Your Privacy Matters

Privacy Policy

At Iterative Billing, we are committed to protecting the privacy and security of your personal information. This policy explains how we collect, use, store, and safeguard your data.

Last updated: April 5, 2026 · Effective immediately upon posting

1. Definitions & Interpretation

In this Privacy Policy, the following terms shall have the meanings ascribed to them below, unless the context requires otherwise:

  • "Platform" refers to the Iterative Billing software-as-a-service application, including all associated websites, APIs, mobile applications, and related services operated by Iterative Billing.
  • "We," "Us," "Our," or "Company" refers to Iterative Billing, the entity that owns and operates the Platform.
  • "Tenant" or "ISP Client" refers to any internet service provider, business, or organization that subscribes to and uses the Platform to manage their operations, billing, and customer relationships.
  • "End User" or "Subscriber" refers to the customers of our Tenants: individuals or entities who receive internet services from ISPs that use our Platform.
  • "User" or "You" refers to any individual who accesses or uses the Platform, whether as a Tenant, End User, or visitor.
  • "Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to names, email addresses, phone numbers, IP addresses, device identifiers, location data, and financial information.
  • "Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
  • "Data Controller" means the entity that determines the purposes and means of Processing Personal Data. Iterative Billing acts as a Data Controller for Tenant account data and as a Data Processor for End User data managed by Tenants.
  • "Data Processor" means the entity that Processes Personal Data on behalf of the Data Controller.
  • "Sub-Processor" means any third party engaged by Us to Process Personal Data on behalf of a Tenant.
  • "Sensitive Personal Data" means Personal Data revealing racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, or financial account details, as defined under applicable data protection laws.

2. Information We Collect

We collect various categories of information depending on your relationship with our Platform. The scope and nature of data collected is strictly limited to what is necessary for the provision of our services.

2.1 Tenant Account Information

When an ISP registers for and uses our Platform, we collect:

  • Business name, registration details, and tax identification numbers
  • Contact information including name, email address, phone number, and physical address of authorized representatives
  • Billing and payment information including bank account details, M-Pesa Till/Paybill numbers, and payment gateway credentials
  • MikroTik router configuration data including IP addresses, API credentials, and network topology information
  • Service package configurations, pricing structures, and billing cycle preferences
  • Staff and administrator account details including names, roles, and access permissions
  • Communication preferences and support interaction history
  • White-label branding assets including logos, color schemes, and custom domain configurations

2.2 End User / Subscriber Information

On behalf of our Tenants, we process the following End User data:

  • Full name, email address, phone number, and physical or installation address
  • National identification or passport numbers where required by the Tenant for KYC compliance
  • Internet service subscription details including package type, bandwidth allocation, and connection status
  • PPPoE and Hotspot authentication credentials (usernames; passwords are stored in hashed format)
  • Payment transaction records including amounts, dates, payment methods, and transaction reference numbers
  • Network usage data including session duration, data consumption, and bandwidth utilization
  • IP addresses assigned during internet sessions
  • SMS and communication logs related to billing notifications, payment reminders, and service alerts
  • Support tickets and customer service interaction records

2.3 Automatically Collected Information

When you access our Platform, we automatically collect:

  • Device information including device type, operating system, browser type and version, and screen resolution
  • IP address, approximate geographic location derived from IP, and internet service provider information
  • Usage data including pages visited, features used, click patterns, session duration, and navigation paths
  • Referral source, search terms, and campaign attribution data
  • Error logs, crash reports, and performance diagnostics
  • Cookies, pixel tags, web beacons, and similar tracking technologies (see Section 8)

2.4 Information from Third Parties

We may receive information from:

  • Payment processors (M-Pesa, KopoKopo, Flutterwave, SasaPay, Stripe, PayStack) regarding transaction confirmations and payment status
  • MikroTik routers via API integration regarding network status, user sessions, and bandwidth data
  • SMS gateway providers regarding message delivery status
  • Domain registrars and SSL certificate providers for white-label configurations
  • Publicly available business registries for Tenant verification purposes

3. How We Use Your Information

We use the information we collect for the following purposes, each of which is essential to the operation and improvement of our Platform:

