PRIVACY POLICY
Data Controller: Melian Dialogue Limited (the "Company", "we", "us", or "our") Jurisdiction of Incorporation: Republic of Kenya Registered Office: P.O. Box B1003, Urban Oasis Apartments, Kingara Road, Lavington, Nairobi Company Registration No.: PVT-27ULY98K KRA PIN: P052416974R Primary Contact Email: info@meliandialogue.com Data Protection Contact: privacy@meliandialogue.com Effective Date: 25 February 2026 Version: 1.3 — Current Configuration
Current Configuration Note (Feb 2026)
As of February 2026 the Platform operates with the following practical consequences for personal data:
- Hosting. The Platform is hosted end-to-end on the Emergent managed platform-as-a-service. No independent third-party IaaS provider (AWS, GCP, Azure, or otherwise) is directly contracted by the Company; all cloud infrastructure is procured and administered by Emergent on the Company's behalf under a written data-processing addendum.
- Payments. No third-party payment processor is integrated. Individuals never pay; institutional subscriptions settle by direct bank transfer to Melian Dialogue Limited's Kenyan bank account and are verified manually by an authorised administrator. No card details, mobile-money credentials, or tokenised payment identifiers are handled by any third party on behalf of the Company.
- Communications. No third-party email or SMS gateway is integrated. Transactional and notification communications are delivered exclusively via the in-app notification bell and in-app inbox.
- Authentication. Users authenticate via either (a) email + password with ten (10) single-use recovery codes issued at registration, or (b) Google Sign-In routed through Emergent-managed Google OAuth. No other third-party OAuth / social sign-in provider is integrated.
- KYC / identity verification. No facial-recognition or document-upload KYC step is applied to any user tier. Institutional identity is verified once, out of band, via the licensed institution's uploaded CMA licence or MoE Certificate of Registration reviewed by an authorised administrator.
- Analytics. Vendors listed in Section 6.4 remain reserved and are activated only for Users who affirmatively opt in via the cookie preferences panel.
Retained third-party integrations at this time are limited to (i) the Emergent-managed universal AI service that powers the AI Trading Assistant, (ii) Emergent-managed Google OAuth for optional social sign-in, and (iii) the Emergent-managed hosting environment.
1. Introduction and Scope
This Privacy Policy (the "Policy") governs the manner in which Melian Dialogue Limited collects, processes, stores, discloses, and otherwise handles Personal Data of natural persons who access, register with, or otherwise use the Melian Dialogue platform, including any associated mobile progressive web applications, application programming interfaces, marketing sites, and related digital properties (collectively, the "Platform").
The Company is registered with the Office of the Data Protection Commissioner of Kenya as a Data Controller pursuant to Section 18 of the Kenya Data Protection Act, 2019 (the "KDPA"). Where applicable, we additionally comply with (i) the European Union General Data Protection Regulation 2016/679 ("GDPR"), (ii) the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act ("CCPA/CPRA"), (iii) the Kenya Consumer Protection Act, 2012, and (iv) the National Payment System Act, 2011 and related regulations of the Central Bank of Kenya ("CBK").
By accessing or using the Platform, the User (as defined below) acknowledges having read, understood, and agreed to this Policy.
The Platform serves three categories of Users, each of whom is subject to this Policy:
- Individual Users — natural persons who register directly for personal use.
- CMA-Regulated Institutional Users — bodies corporate licensed by the Capital Markets Authority of Kenya, together with the individual clients or authorised representatives whom they onboard onto the Platform under the Institutional Subscription. Institutional identity is verified via the uploaded CMA licence reviewed by an authorised administrator. No facial-recognition or document-upload KYC is applied to institutional users or to the individuals they onboard.
- Ministry-of-Education Institutional Users — educational institutions holding a valid Certificate of Registration issued by the Ministry of Education of the Republic of Kenya, together with the individual faculty, staff, or students they onboard for pedagogical purposes. Institutional identity is verified via the uploaded MoE Certificate of Registration reviewed by an authorised administrator. No facial-recognition or document-upload KYC is applied.
2. Definitions
- "Personal Data" has the meaning ascribed to it in Section 2 of the KDPA and Article 4(1) of the GDPR, being any information relating to an identified or identifiable natural person.
- "Sensitive Personal Data" has the meaning ascribed to it in Section 2 of the KDPA and Article 9(1) of the GDPR.
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means.
- "Data Subject" or "User" means the natural person to whom the Personal Data relates.
- "Data Processor" means any third party that processes Personal Data on behalf of the Company.
