This Privacy Policy explains how [Company Name] ("we", "us", "our"), operating this HR management platform ("the Service"), collects, uses, stores, and protects personal data belonging to client organisations ("Client", "you") and their employees, in line with the Data Protection Act, 2019 (the "DPA"), its subsidiary regulations, and Article 31 of the Constitution of Kenya, 2010.
Where a Client uses the Service to manage its own employees' records (attendance, leave, timesheets, payroll, performance, and related HR data), the Client is the data controller of that employee data, and we act as a data processor on the Client's instructions. For account, billing, and platform-usage data relating to the Client organisation itself, we act as the data controller.
Depending on how the Service is used, we (or the Client, as controller) may collect:
Personal data is processed on one or more lawful bases recognised under section 30 of the DPA: performance of the employment or client contract, compliance with a legal obligation (for example, statutory payroll reporting to the Kenya Revenue Authority, NSSF, or SHA), the Client's legitimate interests in managing its workforce, or, where required, the data subject's consent.
In line with section 25 of the DPA, personal data processed through the Service is:
We use collected information to operate and improve the Service, process payroll and statutory calculations, provide customer support, detect and prevent misuse, and communicate important account or billing updates. We do not use Client employee data for our own marketing purposes.
We do not sell personal data. Information may be shared with sub-processors who help us operate the platform (for example, hosting or payment providers), under written data processing terms, or disclosed where required by Kenyan law or a lawful order of a competent authority. Where personal data is transferred or stored outside Kenya, we do so only where the recipient country has adequate data protection safeguards, appropriate contractual clauses are in place, or another basis recognised under section 48 of the DPA applies.
We apply reasonable technical and organisational measures — including access controls, encryption in transit, and role-based permissions — to protect personal data processed through the Service, consistent with the security obligations in section 41 of the DPA.
In the event of a personal data breach that is likely to result in risk to the rights and freedoms of data subjects, we will notify the affected Client (as controller) without undue delay, and will support the Client in meeting its own obligation to notify the Office of the Data Protection Commissioner ("ODPC") within 72 hours of becoming aware of the breach, and affected data subjects without undue delay where the breach poses a high risk, as required under the Data Protection (General) Regulations, 2021.
We retain organisation and employee data for as long as the Client's account is active, or as needed to meet statutory retention obligations (for example, payroll and tax records under Kenyan employment and tax law), after which data is deleted or anonymised in accordance with the Client's instructions and applicable law.
Under section 26 of the DPA, data subjects have the right to: be informed of how their personal data is used; access their personal data; object to processing; request correction of false or misleading data; and request deletion of false or misleading data about them. Employees should direct such requests to their employer (the data controller) in the first instance; the Client should direct requests concerning organisation-level data to us. Requests are handled within the timeframes prescribed under the Data Protection (General) Regulations, 2021.
Where a data subject is a minor or has a disability affecting their capacity to exercise these rights directly, the rights above may be exercised on their behalf by a parent, guardian, or duly authorised representative, as provided under section 27 of the DPA.
If you believe your personal data has been processed unlawfully, you may lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at www.odpc.go.ke, in addition to any complaint you raise with us directly.
We may update this Privacy Policy from time to time to reflect changes in the law or our practices. The "Last updated" date at the top of this page shows when it was last revised. Continued use of the Service after changes are posted constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy, or wish to exercise a data subject right, please contact us through the details provided on our website.