At M.Merkes Limited, we translate the precision of code into measurable results, automating HR, payroll, and financial operations so your teams can focus on what truly matters: growth.
Ready to upgrade how your organization operates?
M.Merkes Limited is a technology company that specializes in developing web and mobile enterprise software for the HR, payroll, tax, finance, and accounting sectors.
To become a global leader in accessible enterprise software, where every organization can access powerful, intelligent, and fully automated management systems.
We use the latest technologies, including artificial intelligence, to provide our customers with reliable and efficient solutions that meet their operational and strategic requirements. Our mission is to eliminate operational complexity, automate critical business processes, enhance efficiency and decision-making, and adapt to each organization's growth.
Intuitive solutions that remove complexity.
Enterprise-grade software without barriers.
Continuously improving for evolving needs.
Solutions that grow with our clients.
Software engineered for the realities of African enterprise — fast to deploy, built to scale, and secure at every layer.
Agile development that gets your solution live faster, without compromising on quality.
From 10 to 10,000 employees across multiple countries, the platform grows with you.
Multilingual, multicurrency and locally compliant from the ground up.
Industry-standard data protection applied at every layer of the system.
Custom web applications for HR, payroll, finance, and accounting, built for performance, security, and scalability.
Cross-platform mobile apps delivering seamless experiences on iOS and Android, accessible online and offline.
Next-generation HR management: multilingual, multicurrency, and fully adaptable.
View details →Comprehensive financial management for accounting, tax compliance, and reporting.
Coming SoonReady to see the difference software built for Africa can make? Reach out to the M.Merkes Limited team.
Enterprise software solutions designed to automate and modernize critical operations for organizations across Africa.
Next-generation HR management: multilingual, multicurrency, and fully adaptable.
View details →Comprehensive financial management for accounting, tax compliance, and reporting.
Coming soonA new generation of HR management: comprehensive, flexible, multilingual, and multicurrency. Accessible online and offline from PC, smartphone, or tablet.
Attendance, leave, payroll, and compliance — one platform, accessible everywhere.
Centralized, cloud-based platform for all employee data (contracts, IDs, HR records) with advanced access controls across multiple locations.
Real-time tracking with geolocation and Face ID verification for remote and hybrid teams, ensuring accountability and operational control.
Intelligent Gantt chart system for planning leave, submitting requests, and approvals, with full visibility across the organization.
Automated payroll engine supporting bank and mobile money disbursements, with CSV/XML/TXT accounting entries for ERP integration.
Enter your details and we'll send you instant access to the 4Waajiri demo.
M. Merkes Limited (” M. Merkes “,” we “,” us “,” our “) is a Kenyan technology company that designs, develops and operates Software-as-a-Service (SaaS) solutions, fully hosted in the cloud, including in particular:
4Waajiri: a human resources management platform (personnel files, attendance management, payroll management);
4Fedha: an accounting and financial management solution (bookkeeping, treasury, mobile money transactions).
Our vision is to serve businesses and individuals with solutions that simplify their lives. This mission is built on trust. Protecting the personal data we process some of which is highly sensitive is therefore central to our commitment.
This Privacy Policy (the ” Policy “) describes what personal data we collect, why and how we process it, with whom we share it, how we protect it, and the rights available to you.
It is established in accordance with:
the Constitution of Kenya, 2010 (Article 31, right to privacy);
the Kenyan data protection law, the Data Protection Act, 2019 (Cap. 411C) (the ” DPA “) and its 2021 implementing regulations;
the guidance notes published by the Office of the Data Protection Commissioner (ODPC), in particular on biometric data, consent and data sharing;
international best practice, in particular the standards of the European Union’s General Data Protection Regulation (GDPR), which we adopt as the most demanding compliance benchmark for all our users, wherever they are located.
For the purposes of this Policy, and in accordance with the DPA:
Personal data: any information relating to an identified or identifiable natural person.
Sensitive personal data: data revealing, among other things, a natural person’s race, health status, ethnic or social origin, conscience, belief, genetic data, biometric data, property details, marital status or family details, sex or sexual orientation.
Biometric data: data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a person, enabling their unique identification (fingerprints, facial recognition, etc.).
Processing: any operation performed on personal data (collection, recording, storage, consultation, use, disclosure, erasure, etc.).
Data controller: the person who determines the purposes and means of processing.
Data processor: the person who processes personal data on behalf of the data controller.
