Privacy Policy
Effective date: June 2026
KMG Vital Links Ltd ("KMG", "we", "us", "our") operates the Uza mobile application, the Tayari WhatsApp service and the VitalBot reseller platform. This policy explains how we collect, use, share and retain personal data.
1. Who We Are
KMG Vital Links Ltd is the controller for personal data processed through the Services unless a specific product flow states otherwise. For regulated payment services provided through Gemba Finance Limited, customer and transaction data may also be processed by Gemba for payment execution, safeguarding, compliance oversight and regulatory reporting.
2. Data We Collect
We may collect:
- Identity data: name, date of birth, nationality, ID or passport details, photos, selfie/liveness checks and business documents for KYB.
- Contact data: phone number, WhatsApp ID, email address and postal address.
- Account and security data: username, password hash, OTP records, device identifiers, IP address, login history and risk signals.
- Financial and transaction data: wallet balances, payment references, beneficiaries, products, amounts, currencies, payment method tokens, bank or mobile money details, refunds and chargebacks.
- Compliance data: KYC/KYB status, sanctions and PEP screening outcomes, risk ratings, source-of-funds information, source-of-wealth information where required, review notes and audit logs.
- Communications data: support messages, complaints, WhatsApp interactions, email records and call notes.
- Marketing data: preferences, consent records, campaign engagement and opt-out history.
- Vulnerability support data: only where you disclose circumstances that affect the support you need; we minimise access and record only what is necessary.
3. How We Use Data
We process personal data to:
- provide, maintain, secure and improve the Services;
- onboard customers, merchants, resellers, agents and developers;
- process transactions, payments, settlement, remittances and fulfilment;
- perform KYC, KYB, AML, sanctions, PEP, fraud and risk monitoring;
- comply with legal, regulatory, tax, audit and record-keeping obligations;
- investigate complaints, disputes, suspicious activity and security incidents;
- communicate operational, security, support and service updates;
- send marketing where permitted and honour opt-outs.
4. Lawful Bases
Our lawful bases include contract, legal obligation, legitimate interests, consent and, where applicable, substantial public interest for limited vulnerability or financial-crime processing. You can withdraw consent for optional marketing at any time.
5. Sharing
We share personal data only where necessary, including with:
- Gemba Finance Limited for regulated payment services, safeguarding, oversight and reporting;
- payment and product providers such as Stripe, PayFast, Paystack, Paynow, DT One, BlueLabel, Reloadly, Esolutions, EcoCash, InnBucks and similar providers;
- identity verification, AML, sanctions, PEP and fraud-prevention providers;
- telecoms, utility, delivery and fulfilment providers needed to complete a transaction;
- Meta and communications providers for WhatsApp, email and support messaging;
- hosting, security, analytics, monitoring and support infrastructure providers under appropriate contractual controls;
- professional advisers, auditors, insurers and compliance consultants;
- regulators, law enforcement, tax authorities, courts or ombudsman bodies where required or appropriate.
We do not sell personal data.
6. International Transfers
Some providers, counterparties and fulfilment partners operate outside the United Kingdom. Where personal data is transferred internationally, we use appropriate safeguards such as adequacy decisions, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, transfer risk assessments and technical controls such as encryption.
7. Retention
We retain data only for as long as needed for the purpose collected, including:
- KYC, AML, sanctions, complaints and transaction records: generally 5 years after the end of the relationship or relevant transaction, unless a longer legal hold applies.
- Tax, statutory accounting, payroll and corporate records: generally 6 years from the relevant year-end.
- Technical, device and security logs: generally up to 2 years, unless needed for investigation or security.
- Marketing data: until you opt out, then suppression records are retained so we can honour the opt-out.
When retention ends, records are deleted, anonymised or securely archived where lawful.
8. Your Rights
Subject to applicable law and regulatory retention obligations, you may request access, correction, deletion, restriction, portability or objection to processing. You may object to direct marketing at any time.
Contact privacy@kmgvitallinks.co.uk to exercise your rights. You may also complain to the UK Information Commissioner's Office.
9. Security
We use technical and organisational controls including TLS encryption in transit, encryption at rest for sensitive data, hashed passwords, OTP-based authentication, role-based access control, audit logging, vulnerability management and security monitoring.
No system is fully secure. Report suspected vulnerabilities or account compromise to security@kmgvitallinks.co.uk.
10. Breaches
Where a personal data breach occurs, we assess, contain, investigate and record it. If a breach is likely to result in risk to individuals, we notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware. If a breach is likely to result in high risk to affected individuals, we notify those individuals where required.
11. Children
The Services are intended for adults aged 18 and over. We do not knowingly provide the Services to children.
12. Cookies and Marketing
We use strictly necessary cookies for authentication, security and service operation. Non-essential cookies or direct marketing to non-customers require consent where applicable. Every marketing communication includes an opt-out route.
13. Changes
We may update this Privacy Policy from time to time. Material changes will be notified in-app, by email, WhatsApp or another reasonable channel.
14. Contact
KMG Vital Links Ltd.
Privacy: privacy@kmgvitallinks.co.uk Security: security@kmgvitallinks.co.uk Support: support@kmgvitallinks.co.uk