Two kinds of data reach us: what you type into the application form, and the invoices your system sends once you are live. They are treated differently.
VeTims is a service of Vutia Enterprises, Nairobi, Kenya. For the application form we are the data controller: we decide what is asked and why. For the invoices your system sends us we are a data processor acting on your instructions — the data is yours, we hold it to fiscalize it and to show it back to you.
Questions, requests and complaints: hello@ve.ke.
So we know who applied and how to reply.
Optional on the form. It is what a device is registered under, so we ask for it early.
To size and provision the right sandbox setup.
To configure where signed results are sent.
Only what you choose to tell us.
Kept to detect abuse of a public form. Nothing else is read from it.
Which page of this site sent you to the form, so we know which ones are worth writing. No cross-site tracking, no profile.
We use it to answer you and to set up a pilot, and for nothing else. We do not send marketing, and we do not pass it to anyone for theirs. An application that does not become an account is deleted after twelve months.
The sale itself. This is what gets signed.
Optional per invoice. The PIN is what lets a business customer claim input VAT.
Signature, internal data, CU invoice number and QR payload, returned to you and retained as the record of the signing.
Invoice data is processed to fiscalize the invoice and to show it back to you in the console and over the API. It is never used to build a profile, sold, or shared with anyone but KRA, which receives what the law requires it to receive. Fiscal records are immutable by design — a signed invoice is a tax record, so it is kept for as long as your account is live and as long as Kenyan tax law requires afterwards. We will sign a data processing agreement on request.
KRA
The point of the service. Invoices are transmitted to eTIMS to be signed.
Mailjet
Delivers our email. It handles the address we write to and the contents of that message.
Our own servers
Run by us. Device keys are encrypted at rest and API tokens are stored hashed.
No one else
No advertising networks, no data brokers, no third-party analytics on this site.
This site sets the session and CSRF cookies it needs to work, and no others. There are no tracking or advertising cookies, and no consent banner, because there is nothing to consent to.
Ask what we hold about you, and get a copy.
Have anything inaccurate corrected.
Ask us to delete it, where we are not required to keep it.
Object to a use, or ask us to restrict it.
Receive it in a portable form.
Complain to the Office of the Data Protection Commissioner.
Write to hello@ve.ke and we will answer within thirty days. If the data is your customers' and reached us through a client's system, ask that client first — we act on their instructions and will refer you to them.
Last reviewed August 2026. Material changes will be dated here.
Write to us with what your system does. We reply with a token, a device and a working example against the KRA sandbox.