3. Categories of Personal Data Collected
The Company collects the following categories of Personal Data:
3.1 Identity and Contact Data
Full legal names; preferred display names; email address; mobile telephone number; and, where the User is an authorised representative of a CMA-regulated brokerage or a Ministry-of-Education institution, the identifying particulars of that institution as they appear on its uploaded regulatory licence or certificate of registration. No national identification number, KRA PIN, passport number, or other personal government-issued identifier is collected from any User at this time.
3.2 Account and Authentication Data
Encrypted password credentials (bcrypt); ten (10) single-use recovery codes issued to the User at registration and stored in hashed form; JWT session identifiers delivered via httpOnly cookies. Users may alternatively authenticate via Emergent-managed Google Sign-In, in which case only the OAuth-provided subject identifier, verified email, and display name are received by the Company. No other third-party OAuth / SSO provider is integrated.
3.3 Transactional and Financial Data
Subscription tier history; billing cycle records; invoice numbers; bank-transfer references submitted by institutional subscribers; virtual trading account balances; simulated trade history; leaderboard positions. For the avoidance of doubt, the Company does not collect, hold, or retain any full primary account numbers ("PANs"), Card Verification Values ("CVV"), M-Pesa PINs, mobile-money credentials, or any equivalent raw payment credential; individuals do not pay for the Platform and no card-processor or mobile-money integration is active.
3.4 Technical and Device Data
Internet Protocol ("IP") address; anonymised device fingerprints; operating system and version; browser type, version, and configuration; screen resolution; approximate geolocation (city / region granularity) derived from IP; time zone; language preferences; PWA installation status; service worker cache identifiers.
3.5 Usage and Behavioural Data
Pages viewed; features accessed; simulated trades executed; lesson completion telemetry; time-on-page; click paths; A/B test cohort assignments; referrer URLs; UTM campaign parameters.
3.6 Communications Data
Messages exchanged via the in-platform chat widget; support ticket contents; email correspondence sent to the Company; contact-form submissions; feedback surveys.
3.7 Marketing Preferences
In-app notification preferences; digest opt-in status; referral programme participation records. No SMS-marketing or email-marketing gateway is currently active.
3.8 Behavioural Micro-Interaction Telemetry (research + system tuning)
Where the User has affirmatively opted in via the Telemetry Consent Modal (surfaced on first login and revocable at any time under Settings › Preferences), the Platform collects and stores in the user_behavioral_telemetry collection a bounded set of timing and geometric micro-interaction signals used to compute the Platform's proprietary cognitive-friction score (Phi_cog) and Behavioral Alpha (alpha_beh) metrics. Specifically:
- Keystroke flight-time deltas (millisecond intervals between key-down events; individual key identities and content are NOT captured).
- Deletion-burst counts (number of Backspace/Delete presses in a 500-millisecond rolling window; content deleted is NOT captured).
- Cursor velocity variance (500-ms sliding window over pointer geometry; individual mouse coordinates are NOT retained after the window is closed).
- Click cadence and focus / blur transitions on top-level containers (page identity is NOT associated with the sample).
Every batch is (i) debounced client-side, (ii) sanitised of any accidentally-captured character content, (iii) hashed with SHA-256 at the boundary before persistence, (iv) subject to a 7-day time-to-live on the underlying collection index, and (v) aggregated into a 60-minute rolling per-user rollup that is what the Fatigue and Tilt cognitive layers actually read. The raw signals never leave the Company's infrastructure. The User's explicit consent constitutes the legal basis for this Processing under Section 30 of the Kenya Data Protection Act, 2019 and Article 6(1)(a) of the GDPR, and consent may be withdrawn at any time without affecting the lawfulness of Processing that took place before withdrawal.
4. Legal Bases for Processing
The Company processes Personal Data solely on one or more of the following lawful bases as recognised under Section 30 of the KDPA and Article 6(1) of the GDPR:
4.1 Consent (KDPA s.30(a); GDPR Art.6(1)(a))
Where the User has given clear, affirmative, informed, and specific consent — for example, when opting into in-app notification categories, accepting non-essential cookies, or granting the AI Trading Assistant permission to read the User's live portfolio context.
4.2 Contractual Necessity (KDPA s.30(b); GDPR Art.6(1)(b))
Processing necessary for the performance of the Terms of Service to which the User is a party, including but not limited to account creation, verification of institutional bank transfers, delivery of the trading simulation engine, and transmission of in-app transactional notifications.
