Privacy Policy
iSKRYPT GROUP
PREAMBLE
iSKRYPT Group (“iSKRYPT”, “we”, “us”, “our”) is committed to protecting the privacy and personal data of every individual who interacts with our business. This Privacy Policy explains how we collect, use, store, share, and protect your personal data in full compliance with:
- The Kenya Data Protection Act, 2019 (Act No. 24 of 2019)
- The Data Protection (General) Regulations, 2021
- The Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021
- The Kenya Information and Communications Act (Cap 411A)
- The Consumer Protection Act, 2012
- The Constitution of Kenya, 2010, particularly Article 31 which guarantees every person the right to privacy
This Policy applies to all personal data collected through our website (iskrypt.com), our services, our social media platforms, and any other interaction you have with iSKRYPT.
We encourage you to read this Policy carefully. If you do not agree with any part of it, please discontinue use of our website and services and contact us at hello@iskrypt.com.
PART A: WHO WE ARE
1. Data Controller Identity
iSKRYPT Group
Website: iskrypt.com
Email: hello@iskrypt.com
Enquiries: enquiries@iskrypt.com
Phone: +254 743 579 875 / +254 708 479 860
Social Media: @iskryptgroup
iSKRYPT is registered as a Data Controller with the Office of the Data Protection Commissioner (ODPC) of Kenya in accordance with the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021.
Where iSKRYPT processes personal data on behalf of a Client, iSKRYPT acts as a Data Processor and the Client acts as the Data Controller. In such cases, processing is governed by a separate Data Processing Agreement between iSKRYPT and the Client.
PART B: WHAT DATA WE COLLECT
2. Categories of Personal Data
Depending on how you interact with iSKRYPT, we may collect the following categories of personal data:
2.1 Identity Data
- Full name
- Job title or role
- Company or organisation name
2.2 Contact Data
- Email address
- Phone number
- Physical or postal address
- Country of residence
2.3 Communication Data
- Messages, enquiries, and feedback submitted through our website contact form, email, or social media
- Records of correspondence between you and iSKRYPT
2.4 Transaction Data
- Details of services purchased or enquired about
- Invoice and payment records
- Billing information
2.5 Technical Data
- IP address
- Browser type and version
- Device type and operating system
- Pages visited on our website
- Time and date of visits
- Referring URLs
- Cookie identifiers
2.6 Usage Data
- Information about how you use our website, products, and services
- Engagement data from marketing emails (open rates, click rates)
2.7 Marketing and Preference Data
- Your preferences for receiving marketing communications from us
- Your communication channel preferences
2.8 Sensitive Personal Data
iSKRYPT does not intentionally collect sensitive personal data as defined under Section 2 of the DPA (including data relating to health, race, religion, political opinion, or biometric data). If such data is inadvertently submitted to us, we will delete it promptly and notify you accordingly.
PART C: HOW WE COLLECT YOUR DATA
3. Sources of Personal Data
We collect personal data through the following means:
3.1 Direct Collection
- When you fill out a contact, enquiry, or quote request form on our website
- When you email, call, or message us directly
- When you engage us for services and sign a Proposal or Statement of Work
- When you subscribe to our newsletter or marketing communications
- When you interact with us on social media platforms
3.2 Automated Collection
- Through cookies and similar tracking technologies when you visit our website (see Clause 10 on Cookies)
- Through analytics tools that monitor website traffic and user behaviour
3.3 Third-Party Sources
- From referral partners or associates who refer you to iSKRYPT
- From publicly available sources such as LinkedIn or company websites where we reach out to you in a business context
- From advertising platforms (such as Google Ads or Meta) where you interact with our paid campaigns
PART D: HOW WE USE YOUR DATA
4. Purposes and Lawful Bases for Processing
iSKRYPT processes personal data only where a lawful basis exists under Section 30 of the Kenya Data Protection Act, 2019. The table below outlines our processing purposes and the corresponding lawful basis for each:
| Purpose | Lawful Basis |
|---|---|
| Responding to enquiries and quote requests | Legitimate interests / Pre-contractual steps |
| Delivering agreed services | Performance of a contract |
| Sending invoices and processing payments | Performance of a contract / Legal obligation |
| Managing our relationship with you as a client | Performance of a contract |
| Sending marketing communications (newsletters, offers, updates) | Consent |
| Analysing website traffic and improving our website | Legitimate interests |
| Complying with legal and regulatory obligations | Legal obligation |
| Protecting iSKRYPT’s legal rights and interests | Legitimate interests |
| Fraud prevention and security | Legitimate interests / Legal obligation |
4.1 Legitimate Interests
Where we rely on legitimate interests as our lawful basis, we have assessed that our interests are not overridden by your rights and freedoms. You may request details of this assessment by contacting us at hello@iskrypt.com.
