Home/Privacy Policy
Data Protection

Privacy Policy

We take your privacy seriously. This policy explains exactly what personal data we collect, why we collect it, how we use it, and what rights you have over it. We have written it in plain language so you can actually understand it.

Last Updated

1 March 2026

Effective Date

1 January 2025

Jurisdiction

Republic of Kenya

Compliance

KDPA 2019 + GDPR-aligned

01

Who We Are

Tukoweb Solutions Limited is a software development and technology company registered in Kenya. Our registered address is Senteu Plaza, Galana Road, Nairobi, Kenya 00100. When this policy refers to "Tukoweb", "we", "us", or "our", it means Tukoweb Solutions Limited and any subsidiaries or affiliated entities operating under the same brand.

We are the data controller for the personal information collected through our website at tukoweb.com and through the services we deliver to clients. As a company that builds software for businesses across Kenya and East Africa, we understand that data privacy is not just a legal obligation but a matter of trust. The way we handle your information reflects how seriously we take that trust.

If you have questions about this policy or about how we handle your data, you can reach our Data Protection Officer at privacy@tukoweb.com.

02

Information We Collect

We only collect information that is necessary for a specific purpose. Here is a breakdown of the categories of data we may collect:

Contact and Identity Information

When you fill in a contact form, request a quote, or subscribe to our newsletter, you may provide your full name, email address, phone number, company name, and job title. This information is provided voluntarily by you and is used to communicate with you about your enquiry or to deliver the service you requested.

Project and Business Information

If you engage us for a project, you may share details about your business, technical requirements, existing systems, target users, and budget. This information is treated with strict confidentiality and used solely for the purpose of delivering your project.

Technical and Usage Data

When you visit our website, we automatically collect certain technical information including your IP address, browser type and version, operating system, the pages you visit, the time and duration of your visit, and the referring URL. This data is collected via cookies and similar technologies and is used to improve our website and understand how visitors interact with it.

Communication Records

We keep records of the communications we have with you, including emails, WhatsApp messages, and meeting notes. These records help us provide consistent service and resolve any disputes that may arise.

Payment Information

We do not store payment card details. Any financial transactions are processed through licensed payment processors such as M-Pesa (Safaricom), Pesapal, or bank transfer. We retain records of transaction amounts and references for accounting and legal compliance purposes.

03

How We Use Your Information

We use the information we collect for the following purposes:

  • 1To respond to your enquiries and provide the services you have requested from us.
  • 2To prepare and send proposals, quotations, contracts, and invoices.
  • 3To deliver, manage, and improve the software development projects we undertake on your behalf.
  • 4To send you newsletters and marketing updates about our services, case studies, and technology insights, but only if you have given us consent to do so.
  • 5To improve our website by analysing how visitors use it, which pages are most popular, and where people encounter difficulties.
  • 6To meet our legal and regulatory obligations, including maintaining proper accounting records and complying with Kenyan tax requirements.
  • 7To protect the security and integrity of our systems and to detect and prevent fraud.
  • 8To follow up after project completion for client satisfaction feedback.

We will never use your personal information for purposes that are incompatible with the purpose for which it was originally collected without informing you first and, where required, obtaining your consent.

05

Sharing Your Data

Our commitment

We do not sell, rent, or trade your personal data to third parties for marketing purposes. Full stop.

There are limited circumstances in which we may share your information with others:

  • Service providers and subcontractors: We work with trusted third-party providers for services like email delivery (e.g., Mailchimp), cloud hosting (e.g., AWS, Google Cloud), project management tools, and analytics. These providers are only given the data they need to perform their specific task and are bound by data processing agreements that require them to protect your information.
  • Professional advisors: Our lawyers, accountants, and auditors may access certain information in the course of providing professional services to us. They are bound by professional confidentiality obligations.
  • Legal and regulatory requirements: We may disclose your information if required to do so by law, court order, or at the request of a competent authority such as the Kenya Revenue Authority or law enforcement agencies acting within their legal mandate.
  • Business transfers: If Tukoweb Solutions is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
06

Cookies and Tracking Technologies

Cookies are small text files that a website places on your device when you visit. They help the website remember your preferences and understand how you use the site. Here is how we use them:

Essential Cookies

These are required for the website to function correctly. They enable basic features like page navigation, form submission, and security. You cannot opt out of these without affecting how the site works.

