responsibilities

The Customer remains the employer and decision-maker. The Service does not appoint, discipline, terminate, classify or pay employees on the Customer’s behalf unless a separate written managed-services agreement expressly says so. The Customer is responsible for employment terms, lawful HR decisions, internal approvals, source documents, data accuracy, workplace policies, employee notices and the legality of instructions entered into the Service.

The Customer must maintain appropriate internal controls, including maker-checker approvals where appropriate, access reviews, payroll sign-off, bank-payment verification, statutory filing verification and independent checks before irreversible transactions.

6. Payroll, tax and statutory responsibility

Kebarick provides configured calculation tools and statutory reports; it is not the Customer’s tax adviser, accountant, legal adviser or statutory filing agent unless separately contracted in writing. The Customer must review each payroll before approval and payment and is responsible for correct salary inputs, employment dates, taxable benefits, employee classifications, exemptions, reliefs, bank instructions and statutory registration numbers.

7. Data protection roles and lawful processing

For Customer employee/applicant/workforce data, the Customer will ordinarily act as Data Controller and Kebarick as Data Processor acting on documented Customer instructions, except where Kebarick independently determines purposes and means of processing for its own lawful obligations, security, billing, fraud prevention or corporate administration, in which case Kebarick may act as a separate controller for that limited processing.

The Customer warrants that it has a lawful basis, appropriate privacy notices and any required consent or other authority for Personal Data uploaded to the Service. The Customer must apply data minimisation and should not upload information irrelevant to the employment or service purpose.

Special or sensitive categories of information, including health, biometric, disciplinary, identity and bank information, require heightened care. The Customer is responsible for determining whether such processing is necessary, proportionate and lawful.

8. Kebarick processing instructions

Kebarick will process Customer Data to provide, secure, maintain, support and improve the contracted Service; produce Customer-requested HR/payroll outputs; authenticate users; deliver authorised communications; maintain audit records; prevent abuse; and comply with applicable law. Kebarick will not sell Customer employee data or use Customer payroll data for unrelated advertising.

If Kebarick reasonably believes a Customer instruction infringes applicable data-protection law, Kebarick may notify the Customer and suspend the affected instruction pending clarification, where permitted by law.

9. Security, confidentiality and access controls

Each party must protect the other’s confidential information using appropriate organisational and technical safeguards. Kebarick may use tenant isolation, authentication, role-based access, audit trails, encrypted transport, secret management, backups, monitoring and other controls appropriate to the Service. No internet-connected service is absolutely secure and no security measure eliminates all risk.

Customer administrators are responsible for least-privilege access, strong credentials, approved devices where required, prompt revocation, internal confidentiality obligations and preventing unauthorised export or sharing. Downloaded payroll files and payslips become the Customer’s responsibility once delivered to an authorised user or destination.

10. Personal-data breach and security-incident handling

Where an incident involving Customer Personal Data is confirmed, the parties will cooperate in accordance with applicable law and their respective controller/processor roles. Where Kebarick acts as processor, it will notify the Customer without undue delay after becoming aware of a qualifying Personal Data breach and provide information reasonably available to assist the Customer. Kenyan data-protection law may require a processor to notify the controller without delay and, where reasonably practicable, within forty-eight hours; a controller may have a separate notification duty to the Data Commissioner within seventy-two hours where the statutory threshold is met. The Customer remains responsible for determining its legal notification duties unless Kebarick is the relevant controller.

Incident information may include the nature of the breach, affected data/categories, likely consequences, mitigation and contact information, to the extent known. Neither party will issue a public statement naming the other without prior consultation unless legally required.

11. Data-subject requests and privacy rights

Where Kebarick acts as processor, the Customer is responsible for responding to employees/applicants exercising applicable rights. Taking into account the nature of processing, Kebarick will provide reasonable technical assistance through available access, correction, export, restriction or deletion functionality and support where necessary. The Customer must verify requester identity and preserve records where retention is legally required.

12. Cross-border transfers and hosting

Customer Data may be hosted or processed using infrastructure or service providers in Kenya or other jurisdictions, depending on deployment and integration. Where Personal Data is transferred outside Kenya, the parties must use a lawful transfer basis and appropriate safeguards as required by applicable Kenyan data-protection law, including adequacy, appropriate safeguards, necessity or valid consent where applicable. The Customer must not configure an external integration that transfers Personal Data unlawfully.

13. Subprocessors and service providers

Kebarick may use hosting, email, SMS, monitoring, backup, support, payment or other providers to deliver the Service. Kebarick will impose appropriate confidentiality and data-protection obligations where the provider processes Customer Personal Data on Kebarick’s behalf. The Customer authorises such processing subject to applicable law and any enterprise subprocessor terms. Third-party services selected directly by the Customer are governed by the Customer’s relationship with that provider.

14. Data retention, backup, portability and deletion

The Customer determines operational retention periods subject to applicable employment, tax, audit and other legal obligations. Kebarick may maintain operational backups, audit records and security logs for defined recovery/security periods. Deletion from an active screen may not immediately remove data from protected backups. Backups may age out according to the backup cycle rather than be individually edited.

Customers should export records needed for independent business continuity and statutory retention. On termination, Kebarick may provide a reasonable export window subject to plan, technical feasibility, outstanding fees and legal restrictions. Data may then be deleted, anonymised or retained only where required for law, fraud/security, audit or dispute purposes.

15. Devices, APIs and third-party integrations

The Service may integrate with attendance devices, banks, email/SMS providers, payment platforms, recruitment services, statutory systems or APIs. The Customer is responsible for valid credentials, authorised endpoints and third-party terms. Kebarick does not control third-party uptime, policy, data quality or fee changes. An integration failure does not automatically establish a defect in Kebarick.

