Miser logoMiser

Privacy Policy

How Miser handles accountant and client data

Last updated: 19 August 2026

1. Overview

This Privacy Policy explains how Miser collects, uses, shares, stores, and protects information when accountants, firms, clients, and portal users use the Miser platform.

Miser is designed for Kenyan tax compliance, bookkeeping, eTIMS invoicing, document collection, working-paper compilation, reminders, billing, and accountant-led review workflows.

2. Roles under Kenyan data protection law

For firm account information, billing information, product analytics, and platform security data, Miser generally acts as a data controller because we decide how that data is used to operate the service.

For client records uploaded or entered by an accountant, such as KRA PIN details, payroll records, invoices, receipts, statements, tax documents, and filing records, Miser generally acts as a data processor for the accountant or firm, unless the law or a specific feature requires another role.

Accountants and firms are responsible for ensuring that they have a lawful basis, authority, client instructions, or consent where required before placing client data in Miser.

3. Information we collect

  • Account and firm details: names, emails, phone numbers, firm names, roles, KRA agent details, login/session data, and account preferences.
  • Client and taxpayer details: client names, KRA PINs, taxpayer type, obligations, compliance checks, contacts, filing periods, tax schedules, and related notes.
  • Documents and accounting records: invoices, receipts, payroll files, bank statements, M-Pesa statements, spreadsheets, PDFs, images, parsed markdown, extracted tables, working papers, and Google Sheet exports.
  • eTIMS and invoicing data: seller profiles, logos, item catalogues, stock data, invoice drafts, credit notes, OSCU payloads, KRA/GavaConnect responses, and generated PDFs.
  • Payment and billing data: active client counts, billing status, transaction references, invoices, card authorization metadata from payment providers, and access-entitlement checks.
  • Google data: if you connect Google, we may process the minimum Google account, Gmail, Drive, and Sheets data needed to send approved reminders or publish working papers.
  • Technical data: device/browser information, IP address, logs, error reports, security events, API usage, and performance information.

4. How we use information

  • To create and secure accounts, authenticate users, manage firms, and provide the dashboard.
  • To verify clients, request documents, preview files, parse documents, compile working papers, calculate tax-support values, and support accountant review.
  • To generate reminders, notifications, client portal links, Google Sheets, PDFs, invoices, credit notes, and eTIMS/OSCU-related records.
  • To process billing, enforce paid access, prevent abuse, debug errors, improve performance, and maintain audit trails.
  • To comply with legal obligations, security requirements, provider obligations, and legitimate operational needs.

5. AI, parsing, and automation

Miser may send uploaded documents, parsed markdown, extracted tables, prompts, and relevant metadata to AI or document-parsing providers to classify records, extract useful fields, normalize tables, identify warnings, and prepare working papers.

AI is used as an assistant, not as the final professional decision-maker. Miser aims to calculate deterministic values in backend logic where practical, but accountants must review outputs before using them for filing, invoicing, advice, or client communication.

We do not use Google Workspace API data to train general AI models. If third-party AI or parsing providers process your data, they do so to provide the requested Miser functionality under their applicable provider terms and safeguards.

6. Legal bases and Kenyan principles

Depending on the workflow, we process personal data based on contract performance, consent, compliance with legal obligations, legitimate interests, or accountant/client instructions.

We aim to follow Kenyan data protection principles including lawful, fair, transparent processing; explicit and legitimate purposes; data minimisation; accuracy; storage limitation; security; and appropriate safeguards for transfers outside Kenya.

7. Sharing and subprocessors

We share data only where needed to run Miser, provide requested integrations, comply with law, protect the service, process payment, or follow authorised accountant instructions.

Current or likely subprocessors and service categories include hosting providers, Supabase/database and storage, Google APIs, email providers, payment providers such as Paystack, AI providers, document parsing providers, GavaConnect/KRA-related APIs, logging/error monitoring, and analytics or security tooling.

We do not sell client tax records, payroll records, documents, or Google user data.

8. International transfers

Some providers may process or store data outside Kenya. Where this happens, we use contractual, technical, organisational, or consent-based safeguards where appropriate, and we aim to limit transferred data to what is necessary for the requested service.

9. Retention

We keep account, billing, tax workflow, eTIMS, document, and audit records for as long as needed to provide the service, meet legal/accounting obligations, resolve disputes, prevent abuse, or support accountant audit trails.

You may request deletion or export of eligible data. Some records may need to be retained where required by law, payment rules, tax audit needs, security logs, backup cycles, or legitimate dispute-resolution purposes.

10. Security

We use reasonable technical and organisational measures designed to protect data, including access controls, authentication, provider security controls, encrypted transport where available, role-based workflows, audit-oriented logs, and careful handling of secrets.

No system is perfectly secure. You should use strong passwords, restrict account access, review connected Google accounts and API credentials, and avoid sending portal links to unauthorised people.

11. Your rights

Under Kenyan data protection law, data subjects have rights including being informed about use of personal data, access, objection, correction of false or misleading data, deletion of false or misleading data, restriction in certain cases, and data portability where applicable.

If you are a client whose accountant uses Miser, please first contact that accountant or firm because they may be the primary controller for your records. You may also contact us and we will help route the request where appropriate.

12. Google API limited-use notice

If you connect a Google account, Miser uses Google access only for user-approved features such as sending Gmail reminders or creating and sharing Google Sheets/Drive working papers.

Miser’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

13. Children’s data

Miser is intended for business, accounting, and tax workflows, not for children. Do not intentionally submit children’s personal data unless you have the required authority and the processing is lawful and necessary for the relevant accounting or tax purpose.

14. Changes and contact

We may update this Privacy Policy as Miser, Kenyan law, provider requirements, or our processing activities change. Material changes will be communicated through reasonable product or account notices.

For privacy questions, data requests, or security concerns, contact us at privacy@miser.co.ke.