TNL HOLDINGS LIMITED – PRIVACY POLICY

  1. Introduction

TNL Holdings Limited (“TNL”, “we”, “us”, or “our”) is committed to protecting your privacy and ensuring that your personal data is processed lawfully, transparently, and securely.

This Privacy Policy explains how we collect, use, disclose, store, and protect your personal data when you interact with us through our websites, branches, digital platforms, or when you purchase products or services from any of our subsidiaries.

This Policy Applies to customers, employees, job applicants, contractors, consultants, interns, associates, business partners and any individuals whose personal data is processed by TNL Group.

By providing personal data to us—whether online, through our offices, or via telephone—you acknowledge that you have read and understood this Policy.

  1. Who We Are

TNL Holdings Limited is a Kenyan holding company headquartered at:

Industrial Area, Bandari Road, Warehouse 04
P.O Box 74093 – 00200,

Nairobi, Kenya

TNL Holdings Limited (“the Group”) oversees the management and operations of the following subsidiaries in Kenya:

  1. TNL Motors Limited – Commercial vehicle sales, trailers, cargo tuk-tuks (Bomba Africa), and automotive financing partnerships.
  2. Happy Feeds Limited – Animal nutrition and agricultural products.
  3. Transport and Lifting Services Limited – Logistics, lifting services, and fleet support.
  4. Casuarina Limited – Real estate and property development.

Group Data Governance

TNL Holdings Limited and its subsidiaries operate under a unified data governance framework.

Depending on the nature of processing:

  1. A subsidiary may act as an independent Data Controller;
  2. TNL Holdings Limited and one or more subsidiaries may act as Joint Controllers: or
  • An entity may act as a Data Processor on behalf of another group entity.

Where personal data is shared within the TNL Group:

  1. Such sharing is conducted for legitimate business purposes;
  2. All entities adhere to this Privacy Policy and applicable data protection laws;
  • Appropriate internal data-sharing safeguards are implemented to ensure confidentiality and security.

This unified policy governs all intra-group processing activities.

  1. Definitions

For purposes of this Policy:

  1. CRB: Credit Reference Bureau
  2. Data Controller: Entity determining the purpose and means of processing.
  • Data Processor: Entity processing personal data on behalf of a controller
  1. Data Subject: An individual whose personal data is processed
  2. ODPC: Office of the Data Protection Commissioner of Kenya
  3. Personal Data: Information relating to an identified or identifiable natural person
  • Processing: Collection, recording, storage, use, disclosure, or deletion of data
  • Sensitive Personal Data: Includes financial data, biometric data, health data, and location data.
  1. Personal Data We Collect

We may collect and process the following categories of personal data:

  1. Ordinary Personal Data
  1. Identification: Name, National ID/Passport, KRA PIN, Driving Licence
  2. Contact: Phone number, email address, postal address, location
  3. Employment/Business: Company name, title, role, fleet details
  4. Transaction Data: Purchase history, service records, payment details
  5. Digital Data: IP address, device identifiers, cookies, analytics data
  6. Communication Records: Queries, complaints, call logs, support tickets
  7. Surveillance data: CCTV footage and access control records.
  1. Sensitive Personal Data

(Processed only where strictly necessary and with additional safeguards)

  1. Financial details used for credit facilities
  2. Biometric data (where applicable e.g., telematics or access control)
  3. Location and behavior data from vehicle tracking systems (SPOT)

Sensitive data is processed only with explicit consent or where otherwise permitted by law.

