TeamKazi Logo
TeamKazi Logo
Sign-In Sign-Up

Privacy Policy

Last updated: July 31, 2025

At TeamKazi, we are committed to protecting your privacy and ensuring the security of your personal information. This policy outlines how we collect, use, and safeguard your data in compliance with Kenya's Data Protection Act (2019).

1

Data Controller

Wise And Agile Solutions Kenya

Valley View Office Park, 4th Floor

Nairobi, Kenya

As the data controller, we determine the purposes and means of processing your personal data. We are registered with the Office of the Data Protection Commissioner in Kenya and comply with all relevant data protection regulations.

2

Information We Collect

We process the following categories of personal data to provide and improve our services:

Account Data

Email address, phone number, password (hashed)

Usage Data

Task history, system interactions, site visit timestamps

Content Data

Task details, comments, uploaded files

Payment Data

Processed exclusively through PesaPal (we never store payment details)

We collect this information directly from you when you register, use our services, or communicate with us. Some data may be collected automatically through cookies and similar technologies when you use our platform.

4

Security Measures

We implement comprehensive technical and organizational measures to protect your data:

Bcrypt Hashing

For password security

RBAC System

Role-Based Access Control

Annual VAPT

Vulnerability testing

SSL/TLS

Data transmission encryption

Secure Infrastructure

Regular patching

Our security protocols are regularly reviewed and updated to address emerging threats. All employees receive data protection training and are bound by confidentiality agreements.

5

Third-Party Data Sharing

We share data with trusted third parties only when necessary for service delivery:

  • PesaPal: Payment processing (PCI-DSS compliant)
  • Brevo: Transactional email delivery (SMTP services)
  • Secure Location: Cloud hosting provider

All third-party providers undergo rigorous security assessments and sign data processing agreements that require them to protect your information and comply with Kenyan data protection laws.

6

Your Rights (Kenya DPA 2019)

Under the Data Protection Act, you have the following rights:

  • Request Access to your personal data
  • Demand Correction of inaccurate information
  • Delete your account (hard deletion via support request)
  • Object to data processing activities

Submit requests to: info@teamkazi.com
We respond to all valid requests within 30 days. Note: Soft-deleted data may persist in backups.

7

Data Retention

We retain personal data only as long as necessary for the purposes outlined:

  • Active accounts: Retained until deletion request
  • Financial records: 7 years per Kenyan tax laws
8

Data Transfers

All data is primarily stored in Secure Location.

Any secondary transfers comply with:

  • Kenya's Data Protection Act 2019
  • Cross-border data transfer regulations
9

Breach Notification

In the unlikely event of a data breach affecting your personal information:

  • Notify Kenya's Office of the Data Protection Commissioner (ODPC) within 72 hours
  • Alert affected users via email within 96 hours
10

Policy Updates

We may update this policy periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated through:

  • Email alerts to registered users
  • Updated timestamp on this policy page
11

Contact Us

For questions about this policy or to exercise your data rights:

Office

Wise And Agile Solutions Kenya

Valley View Office Park, 4th Floor

Nairobi, Kenya

12

Key Addition Compliance

We provide the following additional disclosures for transparency and compliance:

Soft Deletion Process

When you request account deletion, we perform a soft deletion. Your data remains in our encrypted backups.

Annual Security Testing

We conduct comprehensive Vulnerability Assessment and Penetration Testing (VAPT) annually through certified cybersecurity partners to maintain the highest security standards.

Brevo Subprocessor

We use Brevo (Sendinblue) as our email service provider. Brevo processes transactional emails on our behalf under strict data processing agreements compliant with Kenya's Data Protection Act.