Data subject: the natural person to whom the personal data relates.
Client: the company, organisation or individual that has subscribed to one of our Services.
User: any natural person accessing our platforms (an employee of a Client, an administrator, a website visitor, etc.).
This Policy applies to:
our website and our SaaS platforms (4Waajiri, 4Fedha and any future solution);
the personal data of Clients, Users, prospects and visitors to our website;
personal data processed by our solutions on behalf of our Clients (e.g., data of a Client’s employees within 4Waajiri).
It applies regardless of the location of the data subject, in accordance with section 4 of the DPA, which covers the processing of data by a controller or processor established in Kenya.
It is essential to understand how responsibilities are allocated:
4.1. M. Merkes acts as data controller for:
the account, contact and billing data of our Clients and their administrators;
the data of visitors to our website and prospects (contact forms, demo requests, newsletters);
technical connection and security data relating to our platforms;
the data of our own employees and service providers.
4.2. M. Merkes acts as data processor for:
the data of a Client’s employees processed through 4Waajiri (personnel files, biometric attendance data, payroll data). In this case, the Client (the employer) is the data controller: it determines the purposes and must ensure the lawfulness of collection, including informing and, where applicable, obtaining the consent of its employees;
the accounting, financial and transactional data entered or imported by the Client into 4Fedha, including data relating to third parties (the Client’s own customers, suppliers, and beneficiaries of mobile money transactions).
Where we act as data processor, we process data solely on the Client’s documented instructions, under a data processing agreement compliant with section 42(2) of the DPA, incorporated into our Terms of Use.
5.1. Account and billing data (we act as data controller)
Identity and contact details: first name, surname, job title, company, email address, telephone number, address;
Login credentials (password stored in hashed form);
Billing data and subscription history;
Correspondence with our support team.
5.2. Payment data
To process subscription payments, we collect:
bank card number, expiry date and security code;
mobile money phone number and transaction references.
Important: bank card data is never stored in plain text on our servers. It is collected and processed directly by our licensed, PCI DSS-certified payment service providers (including Flutterwave), who tokenise it. We retain only transaction references, the last four digits of the card, and the metadata necessary for billing and fraud prevention.
5.3. HR data processed through 4Waajiri (on behalf of our Clients)
Depending on the configuration chosen by the employer Client:
Personnel file: full identity, photograph, identity documents, employment contract, CV, qualifications, contact details, emergency contacts, family status;
Biometric data for attendance management (see section 7);
Payroll data: salaries, bonuses, deductions, employees’ bank or mobile money details, tax and social security data.
Several of these categories constitute sensitive personal data within the meaning of section 2 of the DPA (biometric data, marital and family status, property details).
5.4. Financial and accounting data processed through 4Fedha (on behalf of our Clients)
Accounting entries, financial statements, and treasury data of the Client;
Transactional data, including mobile money transactions, which may contain information about individuals (name, phone number, amounts, dates).
5.5. Technical and usage data
Connection logs (IP address, timestamp, device and browser type);
Platform usage data (pages viewed, actions performed), for security, audit and service improvement purposes;
Cookies and similar technologies (see section 10).
In accordance with section 30 of the DPA, we only process personal data where a legal basis permits it:
Purpose
Legal basis (s. 30 DPA)
Creating and managing accounts, providing the SaaS services
Performance of a contract
Billing and collection of payments
Performance of a contract; legal obligation (accounting, tax)
Processing HR, payroll and accounting data on behalf of the Client
Client’s instructions as data controller (data processing agreement)
Processing biometric attendance data
Explicit consent of the data subject, obtained under the Client’s responsibility (ss. 44–45 DPA)
Security of the platforms, prevention of fraud and abuse
Legitimate interest; legal obligation
Customer support and service communications
Performance of a contract
Marketing and newsletters
Consent (with a simple opt-out mechanism available at all times, in accordance with s. 37 DPA)
Compliance with legal obligations (tax, judicial, regulatory)
Legal obligation
Service improvement and statistics
Legitimate interest, based on aggregated or pseudonymised data
We do not make any decision based solely on automated processing that produces legal effects in respect of data subjects without human intervention, in accordance with section 35 of the DPA.