3.1 Service Delivery & Operations

  • Provisioning, maintaining, and administering Tenant accounts and their subscriber management systems
  • Processing billing cycles, generating invoices, and facilitating payment collection through integrated gateways
  • Managing MikroTik router integrations including PPPoE/Hotspot user provisioning, bandwidth management, and CoA (Change of Authorization) operations
  • Sending transactional communications including billing notifications, payment confirmations, service alerts, and account updates via SMS and email
  • Providing RADIUS authentication services for subscriber internet access
  • Generating financial reports, analytics dashboards, and business intelligence for Tenants
  • Facilitating white-label portal customization and branding

3.2 Platform Improvement & Analytics

  • Analyzing usage patterns to improve Platform features, performance, and user experience
  • Conducting aggregated and anonymized statistical analysis for product development
  • Monitoring system performance, uptime, and infrastructure health
  • Identifying and resolving technical issues, bugs, and security vulnerabilities
  • Developing new features and services based on aggregated usage trends

3.3 Security & Fraud Prevention

  • Detecting, preventing, and investigating unauthorized access, fraud, abuse, and security incidents
  • Verifying user identities and authenticating access to accounts and administrative functions
  • Monitoring for suspicious payment activities and potential financial fraud
  • Enforcing our Terms of Service and Acceptable Use Policy
  • Protecting the rights, property, and safety of our Users, Tenants, and the public

3.4 Legal & Regulatory Compliance

  • Complying with applicable laws, regulations, legal processes, and governmental requests
  • Responding to lawful requests from law enforcement and regulatory authorities
  • Maintaining records as required by tax, financial, and telecommunications regulations
  • Exercising or defending legal claims and rights
  • Fulfilling obligations under the Kenya Data Protection Act 2019, GDPR, CCPA/CPRA, and other applicable privacy frameworks

3.5 Communications & Marketing

  • Sending service-related announcements, maintenance notifications, and security alerts (these are non-optional)
  • Providing customer support and responding to inquiries
  • Sending promotional communications about new features, updates, and offers (with your consent, where required)
  • Conducting surveys and collecting feedback to improve our services

4. Legal Basis for Processing

We process Personal Data only when we have a valid legal basis to do so. Depending on the context, our legal bases include:

4.1 Contractual Necessity

Processing is necessary for the performance of our contract with you, including account creation, service delivery, billing, payment processing, and technical support. Without this processing, we cannot provide our services.

4.2 Legitimate Interests

We process data where we have a legitimate business interest that is not overridden by your rights, including:

  • Improving and optimizing our Platform and services
  • Ensuring network and information security
  • Preventing fraud and unauthorized access
  • Conducting business analytics using aggregated, anonymized data
  • Marketing our services to existing customers (with easy opt-out)

4.3 Consent

Where required by law, we obtain your explicit consent before processing, particularly for:

  • Sending promotional marketing communications
  • Placing non-essential cookies and tracking technologies
  • Processing sensitive personal data
  • Transferring data to jurisdictions without adequate data protection frameworks

You may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

4.4 Legal Obligation

We process data where necessary to comply with legal obligations, including tax reporting, financial record-keeping, telecommunications regulations, anti-money laundering requirements, and responding to lawful government requests.

4.5 Vital Interests

In rare circumstances, we may process data to protect the vital interests of an individual, such as in emergency situations involving threats to personal safety.

5. Data Sharing & Third Parties

We do not sell, rent, or trade your Personal Data to third parties for their marketing purposes. We share data only in the following limited circumstances:

5.1 Payment Processors

We share necessary transaction data with integrated payment gateways to process payments:

  • M-Pesa (Safaricom PLC): for mobile money transactions via Till Number and Paybill
  • KopoKopo: for M-Pesa payment processing and settlement
  • Flutterwave: for card payments and multi-currency transactions
  • SasaPay: for mobile wallet and bank transfer processing
  • Stripe: for international card payments and recurring billing
  • PayStack: for card and bank transfer payments

Each payment processor operates under its own privacy policy and PCI-DSS compliance obligations. We share only the minimum data required to complete transactions.

5.2 Infrastructure & Service Providers

We engage trusted third-party service providers who process data on our behalf under strict contractual obligations:

  • Cloud hosting and infrastructure providers for data storage and computing
  • SMS gateway providers for delivering billing notifications and alerts
  • Email delivery services for transactional and marketing communications
  • Content delivery networks (CDNs) for performance optimization
  • Analytics providers for aggregated usage insights
  • Customer support tools for ticket management

All sub-processors are bound by Data Processing Agreements (DPAs) that require them to protect your data to standards no less protective than this Policy.