4.3 Legal Obligation (KDPA s.30(c); GDPR Art.6(1)(c))
Processing required to comply with legal obligations to which the Company is subject, including tax reporting to the Kenya Revenue Authority and lawful requests from Kenyan regulatory or law-enforcement authorities.
4.4 Legitimate Interests (KDPA s.30(f); GDPR Art.6(1)(f))
Processing necessary for the legitimate business interests of the Company, including fraud prevention, network and information security, product analytics, service improvement, and the enforcement of the Company's rights — provided such interests are not overridden by the fundamental rights and freedoms of the User.
4.5 Vital Interests and Public Interest
Where processing is necessary to protect the vital interests of a natural person, or to perform a task carried out in the public interest, in each case as recognised under Section 30 of the KDPA.
5. Purposes of Processing
The Company processes Personal Data for the following purposes only:
(i) to authenticate the User and administer their account; (ii) to deliver the trading simulation, community, copy-trading, and market intelligence features of the Platform; (iii) to process subscription payments and issue receipts and invoices; (iv) to enforce the Terms of Service, protect against fraud, abuse, and prohibited activities; (v) to comply with legal, regulatory, and audit obligations under Kenyan law; (vi) to communicate transactional, security, and service-status notifications; (vii) to send marketing communications where consented; (viii) to conduct internal research and product analytics; (ix) to respond to Data Subject Access Requests and other rights requests.
Personal Data shall not be further processed in a manner incompatible with these purposes.
6. Data Sharing and Third-Party Disclosures
The Company shares Personal Data only with the categories of recipients listed below, in each case pursuant to a written data processing agreement compliant with Section 42 of the KDPA and, where applicable, Article 28 of the GDPR:
6.1 Payment Processors
None integrated. Institutional subscriptions are paid by direct bank transfer from the institution's account to Melian Dialogue Limited's Kenyan operational account; the details of the transfer are shared only with the receiving Kenyan commercial bank as part of ordinary interbank settlement. No card processor, mobile-money processor, or online payment gateway of any kind is integrated with the Platform.
6.2 Cloud Infrastructure and Hosting Providers
The Platform is hosted on the Emergent managed platform-as-a-service. All underlying cloud infrastructure — compute, database, object storage, content delivery, and networking — is procured and administered by Emergent on the Company's behalf under a written data-processing addendum. The Company does not directly contract with any independent IaaS provider (AWS, GCP, Azure, or otherwise).
6.3 Communications and Delivery Providers
None integrated. All User-facing communications are delivered exclusively via the in-app notification bell and in-app inbox. No third-party email gateway, SMS gateway, WhatsApp gateway, or push-notification vendor is integrated with the Platform.
6.4 Analytics and Product Instrumentation
- Google Analytics (via consent-managed loader — inactive until the User opts in via the cookie preferences panel)
- PostHog (product analytics — inactive until the User opts in via the cookie preferences panel)
6.5 AI Model Provider
- The Company uses an Emergent-managed universal AI service, accessed via a single managed API key, solely to power the institutional-tier AI Trading Assistant. Prompt payloads that include portfolio context are limited to the requesting institutional User's own book, are transmitted over TLS, and are not used by the AI service provider to train foundation models pursuant to the Emergent-managed data-processing addendum.
6.6 Regulatory and Governmental Authorities
The Company may disclose Personal Data to the ODPC, CBK, Kenya Revenue Authority, Capital Markets Authority, Financial Reporting Centre, the Judiciary of Kenya, or any competent regulatory or law-enforcement authority, but only pursuant to a validly issued order, subpoena, warrant, or lawful demand under Kenyan or applicable foreign law.
6.7 Professional Advisers and Corporate Transactions
The Company may disclose Personal Data to its auditors, legal counsel, and, in the context of a merger, acquisition, restructuring, or sale of substantially all assets, to any successor entity, subject to equivalent confidentiality and data-protection obligations.
The Company does not sell Personal Data as that term is defined in the CCPA/CPRA.
7. International Data Transfers
Where Personal Data is transferred outside the Republic of Kenya to a jurisdiction that has not been declared to offer adequate protection pursuant to Section 48 of the KDPA, the Company relies on one or more of the following safeguards:
(i) Standard Contractual Clauses ("SCCs") approved by the European Commission (Commission Implementing Decision (EU) 2021/914) or their equivalent adopted by the ODPC; (ii) Binding Corporate Rules of the recipient, where such rules have been approved by the competent supervisory authority; (iii) Explicit informed consent of the Data Subject, obtained in advance, to the specific transfer; (iv) Any derogation permitted under Section 49 of the KDPA or Article 49 of the GDPR.