The biometric data used for attendance management in 4Waajiri constitutes sensitive personal data subject to an enhanced regime (sections 44 to 47 of the DPA and the ODPC Guidance Note on Biometric Data, 2025). Our commitments:
Explicit consent: biometric processing is based on the free, specific, informed and unambiguous consent of the employee, obtained by the employer Client prior to any enrolment. Refusal or withdrawal of consent must not result in any detriment: a non-biometric alternative for clocking in (PIN code, badge, manual validation) is always available within 4Waajiri.
Minimisation: we store encrypted biometric templates (irreversible mathematical models), rather than raw images, wherever the technology allows.
Separation and encryption: biometric data is stored separately from other identification data and encrypted both at rest and in transit.
No repurposing: biometric data is used for no purpose other than the attendance verification configured by the Client. It is never sold, shared, or used for surveillance purposes.
Deletion: an employee’s biometric templates are deleted without delay upon withdrawal of consent, departure of the employee, or termination of the Client’s contract, subject to legal retention obligations.
Human intervention: no adverse decision (disciplinary action, salary deduction) is taken solely on the basis of automated biometric processing; the Client undertakes to provide for human review.
Other sensitive data (family status, property details appearing in HR files) is processed solely within the framework of the employer’s obligations relating to labour law, payroll and social protection, in accordance with section 45(c) of the DPA.
Our Services are intended for professionals and adults. We do not knowingly collect personal data relating to children (under 18) without the consent of a parent or guardian, in accordance with section 33 of the DPA. Where such data appears in an HR file (e.g., the names of an employee’s children for social benefit purposes), it is processed under the responsibility of the employer Client, strictly for those purposes.
We never sell or rent personal data. We only share it with:
Our sub-processors: cloud hosting providers, payment service providers (Flutterwave), support and email tools all bound by written contracts imposing security and confidentiality safeguards equivalent to our own (s. 42(2) DPA). An up-to-date list of sub-processors is available upon request;
The Client as data controller: data processed within 4Waajiri and 4Fedha is accessible to the Client and to the users it has authorised, according to the roles and permissions it configures;
Public authorities: where required by law (tax administration, judicial authorities, ODPC), on the basis of a legally valid request;
Our professional advisers (auditors, lawyers, insurers), who are bound by professional secrecy;
An acquirer or successor in the event of a merger, acquisition or restructuring, with prior notice to data subjects.
All data sharing is carried out in accordance with the ODPC’s Data Sharing Code.
Our website and platforms use:
strictly necessary cookies (authentication, session security, load balancing) which do not require consent;
audience measurement and preference cookies deployed only with your consent, which you may withdraw at any time via the cookie management banner or your browser settings.
As our solutions are hosted in the cloud, some data may be stored or processed on servers located outside Kenya. In accordance with sections 48 and 49 of the DPA:
we only transfer data outside Kenya to jurisdictions or providers offering appropriate safeguards for the security and protection of the data (adequate legislation, contractual data protection clauses, recognised certifications);
the transfer of sensitive data (in particular biometric data) outside Kenya is only carried out with the consent of the data subject and after confirmation of appropriate safeguards;
we document these safeguards and are able to demonstrate them to the Data Commissioner;
where Kenyan regulations require a category of processing to be carried out on servers located in Kenya (s. 50 DPA), we comply accordingly.
Upon request, the Client may obtain information on the location of data and the applicable safeguards.
In accordance with sections 41 and 42 of the DPA and the principle of data protection by design and by default, we implement appropriate technical and organisational measures, including:
encryption of data in transit (TLS) and at rest;
pseudonymisation where relevant;
strict role-based access control (RBAC), strong authentication and access logging;
logical segregation of each Client’s data (secure multi-tenant architecture);
regular backups and a business continuity and disaster recovery plan;
security testing, regular updates and patches;
staff awareness training and confidentiality undertakings;
selection of processors offering sufficient guarantees.
As no system is infallible, we encourage you to protect your credentials and to report any suspicious activity to us immediately.
In accordance with section 39 of the DPA, we only retain personal data for as long as necessary for the purposes pursued:
Category
Indicative retention period
Client account data
Duration of the contract + 5 years (contractual limitation period)
Billing and accounting data
7 years (Kenyan tax and accounting obligations)
HR and payroll data processed for the Client
As instructed by, and in accordance with the retention policy of, the Client as data controller
Biometric templates
Duration of employment; immediate deletion upon withdrawal of consent or departure
Prospect data
2 years after last contact, unless an earlier objection is raised
Connection and security logs
12 months
Data following termination of the Client’s contract
Returned, then deleted or anonymised within 90 days, unless a legal obligation requires otherwise
Upon expiry of these periods, data is deleted, erased, anonymised or pseudonymised.