5.3 Tenant-to-Subscriber Data Flow

As a multi-tenant platform, data flows between Tenants and their Subscribers are governed as follows:

  • Tenants (ISPs) are Data Controllers for their Subscribers' data: they determine what data to collect and how to use it
  • Iterative Billing acts as a Data Processor, processing Subscriber data solely on behalf of and under the instructions of the Tenant
  • We do not access, use, or share Subscriber data for our own purposes except as necessary to provide the Platform services or as required by law
  • Tenants are responsible for obtaining appropriate consents from their Subscribers and for their own compliance with applicable privacy laws
  • Subscriber data is logically isolated between Tenants: no Tenant can access another Tenant's data

5.4 Legal & Regulatory Disclosures

We may disclose Personal Data when we believe in good faith that disclosure is necessary to:

  • Comply with applicable law, regulation, legal process, or enforceable governmental request
  • Enforce our Terms of Service, including investigation of potential violations
  • Detect, prevent, or address fraud, security, or technical issues
  • Protect against harm to the rights, property, or safety of Iterative Billing, our Users, or the public as required or permitted by law
  • Respond to valid court orders, subpoenas, or warrants issued by courts of competent jurisdiction

5.5 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your Personal Data may be transferred as part of that transaction. We will notify affected Users of any change in ownership or control of their Personal Data and any choices they may have regarding their data. The acquiring entity will be bound by the terms of this Privacy Policy with respect to data collected prior to the transfer.

5.6 Aggregated & De-Identified Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify any individual. This data may be used for industry analysis, benchmarking, marketing, and other business purposes without restriction.

6. Multi-Tenant Data Architecture

Iterative Billing operates a multi-tenant architecture where multiple ISP clients share the same infrastructure while maintaining strict data isolation:

6.1 Data Isolation

  • Each Tenant's data is logically separated at the database level using tenant-specific identifiers
  • Access controls ensure that Tenants can only view, modify, and manage their own data and their Subscribers' data
  • Administrative access to cross-tenant data is restricted to authorized Iterative Billing personnel for maintenance and support purposes only
  • API endpoints enforce tenant-level authentication and authorization on every request

6.2 Shared Responsibility Model

  • Iterative Billing is responsible for the security and privacy of the Platform infrastructure, including data encryption, access controls, and system monitoring
  • Tenants are responsible for the accuracy of data they input, the consents they obtain from Subscribers, and their compliance with applicable laws in their jurisdiction
  • Tenants are responsible for managing their staff access permissions and ensuring appropriate use of the Platform
  • We provide tools and features to assist Tenants with their compliance obligations, but we do not guarantee compliance on their behalf

6.3 Data Portability Between Tenants

Subscriber data belongs to the Tenant. Upon termination of a Tenant's account, we will provide data export capabilities and delete Tenant data in accordance with our data retention policy, subject to any legal obligations requiring continued retention.

7. Payment & Financial Data

Given the financial nature of our Platform, we handle payment data with the highest level of care and security:

7.1 Payment Data We Process

  • M-Pesa transaction details including phone numbers, transaction IDs, amounts, and timestamps
  • Bank transfer details including account references and settlement information
  • Card payment tokens (we never store full card numbers: these are tokenized by our payment processors)
  • Invoice records, payment histories, and account balances
  • Refund and credit note records

7.2 Payment Security Standards

  • All payment processing is handled through PCI-DSS compliant payment processors
  • We do not store complete credit card numbers, CVV codes, or PIN numbers on our servers
  • Payment API credentials are encrypted at rest using AES-256 encryption
  • All payment-related communications are transmitted over TLS 1.2 or higher
  • Payment callback endpoints are validated using cryptographic signatures to prevent tampering
  • M-Pesa integration follows Safaricom's Daraja API security protocols including OAuth 2.0 authentication

7.3 Financial Record Retention

Financial transaction records are retained for a minimum of seven (7) years in compliance with applicable tax and financial regulations, even after account termination. This retention is a legal obligation and is not subject to deletion requests.

8. Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze usage, and support our operations:

8.1 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for Platform functionality including authentication, session management, security tokens, and load balancing. These cannot be disabled.
  • Functional Cookies: Remember your preferences such as language, theme (dark/light mode), timezone, and display settings.
  • Analytics Cookies: Help us understand how Users interact with the Platform, which features are most popular, and where Users encounter issues. We use aggregated analytics data to improve our services.
  • Performance Cookies: Monitor Platform performance, page load times, and error rates to ensure optimal service delivery.

8.2 Third-Party Tracking

We may use third-party analytics services that set their own cookies. These services process data under their own privacy policies:

  • Analytics services for usage pattern analysis
  • Error monitoring services for crash reporting and debugging
  • Performance monitoring tools for infrastructure optimization

8.3 Managing Cookies

You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. However, blocking essential cookies may impair Platform functionality. Where required by law, we will obtain your consent before placing non-essential cookies.

8.4 Do Not Track Signals

Our Platform currently does not respond to "Do Not Track" (DNT) browser signals, as there is no universally accepted standard for how to respond to such signals. We will update this policy if a standard is established.

9. Data Retention & Deletion

We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:

9.1 Retention Periods

  • Active Account Data: Retained for the duration of the account relationship plus thirty (30) days after account closure to facilitate reactivation requests.
  • Financial & Transaction Records: Retained for seven (7) years after the transaction date, as required by tax and financial regulations.
  • Network & Session Logs: Retained for twelve (12) months for security monitoring and troubleshooting purposes.
  • Support Tickets & Communications: Retained for three (3) years after resolution for quality assurance and dispute resolution.
  • Analytics & Usage Data: Aggregated and anonymized data may be retained indefinitely. Identifiable usage data is retained for twenty-four (24) months.
  • Marketing Consent Records: Retained for the duration of consent plus five (5) years as evidence of lawful processing.
  • Backup Data: Encrypted backups are retained for ninety (90) days on a rolling basis and are automatically purged thereafter.

9.2 Account Deletion

Upon receiving a valid deletion request or upon account termination:

  • Active account data will be deleted or anonymized within thirty (30) days
  • Data subject to legal retention requirements will be archived securely and access-restricted until the retention period expires
  • Backup copies will be purged within ninety (90) days through our automated backup rotation
  • We will provide confirmation of deletion upon request
  • Certain anonymized or aggregated data derived from your information may persist, as it can no longer be linked to you

9.3 Tenant Data Upon Termination

When a Tenant terminates their account, we will:

  • Provide a data export in a commonly used, machine-readable format upon request within thirty (30) days of termination
  • Delete all Tenant and associated Subscriber data within sixty (60) days of termination, subject to legal retention obligations
  • Provide written confirmation of data deletion upon request
  • Retain financial records as required by law (see Section 7.3)

10. International Data Transfers

As a platform serving ISPs across multiple regions, your data may be transferred to and processed in countries other than your country of residence:

10.1 Transfer Mechanisms

  • Where data is transferred outside of Kenya, the European Economic Area (EEA), or the United Kingdom, we ensure appropriate safeguards are in place
  • We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to countries without adequate data protection frameworks
  • We assess the data protection laws of recipient countries and implement supplementary measures where necessary
  • Our cloud infrastructure providers maintain certifications and compliance frameworks recognized by international data protection authorities

10.2 Data Localization

We endeavor to process and store data in regions that provide adequate data protection. Where Tenants have specific data residency requirements, we will work to accommodate such requirements within the capabilities of our infrastructure, subject to additional terms.

10.3 Cross-Border Safeguards

  • All international data transfers are encrypted in transit using TLS 1.2 or higher
  • Data at rest is encrypted using AES-256 encryption regardless of storage location
  • Access to data from different jurisdictions is logged and auditable
  • We maintain Data Processing Agreements with all sub-processors that include international transfer provisions

11. Data Security Measures

We implement comprehensive technical and organizational measures to protect your Personal Data against unauthorized access, alteration, disclosure, or destruction:

11.1 Technical Safeguards

  • End-to-end encryption for data in transit (TLS 1.2+) and at rest (AES-256)
  • Secure password hashing using industry-standard algorithms (bcrypt/Argon2)
  • Multi-factor authentication (MFA) available for all administrative accounts
  • Role-based access control (RBAC) with principle of least privilege
  • Regular security patching and vulnerability assessments
  • Web Application Firewall (WAF) protection against common attack vectors
  • DDoS mitigation and rate limiting on all API endpoints
  • Intrusion detection and prevention systems (IDS/IPS)
  • Automated security scanning of code and dependencies
  • Database encryption and secure key management

11.2 Organizational Safeguards

  • Employee background checks and confidentiality agreements for all staff with data access
  • Regular security awareness training for all employees
  • Strict access controls: data access is granted on a need-to-know basis only
  • Documented incident response procedures and escalation protocols
  • Regular internal and external security audits
  • Vendor security assessments for all third-party service providers
  • Business continuity and disaster recovery plans with regular testing

11.3 No Absolute Guarantee

While we implement industry-leading security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data. You acknowledge and accept this inherent risk when using any internet-based service. In the event of a security breach, we will follow our breach notification procedures as outlined in Section 15.

12. Your Rights & Choices

Depending on your jurisdiction, you may have the following rights regarding your Personal Data. We are committed to facilitating the exercise of these rights in a timely manner:

12.1 Universal Rights

  • Right of Access: You may request a copy of the Personal Data we hold about you, along with information about how it is processed.
  • Right to Rectification: You may request correction of inaccurate or incomplete Personal Data.
  • Right to Erasure (Right to be Forgotten): You may request deletion of your Personal Data, subject to legal retention obligations and legitimate business needs.
  • Right to Restrict Processing: You may request that we limit how we use your data in certain circumstances.
  • Right to Data Portability: You may request your data in a structured, commonly used, machine-readable format.
  • Right to Object: You may object to processing based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
  • Right Not to be Subject to Automated Decision-Making: You may request human review of decisions made solely by automated means that significantly affect you.

12.2 Kenya Data Protection Act 2019 Rights

If you are located in Kenya, you have additional rights under the Data Protection Act 2019, including:

  • The right to be informed of the use to which your Personal Data is to be put
  • The right to object to the processing of your Personal Data
  • The right to correction of false or misleading data
  • The right to deletion of false or misleading data
  • The right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC)

12.3 GDPR Rights (EEA/UK Residents)

If you are located in the European Economic Area or the United Kingdom, you have rights under the General Data Protection Regulation (GDPR) and UK GDPR, including all rights listed above plus:

  • The right to lodge a complaint with your local supervisory authority
  • The right to an effective judicial remedy against a supervisory authority or data controller/processor
  • The right to compensation for material or non-material damage resulting from GDPR violations

12.4 CCPA/CPRA Rights (California Residents)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including:

  • The right to know what Personal Data is collected, used, shared, or sold
  • The right to delete Personal Data held by businesses and their service providers
  • The right to opt-out of the sale or sharing of Personal Data (note: we do not sell Personal Data)
  • The right to non-discrimination for exercising your privacy rights
  • The right to correct inaccurate Personal Data
  • The right to limit use and disclosure of Sensitive Personal Information

12.5 Exercising Your Rights

To exercise any of these rights, please contact us using the details in Section 20. We will respond to your request within thirty (30) days, or within the timeframe required by applicable law. We may need to verify your identity before processing your request. If we cannot fulfill your request, we will explain the reasons and inform you of your right to appeal or lodge a complaint with the relevant supervisory authority.

12.6 End User Rights

If you are an End User (Subscriber of an ISP using our Platform), please direct your privacy requests to your ISP in the first instance, as they are the Data Controller for your data. If your ISP is unable to assist, you may contact us directly and we will coordinate with the relevant Tenant to fulfill your request.