API credentials and tokens must be treated as secrets. The Customer must not place platform-master credentials in tenant-visible settings. Kebarick may rate-limit, suspend or rotate integration access in response to misuse or security risk.

16. Electronic communications and payslip delivery

The Customer authorises operational electronic communications to registered organisation contacts and, when configured by the Customer, to employee contact addresses. The Customer is responsible for maintaining accurate email/phone addresses and ensuring it has authority to send employment communications. A delivery marked “sent” means the configured provider accepted the message; it does not guarantee reading, inbox placement or control of the recipient’s mailbox.

Payslips are confidential. Customers should use appropriate password protection and verified employee addresses. Once a payslip is sent, the underlying approved payroll may be permanently locked to preserve the integrity of the issued record.

17. Acceptable use

The Customer and Authorised Users must not use the Service to violate law; unlawfully discriminate or harass; conduct unlawful surveillance; process data without authority; upload malware; probe another tenant; bypass authentication; defeat licensing; misrepresent payroll records; falsify attendance; unlawfully intercept communications; or use the Service to facilitate fraud or other unlawful conduct. Kebarick may suspend harmful activity immediately where reasonably necessary to protect users, systems or legal obligations.

18. Intellectual property and feedback

Kebarick owns the Service, software, interfaces, documentation, system architecture, templates and related intellectual property excluding Customer Data and Customer-owned branding. The Customer may use generated outputs for its lawful internal business. If the Customer provides suggestions or feedback, Kebarick may use them to improve the Service without transferring Customer confidential information.

19. Availability, maintenance, support and force majeure

Kebarick aims for reliable availability but does not guarantee uninterrupted service unless a signed SLA states otherwise. Planned maintenance, emergency maintenance, internet failures, infrastructure incidents, third-party outages, government action and events beyond reasonable control may affect operation. Support priority and response commitments depend on the applicable plan or agreement.

20. Warranties and disclaimers

Each party warrants that it has authority to enter into the agreement. Kebarick will provide the Service with reasonable care and skill. Except to the extent prohibited by law, the Service is otherwise provided on an “as available” basis. Kebarick does not warrant that Customer-entered information, Customer decisions, third-party data or every statutory interpretation is correct, or that a third-party service will remain available.

21. Liability allocation and indemnities

Nothing in these Terms excludes liability that cannot lawfully be excluded, including liability where mandatory law requires otherwise. To the maximum extent permitted by law, neither party is liable for indirect, special, incidental or consequential losses, loss of profit, loss of anticipated savings or loss arising solely from the other party’s failure to maintain reasonable internal controls.

Any financial liability cap should be read with the Customer’s applicable order or enterprise agreement. Where no negotiated cap exists, Kebarick’s aggregate contractual liability should not exceed fees paid or payable for the affected Service during the twelve months preceding the event giving rise to the claim, except where such limitation is prohibited by law or the claim concerns fraud, wilful misconduct or another non-excludable category.

The Customer will be responsible for claims, penalties or losses arising from unlawful Customer instructions, unauthorised data supplied by the Customer, Customer employment decisions, Customer failure to review payroll, or Customer misuse, except to the extent caused by Kebarick’s breach. Kebarick remains responsible for its own proven breach subject to applicable law and agreed limitations.

22. Audit logs, approvals and evidentiary records

The Service may record sign-ins, approvals, changes, payroll transitions, exports, communications, administrative actions and other audit events. Customers must not tamper with audit records. Electronic records may be used to investigate access, resolve disputes and demonstrate workflow history, subject to applicable evidentiary law. Audit logs do not replace the Customer’s statutory books and records.

23. Suspension, termination and exit

Kebarick may suspend access for material security threats, unlawful use, repeated policy violations or persistent non-payment, with notice where reasonable. Either party may terminate in accordance with the applicable subscription or signed agreement. Termination does not extinguish accrued payment obligations, confidentiality, intellectual-property, data-protection, audit, liability or dispute provisions intended to survive.

24. Changes to the Service, statutory rules and these Terms

Kebarick may improve features, interfaces and security controls. Material contractual changes will be versioned and presented to an authorised administrator or otherwise notified electronically. A new Terms version may require renewed acceptance. Statutory calculation rules may be updated separately when law or official guidance changes.

25. Governing law, complaints and disputes

Unless a signed agreement states otherwise, these Terms are governed by the laws of Kenya. The parties should first attempt good-faith resolution through authorised representatives. Nothing prevents a Data Subject or party from exercising rights before the Office of the Data Protection Commissioner (ODPC), a court, regulator or other competent body where the law provides such a right.

26. General provisions

Schedule A — Data Processing Terms

A1. Subject matter and duration

Processing covers the Customer Data necessary to provide the subscribed HR/payroll Service for the subscription term plus lawful backup, security and exit-retention periods.

A2. Nature and purpose

Collection, recording, organisation, storage, retrieval, consultation, calculation, reporting, communication, export, backup, support and deletion required for employee administration, attendance, leave, payroll, ESS, recruitment and related Customer instructions.

A3. Categories of Data Subjects

Employees, former employees, applicants, contractors, consultants, interns, volunteers, next of kin/emergency contacts, authorised Customer users and other individuals whose information the Customer lawfully enters.

A4. Types of Personal Data

Names, contact information, identifiers, employment data, salary/payroll information, statutory numbers, bank/payment information, attendance, leave, performance, disciplinary, recruitment, documents, emergency contacts, device identifiers and, where lawfully required, health/biometric or other sensitive information.

A5. Processor commitments

A6. Customer controller commitments

Administrator acknowledgement: Kebarick records the accepted Terms version, acceptance time and accepting authorised account for the organisation. Version 2026-09-03 supersedes the prior online Terms when accepted.