4.2 Consent
Where we rely on consent as our lawful basis, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, contact us at hello@iskrypt.com or use the unsubscribe link in any marketing email.
PART E: HOW WE SHARE YOUR DATA
5. Disclosure of Personal Data
iSKRYPT does not sell, rent, or trade your personal data to any third party. We may share your data in the following limited circumstances:
5.1 Service Providers and Sub-Processors
We engage trusted third-party service providers who process personal data on our behalf to support our operations. These include:
- Website hosting and cloud infrastructure providers
- Email marketing platforms
- Payment processing providers
- Analytics and advertising platforms (e.g. Google Analytics, Meta Ads)
- Project management and communication tools
- Accounting and invoicing software
All such providers are contractually required to process data only on our instructions, maintain appropriate security measures, and comply with applicable data protection law. Where such providers are located outside Kenya, we ensure adequate safeguards are in place as required under Section 48 of the DPA.
5.2 Professional Advisors
We may share data with our legal, financial, or professional advisors where necessary, subject to binding confidentiality obligations.
5.3 Legal and Regulatory Authorities
We may disclose personal data to government bodies, regulators, law enforcement agencies, or courts where required to do so by applicable Kenyan law, court order, or regulatory requirement. Where legally permissible, we will notify you of such disclosure.
5.4 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of iSKRYPT’s business, personal data may be transferred to the successor entity, subject to equivalent privacy protections. Affected individuals will be notified in advance where reasonably practicable.
5.5 With Your Consent
We may share your data with third parties not listed above where you have given us explicit, informed consent to do so.
PART F: INTERNATIONAL DATA TRANSFERS
6. Cross-Border Data Transfers
Where it is necessary to transfer your personal data outside Kenya, iSKRYPT shall ensure that such transfers are made in compliance with Section 48 of the Kenya Data Protection Act, 2019. Safeguards we rely on include:
- Transfers to countries determined by the Cabinet Secretary to have an adequate level of data protection.
- Standard contractual clauses approved by the Office of the Data Protection Commissioner.
- Binding corporate rules where applicable.
- Your explicit consent where no other safeguard applies.
You may request details of the safeguards in place for any specific international transfer by contacting us at hello@iskrypt.com.
PART G: DATA RETENTION
7. How Long We Keep Your Data
iSKRYPT retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable Kenyan law. Our general retention periods are as follows:
| Data Category | Retention Period |
|---|---|
| Client contract and project records | 7 years from project completion (in line with the Limitation of Actions Act) |
| Invoice and payment records | 7 years (as required by the Tax Procedures Act, 2015) |
| Enquiry and communication records | 2 years from last interaction |
| Marketing consent records | Until consent is withdrawn, plus 1 year |
| Website analytics data | 26 months (rolling) |
| Job application data (unsuccessful) | 6 months from application date |
Upon expiry of the applicable retention period, personal data shall be securely deleted or irreversibly anonymised. You may request early deletion of your data subject to the conditions outlined in Clause 8.
PART H: YOUR RIGHTS
8. Data Subject Rights
In accordance with Part IV of the Kenya Data Protection Act, 2019, you have the following rights in relation to your personal data:
8.1 Right of Access
You have the right to request confirmation of whether iSKRYPT holds personal data about you, and to receive a copy of that data together with information about how it is processed.
8.2 Right to Rectification
You have the right to request correction of any personal data we hold about you that is inaccurate, incomplete, or out of date.
8.3 Right to Erasure
You have the right to request deletion of your personal data where:
- The data is no longer necessary for the purpose for which it was collected.
- You withdraw consent and there is no other lawful basis for processing.
- You object to processing and there are no overriding legitimate grounds.
- The data has been unlawfully processed.
- Deletion is required to comply with a legal obligation.
8.4 Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example where you contest the accuracy of the data or object to its processing.
8.5 Right to Data Portability
You have the right to receive personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another data controller where technically feasible.
8.6 Right to Object
You have the right to object at any time to the processing of your personal data where we rely on legitimate interests as our lawful basis, including profiling based on those interests. You also have the absolute right to object to processing of your data for direct marketing purposes.
8.7 Right Not to Be Subject to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on you, except where necessary for a contract, authorised by law, or based on your explicit consent.
8.8 Right to Lodge a Complaint
You have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya if you believe your data protection rights have been violated:
Office of the Data Protection Commissioner
Website: odpc.go.ke
Email: info@odpc.go.ke
Phone: +254 20 2628 000
8.9 How to Exercise Your Rights
To exercise any of the above rights, please contact us at:
Email: hello@iskrypt.com
Phone: +254 743 579 875
We will respond to all verified requests within the timeframes prescribed by the DPA, generally within thirty (30) days. We may request proof of identity before processing your request to protect against unauthorised access to your data.