A copy of the executed SCCs applicable to a specific transfer will be made available on written request to info@meliandialogue.com, subject to redaction of commercially sensitive terms.
8. Data Retention
Personal Data shall be retained only for so long as is necessary for the purpose for which it was collected, or as required by applicable law:
- Account and profile data: for the duration of the account and for seven (7) years following account closure, in line with retention obligations under the Kenya Companies Act, 2015 and the Tax Procedures Act, 2015.
- Transactional and payment data: seven (7) years from the date of the transaction.
- Authentication logs, security event logs, and IP address logs: eighteen (18) months.
- Marketing consent records: until consent is withdrawn plus twelve (12) months.
- Support ticket and chat records: three (3) years from case closure.
Upon expiry of the applicable retention period, Personal Data shall be securely deleted or irreversibly anonymised.
9. Data Subject Rights
Users have the following rights under Part V of the KDPA and Chapter III of the GDPR:
9.1 Right of Access
The right to obtain confirmation as to whether Personal Data concerning the User is being processed and, where so, a copy of such data and information about the processing.
9.2 Right to Rectification
The right to have inaccurate Personal Data corrected without undue delay and to have incomplete data completed.
9.3 Right to Erasure ("Right to be Forgotten")
The right to have Personal Data erased where the data is no longer necessary for the purposes for which it was collected, where consent is withdrawn, or where processing was unlawful. This right is subject to legal and regulatory retention obligations.
9.4 Right to Restrict Processing
The right to obtain a temporary restriction on processing pending verification of the accuracy of the data or the legitimacy of the processing.
9.5 Right to Data Portability
The right to receive the Personal Data provided to the Company in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
9.6 Right to Object
The right to object at any time to processing based on legitimate interests, including profiling, and to object to processing for direct marketing purposes.
9.7 Right to Withdraw Consent
Where processing is based on consent, the User may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
9.8 Right to Lodge a Complaint
The User has the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya (odpc.go.ke), or with the supervisory authority of their habitual residence within the European Economic Area, or with the California Privacy Protection Agency (cppa.ca.gov) where applicable.
9.9 Exercising Rights — Operational Instructions
All rights requests must be directed to info@meliandialogue.com with:
(i) the subject line "Data Subject Rights Request — [Type of Request]"; (ii) the User's registered email address; (iii) sufficient information to verify the User's identity (which may include a request for further authentication in accordance with Section 34 of the KDPA); (iv) a clear statement of the right being exercised and the scope of the request.
The Company shall respond to a valid request without undue delay and in any event within thirty (30) calendar days of receipt of a verified request, as required by Section 26 of the KDPA. Where the request is complex or numerous, this period may be extended by up to two (2) further months, with prior notification to the User.
10. Security of Processing
The Company implements technical and organisational measures appropriate to the risk, in accordance with Section 41 of the KDPA and Article 32 of the GDPR, including without limitation: encryption in transit (TLS 1.2 or higher); encryption at rest for sensitive fields; hashed password storage using industry-standard adaptive algorithms; role-based access control; principle of least privilege; audit logging; regular security assessments; secure software development lifecycle practices; and incident-response procedures.
11. Data Breach Notification
In the event of a Personal Data breach likely to result in a risk to the rights and freedoms of Data Subjects, the Company shall notify the ODPC within seventy-two (72) hours of becoming aware of the breach, in accordance with Section 43 of the KDPA. Where the breach is likely to result in a high risk, affected Data Subjects shall be notified without undue delay.
12. Children
The Platform is not directed to persons under the age of eighteen (18). The Company does not knowingly collect Personal Data from minors. Where the Company becomes aware that such data has been collected, it shall delete the data forthwith.
13. Automated Decision-Making
The Platform does not subject Users to solely automated decisions producing legal or similarly significant effects, save for automated fraud-scoring of transactions and automated feature-gating based on subscription tier, in each case with human review available upon written request.
14. Changes to this Policy
The Company reserves the right to amend this Policy from time to time. Material changes will be notified to Users by email and by prominent notice on the Platform not less than fourteen (14) days prior to taking effect.
15. Contact and Data Protection Officer
Data Protection Officer / Contact Person: Dr Jim Coke Email: info@meliandialogue.com Postal Address: P.O. Box B1003, Urban Oasis Apartments, Kingara Road, Lavington, Nairobi, Republic of Kenya
This Privacy Policy is issued in the English language, which shall be the controlling language for all interpretation purposes.