In accordance with sections 26 to 40 of the DPA, every data subject has the following rights:
Right to be informed: to be informed of how their data is used (the subject of this Policy and of the notices provided at the point of collection);
Right of access: to obtain confirmation that their data is being processed and to receive a copy of it;
Right to rectification: to have inaccurate, outdated, incomplete or misleading data corrected without undue delay;
Right to erasure: to obtain the deletion of data that we are no longer authorised to retain processed within 14 days in accordance with ODPC guidance;
Right to object: to object to all or part of the processing, in particular for direct marketing purposes;
Right to data portability: to receive their data in a structured, commonly used and machine-readable format, and to transmit it to another data controller processed within 30 days;
Right not to be subject to a decision based solely on automated processing producing legal or significant effects, and to obtain human intervention;
Right to withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
How to exercise your rights:
If your request concerns data processed by M. Merkes as data controller: write to us at compliance@m-merkes.com. We will respond within the statutory time limits, following verification of your identity. The exercise of your rights is free of charge, except where a request is manifestly unfounded or excessive.
If your request concerns data that we process on behalf of your employer or another Client (4Waajiri, 4Fedha): please contact the Client in the first instance, as it is the data controller. We will provide the Client with full assistance in handling your request and will forward without delay any request received directly.
In accordance with section 43 of the DPA:
where we act as data controller, we notify the ODPC of any data breach presenting a real risk of harm within 72 hours of becoming aware of it, and inform affected data subjects in writing within a reasonable period where unauthorised access has occurred;
where we act as data processor, we inform the Client as data controller within 48 hours of becoming aware of the breach;
we document all breaches, their effects, and the corrective measures taken.
Given the nature of our activities large-scale processing of sensitive data, including biometric data M. Merkes:
is registered with the ODPC as a data controller and data processor [registration number to be inserted upon completion of registration];
has appointed a Data Protection Officer (DPO), in accordance with section 24 of the DPA, who may be contacted at: dpo@m-merkes.com;
carries out Data Protection Impact Assessments (DPIAs) prior to any high-risk processing, in particular before deploying biometric functionality.
If you believe that the processing of your data does not comply with the law, you may, without prejudice to any other remedy:
contact us in the first instance at compliance@m-merkes.com; we undertake to review any complaint diligently;
lodge a complaint with the Office of the Data Protection Commissioner (ODPC): www.odpc.go.ke P.O. Box 30920-00100, Nairobi, Kenya;
seek judicial redress and, where applicable, claim compensation for any harm suffered (s. 65 DPA).
We may amend this Policy to reflect legal, technical or service-related developments. Any material change will be notified to Clients and Users (by email, or notification on the platform) at least 30 days before it takes effect. The current, dated version is permanently published on our website.
This Policy is governed by Kenyan law, in particular the Data Protection Act, 2019 (Cap. 411C) and its implementing regulations. It is drafted in French and in English; in the event of any discrepancy, the English version shall prevail for the purposes of the Kenyan authorities.
These Terms of Use (the ” Terms “) govern access to and use of:
the website of M. Merkes Limited (” M. Merkes “,” we “,” us “,” our “);
the Software-as-a-Service (SaaS) software solutions published and operated by M. Merkes, in particular 4Waajiri (human resources management: personnel files, attendance management, payroll) and 4Fedha (accounting and financial management, including mobile money transactions), together with any associated solution, module, mobile application, API or service (collectively, the ” Services “).
Any access to or use of the Services constitutes full and unreserved acceptance of these Terms and of our Privacy Policy, which forms an integral part hereof. If you accept these Terms on behalf of a company or organisation, you represent that you have the authority to bind it.
If you do not accept these Terms, you must not use the Services.
Client: the legal entity or natural person that has subscribed to the Services.
User: any natural person authorised by the Client to access the Services (administrator, HR manager, accountant, employee, etc.) or any website visitor.
Account: the personal, secure space through which the Services are accessed.
Client Data: all data, files and content entered into, imported into, or generated within the Services by or for the Client, including the personal data of its employees and of its own customers.
Subscription: the right of access to the Services subscribed to by the Client according to the plan, term and price selected.
Documentation: the guides, manuals and help materials relating to the Services.
