Privacy Policy
This Privacy Policy explains how we collect, use, disclose and protect personal information in connection with our services. It is written to comply with the Data Protection Act, 2019 of Kenya and related regulations.
1. Data Controller
For the purposes of the Data Protection Act, 2019, the data controller is the operator of this website and service. If you need to contact the controller about privacy matters, use the contact details at the end of this policy.
2. Information We Collect
We collect the following categories of personal data:
- Identity data (name, username).
- Contact data (email address, phone number, postal address).
- Account and authentication data (password hashes, login timestamps).
- Usage data (pages viewed, features used, timestamps, IP address, device/browser information).
- Communications (messages you send to us for support or via the service).
- Payment and billing data where applicable (billing name, payment method details — we do not store full card numbers; payments are processed by third-party providers).
3. How We Collect Data
- Directly from you when you register, update your account or contact support.
- Automatically when you use the service (logs, cookies and similar technologies).
- From third parties where you have authorised them to share data with us (e.g. payment processors, integrations).
4. Purposes and Legal Basis for Processing
We process your personal data for lawful purposes including:
- Providing and operating the service, and managing your account (performance of a contract).
- Communicating with you about your account, updates and support (consent or contractual necessity).
- Fraud prevention, security and to meet legal obligations (legal obligation and legitimate interests).
- Improving the service and for analytics (legitimate interests and/or consent where required).
- Marketing communications where you have opted in (consent). You may opt out at any time.
5. Cookies and Tracking
We use cookies and similar technologies to operate the site, remember your preferences and analyse usage. You can control cookies through your browser settings. Essential cookies required to provide the service will not be disabled without affecting the service.
6. Disclosure and Sharing
We may share personal data with: service providers (hosting, payments, analytics), legal and regulatory authorities where required by law, and other parties with your consent. We require third parties to provide appropriate safeguards and to process data only on our instructions.
7. International Transfers
Personal data may be transferred or accessed outside Kenya where our providers operate. Where data is transferred internationally we use appropriate safeguards (standard contractual clauses, security controls, or rely on permitted exceptions under applicable law) to ensure an adequate level of protection.
8. Data Retention
We retain personal data only as long as necessary to fulfil the purposes listed above, to comply with legal obligations, resolve disputes and enforce agreements. Retention periods vary by data category — if you need a specific retention period for a category of your data please contact us (see Contact section).
9. Security
We implement reasonable technical and organisational measures to protect personal data from unauthorised access, loss, alteration or destruction. However, no system is completely secure — if you suspect a security breach affecting your personal data, please contact us immediately.
10. Your Rights (under the Data Protection Act, 2019)
Under Kenyan law, you have rights in relation to your personal data. These include the right to:
- Access: request confirmation whether we are processing your personal data and obtain a copy.
- Correction: have inaccurate data corrected without undue delay.
- Erasure (right to be forgotten): request deletion where processing is no longer necessary or you have withdrawn consent and there is no other legal basis for processing.
- Object: object to processing based on our legitimate interests (we will review and either stop or justify continued processing).
- Restriction: request restriction of processing while a dispute is resolved.
- Portability: obtain a copy of your data in a commonly used, machine-readable format where applicable.
- Lodge a complaint with the Office of the Data Protection Commissioner of Kenya:
Office of the Data Protection Commissioner
P.O. Box 49510‑00100, Nairobi, Kenya
https://www.odpc.go.ke
11. Exercising Your Rights
To exercise any of the rights above, please contact our data protection contact (see Contact section). We will respond in accordance with the Data Protection Act and applicable timelines. We may request identity information before fulfilling a request to protect your data and privacy.
12. Children
Our services are not intended for children under 13 (or the age required by local law). We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us and we will take steps to delete the information and terminate the account where appropriate.
13. Changes to This Policy
We may update this policy from time to time. We will post the updated policy on this page with a revised effective date. Where required by law, we will provide notice of material changes and obtain consent if necessary.
14. Contact
If you have questions, wish to exercise your rights or make a complaint, contact:
Data Protection Contact
Email: privacy@kasilabs.com
Effective date: 10 November 2025