Legal
Privacy Policy
This Privacy Policy explains how Vanguard BI operates Moja and handles personal data when you create, manage, share, or view a digital business card.
Effective date: July 22, 2026
1. Who We Are
Moja is a digital business card service operated by Vanguard BI ("Vanguard BI", "Moja", "we", "us", or "our"). For data protection purposes, we are generally the data controller, responsible party, or data controller equivalent for personal data we collect to provide and operate Moja.
If an organisation uses Moja to create or manage cards for its staff, that organisation may also be an independent controller or responsible party for the personal data it decides to place on those cards. In that case, we may act as a processor or operator for some processing activities, subject to the agreement with that organisation.
Contact for privacy requests: privacy@vanguard.bi.
2. Scope
This Policy applies to Moja websites, card pages, account features, QR code features, lead forms, support communications, authentication emails, product emails, and related services that link to this Policy. It does not apply to websites, apps, or services operated by third parties, even if they are linked from Moja.
We have written this Policy with the EU and UK GDPR principles, Kenya's Data Protection Act, 2019 and related regulations, and South Africa's Protection of Personal Information Act, 2013 (POPIA) in mind. Where a law gives you stronger rights than this Policy, that law controls.
3. Personal Data We Collect
We collect personal data in the following categories.
- Account and authentication data: your name, email address, authentication provider, Firebase user ID, sign-in status, and magic-link delivery information.
- Card content: the details you choose to add to a card, such as first name, last name, job title, company, phone numbers, email addresses, links, addresses, profile photo, cover image, brand colour, and similar contact or professional information.
- Public card data: the card content published at your share link and encoded into or associated with your QR code. This information is intended to be viewed by people with the link or QR code.
- Usage and analytics data: events such as card creation, card publishing, link copying, page views, view counts, approximate device/browser data, referrer, and general interaction data.
- Lead and enquiry data:information you submit through a card's optional contact form or when asking Vanguard BI to contact you, such as name, phone number, work email address, the card used, company, team size, current email provider, product interest, consent, and campaign source.
- Support and communications data: messages, attachments, feedback, requests, and records of our responses.
- Technical and security data: IP address, logs, device identifiers, error reports, timestamps, and information needed to protect the service from abuse, fraud, or unauthorised access.
We do not intentionally collect special category or sensitive personal data, such as health information, race, religion, political opinions, biometric identifiers, or information about children. Please do not add such information to your card unless it is necessary, lawful, and you understand that published card content may be visible to others.
We do not currently collect payment card details through Moja. If we introduce paid plans or paid services, payment details will be handled by a payment provider and will be covered by additional notices where required.
4. How We Collect Personal Data
- Directly from you when you create an account, build a card, upload images, submit a form, contact us, or request a magic link.
- Automatically when you use Moja, through logs, analytics, cookies or similar technologies, and security tools.
- From authentication and infrastructure providers that help us confirm your identity and operate the service.
- From an organisation that creates or manages cards for its employees, contractors, or representatives.
- From people who interact with your card, for example through aggregated view counts or technical request logs.
5. Why We Use Personal Data
We process personal data for these purposes:
- To create, publish, host, display, update, and delete digital business cards.
- To generate and support share links, QR codes, and vCard downloads.
- To authenticate users and secure accounts.
- To enforce the card limit and other product rules.
- To send service emails, including sign-in links, account notices, and first-card onboarding emails.
- To deliver card-form leads to the relevant card owner and, for managed cards, their organisation.
- To notify card owners when someone shares contact details through their card.
- To respond to enquiries, support requests, and requests for business services from Vanguard BI.
- To measure product usage, improve Moja, understand which features are useful, and troubleshoot errors.
- To prevent spam, fraud, misuse, unauthorised access, and security incidents.
- To comply with legal obligations, enforce our terms, resolve disputes, and protect our rights and the rights of others.
- To provide information about Vanguard BI services where permitted by law or with your consent where consent is required.
6. Lawful Bases
Depending on where you are located and the activity involved, we rely on one or more of these lawful bases or equivalent grounds under applicable law:
- Performance of a contract: to create your account, provide Moja, publish cards, support QR codes, and maintain your card links.
- Consent: where required for certain analytics, marketing, optional communications, or processing that depends on your clear permission. You may withdraw consent at any time.
- Legitimate interests: to secure the service, improve product functionality, prevent abuse, communicate with users about the service, and understand business interest, where those interests are not overridden by your rights.
- Legal obligation: to comply with applicable laws, lawful requests, record-keeping duties, and regulatory obligations.
- Pre-contractual steps: to respond when you ask us to contact you about Moja, printed cards, Google Workspace, cloud, analytics, or other Vanguard BI services.
7. Public Nature of Card Pages
Moja is designed for sharing contact details. When you publish a card, the information on that card can be accessed by people who receive the link or scan the QR code. They may save the details to their contacts, forward the link, screenshot the page, or otherwise use the information outside Moja.