3.1. M. Merkes provides Services that are 100% cloud-hosted, accessible online via an internet connection, with no local installation, on a software-as-a-service (SaaS) basis.
3.2. 4Waajiri enables, among other things: the management of personnel files (identity, contracts, CVs, photographs, documents), attendance management (including, optionally, by biometric devices), and the management of payroll and related statutory filings.
3.3. 4Fedha enables, among other things: bookkeeping, financial and treasury management, and the tracking of transactions, including mobile money.
3.4. The exact scope of the features depends on the Subscription plan selected, as described on our website or in the order form. M. Merkes may enhance the features of the Services, without materially degrading their substance, as part of continuous improvement.
3.5. The Services are management tools. They do not constitute legal, tax or accounting advice. The Client remains solely responsible for the compliance of its obligations as an employer and its accounting, tax and social security obligations, as well as for the accuracy of the configurations (payroll scales, rates, rules) and the data entered.
4.1. Use of the Services requires the creation of an Account. The Client warrants that the information provided is accurate, complete and kept up to date.
4.2. The Services are reserved for persons of legal age with the legal capacity to contract. User Accounts for employees are created under the Client’s responsibility.
4.3. Login credentials are strictly personal and confidential. The Client and each User are responsible for maintaining the confidentiality of their credentials and for all actions carried out from their Account. Any suspicious or unauthorised use must be reported to us without delay at support@m-merkes.com.
4.4. The Client administers the roles and permissions of its Users itself and is responsible for the access rights it grants.
5.1. Plans and term. The Services are provided on a Subscription basis (monthly or annual), at the prevailing prices published on our website or agreed in an order form. Unless otherwise stipulated, the Subscription renews automatically for successive periods of the same duration, failing termination notified before the expiry date in accordance with clause 14.
5.2. Free trial. Where a free trial is offered, it is limited in time and in features. At the end of the trial period, access is suspended unless a paid Subscription is taken out.
5.3. Payment. Payment is made using the payment methods offered (bank card, mobile money, bank transfer), through our certified payment service providers. Payments are due in advance. The Client authorises, where applicable, the recurring charging of the Subscription amount.
5.4. Late payment and non-payment. In the event of non-payment on the due date, and after notice that has remained without effect for fifteen (15) days, M. Merkes may suspend access to the Services until payment is made in full, without prejudice to the termination provided for in clause 14 and to any applicable late-payment penalties.
5.5. Taxes. Prices are stated exclusive of taxes. Any applicable tax (in particular Kenyan VAT) is added to the price and borne by the Client.
5.6. Price revision. M. Merkes may revise its prices upon at least thirty (30) days’ notice before the renewal of the Subscription. A Client who does not accept the new prices may terminate its Subscription before they take effect.
6.1. The Client and Users undertake to use the Services in accordance with the law, these Terms and the Documentation. In particular, it is prohibited to:
use the Services for unlawful or fraudulent purposes, or to infringe the rights of third parties;
enter or process personal data without a legal basis, or in breach of the Data Protection Act, 2019;
attempt to gain unauthorised access to the systems, to other clients’ accounts or to third-party data; circumvent security measures; or carry out penetration testing without prior written agreement;
introduce viruses, malware or any harmful code;
copy, decompile, disassemble or reverse-engineer the Services, save within the limits mandatorily permitted by law;
resell, sublicense, rent out or make the Services available to third parties, save with the written consent of M. Merkes;
use the Services in a manner liable to degrade their performance or availability (abusive load, unauthorised large-scale automated extraction);
remove or alter intellectual property notices.
6.2. In the event of a serious or repeated breach, M. Merkes may immediately suspend access to the Services, after notice where circumstances permit, without prejudice to any claim for damages.
7.1. Roles. With respect to Client Data containing personal data (in particular employee data in 4Waajiri and third-party data in 4Fedha), the Client acts as data controller and M. Merkes acts as data processor, within the meaning of the Data Protection Act, 2019 (Cap. 411C). With respect to account, billing and prospecting data, M. Merkes acts as data controller, on the terms set out in the Privacy Policy.
