Introduction
Your privacy matters to us.
This Privacy Policy explains how Amigo Digital Hub collects, receives, uses, stores, protects, discloses and otherwise processes personal data when you visit or use our website, communicate with us, request or receive our services, or otherwise interact with us.
This Privacy Policy is intended to provide transparent information about our data processing practices and the rights available to individuals under applicable data protection law.
By using our website, communicating with us or engaging our services, you acknowledge that you have read and understood this Privacy Policy. Where the law requires consent for a particular processing activity, we will seek that consent separately.
About Amigo Digital Hub
Amigo Digital Hub is a technology and digital solutions company operating from Kenya. We specialise in software engineering, artificial intelligence, digital growth and related technology services.
We work with startups, small and medium-sized enterprises, established organisations and other business clients to design, develop and scale websites, business software, artificial intelligence solutions and digital experiences.
For purposes of the Data Protection Act, 2019 of Kenya and other applicable data protection laws, Amigo Digital Hub may act as a data controller where we determine the purposes and means of processing personal data.
Depending on the nature of a particular project, Amigo Digital Hub may also act as a data processor on behalf of a client. This may occur where a client provides us with personal data for purposes such as developing, configuring, migrating, maintaining, hosting, securing or supporting a website, application, database or other digital system.
Where we act as a data processor, we will process the relevant personal data primarily in accordance with the client’s lawful instructions and the applicable service agreement or data processing agreement.
Meaning of Personal Data and Related Terms
For purposes of this Privacy Policy:
Personal Data We Collect
We collect and process personal data that is reasonably necessary for legitimate business, contractual, operational, security and legal purposes.
Information Provided Directly
Depending on how you interact with us, we may collect:
- Your name or business name
- Email address
- Telephone or mobile number
- WhatsApp contact details
- Company or organisation details
- Job title or business role
- Website address
- Project requirements and specifications
- Service enquiries
- Messages and correspondence
- Information submitted through contact or enquiry forms
- Information provided when requesting quotations or consultations
- Information provided during client onboarding
- Billing and transaction-related information
- Information contained in contracts, proposals and service records
- Any other information that you voluntarily provide to us
Project Information
When you engage us to develop, manage, host, maintain or support a digital solution, you may provide information required to deliver the relevant project.
This information may include:
- Website content
- Images, documents and media
- Business information
- Product or service information
- Customer information
- User account information
- Technical configuration information
- Domain and hosting information
- Application data
- Database information
- Application programming interface information
- Integration information
- Credentials or access information necessary for project implementation
- Other information reasonably necessary to complete an agreed project
Where project information contains personal data belonging to a client’s customers, employees, users or other individuals, the client is ordinarily responsible for determining the lawful purpose of processing and ensuring that the data is lawfully provided to us.
Technical Information
When you access our website, certain technical information may be collected automatically, depending on the technologies enabled on the website. This may include:
- Internet Protocol address
- Browser type and version
- Device type
- Operating system
- Referring website
- Pages visited
- Approximate usage information
- Date and time of visits
- Technical logs
- Security information
- Error reports
- General information concerning website performance
Technical information will generally be used for website functionality, analytics, performance monitoring, security and fraud prevention.
Information Received from Other Sources
We may receive personal data from:
- An authorised representative of a company or organisation
- A client or prospective client
- A service provider
- A business partner
- A publicly available business source
- A referral source
- A technology, hosting or communication platform
- A person authorised to act on behalf of a data subject
We will take reasonable steps to ensure that personal data received from another source is processed lawfully and for a legitimate purpose.