PART I: DATA SECURITY
9. Security Measures
iSKRYPT implements appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction, consistent with Section 41 of the Kenya Data Protection Act, 2019.
Our security measures include:
- Access controls limiting data access to authorised personnel only
- Encryption of data in transit and at rest where appropriate
- Regular security assessments and vulnerability testing
- Staff training on data protection and information security
- Incident response and data breach management procedures
- Secure disposal of data and physical media
Despite these measures, no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security. In the event of a breach that poses a risk to your rights and freedoms, we will notify you and the ODPC as required by Section 43 of the DPA.
PART J: COOKIES
10. Cookies and Tracking Technologies
10.1 What Are Cookies
Cookies are small text files placed on your device when you visit our website. They help us recognise your device, remember your preferences, and understand how you use our site.
10.2 Types of Cookies We Use
| Cookie Type | Purpose | Lawful Basis |
|---|---|---|
| Strictly Necessary | Essential for the website to function (e.g. session management) | Legitimate interests |
| Analytical/Performance | Measuring website traffic and user behaviour (e.g. Google Analytics) | Consent |
| Functional | Remembering your preferences and settings | Consent |
| Marketing/Targeting | Delivering relevant advertising and tracking campaign performance | Consent |
10.3 Your Cookie Choices
When you first visit our website, you will be presented with a cookie consent banner allowing you to accept or decline non-essential cookies. You may change your cookie preferences at any time through the cookie settings on our website or by adjusting your browser settings.
Please note that disabling certain cookies may affect the functionality of our website.
10.4 Third-Party Cookies
Our website may include cookies from third-party services such as Google Analytics, Meta Pixel, and LinkedIn Insight Tag. These third parties operate under their own privacy policies and we encourage you to review them.
PART K: MARKETING COMMUNICATIONS
11. Direct Marketing
11.1 iSKRYPT may send you marketing communications about our services, case studies, insights, and offers where you have given us your consent to do so, or where we have a legitimate interest in contacting you in a business-to-business context.
11.2 You may opt out of receiving marketing communications from us at any time by:
- Clicking the unsubscribe link in any marketing email.
- Emailing us at hello@iskrypt.com with the subject line “Unsubscribe”.
- Contacting us by phone at +254 743 579 875.
11.3 Please note that opting out of marketing communications does not affect our right to send you transactional or service-related communications necessary for the performance of your contract with us.
PART L: CHILDREN'S PRIVACY
12. Children
Our services are not directed at children under the age of eighteen (18). iSKRYPT does not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at hello@iskrypt.com and we will take prompt steps to delete such data in accordance with Section 31 of the Kenya Data Protection Act, 2019.
PART M: THIRD-PARTY LINKS
13. External Links
Our website may contain links to third-party websites, platforms, or services. This Privacy Policy applies only to iSKRYPT’s own website and services. We are not responsible for the privacy practices or content of any third-party sites and encourage you to review their privacy policies before providing any personal data.
PART N: CHANGES TO THIS POLICY
14. Policy Updates
iSKRYPT reserves the right to update this Privacy Policy at any time to reflect changes in our practices, services, or applicable law. Where changes are material, we will notify you by email or by posting a prominent notice on our website at least fourteen (14) days before the changes take effect.
The current version of this Policy is always available at iskrypt.com/privacy-policy. The version number and effective date at the top of this document indicate when it was last updated.
Your continued use of our website or services after the effective date of any update constitutes acceptance of the revised Policy.
PART O: CONTACT AND COMPLAINTS
15. How to Reach Us
For any questions, concerns, or requests relating to this Privacy Policy or our data protection practices, please contact our designated Data Protection point of contact:
iSKRYPT Group
Email: hello@iskrypt.com
Enquiries: enquiries@iskrypt.com
Phone: +254 743 579 875 / +254 708 479 860
Website: iskrypt.com
Social Media: @iskryptgroup
All privacy-related complaints will be acknowledged within two (2) business days and formally responded to within thirty (30) days in accordance with the Kenya Data Protection Act, 2019.
If you are not satisfied with our response, you have the right to escalate your complaint to the Office of the Data Protection Commissioner of Kenya.
By using iSKRYPT’s website or engaging our services, you confirm that you have read and understood this Privacy Policy.
iSKRYPT GROUP
Innovating Tomorrow Today
© 2026 iSKRYPT Group. All rights reserved.
Legal Note: This Privacy Policy has been drafted with reference to the Kenya Data Protection Act, 2019 and its subsidiary regulations as of July 2026. iSKRYPT recommends periodic review of this Policy by qualified Kenyan legal counsel, particularly as the Office of the Data Protection Commissioner continues to issue guidance and regulations under the DPA. This is especially important before processing any sensitive personal data, launching new services involving automated decision-making, or expanding operations to new jurisdictions.