7.2. M. Merkes’s undertakings (as data processor). M. Merkes undertakes to:
process personal data solely on the Client’s documented instructions and only for the purposes of providing the Services;
implement the appropriate technical and organisational measures provided for in sections 41 and 42 of the DPA (encryption, access control, logging, data segregation);
ensure that its personnel maintain the confidentiality of the data;
engage sub-processors only under equivalent safeguards and inform the Client thereof;
notify the Client of any personal data breach within 48 hours of becoming aware of it (s. 43 DPA);
reasonably assist the Client in complying with its obligations (responding to data-subject rights requests, impact assessments, security);
upon termination of the contract, return and then delete or anonymise the data in accordance with clause 14.4;
transfer data outside Kenya only in compliance with sections 48 and 49 of the DPA and the safeguards described in the Privacy Policy.
7.3. The Client’s undertakings (as data controller). The Client warrants that it:
has a valid legal basis for all processing carried out through the Services and has provided data subjects with the required information;
obtains, prior to any biometric enrolment in 4Waajiri, the explicit, free and informed consent of each employee concerned, offers a non-biometric alternative, and manages withdrawals of consent;
complies with the statutory retention periods applicable to its sector and configures the Services accordingly;
is, where applicable, duly registered with the ODPC;
responds to the rights requests of its employees and data subjects, M. Merkes undertaking to forward to it without delay any request received directly;
does not use the Services to process categories of data not provided for without informing M. Merkes.
7.4. The Client shall indemnify and hold M. Merkes harmless against any third-party claim or penalty resulting from the Client’s breach of its obligations as data controller.
8.1. M. Merkes’s ownership. The Services, their source code, their architecture, their structural databases, their interfaces, the Documentation, the trademarks, logos and domain names, and all intellectual property rights therein, are and shall remain the exclusive property of M. Merkes Limited. The 4Waajiri and 4Fedha software programs are protected by copyright, in particular the Copyright Act of Kenya, and registered with the Kenya Copyright Board (KECOBO).
8.2. Licence to use. The Subscription grants the Client a personal, non-exclusive, non-assignable and non-transferable right to use the Services, for its internal needs, for the duration of the Subscription and within the limits of the plan subscribed to. No proprietary right is transferred to the Client.
8.3. Client Data. Client Data remains the exclusive property of the Client. The Client grants M. Merkes a limited licence, for the duration of the contract, solely for the purposes of hosting, processing and providing the Services. M. Merkes may use aggregated and anonymised data which does not permit the identification of either the Client or any individual for statistical and service-improvement purposes.
8.4. Suggestions. Improvement suggestions communicated by the Client may be freely implemented by M. Merkes, without obligation or remuneration.
Each party undertakes to preserve the confidentiality of the non-public information of the other party of which it becomes aware in connection with the contract (commercial, technical and financial information), throughout the term of the contract and for five (5) years thereafter. This obligation does not apply to information that has entered the public domain without fault, that has been developed independently, or whose disclosure is required by law or by a competent authority (subject to prior notice to the other party where lawful to give such notice).
10.1. M. Merkes uses its best efforts to ensure the availability of the Services 24 hours a day, 7 days a week, with a target monthly availability of 99.5%, excluding scheduled maintenance and force majeure events.
10.2. Scheduled maintenance operations are, as far as possible, carried out outside business hours (Nairobi time, EAT) and notified at least 48 hours in advance. Emergency (security) maintenance may be carried out without notice.
10.3. Support is available by email / support portal at support@m-merkes.com, on business days and during business hours, according to the Subscription plan.
10.4. Access to the Services requires equipment and an internet connection that are the Client’s responsibility; M. Merkes is not liable for malfunctions attributable to the Client’s network, equipment or software.
M. Merkes implements the security measures described in the Privacy Policy (encryption in transit and at rest, access control, logging, multi-tenant segregation) and performs regular backups of Client Data enabling its restoration in the event of an incident. The Client remains responsible for the security of its own systems, of its credentials, and of the data exports it carries out.
12.1. M. Merkes warrants that the Services are provided with the reasonable care and skill of a professional software publisher and substantially in conformity with the Documentation.
12.2. Except as set out above, and to the extent permitted by law, the Services are provided “as is” and “as available”. M. Merkes does not warrant that the Services will be free from any error or interruption, that they will meet all the Client’s specific needs, or that the results produced from data or configurations provided by the Client will be accurate.
12.3. Nothing in these Terms excludes or limits any warranty or liability that cannot be excluded or limited under the applicable mandatory law, including, where applicable, the Consumer Protection Act, 2012 of Kenya in respect of consumers.
