Privacy Policy

Nesthub Global | Protecting Your Rental Data System


Last Updated: April 7, 2026 | Version 2.0

Effective for all Nesthub Global rental management products and services

Nesthub Global

A Software Product by Xfix Global Limited

Nesthub Global is a premier rental management software system and a proud product of Xfix Global Limited, an enterprise-grade software engineering company dedicated to building innovative technological solutions that power businesses across Africa and beyond. Nesthub Global specializes in comprehensive property management solutions, connecting landlords, property managers, tenants, and service providers through an integrated, secure, and intuitive platform.

This Privacy Policy governs all Nesthub Global software products, services, and platforms, including but not limited to the Nesthub Landlord Portal, Tenant Portal, mobile applications (iOS and Android), payment processing systems, maintenance request modules, lease management tools, and all integrated services within our rental management system. As a product of the Xfix Global Limited family, we adhere to the highest enterprise security standards while maintaining specific privacy commitments tailored to the unique needs of the rental housing industry. We are committed to protecting your privacy and ensuring the highest standards of data security across our entire property management software.

1

Information We Collect Across Nesthub Platforms

As a specialized rental management software serving landlords, property managers, tenants, and housing cooperatives, Nesthub Global collects various categories of information to facilitate seamless property management, secure financial transactions, and maintain legal compliance. Our data collection practices are transparent, lawful, and aligned with international privacy standards as well as local housing regulations. The types of information we collect include:

🏒 Landlord & Property Manager Information

  • Full legal name and business registration details
  • Company registration number and tax identification (KRA PIN, etc.)
  • Physical address of management office and properties
  • Email addresses (business and personal)
  • Phone numbers (office, mobile, emergency contact)
  • Property ownership documentation and land registration details
  • Bank account information for rental collections
  • Rental license numbers and regulatory compliance certificates
  • Agent identification and professional credentials

πŸ‘₯ Tenant & Occupant Information

  • Full legal name and preferred name
  • Government-issued identification (National ID, Passport, Alien Card)
  • Date of birth and age verification for legal capacity
  • Current and previous residential addresses
  • Employer details, job title, and work contact information
  • Emergency contact information (name, relationship, phone)
  • Family member and co-occupant details
  • Vehicle information for parking management (make, model, license plate)
  • Pet information for properties allowing animals

πŸ“„ Lease & Tenancy Documentation

  • Lease agreements and tenancy contracts
  • Rental payment history and rent ledgers
  • Security deposit amounts and holding details
  • Lease start and end dates, renewal options
  • Rent amount, payment due dates, and late fee policies
  • Utility billing information and consumption data
  • Property inspection reports (move-in, periodic, move-out)
  • Notice to vacate and lease termination documentation
  • Rent arrears and recovery proceedings

πŸ’° Financial & Payment Data

  • Payment method details (credit/debit cards, M-Pesa, bank transfers, ACH)
  • Mobile money phone numbers (Safaricom, Airtel, Telkom)
  • Bank account details for automatic rent deductions
  • Rent payment history, receipts, and statements
  • Deposit transactions and refund records
  • Late payment fees, penalties, and concessions
  • Utility bill payments (water, electricity, internet, garbage)
  • Service charge and maintenance fee transactions
  • Dispute resolution and refund processing records

πŸ”§ Maintenance & Service Requests

  • Maintenance request details and descriptions
  • Photos, videos, and documentation of property issues
  • Service provider assignments and work orders
  • Repair history and property condition logs
  • Emergency maintenance contact information
  • Contractor and vendor performance records
  • Cost estimates, invoices, and payment confirmations
  • Tenant satisfaction ratings and feedback on maintenance

πŸ“Š Usage & Analytics Data

  • IP addresses and geolocation data
  • Browser type, version, and language preferences
  • Operating system and device information
  • Login history and session activity logs
  • Feature usage patterns (payment views, maintenance requests, lease downloads)
  • Mobile app interaction data and crash reports
  • Notification delivery and read receipts
  • Portal engagement metrics and time-based analytics

Collection Methods: We collect this information through direct user input during account registration, lease signing, and maintenance requests; automated tracking technologies (cookies, session tokens, and analytics scripts); third-party integrations (payment gateways like M-Pesa, Stripe, and bank APIs); property management system imports; and indirect sources such as credit reference bureaus with proper consent.

