Privacy Policy
We take your privacy seriously. This policy explains exactly what personal data we collect, why we collect it, how we use it, and what rights you have over it. We have written it in plain language so you can actually understand it.
Last Updated
1 March 2026
Effective Date
1 January 2025
Jurisdiction
Republic of Kenya
Compliance
KDPA 2019 + GDPR-aligned
Who We Are
Tukoweb Solutions Limited is a software development and technology company registered in Kenya. Our registered address is Senteu Plaza, Galana Road, Nairobi, Kenya 00100. When this policy refers to "Tukoweb", "we", "us", or "our", it means Tukoweb Solutions Limited and any subsidiaries or affiliated entities operating under the same brand.
We are the data controller for the personal information collected through our website at tukoweb.com and through the services we deliver to clients. As a company that builds software for businesses across Kenya and East Africa, we understand that data privacy is not just a legal obligation but a matter of trust. The way we handle your information reflects how seriously we take that trust.
If you have questions about this policy or about how we handle your data, you can reach our Data Protection Officer at privacy@tukoweb.com.
Information We Collect
We only collect information that is necessary for a specific purpose. Here is a breakdown of the categories of data we may collect:
Contact and Identity Information
When you fill in a contact form, request a quote, or subscribe to our newsletter, you may provide your full name, email address, phone number, company name, and job title. This information is provided voluntarily by you and is used to communicate with you about your enquiry or to deliver the service you requested.
Project and Business Information
If you engage us for a project, you may share details about your business, technical requirements, existing systems, target users, and budget. This information is treated with strict confidentiality and used solely for the purpose of delivering your project.
Technical and Usage Data
When you visit our website, we automatically collect certain technical information including your IP address, browser type and version, operating system, the pages you visit, the time and duration of your visit, and the referring URL. This data is collected via cookies and similar technologies and is used to improve our website and understand how visitors interact with it.
Communication Records
We keep records of the communications we have with you, including emails, WhatsApp messages, and meeting notes. These records help us provide consistent service and resolve any disputes that may arise.
Payment Information
We do not store payment card details. Any financial transactions are processed through licensed payment processors such as M-Pesa (Safaricom), Pesapal, or bank transfer. We retain records of transaction amounts and references for accounting and legal compliance purposes.
How We Use Your Information
We use the information we collect for the following purposes:
- 1To respond to your enquiries and provide the services you have requested from us.
- 2To prepare and send proposals, quotations, contracts, and invoices.
- 3To deliver, manage, and improve the software development projects we undertake on your behalf.
- 4To send you newsletters and marketing updates about our services, case studies, and technology insights, but only if you have given us consent to do so.
- 5To improve our website by analysing how visitors use it, which pages are most popular, and where people encounter difficulties.
- 6To meet our legal and regulatory obligations, including maintaining proper accounting records and complying with Kenyan tax requirements.
- 7To protect the security and integrity of our systems and to detect and prevent fraud.
- 8To follow up after project completion for client satisfaction feedback.
We will never use your personal information for purposes that are incompatible with the purpose for which it was originally collected without informing you first and, where required, obtaining your consent.
Legal Basis for Processing
Under the Kenya Data Protection Act 2019, we are required to have a valid legal basis for processing your personal data. Depending on the situation, we rely on one or more of the following grounds:
Contract Performance
When processing is necessary to fulfil a contract with you or to take steps you have requested before entering into a contract.
Consent
When you have given us clear, specific consent, such as subscribing to our newsletter. You can withdraw this consent at any time.
Legitimate Interests
When processing is necessary for our legitimate business interests, provided those interests do not override your fundamental rights and freedoms.
Legal Obligation
When processing is necessary to comply with a legal obligation, such as maintaining financial records for tax purposes.
Data Retention
We only keep your personal data for as long as it is necessary for the purpose it was collected, or as required by law. Here is a summary of our retention periods:
| Data Type | Retention Period | Reason |
|---|---|---|
| Contact form submissions | 3 years | Business correspondence and dispute resolution |
| Newsletter subscriber data | Until you unsubscribe + 1 year | Consent management records |
| Client project records | 7 years | Legal and tax compliance requirements |
| Financial transaction records | 7 years | Kenya Revenue Authority requirements |
| Website analytics data | 26 months | Google Analytics default retention |
| Job application data | 1 year | Future vacancy consideration (with consent) |
Once the retention period expires, we will securely delete or anonymise your personal data. If you request deletion before the retention period ends, we will comply unless we have a legal obligation to retain the data.
International Data Transfers
Some of the third-party service providers we use are based outside Kenya, which means your personal data may be transferred to and processed in countries other than Kenya. For example, Google Analytics processes data on servers in the United States, and some of our cloud infrastructure may be hosted in South Africa or Europe.
Where your data is transferred outside Kenya, we take steps to ensure it receives an equivalent level of protection. These steps may include:
- Using service providers that are certified under recognised privacy frameworks such as the EU-US Data Privacy Framework.
- Entering into standard contractual clauses approved by the Office of the Data Protection Commissioner (ODPC) of Kenya.
- Choosing cloud providers that offer data residency in African regions where available, such as AWS af-south-1 (Cape Town) and Azure South Africa North.
Your Rights
Under the Kenya Data Protection Act 2019, you have specific rights regarding your personal data. We are committed to honouring these rights and will respond to any request within 21 days as required by law.
Right to Access
You can request a copy of all the personal data we hold about you, along with information about how we use it.
Right to Rectification
If any of the information we hold about you is inaccurate or incomplete, you have the right to have it corrected.
Right to Erasure
Also known as the right to be forgotten. You can ask us to delete your personal data, subject to certain legal exceptions.
Right to Restriction
You can ask us to pause processing of your data, for example while a dispute about accuracy is being resolved.
Right to Portability
You can request your data in a structured, commonly used, machine-readable format so you can transfer it to another provider.
Right to Object
You can object to processing based on legitimate interests, and you can always withdraw consent for marketing at any time.
How to exercise your rights
Send a written request to privacy@tukoweb.com with "Data Rights Request" in the subject line. We may need to verify your identity before processing the request. If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya.
Children's Privacy
Our website and services are intended for businesses and individuals who are at least 18 years old. We do not knowingly collect or solicit personal data from anyone under the age of 18. If you believe we have inadvertently collected information from a child, please contact us immediately at privacy@tukoweb.com and we will take steps to delete it as quickly as possible.
Security Measures
We implement a range of technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These include:
- Encryption of data in transit using TLS 1.2 or higher.
- Access controls that limit who within our team can access personal data, based on the principle of least privilege.
- Regular security training for all team members who handle personal data.
- Secure, password-protected systems with multi-factor authentication required for access to sensitive systems.
- Regular security audits and vulnerability assessments of our systems and the systems we build for clients.
- Documented incident response procedures in case of a data breach.
While we take all reasonable steps to protect your data, no method of transmission over the internet or method of electronic storage is completely secure. If you have reason to believe that your data has been compromised in connection with our services, please notify us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes, we will update the "Last Updated" date at the top of this page. If we make material changes that significantly affect how we use your personal data, we will notify you by email (if we have your email address) or by posting a prominent notice on our website before the changes take effect.
We encourage you to review this policy periodically to stay informed about how we protect your data. Your continued use of our website after any changes constitutes your acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or how we handle your personal data, please reach out to our Data Protection Officer. We are committed to addressing your concerns promptly and transparently.
Office
Senteu Plaza, Galana Road
Nairobi, Kenya 00100