1. Who you're contracting with
The service is operated by Tambua by Helloduty, a company registered in Nairobi, Kenya. Throughout this document "Tambua", "we" or "us" refers to that company. "You" refers to the entity using the API.
2. What we provide
Tambua provides programmatic verification (OTP) sending and verification across SMS, WhatsApp, Voice and Email channels, plus a console for managing apps, templates, webhooks and billing. Channels currently in coming soon status are not part of the service.
3. Acceptable use
- You must only send verification codes to phone numbers and email addresses you have consent to message.
- You may not use the API for marketing, promotional or transactional content unrelated to verification.
- You may not attempt to circumvent rate limits, route messages through inappropriate countries, or impersonate other businesses.
4. Billing
The service is pre-paid: you top up your app balance and we debit successful sends at the per-country rate published on the pricing page. Failed sends are not billed. We reserve the right to update rates with 30 days notice via the dashboard.
5. Termination
You may close any app at any time from the console. We may suspend an app for serious or repeated abuse; we will refund any unused balance.
6. Liability
The API is provided "as is". We do our best to keep delivery rates high and incidents short, but we are not liable for missed verifications, delayed deliveries or downstream business impact. Maximum liability in any 12-month period is capped at the fees paid by you to Tambua in that period.
7. Changes
Material changes to these terms will be announced via email to account owners at least 14 days before they take effect.
8. Data Processing
For data processed via the Tambua API, you (the Customer) act as the data controller and Tambua acts as a data processor. You determine why and how personal data is processed; Tambua processes it only on your documented instructions.
8.1 Scope
- Categories of data: phone numbers, email addresses, verification purposes, delivery metadata.
- Categories of data subjects: your end users being verified.
- Purpose: sending and verifying one-time codes on your behalf.
- Duration: lifetime of your Tambua account plus a 30-day log retention window.
8.2 Security measures
Technical and organisational measures are described on our security page. Highlights: encryption in transit and at rest, per-app JWT secrets, HMAC-signed webhooks, role-based access in the console.
8.3 International transfers
Tambua operates from Nairobi, Kenya. Where messages must transit through subprocessors located outside Kenya, transfers rely on standard contractual clauses or equivalent safeguards.
8.4 Audit rights
Once per 12 months, with reasonable notice, the Customer may audit Tambua's compliance with these terms. Audits are usually satisfied by sharing our latest security documentation; on-site audits are available for enterprise customers.
8.5 Signing a separate DPA
If your organisation requires a counter-signed copy of these data-processing terms as a stand-alone document, email legal@tambua.me.
9. Subprocessors
The third parties below help Tambua deliver verifications. We notify customers via the dashboard at least 14 days before adding a new subprocessor — if you object, contact legal@tambua.me within that window.
| Subprocessor | Purpose | Region |
|---|---|---|
| Advanta SMS | SMS delivery — Kenya | Nairobi, KE |
| Vercel | Application hosting and CDN | Global edge |
| Supabase | Postgres database + auth | eu-west / af |
Beyond the subprocessors above, each verification is routed through a per-country mobile carrier (e.g. Safaricom, MTN, Airtel) to reach the recipient's SIM. Carriers are common carriers acting on the routed message only.
10. Contact
Questions: legal@tambua.me.