Privacy Policy

Last updated: December 30, 2024

Your data is YOUR data, not ours! Privacy is fundamental to how we operate. Here's what we collect, why, and your rights.

What We Collect and Why

Our guiding principle: collect only what we need.

Identity & Access

When you sign up, we ask for your name, email, phone number, and business name. This lets you personalize your account and allows us to send essential updates. You may optionally add a profile picture. We never sell your personal information to third parties and won't use your name or company in marketing without permission.

Geolocation Data

We log all account access by IP address to verify no unauthorized access occurs. We keep this data as long as your account is active. We also log IP addresses used during signup.

Website Interactions

Your browser shares information like operating system and browser version. We track pages visited, load times, and referral sources for statistical purposes and design testing. This data is tied to your IP address and account if signed in. We anonymize all individual identifiers after 30 days.

Cookies

We use first-party cookies to store preferences and support analytics. Cookies help remember login information and site preferences. You can adjust cookie settings in your browser. Visit www.allaboutcookies.org to learn more. Our sites do not currently respond to Do Not Track signals.

Voluntary Correspondence

When you contact us for support, we keep that correspondence including your email address for future reference. We store information you volunteer in surveys. For customer interviews, we only record with your express consent.

What We DON'T Collect

We don't collect protected characteristics like age, race, gender, religion, sexual orientation, gender identity, or disabilities. We don't collect biometric data. Profile pictures are for your use only - we don't extract information from them.

Mobile App Permissions

We ask for minimum permissions needed for great app experience with maximum privacy. By default, we only access the network for Internet connectivity. We request just-in-time permissions for contacts, camera, and calendar so you can decide whether to grant access. You're never required to grant permissions, though features may not work without them.

When We Access or Share Your Information

Our default: we don't access your information. We only access or share when:

  • Helping you troubleshoot with your explicit consent
  • Required by Kenyan law with proper warrant, subpoena, or court order
  • Compelled by Kenyan government through proper legal procedures

NeNe's Systems is a Kenyan company with data infrastructure in Kenya. We reject requests from law enforcement without proper legal authority. We inform affected customers unless legally prohibited. For non-Kenyan authorities, we refuse unless compelled through mutual legal assistance treaties.

Your Rights

We apply the same data rights to all customers worldwide:

  • Right to Know: What personal information is collected, used, shared, or sold
  • Right of Access: Access your personal information and learn about sharing, storage, and processing
  • Right to Correction: Request correction of your personal information
  • Right to Erasure: Request deletion of your personal information (may result in account closure)
  • Right to Complain: File complaints with appropriate supervisory authorities
  • Right to Restrict Processing: Control how and why your information is used
  • Right to Object: Object to how your information is processed
  • Right to Portability: Receive and transmit your personal information
  • Right to Avoid Automated Decisions: Prevent solely automated decision-making with legal effects

Exercise most rights by signing in and updating your account. For assistance, contact hilarymwendia23@gmail.com. For deletion or data requests, we verify identity using at least two pieces of collected information.

Data Security

All data is encrypted via SSL/TLS during transmission. Database backups are encrypted. Every field with personal data is encrypted with its own key. Storage disks are also encrypted. Servers decrypt data only when you need it.

Data Deletion

Trashed data in active accounts is deleted from our systems and logs immediately. After account cancellation, all data is purged within 60 days. Retrieving single-account data from backups is cost-prohibitive, so decide before deletion from active servers.

Changes & Questions

We may update this policy to comply with regulations and reflect new practices. Significant changes will be announced via hilarymwendia23@gmail.com.

Questions about privacy, your data, or your rights?

Email us at hilarymwendia23@gmail.com or call +254 798 616 730 and we'll be happy to help!