2

How Nesthub Global Uses Your Information

Nesthub Global processes your information for specific, legitimate purposes that enable us to deliver exceptional property management solutions and maintain the highest standards of service for both property owners and tenants. Our processing activities are grounded in legal bases including contractual necessity (lease agreements), legitimate business interests, compliance with legal obligations (housing laws, tax regulations), and user consent where required. We use your information for:

🏠
Core Rental Management
  • Facilitating lease creation, signing, and management
  • Processing rent payments and security deposits
  • Managing tenant screening and verification
  • Tracking property occupancy and vacancy rates
  • Generating lease renewals and termination notices
  • Managing utility billing and sub-metering
  • Coordinating move-in and move-out inspections
  • Maintaining digital property files and documentation
πŸ”§
Maintenance & Operations
  • Receiving, tracking, and resolving maintenance requests
  • Dispatching service providers and contractors
  • Scheduling preventive maintenance activities
  • Managing emergency repair responses
  • Tracking maintenance costs and budgeting
  • Maintaining property condition history
  • Generating maintenance reports for property owners
  • Ensuring compliance with housing quality standards
πŸ“’
Communication & Engagement
  • Sending rent payment reminders and receipts
  • Delivering lease renewal notifications and offers
  • Notifying about property inspections or visits
  • Sharing community announcements and events
  • Responding to inquiries via chat, email, or phone
  • Managing dispute resolution communications
  • Conducting tenant satisfaction surveys
βš–οΈ
Legal & Compliance
  • Complying with landlord-tenant laws and regulations
  • Maintaining records for tax and audit purposes
  • Supporting eviction proceedings when legally required
  • Providing evidence for legal disputes
  • Reporting to credit reference bureaus (with consent)
  • Verifying identities for KYC and AML requirements
  • Responding to court orders and regulatory requests
πŸ“ˆ
Analytics & Improvement
  • Analyzing rental market trends and pricing
  • Identifying property maintenance patterns
  • Improving platform performance and user experience
  • Developing new features based on user needs
  • Measuring landlord and tenant satisfaction
  • Optimizing payment collection processes
πŸ›‘οΈ
Security & Fraud Prevention
  • Detecting and preventing rental fraud
  • Monitoring for unauthorized account access
  • Investigating suspicious payment activities
  • Preventing identity theft and impersonation
  • Securing sensitive financial and personal data
  • Maintaining audit trails for compliance
3

Data Sharing, Disclosure, and Third-Party Relationships

Nesthub Global is committed to maintaining your trust and protecting your information. As a product of Xfix Global Limited, we adhere to strict data-sharing policies. We do not sell your personal data to third parties. We share information only under specific circumstances with appropriate safeguards in place:

Recipient Category Purpose of Sharing Safeguards Implemented
Payment Processors
M-Pesa, Stripe, Banks, Airtel Money
Processing rent payments, security deposits, utility bills, and maintenance fees PCI DSS compliance, tokenization, encrypted transmissions, limited data scope
Maintenance Service Providers
Contractors, plumbers, electricians, cleaning services
Dispatching repair services, sharing property access details, scheduling maintenance Limited data access (only name, address, issue description), contractual privacy obligations
Credit Reference Bureaus
Metropol, CreditInfo, TransUnion
Rent payment reporting for tenant credit history (with explicit consent) Separate consent mechanisms, data protection agreements, limited to payment history
Background Check Services
Tenant screening agencies, identity verification providers
Tenant verification, criminal record checks, eviction history Consent-based sharing, encrypted data transfer, compliance with Fair Credit Reporting Act
Parent Company
Xfix Global Limited
Infrastructure management, security monitoring, customer support, product development Internal data processing agreements, shared security standards, need-to-know access
Legal & Regulatory Authorities
Courts, housing tribunals, law enforcement, tax authorities
Compliance with court orders, eviction proceedings, tax audits, regulatory investigations Legal review of requests, minimum necessary disclosure, user notification where permitted
πŸ”’ Additional Sharing Scenarios:
  • Property Owner Disclosure: We share tenant information with property owners as necessary to manage the rental relationship, including payment status, maintenance requests, and lease compliance.
  • Emergency Situations: We may disclose information to emergency services (police, fire, medical) or property emergency contacts to protect the vital interests of tenants or others.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, user information may be transferred. We will provide notice before your information becomes subject to a different privacy policy.
  • With Your Consent: We may share your information with third parties when you provide explicit consent, such as for rental referrals or utility service connections.
  • Aggregated Data: We may share anonymized, aggregated rental market data that does not identify individuals for research or industry benchmarking.
4

Enterprise-Grade Security Measures & Hosting Infrastructure

As a product of Xfix Global Limited, Nesthub Global inherits the same enterprise-grade security infrastructure powered by TrueHost, utilizing Linux-based (Ubuntu, AlmaLinux, Rocky Linux, Debian) and Windows 2019 servers to deliver reliable, high-performance hosting services across our global network. We implement comprehensive security measures to protect sensitive rental and financial information.

🌍 Global Data Center Infrastructure
  • Strategic Locations: Distributed across Tier III and Tier IV data centers in Europe, USA, and Kenya
  • Cloudoon Nameservers: DNS management through ns2.cloudoon.net and ns3.cloudoon.org
  • Server Architecture: Dedicated servers for sensitive rental data
  • Geographic Redundancy: Data replicated across multiple regions for disaster recovery
  • Kenya Data Residency: Local hosting option for compliance with Kenyan housing regulations
πŸ” Encryption & Data Protection
  • In-Transit Encryption: TLS 1.2/1.3 for all data transmissions
  • At-Rest Encryption: AES-256 for stored rental agreements and financial records
  • Database Encryption: Encrypted volumes for tenant and landlord databases
  • Backup Encryption: Encrypted backups with 90-day retention
  • Payment Tokenization: No storage of raw payment credentials
πŸ‘₯ Access Controls & Authentication
  • Role-Based Access: Landlord, tenant, agent, admin roles with different permissions
  • Multi-Factor Authentication: Optional for tenants, required for landlords and admins
  • Session Management: Automatic logout after inactivity
  • IP Whitelisting: Available for enterprise property managers
  • Audit Logging: Complete traceability of data access
πŸ” Monitoring & Compliance
  • 24/7 Security Monitoring: Real-time threat detection
  • Fraud Detection Systems: Suspicious payment pattern monitoring
  • Regular Penetration Testing: Quarterly security assessments
  • Vulnerability Scanning: Weekly automated scans
  • Incident Response Team: Dedicated 24/7 security response
πŸ”„ Backup & Disaster Recovery
  • Automated Backups: Daily backups with 90-day retention for all rental data
  • Geographic Distribution: Backups replicated across Europe, USA, and Kenya
  • Recovery Time Objective (RTO): 4 hours for critical rental management systems
  • Recovery Point Objective (RPO): 24-hour maximum data loss
  • Regular Testing: Quarterly disaster recovery drills simulating data center failures
Important Security Notice: While we implement industry-leading security measures across our TrueHost-powered infrastructure, no system is 100% secure. We encourage you to protect your account by using strong, unique passwords, enabling multi-factor authentication, logging out after each session, and promptly reporting any suspicious activity to security@xfixglobal.com.
5

