Acceptable Use Policy
Plain language summary: Risiti is for genuine, authorized business and tax records. Do not submit fake invoices, credit notes, purchases, stock movements, supplier records, consent records, or buyer-initiated invoices. Do not lend an identity or API key to another person. Misuse can result in blocked requests, immediate suspension, API-key revocation, permanent removal without refund, and reporting where required or permitted by law.
1. Permitted Use
Risiti is designed for legitimate compliance operations: recording and transmitting genuine business transactions and related eTIMS records for authorized Kenyan businesses.
You are permitted to use Risiti for:
- Issuing eTIMS-compliant invoices for goods sold or services rendered to customers in Kenya.
- Registering your inventory items with KRA via the item catalog feature.
- Sharing KRA-verified invoices with your customers via SMS, WhatsApp, or PDF download.
- Checking the eTIMS compliance status of your suppliers.
- Exporting your invoice data for your own record-keeping, accounting, or tax filing.
- Using invoice templates to speed up invoicing for recurring customers or product types.
- Issuing credit notes for genuine corrections, returns, cancellations, or refunds against the correct original invoice.
- Maintaining accurate supplier purchases, item catalogues, and stock movements supported by real commercial records.
- Using buyer-initiated invoicing only where the buyer and seller are eligible, authorized, and have completed the declarations and consent required by KRA.
2. Prohibited Use
The following uses are strictly prohibited and constitute grounds for immediate account suspension, reporting to authorities, and civil or criminal legal action.
- Fraudulent invoicing. Issuing invoices for transactions that did not occur, for inflated amounts, for fictitious goods or services, or for the purpose of creating false business records.
- Tax evasion. Using Risiti to facilitate, conceal, or assist in any form of tax evasion or manipulation of tax records, in violation of the Tax Procedures Act, 2015.
- Money laundering. Using invoice records to disguise the proceeds of criminal activity, in violation of the Proceeds of Crime and Anti-Money Laundering Act, 2009.
- Unauthorized account sharing. Sharing your Risiti account credentials with third parties who are not authorized representatives of your registered business.
- Platform abuse. Attempting to hack, reverse-engineer, scrape, exploit, or disrupt the Risiti platform, its APIs, or underlying infrastructure, in violation of the Computer Misuse and Cybercrimes Act, 2018.
- Malware or cyberattacks. Using the platform to transmit malicious code, viruses, or to conduct cyberattacks against KRA, Safaricom, other users, or any third party.
- Unauthorized resale. Reselling, sublicensing, or providing third-party access to Risiti's features or your account without PesaStack's prior written consent.
- False identity or misrepresentation. Registering with false KRA PIN credentials, impersonating another business, or misrepresenting your identity or business type.
- Automated abuse. Using bots, scripts, or automated tools to bulk-generate invoices, scrape data, or spam the platform in ways that degrade service for other users.
- False supporting records. Creating or transmitting false, inflated, backdated, duplicated, or misleading credit notes, purchases, supplier records, item records, stock movements, returns, refunds, or consent records.
- Unauthorized buyer-initiated invoicing. Creating an invoice for a seller without lawful authority, eligibility, required declarations, or seller consent, or using the workflow to bypass VAT or eTIMS rules.
- Control circumvention. Bypassing or attempting to bypass sandbox separation, production approval, subscriptions, API scopes, rate limits, idempotency, validation, account suspension, security controls, or KRA eligibility checks.
- Unauthorized data use. Submitting another person's KRA PIN, business identity, personal data, invoices, or transaction records without a lawful basis and appropriate authority.
3. Consequences of Misuse
If PesaStack determines, in its reasonable judgment, that you are violating this Acceptable Use Policy:
- Immediate containment: We may block requests, revoke API keys, disable live access, or suspend the account and affected connected businesses without notice while we investigate.
- Permanent termination: Verified or serious misuse may result in permanent removal from Risiti with no refund of subscription fees.
- Record preservation: We may preserve relevant request, consent, submission, security, and audit records for investigation, legal compliance, and the protection of users and third parties.
- Reporting to KRA: We may report suspected fraudulent or abusive eTIMS activity to KRA where required or permitted by law.
- Reporting to law enforcement: Where misuse may involve criminal conduct, we may report it to the Directorate of Criminal Investigations or another competent authority where required or permitted by law.
- Civil liability: PesaStack reserves the right to pursue civil damages for any losses incurred as a result of your misuse of the platform.
4. Reporting Misuse
If you believe another user is misusing Risiti — including fraudulent invoicing or impersonating a business — please report it to us immediately:
- Email: hello@getrisiti.com (subject: "Misuse Report")
- All reports are treated confidentially. We will investigate and take appropriate action.
5. Updates to This Policy
PesaStack may update this Acceptable Use Policy as the Service evolves or as Kenyan law requires. Material changes will be communicated via email and in-app notification with at least 30 days' notice. Continued use of Risiti constitutes acceptance of the updated policy.