13.1. M. Merkes is liable for proven direct damage resulting from a breach of its contractual obligations.
13.2. To the extent permitted by law, M. Merkes shall not be liable for indirect damage (loss of profits, loss of revenue, loss of goodwill or clientele, damage to reputation, loss of data attributable to the Client), nor for damage resulting from: (i) non-compliant use of the Services; (ii) erroneous data, configurations or instructions provided by the Client; (iii) a breach by the Client of its obligations, in particular in relation to data protection; or (iv) the act of a third party or a force majeure event.
13.3. Cap. Save in the case of gross negligence or wilful misconduct, or where the law prohibits such limitation, M. Merkes’s total aggregate liability under the contract is capped at the total amount actually paid by the Client during the twelve (12) months preceding the event giving rise to the claim.
13.4. No limitation applies to personal injury, death, fraud, or to liabilities that the law prohibits from being limited.
14.1. Term. The contract takes effect upon subscription to the Services and continues for the term selected, renewable in accordance with clause 5.1.
14.2. Termination by the Client. The Client may terminate its Subscription at any time with effect at the end of the current period, via its Account area or by written notice. Unless otherwise provided by law, amounts paid are not refunded on a pro rata basis.
14.3. Termination for breach. Either party may terminate the contract as of right in the event of a material breach by the other party that is not remedied within thirty (30) days of a written formal notice. M. Merkes may, in addition, suspend or terminate immediately in the event of a breach of clause 6 (acceptable use), persistent non-payment, or a legal requirement.
14.4. Reversibility and fate of the data. Upon termination of the contract, for whatever reason:
the Client has a period of thirty (30) days to export its Client Data in a structured, commonly used and machine-readable format, via the export features of the Services or with the assistance of M. Merkes (extended assistance may be subject to reasonable charges);
upon expiry of that period, M. Merkes deletes or anonymises the Client Data within a maximum of ninety (90) days, save for any legal retention obligation;
biometric templates are deleted without delay.
Neither party shall be liable for any failure caused by a force majeure event: natural disaster, war, act of terrorism, epidemic, decision of the authorities, general failure of telecommunications or electricity networks, major externally originating cyberattack, or any unforeseeable, irresistible and external event. The affected party shall inform the other without delay. If the event persists for more than sixty (60) days, either party may terminate the contract without compensation.
M. Merkes may amend these Terms. Any material amendment is notified to the Client (by email, or notification within the Services) at least thirty (30) days before it takes effect. Continued use of the Services after the effective date constitutes acceptance. A Client that rejects the amendments may terminate its Subscription before they take effect.
17.1. Entire agreement. These Terms, the Privacy Policy and, where applicable, the order form and any service level agreement constitute the entire agreement between the parties. In the event of a conflict, the order form prevails over these Terms.
17.2. Assignment. The Client may not assign the contract without the prior written consent of M. Merkes. M. Merkes may assign the contract in connection with a reorganisation, merger or transfer of business, with notice to the Client.
17.3. Severability. If any provision is held to be void or unenforceable, the remaining provisions shall remain in force; the provision concerned shall be replaced by a valid provision of equivalent economic effect.
17.4. No waiver. The failure to enforce a breach shall not constitute a waiver of the right to enforce it subsequently.
17.5. Evidence. The records, logs and electronic records of M. Merkes shall be admissible as evidence between the parties, save proof to the contrary.
17.6. Languages. These Terms are published in French and in English. In the event of a discrepancy in interpretation, the English version shall prevail.
18.1. These Terms are governed by the law of the Republic of Kenya.
18.2. The parties shall endeavour to resolve any dispute amicably within thirty (30) days of its written notification.
18.3. Failing amicable resolution, any dispute shall be submitted to the jurisdiction of the courts of Nairobi (Kenya). The parties may, by mutual agreement, submit the dispute to arbitration in accordance with the Arbitration Act, 1995 of Kenya, the seat of arbitration being Nairobi.
18.4. Nothing in this clause deprives a data subject of the right to bring a matter before the Office of the Data Protection Commissioner (ODPC) or any competent authority.
For any question relating to these Terms:
M. Merkes Limited
Physical address: Delta Corner 2, Oracle Tower, 13th Floor, Westlands
P.O. Box 13796-00800, Nairobi, Kenya
Email: contacts@m-merkes.com; Data protection: dpo@m-merkes.com; Compliance: compliance@m-merkes.com