Contents
- 1. Introduction
- 2. Who is the controller
- 3. Data we collect
- 4. How we use it
- 5. Legal basis
- 6. Who we share with
- 7. Sub-processors
- 8. International transfers
- 9. Retention
- 10. Security
- 11. End-to-end encryption
- 12. Lawful access & escrow
- 13. Your rights
- 14. How to exercise them
- 15. Cookies & analytics
- 16. Children
- 17. AI & automated decisions
- 18. Breach notification
- 19. Changes
- 20. Contact & complaints
1. Introduction
This Privacy Policy explains how Lilos Dynamics ("boukd", "we") collects, uses, shares and protects information about you when you use the boukd mobile and web apps, our APIs and our related services (the "Service"). It applies alongside our Terms of Service and any product-specific notices we show you in-app.
Where the Kenya Data Protection Act, 2019 (the "DPA") and equivalent laws apply (e.g. the GDPR for users in the European Economic Area, the UK GDPR for users in the United Kingdom, NDPR for users in Nigeria), we have designed our practices to meet the higher of the two standards.
2. Who is the controller
Lilos Dynamics is the data controller for personal data processed via the Service, except where we expressly act as a data processor on behalf of an Agency or Bookable workspace using our enterprise tools - in which case our customer is the controller and our processing is governed by a separate Data Processing Addendum.
Our Data Protection Officer can be reached at [email protected].
3. Data we collect
| Category | Examples | Source |
|---|---|---|
| Identity & account | First / last name, account type, email, phone (E.164), country code, password hash, profile picture, agency name (if any), date of birth (where required for age-gating). | You, at sign-up. |
| Verification (KYC) | Government ID image, ID number, selfie/liveness video, proof of address, business registration, tax ID, beneficial ownership info, sanctions screening result. | You + verification partners. |
| Bookable profile | Bio, rates, service categories, availability, Studio media, livestream metadata, ratings, reviews. | You. |
| Tribe & social | Who you follow, who follows you, posts, comments, likes, reactions, shares, story views. | You + other Users. |
| Bookings & transactions | Booking details, scheduled times, location (when you choose to share it), prices, taxes, payment method last-4 / mobile-money number, payout method, escrow state, refund history. | You + payment processors. |
| Messaging metadata | Conversation IDs, participant IDs, timestamps, delivery / read receipts, message size, encrypted ciphertext, device public keys. | The Service. |
| Device & network | Device model, OS, app version, locale, time zone, push token, IP address, approximate location derived from IP, crash reports, performance traces. | Your device. |
| Cookies & storage | Session cookies on web, secure key-value storage on mobile (AsyncStorage / Keychain / Keystore). | Your browser / device. |
| Support & safety | Tickets, abuse reports, evidence you submit, decisions, takedown notices. | You + other Users. |
4. How we use it
- Provide the Service - create your account, host your content, deliver messages, run livestreams, match Bookables and tribe members.
- Payments & payouts - process bookings, hold funds in escrow, calculate fees, prevent fraud, run KYC and AML checks, settle taxes.
- Personalisation - sort your feed, suggest Bookables to follow, surface livestreams you might enjoy.
- Safety & integrity - detect spam, harassment, ban evasion, payment fraud, unauthorised access; investigate abuse reports.
- Communication - service announcements, security alerts, OTP codes, receipts, and (where you've opted in) marketing.
- Legal compliance - respond to lawful orders, defend legal claims, exercise or defend our rights.
- Improve boukd - measure performance, debug crashes, run experiments, train safety models on aggregated or properly de-identified signals.
We do not sell your personal data.
5. Legal basis
| Activity | Lawful basis (DPA s.30 / GDPR Art.6) |
|---|---|
| Creating your account, delivering bookings, payments | Performance of a contract |
| KYC / AML, sanctions screening, tax reporting, lawful access | Legal obligation |
| Marketing communications you have opted into | Consent (withdrawable at any time) |
| Security, anti-fraud, abuse moderation, product improvement | Legitimate interests, balanced against your rights |
| Sensitive data (e.g. ID images, biometric liveness) | Substantial public interest / explicit consent under DPA s.46 |
6. Who we share with
- Other Users - public profile fields, posts, livestreams, reviews you publish; the masked destination of your messages where you initiate them.
- Bookables / tribe members in a transaction with you - name, contact details needed to deliver the booking, reviews you've left.
- Sub-processors - see Section 7.
- Payment partners - Safaricom (M-Pesa), card networks, bank rails, mobile-money operators, anti-fraud bureaus.
- Authorities - only on receipt of a binding legal request that we have reviewed and not successfully challenged. See Section 12.
- Acquirers - if boukd is sold, merged or restructured, the buyer will be notified of, and bound by, this Privacy Policy. We will give you notice and a meaningful opportunity to delete your account before any change of controller.
7. Sub-processors
We engage carefully selected sub-processors under written contracts that meet DPA s.42 (and Article 28 GDPR where relevant) requirements. The principal categories at the date of this Policy are:
| Category | Purpose | Region |
|---|---|---|
| Cloud hosting (Cloudflare R2, managed Postgres, Redis) | App hosting, storage, CDN | Global, with primary data plane in EU/Africa where available |
| Payment processing (Safaricom M-Pesa, card networks, mobile-money APIs) | Payments, payouts, refunds | Kenya / region of payment |
| Communications (Gmail SMTP / Resend; Africa's Talking; Twilio) | Transactional email, SMS, OTP | Kenya, EU, US |
| Analytics & crash reporting | Performance, stability | EU / US (privacy-first vendors only) |
| Identity verification | KYC, AML, liveness, sanctions screening | Kenya / EU |
| Customer support | Help desk, ticketing | EU / US |
A current sub-processor list is maintained at boukd.app/legal/sub-processors. We will
give at least thirty (30) days' notice before adding or replacing a sub-processor
that handles your personal data, and you may object on reasonable grounds.
