Skip to content
PennyPay
Platform
How it worksSignals in, decision out The four modulesRisk, Graph, Decision, Investigate Graph intelligenceEntity relationships and clusters ArchitectureGPU feature processing and inference ExplainabilityThe reason behind every score
Solutions
BanksTransaction fraud and account takeover NeobanksAPI decisioning and device intelligence Digital walletsPeer-to-peer fraud and mule networks Payment platformsMerchant and recipient risk
Developers
The APIOne call, scored before the payment completes Live consoleThe operations console on synthetic data
Company
PartnersThe partnership programme and what it exchanges SecurityImplemented, in progress and planned
About us
Console Start an evaluation
Legal

Privacy policy

Last updated 26 August 2026 Version 1.0 Applies to this website and the console

The short version

  • The only personal data this site collects is what you type into the evaluation form. Nothing else asks you for anything.
  • There are no cookies, no analytics, no tracking pixels and no advertising on this site. We are not counting you.
  • The console at demo.html runs entirely in your browser on invented data. Nothing you click there leaves your machine.
  • Transaction data belonging to a financial institution is a different matter, governed by a separate agreement rather than this page. The last section explains the split.

This summary is here to be useful, not to be relied on. The numbered sections below are the policy.

What the form collects What happens when you browse The console Why we process it Who else sees it Where it goes How long we keep it How it is protected Data we hold for institutions

What the form collects

One form on this site asks you for anything: the evaluation request at the foot of the home page. It collects exactly five things, and they are the five fields you can see:

  • Name — so a reply is addressed to a person
  • Work email — so there is somewhere to send it
  • Institution — so we know who is asking
  • Institution type — bank, neobank, digital wallet, payment platform or other
  • What you want to test — optional free text, and whatever you choose to put in it

There are no hidden fields. We do not append a device fingerprint, a referrer, a marketing identifier or an enrichment lookup against your email address.

Depending on configuration, the form either posts to our own endpoint or opens a message in your email client with those fields filled in. In the second case the message travels through your employer’s mail system before it reaches us, under their policies rather than ours, and you can edit or discard it before it sends.

What happens when you browse

No cookies, no analytics

This site sets no cookies, writes nothing to local storage, and carries no analytics, heatmap, session-replay or advertising script. There is no consent banner because there is nothing to consent to. That is a statement about the site as it exists on the date at the top of this page; if it changes, this policy changes with it and that date moves.

Server logs

Our hosting provider records ordinary web server logs — IP address, timestamp, the file requested, the response code, and the user-agent string your browser sends. These are generated by the act of serving a page and are used only to keep the site running and to investigate abuse or faults.

Google Fonts

Three typefaces are loaded from fonts.googleapis.com and fonts.gstatic.com. Your browser makes that request directly, which discloses your IP address and user-agent to Google under its own terms. We receive nothing from it and cannot see who requested what. A content blocker will prevent the request, and the site falls back to your system fonts without breaking.

Links we do not control

Several sections link to outside sources — a regulator, a central bank, a research paper. Following one takes you to a site with its own policy, and this one stops applying at that point.

The console

The operations console at demo.html contains no real data and collects none. Every transaction, customer name, account, device and risk score in it is generated in your browser from a fixed seed, which is why it looks the same each time you open it.

Filtering, searching, opening an investigation and pressing the action buttons all happen locally. None of it is transmitted, logged or stored, and closing the tab discards it.

Why we process it, and on what basis

  • To answer you. When you submit the form you are asking us to get in touch, and we process what you sent in order to do that. Basis: your consent, and performance of steps taken at your request.
  • To run an evaluation. If a request becomes an actual engagement, the same details are used to organise it and to draw up the agreement covering it. Basis: steps taken prior to entering a contract.
  • To keep the site working and secure. Server logs are used to diagnose faults and identify abuse. Basis: our legitimate interest in operating a service that works and is not being attacked.
  • To meet a legal obligation. Where a law requires us to retain or produce something, we comply with it.

We do not use anything collected here for automated decision-making or profiling about you, and we do not sell it, rent it, or trade it. That last sentence appears in most privacy policies. In ours it is straightforward, because we have no advertising business and nothing to sell you into.

Who else sees it

Personal data from this site is shared only with:

  • Our hosting and email providers, which necessarily handle it in the course of serving pages and delivering mail on our behalf
  • The form endpoint, if the form is configured to post to a third-party form service rather than to our own infrastructure
  • Professional advisers, where we are obliged to take advice on something
  • A public authority, where the law requires disclosure and we have satisfied ourselves that it does

Each provider acts on our instructions under a written agreement and cannot use your data for its own purposes. We do not share anything with advertising networks or data brokers, because we use neither.

Where it goes

Our providers may store or process data outside Kenya, which makes those transfers subject to Part VI of the Data Protection Act. Where that happens we rely on the safeguards the Act permits — appropriate contractual protections and, where required, your consent — and we will name the destinations on request rather than describing them vaguely here.

How long we keep it

  • Form submissions that go nowhere: deleted within 24 months of the last contact.
  • Correspondence that becomes an engagement: retained for the life of the relationship and then for as long as the relevant limitation period requires.
  • Server logs: retained on the hosting provider’s ordinary cycle, typically no more than 90 days.

If you want something deleted sooner than that, ask us through the form on the home page.

How it is protected

The site is served over HTTPS, access to anything submitted through it is limited to the people who need it, and that access is authenticated. The security section on the home page is candid about which of our broader controls are implemented today, which are in progress, and which are planned, and we would rather point you at that than imply more here.

No one can promise that a transmission over the internet is completely secure, and we are not going to be the first to try.

Data we hold for institutions

Where a financial institution runs an evaluation or a deployment with us, we process transaction and customer data belonging to that institution. In that relationship the institution is the data controller and PennyPay is a data processor acting on its documented instructions.

That processing is governed by the data processing agreement signed with the institution, not by this policy, and that agreement sets the purposes, retention, security measures, sub-processors and deletion terms. This page cannot vary it.

If you are an individual customer of a bank or wallet and believe your transaction may have been scored by us, your route is through that institution: it holds the relationship with you and decides what happens to your data. Tell us and we will pass it on, but we cannot act on it directly.
PennyPay

Real-time financial risk intelligence for institutions moving money instantly.

Platform

How it worksThe four modulesGraph intelligenceArchitectureExplainability

Solutions

BanksNeobanksDigital walletsPayment platforms

Developers

The APILive console

Company

About usPartnersSecurity

© 2026 PennyPay · Financial Risk Intelligence · All product interfaces and figures shown on this site use demonstration data.

Privacy · Nairobi, Kenya