Privacy Policy
Draft: have a Kenyan advocate review this page, then delete this label.
This policy explains what personal information we collect, why we use it, who we share it with, and the choices you have. We follow the Data Protection Act, 2019 of Kenya.
1. Who we are
In this policy, “we” and “us” mean the company below. We work under the name Synos Labs.
- Company
- [REGISTERED COMPANY NAME] Limited
- Registration number
- [COMPANY REGISTRATION NUMBER]
- Registered address
- [REGISTERED ADDRESS], Nairobi, Kenya
- Data protection contact
- [EMAIL ADDRESS]
- ODPC registration
- [ODPC REGISTRATION NUMBER, if registered]
2. What we collect
- When you contact us: your name, your phone number if you give it, your type of business, and the message you send through the form, WhatsApp or email.
- When you become a client: business records you share with us for an audit or reporting, such as sales, stock, cash, fuel and takings records. These may include personal information about your staff or customers.
- When you visit this website: our website host, GitHub Pages, may log technical information such as your IP address and browser type. We do not use cookies, advertising trackers or analytics on this website, and we load our fonts from our own site. If that changes, we will update this policy first.
3. How and why we use it
- To reply to your enquiry and arrange a pilot. We rely on your consent, and on taking steps you ask for before we enter an agreement.
- To carry out work for our clients. We rely on the agreement we have with the client.
- To keep records, keep our systems secure and meet legal duties. We rely on our legal obligations and our legitimate interest in running the business safely.
We do not sell personal information. We do not send marketing messages unless you have asked us to.
4. Client business records
When a client shares business records with us, the client decides what is shared and why. We handle those records only to do the agreed work and only on the client's instructions. We do not use them for other clients or for any other purpose, and we will not name a client or use their data as an example without written permission.
Please share only the records we need. If a file contains personal information that is not needed, remove it or tell us and we will help you leave it out.
5. Confidentiality
Client data is treated as confidential and only used for the agreed work. Only people working on your project can see it, and they are bound to keep it confidential.
6. Who we share it with
We share personal information only with the services we need to communicate and do the work, and only as far as necessary:
- WhatsApp (Meta), when you message us there, under its own privacy terms.
- Our email provider, [EMAIL PROVIDER], when you email us or we email you.
- Tools we use to store and analyse client files: [LIST THE STORAGE AND ANALYSIS TOOLS YOU USE].
- GitHub, which hosts this website.
- Authorities, if the law requires us to.
7. Transfers outside Kenya
Some of the services above process information on servers outside Kenya. Where that happens we take the steps the Data Protection Act, 2019 requires so that your information stays protected.
8. How long we keep it
- Enquiries that do not lead to work: [PERIOD, for example 12 months], then deleted.
- Client records: until the work ends or as the client agrees in writing, then returned, deleted or made anonymous. Once returned or deleted, we do not keep a copy.
- Records we must keep by law, such as invoices: for as long as the law requires.
9. Security
We use reasonable technical and organisational measures to protect personal information, such as password protection, limited access and secure storage. [CONFIRM AND LIST THE MEASURES YOU ACTUALLY USE, for example device encryption and two-step sign-in.]
If there is a personal data breach, we will act as the law requires, including telling the Data Commissioner and the people affected where required.
10. Your rights
Under the Data Protection Act, 2019 you have the right to:
- be told how your information is used;
- ask for a copy of the information we hold about you;
- ask us to correct information that is wrong;
- ask us to delete information, in the cases the law allows;
- object to us using your information in certain ways;
- receive your information in a common format, where that applies; and
- withdraw your consent at any time, without affecting what we did before.
To use any of these rights, contact us at [EMAIL ADDRESS]. We will reply within the time the law allows. If you are not happy with how we handle your information, you can complain to the Office of the Data Protection Commissioner of Kenya (odpc.go.ke).
Our services are for businesses and are not aimed at children.
11. Changes to this policy
We may update this policy. The effective date at the top shows when it last changed. If we make an important change, we will say so on this website.
12. Contact us
Questions about this policy or your information: [EMAIL ADDRESS], or write to us at [REGISTERED ADDRESS], Nairobi, Kenya.