Privacy Policy

Your privacy is our priority. Learn how we collect, use, and protect your personal information in compliance with Kenyan and international data protection laws.

Last updated: July 2025

1. Introduction

At Cognifitech, we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, and protect your information in accordance with the Kenya Data Protection Act 2019, the General Data Protection Regulation (GDPR), and other applicable international privacy laws.

2. Data Controller Information

Cognifitech Limited serves as the data controller responsible for your personal data. Our complete contact details are provided in the 'Contact Us' section at the end of this policy.

3. Information We Collect

Personal Information

We collect your name, email address, phone number, job title, company name, and business address when you contact us or request our services.

Technical Information

We automatically collect your IP address, browser type, device information, operating system, and website usage data through cookies and analytics tools.

Communication Data

We maintain records of your communications with us, including emails, phone calls, and meeting notes to provide better service.

Business Information

We collect information about your business needs, project requirements, and preferences for our AI, cloud, and cybersecurity services.

4. How We Collect Your Data

Directly from you when you fill out forms, contact us, or request services.

Through our website using cookies and analytics tools.

From business cards or information provided during meetings and conferences.

Through referrals from business partners or clients.

From publicly available sources such as company websites and professional networks.

6. How We Use Your Information

We use your personal information for the following purposes:

Providing AI, cloud, cybersecurity, and consulting services.

Communicating about our services and responding to your inquiries.

Processing payments and managing client relationships.

Improving our website and services through data analytics.

Sending marketing communications (only with your consent).

Complying with legal and regulatory requirements.

Protecting against fraud, security threats, and unauthorized access.

7. Information Sharing and Disclosure

We do not sell your personal data to third parties. We may share your information only in the following circumstances:

Service Providers

With trusted third-party providers such as cloud hosting services, email platforms, CRM systems, and analytics tools that help us operate our business securely.

Business Partners

With your explicit consent, we may share relevant information with partners to provide joint services or integrated solutions.

Legal Authorities

When required by law, court order, legal process, or to protect our rights, safety, and the safety of others.

Business Transfers

In connection with mergers, acquisitions, or sales of business assets, subject to appropriate confidentiality protections.

8. International Data Transfers

We may transfer your personal data outside Kenya for cloud hosting and business operations. When we do, we ensure adequate protection through:

Adequacy decisions issued by relevant data protection authorities.

Standard contractual clauses approved by data protection authorities.

Binding corporate rules and recognized certification mechanisms.

Specific authorization for individual transfers where required by law.

9. Data Retention Periods

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:

Client Data

For the duration of our business relationship plus seven (7) years for legal, tax, and audit purposes.

Marketing Data

Until you withdraw consent or after three (3) years of inactivity, whichever comes first.

Website Analytics

Up to twenty-six (26) months for Google Analytics and similar tools.

Communication Records

Up to seven (7) years for business records and legal compliance purposes.

10. Your Privacy Rights

Under Kenyan and international data protection laws, you have the following rights regarding your personal data:

Right of Access

You can request copies of the personal data we hold about you.

Right to Rectification

You can request correction of any inaccurate or incomplete personal data.

Right to Erasure

You can request deletion of your personal data in certain circumstances.

Right to Restrict Processing

You can request that we limit how we use your personal data.

Right to Data Portability

You can request to receive your data in a structured, machine-readable format.

Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

You can withdraw consent at any time for processing activities that require your consent.

11. How to Exercise Your Rights

To exercise any of your privacy rights, please follow these steps:

Email us at info@cognifitech.co.ke with your specific request.

Provide sufficient information to verify your identity for security purposes.

Clearly specify which right you wish to exercise and include relevant details.

Allow up to thirty (30) days for us to respond to your request.

12. Data Security Measures

We implement comprehensive technical and organizational measures to protect your personal data, including:

Encryption of data both in transit and at rest using industry-standard protocols.

Multi-factor authentication and strict access controls for our systems.

Regular security assessments, vulnerability testing, and system updates.

Comprehensive employee training on data protection and security best practices.

Incident response procedures and breach notification protocols.

Secure cloud infrastructure with automated backup and disaster recovery systems.

13. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies for the following purposes:

Ensuring proper website functionality and user experience.

Analyzing website traffic patterns and user behavior.

Personalizing content and improving our services.

Providing social media integration and sharing features.

You can control cookie settings through your browser preferences. For detailed information about our cookie usage, please refer to our separate Cookie Policy.

14. Marketing Communications

We may send you marketing communications about our services only if:

You have given us explicit consent to receive such communications.

We have a legitimate business interest and you have not opted out.

You are an existing client and the communications relate to similar services you have used.

You can opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us directly. Your opt-out will be processed immediately.

15. Automated Decision-Making and Profiling

We do not engage in automated decision-making or profiling that would produce legal effects or significantly impact you without human oversight. Any AI tools we use in our business operations are subject to human review and intervention to ensure fair and accurate outcomes.

17. Children's Privacy Protection

Our services are designed for business use and are not intended for individuals under eighteen (18) years of age. We do not knowingly collect personal information from minors. If you become aware that a child has provided us with personal information, please contact us immediately so we can take appropriate action.

18. Data Breach Notification Procedures

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will:

Notify the Office of the Data Protection Commissioner (Kenya) within seventy-two (72) hours of becoming aware of the breach.

Inform affected individuals without undue delay if there is a high risk to their rights and freedoms.

Document the breach incident and our response measures in detail.

Take immediate steps to contain the breach, assess the damage, and implement remedial measures.

19. Complaints and Supervisory Authorities

If you have concerns about how we handle your personal data, you have the right to file a complaint. You can:

Contact us directly using the contact information provided below – we will investigate and respond promptly.

File a complaint with the Office of the Data Protection Commissioner (Kenya) as our primary supervisory authority.

Contact your local data protection authority if you are located in the EU or other jurisdictions with applicable privacy laws.

Office of the Data Protection Commissioner (Kenya)

Website: https://odpc.go.ke

Email: info@odpc.go.ke

20. Updates to This Privacy Policy

We may periodically update this Privacy Policy to reflect changes in our practices, services, or legal requirements. When we make updates, we will:

Post the updated policy on our website with a revised 'Last Updated' date.

Notify you of material changes via email or prominent website notice.

Maintain previous versions of this policy for reference where required by law.

Provide reasonable notice before any changes take effect, where legally required.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Cognifitech Limited

Data Protection Officer

Nairobi, Kenya
East Africa

For general inquiries about our services, please visit our contact page.