International Data Transfers & Data Center Locations

As a global rental management software serving landlords and tenants across multiple countries, your information may be transferred to and processed in countries outside your residence. Nesthub Global leverages Xfix Global Limited's TrueHost infrastructure with data centers strategically located across three continents:

🌍
Europe

GDPR-compliant data centers for EU landlords and tenants with enhanced privacy protections

πŸ‡ΊπŸ‡Έ
USA

North American data centers serving US property managers with CCPA compliance

πŸ‡°πŸ‡ͺ
Kenya

Local African data centers ensuring low-latency access and compliance with Kenya Data Protection Act and housing regulations

We ensure appropriate safeguards for international data transfers including:

  • Standard Contractual Clauses (SCCs): EU-approved contractual provisions for data transfers from the European Economic Area
  • Data Residency Options: Upon request, property managers can configure data storage to specific geographic regions to meet local data residency requirements
  • Kenya Data Protection Act Compliance: Full compliance with Kenya's data protection regulations for rental data processed within Kenyan data centers
  • Cross-Border Data Transfer Mechanisms: Appropriate safeguards for transfers to countries without adequacy decisions
  • Data Processing Agreements: Contractual commitments from all infrastructure providers ensuring compliance with applicable data protection laws
6

Cookies & Tracking Technologies

We use cookies, web beacons, and similar technologies to enhance functionality, analyze usage, and personalize experiences across Nesthub platforms.

Cookie Categories: Essential (required for login and payments), Functional (preferences like default property), Analytics (performance monitoring), and Marketing (optional for rental recommendations). You can manage cookie preferences through browser settings or our cookie consent tool.

7

Data Retention Policy

We retain personal information for as long as your account is active or as needed to provide services. Retention periods: active lease data (duration of tenancy + 7 years for legal compliance), payment transactions (7 years for tax purposes), maintenance records (3 years), security logs (12 months), and backups (90 days). After retention periods expire, data is securely deleted or anonymized. Former tenants may request data deletion after 24 months of lease termination.

8

Your Privacy Rights

Depending on your jurisdiction (GDPR, CCPA, Kenya Data Protection Act, etc.), you may have rights to access, correct, delete, restrict processing, data portability, object to processing, and withdraw consent. Landlords and tenants have equal rights under this policy. To exercise rights, contact privacy@xfixglobal.com. We respond within 30 days. Tenants may also request redaction of sensitive information from lease documents.

9

Children's Privacy & Student Housing

Nesthub is not intended for children under 13 (or under 16 in certain jurisdictions). For student housing, we may collect information from students aged 16+ with parental or institutional consent where required. We do not knowingly collect personal information from children under 13. If we learn we have inadvertently collected such information, we will delete it promptly. Educational institutions using Nesthub for student housing must obtain proper consent from students or guardians.

10

Policy Updates & Notifications

We may update this Privacy Policy periodically to reflect changes in laws, rental regulations, or our practices. Material changes will be notified via email (30 days advance notice for landlords, 14 days for tenants), platform notifications, and website updates. The "Last Updated" date at the top reflects the latest revision. Continued use of Nesthub after changes constitutes acceptance of the updated policy. Significant changes affecting tenant rights will require explicit acknowledgment.

Contact Nesthub Global

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, our dedicated privacy team is here to help landlords, tenants, and property managers.

πŸ“§ Privacy & Data Protection

Email: privacy@xfixglobal.com

Data Protection Officer: dpo@xfixglobal.com

πŸ’¬ Tenant/Landlord Support

Tenants Support: tenants@xfixglobal.com

Landlord Support: landlords@xfixglobal.com

πŸ“ Physical Address

c/o Xfix Global Limited, Nairobi, Kenya | Remote Global Operations

🌐 Online Resources

Website: https://nesthub.xfixglobal.com

Security Reports: security@xfixglobal.com

For privacy-related complaints, you may also contact your local data protection authority or housing tribunal. We are committed to resolving any concerns promptly and transparently. As a product of Xfix Global Limited, we adhere to the highest enterprise standards for data protection.