What governs your relationship with NexumPay.
A summary of the policies that apply to every customer, business and institutional partner. Full legal texts are available on request from Nexslate Company Limited and should be reviewed by counsel before being relied upon.
Policy summaries
Nexslate Company Limited collects only the information needed to open a wallet, verify identity, and process transactions — including identity details, contact information, and transaction history.
- Personal data is used to run your account, meet regulatory obligations, and improve service reliability — not sold to third parties.
- Data is retained only as long as needed for the relationship and applicable legal or tax requirements.
- You can request a copy of the data we hold about you, or ask us to correct it, at any time.
Using a NexumPay wallet or API means accepting the terms that govern how the platform may be used.
- Wallets may only be used for lawful transactions; fraudulent or deceptive use results in suspension.
- Business accounts are responsible for the actions of the signatories and staff they authorize.
- Fees, limits and processing times are disclosed before a transaction is confirmed, never after.
- Nexslate Company Limited may update these terms with reasonable notice as the product evolves.
NexumPay is built around identity verification and transaction monitoring appropriate for a regulated payment platform.
- Individuals and businesses complete identity verification (KYC) before wallet limits are raised.
- Transactions are screened for patterns consistent with money laundering or terrorist financing.
- Nexslate Company Limited is structured to operate within the regulatory frameworks that govern payment service providers in Kenya, including alignment with Central Bank of Kenya guidance on national payment systems.
- Suspicious activity may result in a transaction being held pending review, with the customer notified where legally permitted.
Financial data is treated as sensitive by default.
- All data in transit is encrypted over HTTPS; access to stored data is restricted by role.
- Every access to a customer's financial record is logged and auditable internally.
- Data is not shared with third parties beyond what's required to process a transaction or meet a legal obligation.
Because every transaction is ledgered, disputes are investigated against a full audit trail rather than a partial record.
- Report a disputed or failed transaction and it's investigated against the underlying ledger entries.
- Confirmed failed transactions — money debited but not delivered — are reversed to the sender's wallet.
- Multi-signatory business transactions can only be reversed with the same approval standard used to send them.
Nexslate Company Limited welcomes responsible disclosure of potential security issues.
- Report suspected vulnerabilities directly to our security contact rather than testing them against live customer accounts.
- We aim to acknowledge credible reports promptly and keep the reporter informed as an issue is resolved.
- Customers are never asked for a wallet PIN, OTP, or password by staff, by phone, or by email — treat any such request as fraudulent.
Questions about a specific policy?
Reach out and our team in Nairobi will walk you through the full legal text behind any of these summaries.