13. Children's Privacy

Our Platform is designed for business use by ISPs and is not directed at children under the age of sixteen (16), or under the age of thirteen (13) in jurisdictions where COPPA applies:

  • We do not knowingly collect Personal Data from children under the applicable minimum age
  • Tenants are responsible for ensuring that they do not input data of minors into the Platform without appropriate parental or guardian consent as required by their local laws
  • If we become aware that we have inadvertently collected Personal Data from a child without appropriate consent, we will take immediate steps to delete such data
  • If you believe that a child's data has been submitted to our Platform without proper consent, please contact us immediately at the details provided in Section 20
  • In compliance with COPPA, we will not condition a child's participation in any activity on the disclosure of more Personal Data than is reasonably necessary

14. AI & Automated Decision-Making

Our Platform incorporates artificial intelligence and automated processing capabilities. We are committed to transparency about how these technologies are used:

14.1 AI-Powered Features

Our Iterative AI Engine may be used for:

  • Predictive analytics for revenue forecasting and churn prediction
  • Automated billing cycle optimization and payment reminder scheduling
  • Network anomaly detection and performance optimization recommendations
  • Fraud detection and suspicious activity flagging
  • Customer segmentation and service recommendation
  • Automated report generation and business intelligence insights

14.2 Automated Decision-Making Safeguards

  • No fully automated decisions are made that produce legal effects or similarly significant effects on individuals without human oversight
  • Automated fraud detection flags are reviewed by human operators before any account action is taken
  • Tenants retain full control over billing decisions: AI provides recommendations, not binding decisions
  • You have the right to request human review of any automated decision that affects you
  • We do not use Personal Data for automated profiling that results in discrimination based on protected characteristics

14.3 AI Training Data

  • We may use aggregated, anonymized, and de-identified data to train and improve our AI models
  • Individual Tenant or Subscriber data is never used to train AI models that benefit other Tenants without explicit consent
  • AI models are regularly audited for bias and accuracy
  • Tenants may opt out of having their anonymized data used for AI model improvement by contacting us

15. Data Breach Notification

In the event of a Personal Data breach, we will follow a structured notification process in compliance with applicable laws:

15.1 Breach Detection & Response

  • We maintain 24/7 security monitoring and automated breach detection systems
  • Upon detecting a potential breach, our incident response team is immediately activated
  • We will contain the breach, assess its scope and impact, and begin remediation
  • All breach incidents are documented with detailed timelines and impact assessments

15.2 Notification to Authorities

  • We will notify the relevant supervisory authority (including the Kenya ODPC, ICO, or applicable EU supervisory authority) within seventy-two (72) hours of becoming aware of a breach that poses a risk to individuals' rights and freedoms
  • The notification will include the nature of the breach, categories and approximate number of affected individuals, likely consequences, and measures taken to address the breach

15.3 Notification to Affected Parties

  • We will notify affected Tenants without undue delay when a breach affects their data or their Subscribers' data
  • Where a breach is likely to result in a high risk to individuals' rights and freedoms, we will notify affected individuals directly
  • Notifications will include a description of the breach, the data affected, steps we are taking, and recommendations for protective measures
  • Tenants are responsible for notifying their own Subscribers as required by applicable law, and we will assist them in doing so

15.4 Post-Breach Measures

  • We will conduct a thorough post-incident review to identify root causes and prevent recurrence
  • Security measures will be updated based on lessons learned
  • Affected parties will be kept informed of remediation progress
  • We maintain cyber insurance to help cover costs associated with data breaches

16. Limitation of Liability

To the maximum extent permitted by applicable law:

  • Iterative Billing shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, business opportunities, goodwill, or other intangible losses, arising out of or in connection with your use of the Platform or any breach of this Privacy Policy.
  • Our total aggregate liability for any claims arising under or related to this Privacy Policy shall not exceed the greater of: (a) the total fees paid by you to Iterative Billing in the twelve (12) months preceding the event giving rise to the claim, or (b) one hundred United States dollars (USD $100).
  • We shall not be liable for any unauthorized access to, alteration of, or destruction of your data resulting from: (i) your failure to maintain the security of your account credentials; (ii) your failure to implement recommended security measures; (iii) actions of third parties beyond our reasonable control; or (iv) force majeure events including natural disasters, war, terrorism, pandemics, government actions, or failures of third-party infrastructure.
  • We shall not be liable for the privacy practices, data handling, or security measures of our Tenants. Each Tenant is independently responsible for their compliance with applicable privacy laws regarding their Subscribers' data.
  • We shall not be liable for any data loss or corruption resulting from Tenant misuse of the Platform, including but not limited to improper API usage, unauthorized modifications, or failure to maintain adequate backups.
  • The limitations in this section apply regardless of the legal theory upon which the claim is based, whether in contract, tort (including negligence), strict liability, or otherwise, even if we have been advised of the possibility of such damages.
  • Some jurisdictions do not allow the exclusion or limitation of certain damages. In such jurisdictions, our liability shall be limited to the maximum extent permitted by law.

