Miliki Office
Policies & User Agreement
Version 2026-05-25, effective 25 May 2026. These operating policies support internal controls for client, property, financial, title, document, and office records.
The policy is designed around prudent controls for high-value real estate transactions, sensitive personal data, payment records, scanned identity documents, and audit evidence.
- Use Miliki Office only for authorised company work.
- Do not export, copy, or share client, title, payment, or identity records unless your role and the transaction require it.
- Verify payment, allocation, refund, title, and document actions before saving them.
- Expect system activity to be logged for audit, fraud prevention, and dispute handling.
- Report suspected incorrect records, unauthorised access, lost devices, or data exposure immediately.
Miliki Office is an internal operations system for authorised Milikispace personnel and approved representatives only.
Users must keep login credentials private, use strong passwords, sign out on shared devices, and must not allow another person to operate under their account.
Users are responsible for the accuracy of records they create or approve, especially client identity details, project allocations, payment records, refunds, title movements, and scanned documents.
The company may suspend access, review activity, and restrict roles where misuse, suspected compromise, or operational risk is detected.
The system stores personal, financial, property, and legal records needed to manage client relationships, projects, allocations, payments, documents, title processing, office operations, approvals, and audits.
Personal data should be collected and processed only for legitimate company purposes, using the minimum information needed for the task.
Client records, next of kin records, identity documents, KRA PIN details, payment evidence, title documents, and correspondence must be accessed only by users with a business need.
Data subjects may have rights to request access, correction, deletion, objection, or restriction where applicable under Kenyan data protection law and company policy.
Every payment, deposit, installment, service charge, title processing charge, refund request, adjustment, and receipt must be recorded accurately and traceably.
Users must not delete or alter financial evidence to hide mistakes. Corrections should be handled through approved reversal, adjustment, or audit workflows.
High-value or sensitive actions may require CEO, Managing Director, developer, or finance-authorised approval before completion.
Scanned IDs, passports, birth certificates, tax PINs, title deeds, allocation maps, mutations, legal company documents, bank documents, and client files are confidential.
Documents must not be downloaded, printed, sent by WhatsApp, email, or external links unless required for an authorised client, legal, banking, or operational process.
Physical document pickup, release, courier, and parcel movement records must include the responsible person and verification details.
The system may record access, changes, approvals, uploads, payment actions, document movement, title release, and operational events.
Users must report suspected unauthorised access, lost devices, exposed passwords, suspicious payment instructions, client disputes, and data leakage immediately.
Idle sessions are automatically signed out after 10 minutes to reduce the risk of unattended access.