  1. How We Use Your Personal Data
  2. We process your personal data for the following purposes:
  1. Processing purchases, quotations, financing requests, and vehicle registrations
  2. Providing after‑sales support, warranties, servicing, and maintenance
  3. Enabling GPS, telematics and SPOT Tracking services for safety, compliance, and performance monitoring
  4. Meeting legal and regulatory obligations (tax, transport, compliance audits)
  5. Improving our systems, customer experience, and product offerings
  6. Conducting marketing, promotions, or surveys (with your consent)
  7. Fraud prevention, risk management, security and internal investigations
  1. We do not process your data for purposes incompatible with the original collection purpose unless required by law.
  2. Legal Basis for Processing
  3. We process personal data based on one or more lawful bases under the Data Protection Act (2019):
  1. Performance of a Contract – sales, service, or financing
  2. Legal Obligation – statutory compliance and reporting
  3. Legitimate Interests – service improvement, analytics, fraud detection
  4. Consent – marketing communications, telematics tracking, sensitive data
  5. Public Interest – safety‑related disclosures to authorities
  1. You may withdraw consent at any time.
  2. Automated Decision-Making

TNL may use automated or semi-automated systems in:

  1. Job applicant evaluations.
  2. Credit assessments and financing decisions (including CRB checks).
  3. Fraud detection and risk profiling.

Where decisions significantly affect individuals:

  1. They are not based solely on automated processing without human review.
  2. You may request human intervention.
  3. You may contest decisions and request explanations.
  1. Sharing & Disclosure of Data
  2. We may share your data with trusted entities where necessary:
  1. Financial partners and banks for financing
  2. Licensed dealers, workshops, and service providers
  3. Logistics, insurance, and risk‑management partners
  4. Technology and cloud service providers (CRM, email, hosting, telematics)
  5. Government agencies and regulators where required by law
  6. Subsidiaries within TNL Group under confidentiality and data‑processing agreements
  1. When sharing data with third parties, we ensure:
  1. Data Processing Agreements (DPAs) are in place
  2. Third parties act only on our instructions
  3. Appropriate security controls are maintained
  1. We do not sell, rent, or trade your personal data.
  2. International Data Transfers

Where personal data is transferred outside Kenya, we ensure:

  1. ODPC‑approved safeguards
  2. Contractual clauses ensuring data protection
  3. Transfers only to jurisdictions offering adequate protection
  1. Data Retention
  2. We retain your data only for as long as necessary:
  1. To fulfil contractual obligations
  2. To comply with tax, regulatory, and audit requirements
  3. To resolve disputes or enforce agreements
  1. When no longer required, data is securely deleted or anonymized.
  2. Data Security

We implement administrative, technical, and physical security measures, including:

  1. Encryption and secure servers
  2. Access control and staff confidentiality agreements
  3. Regular system monitoring and updates
  4. Secure disposal protocols
  1. Data Subject Rights

Under the Data Protection Act (2019), you have the right to:

  1. Be informed how your data is processed
  2. Access your personal data
  3. Request correction of inaccurate or incomplete data
  4. Request erasure (subject to legal limitations)
  5. Restrict processing
  6. Object to direct marketing or processing based on legitimate interests
  7. Withdraw consent
  8. Request data portability

We respond to requests within 7 days, extendable to 14 with justification.

Submit requests to:
📩 info@tnl.co.ke
Subject Line: Data Protection Request

  1. Cookies & Tracking Technologies

Our websites may use cookies and tracking technologies to:

  1. Improve navigation
  2. Measure performance and usage patterns
  3. Personalize marketing content

You may decline cookies through browser settings, but certain features may be limited.

  1. Data Breach Notification

In the event of a data breach:

  1. TNL will notify the Office of the Data Protection Commissioner (ODPC) within 72 hours.
  2. Affected individuals will be informed without undue delay if the breach poses a risk to their rights or freedoms.
  1. Children’s Data

We do not intentionally collect data from persons under 18 without verifiable parental or guardian consent.

We implement age verification measures as necessary.

  1. Contact Us

For questions, complaints, or concerns about data protection:

Legal Counsel
TNL Holdings Limited
Industrial Area, Bandari Road, Warehouse 04
Nairobi, Kenya
📩 legal@tnl.co.ke

  1. Updates to This Policy

We may update this Policy periodically. Any changes will be posted on our website with a revised “Last Updated” date.

Last Updated: 19th January 2026