You control what you place on your card. Do not publish private, confidential, sensitive, or third-party information unless you have the right to do so. If you delete a card, the Moja link and QR code for that card stop working, but we cannot delete copies that others already saved, downloaded, cached, printed, screenshotted, or shared outside Moja.
8. Your Responsibility for Accuracy and Permissions
You decide what information appears on your card. You are responsible for keeping it accurate, current, and lawful. If you add another person's details, a team member's details, a company logo, a photograph, or a third-party link, you must have the right and lawful basis to do so.
If your organisation manages cards for employees, contractors, or representatives, the organisation is responsible for giving them appropriate privacy notices and ensuring that published card content is authorised, accurate, and not excessive for the intended purpose.
9. Cookies, Local Storage, and Similar Technologies
We may use cookies, local storage, SDKs, pixels, and similar technologies to keep you signed in, remember draft information, secure the service, measure usage, and improve the product. Some technologies are necessary for the service to work. Others, such as analytics or marketing technologies, are used where permitted by law or with consent where consent is required.
These technologies may include:
- Strictly necessary storage: authentication state, security tokens, session information, and settings needed to operate Moja.
- Draft and preference storage: local browser storage that helps preserve a draft card, sign-in email, or interface state on the device you are using.
- Analytics technologies: tools that help us understand aggregate product usage, feature performance, and errors so we can improve Moja.
- Attribution technologies: information such as campaign parameters, referrer, or source that helps us understand how people reached Moja or a Vanguard BI enquiry form.
- Meta measurement: with your permission, Moja uses the Vanguard BI Meta Pixel and Conversions API on marketing pages to measure page visits and successful Vanguard BI enquiry or callback submissions. Browser and server events are matched with an event identifier to avoid double counting. Meta may receive browser identifiers, IP address, user agent, source URL, and hashed contact details supplied with an enquiry.
- Security technologies: logs and signals used to prevent fraud, spam, abuse, and unauthorised access.
You can control cookies through your browser settings. Blocking some technologies may affect sign-in, draft saving, analytics, or other functionality.
Some browsers send "Do Not Track" or similar signals. At this time, Moja does not respond to every such signal in a uniform way because there is no single universally accepted technical standard. Where legally required consent or opt-out mechanisms apply, we will honour them.
10. How We Share Personal Data
We share personal data only when there is a valid reason.
- With people who receive your card link or QR code: published card content is available to those viewers.
- With service providers: hosting, database, authentication, storage, analytics, email delivery, CRM, security, monitoring, and support providers process data for us under appropriate contractual controls.
- With Vanguard BI business tools: enquiries and leads may be recorded in our CRM so we can follow up.
- With a card owner or their organisation:when you knowingly submit the optional contact form on a card, your name, phone number, work email, consent record, and card attribution are shared with that card's owner and, for a managed team card, the organisation responsible for the card.
- For legal and safety reasons: we may disclose data if required by law, court order, regulator, lawful government request, or to protect rights, safety, and security.
- In a business transfer: if Moja or Vanguard BI is involved in a merger, acquisition, financing, restructuring, or sale of assets, data may be transferred subject to appropriate safeguards.
We do not sell personal data. We do not allow service providers to use personal data for their own unrelated purposes.
11. Service Providers and Sub-Processors
We use carefully selected providers to run Moja. The exact providers may change as the product develops, but the main categories include:
- cloud hosting, database, storage, and serverless function providers;
- authentication providers;
- email delivery providers for magic links and service emails;
- analytics, measurement, and error-monitoring providers;
- CRM and lead management providers for Vanguard BI enquiries;
- security, logging, anti-abuse, and operational tooling;
- professional advisers, auditors, and compliance support where needed.
We require providers that process personal data for us to use it only as instructed, keep it confidential, apply appropriate security measures, and assist with data protection obligations where applicable.
12. International Transfers
Moja uses cloud, email, analytics, and business systems that may process data in countries other than where you live, including Kenya, South Africa, the United States, the European Economic Area, and other locations where our providers operate.
When personal data is transferred internationally, we use safeguards required or recognised by applicable law where needed. These may include data processing agreements, contractual transfer safeguards, standard contractual clauses, adequacy decisions, transfer risk assessments, technical and organisational measures, and equivalent protections required by Kenya's Data Protection Act, POPIA, and GDPR-style rules.
13. Data Minimisation and Accuracy
We aim to collect only the personal data that is reasonably needed for the purposes described in this Policy. The builder lets you choose what to publish, and optional fields can be left blank. We encourage you to publish only the contact details that are useful for the audience receiving the card.
You can update your card when your details change. Because shared links and QR codes may be printed or forwarded, keeping published information current helps reduce confusion and unnecessary processing of outdated personal data.
14. Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.
- Account data is kept while your account is active and for a reasonable period afterwards for security, legal, and operational reasons.
- Published card data is kept until you delete the card, your account is closed, or we remove it under our Terms or applicable law.