8. International transfers
Where personal data is transferred outside Kenya, we rely on one or more of the safeguards recognised under DPA s.49: explicit consent for the transfer; necessity for performance of the contract with you; standard data protection clauses; binding corporate rules; or transfer to a country with an adequate level of protection. For transfers to the United States we additionally rely on processor-level certifications (e.g. EU-US Data Privacy Framework, ISO 27001, SOC 2).
9. Retention
| Data | Retention | Reason |
|---|---|---|
| Account profile | Life of account + 30 days grace after deletion request | Allow restore on accidental deletion |
| KYC documents | 7 years from end of relationship | Anti-money-laundering regulations |
| Booking & payment records | 7 years | Tax and accounting law |
| Encrypted messages on the server | Until you or the other party delete the conversation, or 365 days for AI-bot conversations, whichever is shorter | Service operation |
| Push tokens, session tokens | Until logout / token expiry | Service operation |
| Server logs | 30 days (90 days for security-relevant logs) | Operations, security |
| Abuse reports & moderation decisions | 3 years from decision | Repeat-offender detection, defence of claims |
After the retention period, we delete or irreversibly anonymise the data. Aggregated, non-identifying statistics may be kept indefinitely for product analytics.
10. Security
- TLS 1.2+ for all network traffic; HSTS on web.
- At-rest encryption (AES-256) on databases and object storage.
- Per-conversation E2EE for Pulse messages (see Section 11).
- HSM-protected keys for the lawful escrow path.
- Argon2id / bcrypt password hashing.
- Two-factor authentication via OTP for sign-in and sensitive actions.
- Role-based access control with quarterly access reviews.
- Vulnerability disclosure programme:
[email protected]PGP available on request
11. End-to-end encryption
Pulse - boukd's messaging fabric - uses X25519 device key pairs, a per-conversation symmetric key wrapped to each participant device, and XChaCha20-Poly1305 authenticated encryption for message envelopes. boukd's servers store ciphertext and a small set of routing metadata (sender, recipient, timestamp). We do not have the plaintext of your messages.
12. Lawful access & escrow
Each per-conversation key is additionally wrapped to an HSM-backed escrow public key. Decryption of the wrapped key is gated by an M-of-N multi-signature ceremony involving independent senior officers. Every approval, denial and key release is recorded in a hash-chained audit log that is reviewable by our independent legal counsel.
We will only invoke this path:
- on receipt of a valid Kenyan court order, ODPC directive, mutual legal assistance request, or equivalent legal process from a competent jurisdiction we have reviewed;
- where required by anti-terrorism, anti-money-laundering or child-safety law that we cannot lawfully challenge; or
- to investigate a clearly suspected, time-critical threat to life - in which case we will seek post-hoc judicial review.
We publish an annual Transparency Report with the number of requests received, how many were challenged, narrowed or refused, and how many resulted in disclosure.
13. Your rights
Under the DPA (and GDPR / UK GDPR where applicable), you have the right to:
- Access a copy of the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data (subject to legal retention obligations such as KYC);
- Restrict certain processing;
- Object to processing based on legitimate interests, including profiling;
- Withdraw consent where processing is based on consent;
- Portability - receive your data in a structured, machine-readable format;
- Lodge a complaint with the Office of the Data Protection Commissioner of Kenya (or your local supervisory authority).
14. How to exercise them
You can exercise most rights directly in-app at Settings to Privacy & data:
- Download my data - generates a portable export.
- Delete my account - schedules deletion after a 30-day grace period.
- Manage notifications & consents - fine-grained marketing toggles.
For anything you cannot do in-app, write to [email protected]. We will verify your
identity and respond within thirty (30) days (extendable by sixty days for complex
requests, with notice). There is no fee unless your request is manifestly unfounded or excessive.
15. Cookies & analytics
On the boukd web app we use a small number of strictly necessary cookies (session, CSRF, locale) and, with your consent, a privacy-first analytics cookie that does not build cross-site profiles of you. On mobile we use platform secure storage (iOS Keychain, Android Keystore, AsyncStorage) to keep you signed in. You can clear these at any time from your browser or device settings.
16. Children
boukd is not intended for children under sixteen (16). We do not knowingly collect personal data from children under 16. If we become aware that we have, we will delete it promptly. Some features (payments, payouts, Tembo, Bookable profiles) are restricted to adults - see Section 3 of the Terms.
17. AI & automated decisions
We use machine-learning systems to rank your feed, recommend Bookables, detect abuse, prevent
fraud, and power the @boukd-bot concierge. Your conversations with the bot may be used
to improve safety classifiers in aggregate; we do not train general-purpose foundation models on
your private messages. Decisions that have a legal or similarly significant effect
on you (account closure, payout freezes lasting more than 7 days, denial of a Tembo loan) include
human review, and you have the right to contest them by writing to [email protected].
18. Breach notification
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Office of the Data Protection Commissioner within 72 hours as required by DPA s.43, and notify affected Users without undue delay where the risk is high.
19. Changes
We may update this Privacy Policy. If a change is material, we will notify you in-app and by email
at least thirty (30) days before it takes effect. Past versions will be available at
boukd.app/legal/privacy-history.
20. Contact & complaints
Lilos Dynamics
Nairobi, Kenya
Data Protection Officer: [email protected]
Privacy & data requests: [email protected]
Security disclosures: [email protected]
If you are not satisfied with our response, you may lodge a complaint with the
Office of the Data Protection Commissioner of Kenya (odpc.go.ke) or
your local supervisory authority.
v1.1 . Effective 30 August 2026 . Document ID: BOUKD-LEGAL-PRIV-0001