17. Indemnification

By using the Platform, you agree to indemnify, defend, and hold harmless Iterative Billing, its officers, directors, employees, agents, affiliates, successors, and assigns from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees and court costs) arising out of or related to:

  • Your use or misuse of the Platform, including any data you submit, store, or process through the Platform
  • Your violation of this Privacy Policy, our Terms of Service, or any applicable law or regulation
  • Your violation of any third party's rights, including intellectual property rights and privacy rights
  • Any claim by a third party (including your Subscribers or End Users) arising from your data collection, processing, or privacy practices
  • Your failure to obtain necessary consents from your Subscribers or End Users for the collection and processing of their Personal Data
  • Any regulatory action, fine, or penalty imposed on Iterative Billing as a result of your non-compliance with applicable data protection laws
  • Any unauthorized access to the Platform resulting from your failure to maintain the security of your account credentials or to implement recommended security measures
  • Any data breach or security incident caused by your actions, omissions, or negligence

This indemnification obligation shall survive the termination of your account and this Privacy Policy. We reserve the right to assume exclusive defense and control of any matter subject to indemnification by you, at your expense. You agree to cooperate with our defense of such claims.

18. Dispute Resolution & Governing Law

18.1 Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of Kenya, without regard to its conflict of law provisions. For Users located in the European Economic Area, nothing in this section shall deprive you of the protection afforded by mandatory provisions of the law of your country of residence.

18.2 Informal Resolution

Before initiating any formal dispute resolution proceedings, you agree to first contact us and attempt to resolve the dispute informally. We will endeavor to resolve any complaint or dispute within thirty (30) days of receipt.

18.3 Arbitration

Any dispute, controversy, or claim arising out of or relating to this Privacy Policy that cannot be resolved informally shall be settled by binding arbitration administered in Nairobi, Kenya, in accordance with the Arbitration Act of Kenya. The arbitration shall be conducted by a single arbitrator mutually agreed upon by the parties. The language of arbitration shall be English. The arbitrator's decision shall be final and binding.

18.4 Class Action Waiver

To the maximum extent permitted by applicable law, you agree that any dispute resolution proceedings will be conducted only on an individual basis and not in a class, consolidated, or representative action. If this class action waiver is found to be unenforceable, then the entirety of this arbitration provision shall be null and void with respect to such claim.

18.5 Jurisdiction

For any matters not subject to arbitration, you consent to the exclusive jurisdiction of the courts located in Nairobi, Kenya. Notwithstanding the foregoing, we may seek injunctive or other equitable relief in any court of competent jurisdiction to prevent the actual or threatened infringement, misappropriation, or violation of our rights.

18.6 Regulatory Complaints

Nothing in this section prevents you from lodging a complaint with the relevant data protection authority in your jurisdiction, including:

  • The Office of the Data Protection Commissioner (ODPC) in Kenya
  • Your local EU/EEA supervisory authority under the GDPR
  • The Information Commissioner's Office (ICO) in the United Kingdom
  • The California Attorney General under the CCPA/CPRA

19. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors:

  • We will post the updated Privacy Policy on this page with a revised "Last Updated" date
  • For material changes that significantly affect how we handle your Personal Data, we will provide prominent notice through the Platform dashboard, email notification, or other appropriate means at least thirty (30) days before the changes take effect
  • Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Privacy Policy
  • If you do not agree with the updated Privacy Policy, you must discontinue use of the Platform and may request deletion of your data in accordance with Section 9
  • We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data
  • Previous versions of this Privacy Policy are available upon request

20. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through any of the following channels:

Iterative Billing · Data Protection Team

General Support

[email protected]

Response Time

Within 48 hours for privacy inquiries

For data subject access requests, please include sufficient information to verify your identity and specify the rights you wish to exercise. We may request additional verification before processing your request.

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction as outlined in Section 18.6.

This Privacy Policy constitutes a legally binding agreement between you and Iterative Billing. By accessing or using our Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree to this Privacy Policy, you must not access or use the Platform.

© 2026 Iterative Billing. All rights reserved.