Analytics Cookies

We use Google Analytics to understand how visitors interact with our website, which pages they visit most, how long they stay, and where they come from. This data is anonymised and aggregated. You can opt out by adjusting your browser settings or using the Google Analytics opt-out browser add-on.

Preference Cookies

These remember your choices, such as your preferred language or region, so you do not have to set them every time you visit.

Most browsers allow you to control cookies through their settings. If you choose to block all cookies, some features of our website may not work as intended. To learn more about how to manage cookies, visit allaboutcookies.org.

07

Data Retention

We only keep your personal data for as long as it is necessary for the purpose it was collected, or as required by law. Here is a summary of our retention periods:

Data TypeRetention PeriodReason
Contact form submissions3 yearsBusiness correspondence and dispute resolution
Newsletter subscriber dataUntil you unsubscribe + 1 yearConsent management records
Client project records7 yearsLegal and tax compliance requirements
Financial transaction records7 yearsKenya Revenue Authority requirements
Website analytics data26 monthsGoogle Analytics default retention
Job application data1 yearFuture vacancy consideration (with consent)

Once the retention period expires, we will securely delete or anonymise your personal data. If you request deletion before the retention period ends, we will comply unless we have a legal obligation to retain the data.

08

International Data Transfers

Some of the third-party service providers we use are based outside Kenya, which means your personal data may be transferred to and processed in countries other than Kenya. For example, Google Analytics processes data on servers in the United States, and some of our cloud infrastructure may be hosted in South Africa or Europe.

Where your data is transferred outside Kenya, we take steps to ensure it receives an equivalent level of protection. These steps may include:

  • Using service providers that are certified under recognised privacy frameworks such as the EU-US Data Privacy Framework.
  • Entering into standard contractual clauses approved by the Office of the Data Protection Commissioner (ODPC) of Kenya.
  • Choosing cloud providers that offer data residency in African regions where available, such as AWS af-south-1 (Cape Town) and Azure South Africa North.
09

Your Rights

Under the Kenya Data Protection Act 2019, you have specific rights regarding your personal data. We are committed to honouring these rights and will respond to any request within 21 days as required by law.

Right to Access

You can request a copy of all the personal data we hold about you, along with information about how we use it.

Right to Rectification

If any of the information we hold about you is inaccurate or incomplete, you have the right to have it corrected.

Right to Erasure

Also known as the right to be forgotten. You can ask us to delete your personal data, subject to certain legal exceptions.

Right to Restriction

You can ask us to pause processing of your data, for example while a dispute about accuracy is being resolved.

Right to Portability

You can request your data in a structured, commonly used, machine-readable format so you can transfer it to another provider.

Right to Object

You can object to processing based on legitimate interests, and you can always withdraw consent for marketing at any time.

How to exercise your rights

Send a written request to privacy@tukoweb.com with "Data Rights Request" in the subject line. We may need to verify your identity before processing the request. If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya.

10

Children's Privacy

Our website and services are intended for businesses and individuals who are at least 18 years old. We do not knowingly collect or solicit personal data from anyone under the age of 18. If you believe we have inadvertently collected information from a child, please contact us immediately at privacy@tukoweb.com and we will take steps to delete it as quickly as possible.

11

Security Measures

We implement a range of technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These include:

  • Encryption of data in transit using TLS 1.2 or higher.
  • Access controls that limit who within our team can access personal data, based on the principle of least privilege.
  • Regular security training for all team members who handle personal data.
  • Secure, password-protected systems with multi-factor authentication required for access to sensitive systems.
  • Regular security audits and vulnerability assessments of our systems and the systems we build for clients.
  • Documented incident response procedures in case of a data breach.

While we take all reasonable steps to protect your data, no method of transmission over the internet or method of electronic storage is completely secure. If you have reason to believe that your data has been compromised in connection with our services, please notify us immediately.

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes, we will update the "Last Updated" date at the top of this page. If we make material changes that significantly affect how we use your personal data, we will notify you by email (if we have your email address) or by posting a prominent notice on our website before the changes take effect.

We encourage you to review this policy periodically to stay informed about how we protect your data. Your continued use of our website after any changes constitutes your acceptance of the updated policy.

13

Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or how we handle your personal data, please reach out to our Data Protection Officer. We are committed to addressing your concerns promptly and transparently.

Office

Senteu Plaza, Galana Road

Nairobi, Kenya 00100

Need Help? Chat with us