- Deleted card links stop working, but backups, logs, and security records may retain limited information for a restricted period.
- Lead and enquiry records are kept as long as needed to respond, manage the business relationship, and comply with legal obligations.
- Analytics and technical logs are kept for limited periods appropriate to security, troubleshooting, measurement, and improvement.
- Legal, tax, compliance, dispute, and abuse-prevention records may be kept for longer where necessary.
15. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, authentication, encryption in transit where supported, cloud provider security controls, logging, monitoring, least-privilege access, and administrative safeguards.
No online service is perfectly secure. You are responsible for keeping your account access secure, using trusted devices, and publishing only information you are comfortable sharing.
16. How Information Is Stored and Protected
Moja stores card and account-related data in managed cloud services rather than on personal devices controlled by Vanguard BI staff. Published cards are stored so the public card page can be served from the share link. Account and operational records are stored in systems used for authentication, hosting, email delivery, analytics, support, and business follow-up.
We separate access based on purpose. Public card content is intentionally available through its link or QR code. Account, operational, lead, and administrative data are restricted to authorised systems and people who need access for service, security, support, legal, or business purposes.
Protective measures may include managed cloud security controls, encryption in transit, encryption at rest where provided by the cloud platform, authentication controls, Firestore security rules, role-based access, access logging, backups, least-privilege permissions, operational monitoring, and review of unusual activity.
Security also depends on you. Use a secure email account, protect devices used to sign in, avoid forwarding magic links, and remove or update card details you no longer want to share.
17. Data Breaches
If we become aware of a personal data breach or security compromise that requires notification, we will notify affected people and/or relevant regulators as required by applicable law. Depending on the circumstances, this may include the Kenya Office of the Data Protection Commissioner, the South African Information Regulator, an EU/EEA supervisory authority, or another competent authority.
18. Your Rights
Depending on your location and the law that applies, you may have rights to:
- be informed about how your personal data is processed;
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion or erasure of data, subject to legal limits;
- object to certain processing, including direct marketing;
- request restriction of processing;
- request portability of data you provided to us, where applicable;
- withdraw consent where processing is based on consent;
- object to decisions based solely on automated processing that produce legal or similarly significant effects;
- lodge a complaint with a competent data protection authority.
These rights are recognised in different forms under the GDPR, Kenya's Data Protection Act, and POPIA. They may be subject to identity verification, exceptions, and limits under applicable law.
To exercise a right, email privacy@vanguard.bi. Please include enough information for us to identify you and understand your request. We will respond within the timeframe required by applicable law.
19. Complaints
We would like the chance to resolve privacy concerns directly. You can contact us at privacy@vanguard.bi.
You may also have the right to complain to a regulator, including:
- Kenya: the Office of the Data Protection Commissioner at odpc.go.ke.
- South Africa: the Information Regulator at inforegulator.org.za.
- EU/EEA: your local data protection authority. The European Commission provides information about EU data protection rights at commission.europa.eu.
20. Children
Moja is intended for business and professional use. It is not directed to children. You must not use Moja if you are below the age at which you can lawfully enter into these Terms or consent to data processing in your jurisdiction, unless a parent, guardian, or authorised organisation has validly arranged the use. We do not knowingly collect personal data from children without appropriate authority.
21. Direct Marketing
We may contact you about Moja or Vanguard BI services where permitted by law, based on consent or another lawful basis. You can opt out of marketing emails by using the unsubscribe link where available or by contacting us. Service emails, such as sign-in links, security notices, and important account messages, are not marketing and may still be sent.
22. Automated Processing and Profiling
We may use limited automated processing to support authentication, security, analytics, lead routing, spam prevention, and product operation. We do not use Moja to make decisions based solely on automated processing that produce legal or similarly significant effects about users.
We may use simple lead classification or routing to help Vanguard BI respond to enquiries efficiently. This does not determine your legal rights and does not prevent you from contacting us directly.
23. Third-Party Links and Integrations
Your card may include links to third-party websites, profiles, messaging apps, maps, and email or phone actions. Third-party services process data under their own terms and privacy policies. We are not responsible for their privacy practices.
24. Business Changes
If Vanguard BI reorganises, merges, sells assets, raises financing, transfers Moja, or enters a similar business transaction, personal data may be reviewed or transferred as part of that transaction. We will use reasonable measures to ensure that personal data remains protected and continues to be handled consistently with this Policy or a policy that provides materially similar protection.
25. Changes to This Policy
We may update this Policy from time to time. If changes are material, we will take reasonable steps to notify users, such as by updating the effective date, posting a notice, or sending an email. Your continued use of Moja after an update means the updated Policy applies from its effective date.
26. Regulatory References
This Policy was prepared with reference to public guidance and legal materials from the European Commission, Kenya's Office of the Data Protection Commissioner, and South Africa's Information Regulator. Only the applicable laws and authoritative decisions of competent regulators or courts create binding obligations.