At BestIPTV Kenya (“Company,” “we,” “us,” “our”), your privacy is a fundamental priority. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our IPTV subscription service, website, and mobile applications (collectively, the “Service”).
We process your data in accordance with the Data Protection Act, 2019 (No. 24 of 2019) of Kenya . By subscribing to or using our Service, you acknowledge that you have read and understood this policy.
BestIPTV Kenya is the “Data Controller” responsible for your personal data. This means we determine the purposes and means of processing your personal information . We are registered with the Office of the Data Protection Commissioner (ODPC) as required by Kenyan law .
We collect information to provide and improve our services, process your payments, and comply with Kenyan legal requirements .
When you register, purchase a subscription, or contact support, we may collect:
Identity Information: Full name, username, or similar identifier.
Contact Data: Email address, phone number (required for M-Pesa transactions), and billing address.
Payment Information: M-Pesa transaction codes and payment dates. Note: We do not store your M-Pesa PIN or full credit card details; these are processed securely by our third-party payment gateways.
Communication Data: Any information you provide when you contact our customer support team.
When you access our Service, we may automatically collect:
Device Information: IP address, device type (e.g., Smart TV, Android phone), unique device identifiers, operating system, and browser type .
Log Data: Information about your service usage, such as the channels you watch, streaming quality, time of access, and duration of streams.
Troubleshooting Data: Diagnostic data related to buffering or connection errors to help us improve service stability.
We may receive information from payment processors (like Safaricom M-Pesa) to confirm your payment status.
Under the Data Protection Act, 2019, we must have a lawful basis to process your data . We rely on the following bases:
Contractual Necessity: To provide you with the IPTV service you subscribed to (e.g., activating your account, verifying your login) .
Legal Obligation: To comply with Kenyan laws, including the Kenya Information and Communications Act (e.g., maintaining subscriber records for regulatory purposes) .
Legitimate Interests: To improve our service, monitor network performance, and prevent fraud, provided these interests are not overridden by your privacy rights.
Consent: Where we ask for your permission to send you marketing offers, you may withdraw this consent at any time .
We use the information we collect for the following purposes :
To Provide the Service: Authenticating your account, delivering live TV and VOD content, and ensuring the service functions correctly on your device.
To Process Payments: Confirming receipt of your subscription fees and managing billing cycles.
To Communicate with You: Sending service updates, technical support responses, and important notices regarding changes to our terms or policies.
To Improve and Analyze: Monitoring usage trends to understand which content is popular and to fix technical bugs (buffering issues, app crashes).
To Comply with Law: Maintaining subscriber records as required by the Communications Authority of Kenya for security and consumer protection .
We do not sell your personal data. However, we may share your information in the following specific situations :
Service Providers (Data Processors): We engage trusted third-party companies to help us run our business, such as:
Cloud hosting providers (to store our content and databases).
Payment gateways (to process M-Pesa and card payments).
Analytics providers (to help us understand app performance).
These providers are contractually obligated to process your data only on our instructions and to protect it securely.
Legal Requirements: We may disclose your information if required to do so by Kenyan law or in response to a valid request from public authorities (e.g., a court order or request from the Communications Authority of Kenya) .
Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new entity, subject to this Privacy Policy remaining in effect.
We take the security of your data seriously and implement appropriate technical and organizational measures to protect it from unauthorized access, alteration, disclosure, or destruction . These include:
Encryption: We use encryption protocols (such as SSL/TLS) to secure data transmitted between your device and our servers.
Access Controls: Only authorized personnel with a legitimate need have access to your personal data.
Regular Audits: We conduct periodic reviews of our data collection, storage, and processing practices.
While we strive to use commercially acceptable means to protect your data, no method of transmission over the Internet is 100% secure .
We will retain your personal data only for as long as is necessary to fulfill the purposes outlined in this policy :
Active Accounts: For as long as you maintain an active subscription.
Inactive Accounts: If your account is inactive, we may retain your data for a period consistent with legal requirements (e.g., up to [Insert Number] years to comply with tax or audit laws).
Legal Holds: We may retain data longer if required to comply with a legal obligation, resolve disputes, or enforce our agreements.
Under the Data Protection Act, 2019, you have specific rights regarding your personal data . You have the right to:
Be Informed: To know what data we collect and how we use it (this policy serves that purpose).
Access: Request a copy of the personal data we hold about you .
Rectification: Request that we correct any inaccurate or incomplete data .
Erasure (Right to be Forgotten): Request that we delete your personal data, subject to certain legal exceptions (e.g., if we need to keep it for fraud prevention or legal compliance) .
Restriction of Processing: Request that we stop processing your data in certain ways.
Data Portability: Request that we transfer your data to another service provider in a structured, commonly used format .
Object: Object to processing based on legitimate interests or for direct marketing.
Withdraw Consent: Where processing is based on consent, you have the right to withdraw it at any time .
How to Exercise Your Rights:
To exercise any of these rights, please contact us using the details in Section 12. We will respond to your request within a reasonable timeframe and in accordance with the law .
Protecting children’s privacy is critical .
Our Service is not directed at individuals under the age of 18.
We do not knowingly collect personal data from children without verifiable parental consent.
If you are a parent or guardian and believe your child has provided us with information without your consent, please contact us immediately. We will take steps to delete such information .
In line with the Kenya Information and Communications (Registration of Telecommunications Service Subscribers) Regulations, 2025, any subscription for a minor must be registered by a parent or guardian .
We have implemented measures to detect and respond to personal data breaches. In the unfortunate event of a data breach that poses a risk to your rights and freedoms:
We will notify the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware of the breach, as required by law .
If the breach is likely to result in a high risk to your rights, we will also communicate the breach to you (the data subject) directly .
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or industry standards . When we make changes, we will update the “Last Updated” date at the top of this policy.
If we make material changes, we will notify you through a prominent notice on our website or via email .
We encourage you to review this policy periodically to stay informed about how we are protecting your information.
If you have any questions about this Privacy Policy, wish to exercise your rights, or wish to lodge a complaint, please contact us.