How We Collect Personal Data
- Our website
- Contact and enquiry forms
- Telephone calls
- Other communication channels
- Client meetings and consultations
- Project onboarding processes
- Service agreements
- Proposals and quotations
- Direct correspondence
- Website analytics
- Cookies and similar technologies
- Technical logs and security systems
- Information supplied by authorised representatives of an organisation
- Information supplied by clients in connection with a project
Purposes for Which We Use Personal Data
- Responding to enquiries and requests
- Communicating with prospective and existing clients
- Understanding project requirements
- Preparing quotations, proposals and statements of work
- Negotiating and entering into contracts
- Providing requested services
- Developing, configuring and maintaining websites and software
- Providing artificial intelligence and digital technology services
- Providing technical support and maintenance
- Managing client relationships
- Managing contracts and project communications
- Administering user accounts and access permissions
- Processing payments and maintaining accounting records
- Issuing invoices and following up on outstanding payments
- Improving our website, products and services
- Monitoring website performance
- Maintaining system security
- Preventing fraud, abuse and unauthorised access
- Detecting, investigating and addressing technical incidents
- Resolving complaints and disputes
- Protecting our rights, property, systems and business interests
- Complying with legal, regulatory, tax and accounting obligations
- Sending relevant business or service communications where permitted by law
- Performing any other lawful purpose disclosed to you at the time of collection or reasonably compatible with the original purpose
We will not use personal data for purposes that are incompatible with the purpose for which it was collected unless permitted or required by law or otherwise authorised by the relevant data subject or client.
Lawful Bases for Processing
Consent
We may process personal data where you have voluntarily provided consent for a specific processing activity. You may withdraw consent at any time, although withdrawal will not affect processing lawfully undertaken before the withdrawal.
Contractual Necessity
We may process personal data where processing is necessary to enter into, perform or manage a contract with you or with the organisation that you represent.
Legal Obligation
We may process personal data where processing is necessary to comply with a legal, regulatory, tax, accounting, court or law enforcement obligation.
Legitimate Interests
We may process personal data where processing is reasonably necessary for legitimate business, operational, security, service-related or administrative purposes, provided that those interests are not overridden by the rights and freedoms of the data subject.
Other Lawful Grounds
We may process personal data where another lawful basis is available under applicable data protection law, including where processing is necessary to protect vital interests, perform a public function or comply with a lawful order or request.
Client Data and Information Provided to Us
As a technology company, Amigo Digital Hub may receive and process personal data belonging to our clients or their customers, employees, users, suppliers and other business contacts.
During the development, migration, hosting, maintenance or support of a website, software application or other digital system, a client may provide us with customer records, user accounts, documents, databases, communications, transaction records or other business information.
Where we process such information on behalf of a client, we will process it primarily to provide the contracted service and in accordance with the client’s reasonable and lawful instructions.
The client remains responsible for:
- Determining the lawful purpose and means of processing
- Identifying the applicable lawful basis
- Providing appropriate privacy notices to its data subjects
- Obtaining any consent required by law
- Ensuring that the personal data supplied to us is accurate and lawfully obtained
- Giving lawful and documented processing instructions
- Establishing appropriate retention and deletion requirements
- Responding to requests from its data subjects where the client acts as controller
- Ensuring that any special categories of personal data are processed lawfully
We may notify a client where we reasonably believe that an instruction relating to personal data may breach applicable data protection law. We may decline to undertake an instruction that is unlawful or creates an unacceptable legal, security or operational risk.
Confidentiality
Technology projects may involve commercially sensitive, proprietary and confidential information.
We take reasonable steps to restrict access to client and user information to personnel, contractors and service providers who require access for legitimate business, operational, security or project purposes.
Confidential business information provided to us will not ordinarily be publicly disclosed unless:
- You have authorised the disclosure
- Disclosure is necessary to provide an agreed service
- Disclosure is required by law
- Disclosure is required by a court, regulator or lawful authority
- Disclosure is necessary to protect our rights, property, systems or personnel
- Disclosure is permitted under an applicable contract or data processing agreement
Where appropriate, we may enter into a separate confidentiality agreement or non-disclosure agreement with a client. In the event of a conflict between this Privacy Policy and a specific confidentiality agreement, the applicable confidentiality agreement will govern the confidential information covered by that agreement.
Sharing and Disclosure of Personal Data
We do not sell personal data to third parties.
We may share personal data or provide controlled access to personal data where reasonably necessary for legitimate business purposes, service delivery, project implementation, security, compliance or administration.
Recipients may include:
- Website hosting and infrastructure providers
- Domain registration and management providers
- Cloud service providers
- Email delivery providers
- Communication service providers
- Payment processors and financial institutions
- Accounting and professional advisers
- Analytics providers
- Software development and deployment services
- Security and monitoring providers
- Technical support providers
- Information technology service providers
- Contractors and consultants engaged for a legitimate project purpose
- Other providers required to operate our business or deliver a client’s project
We require service providers who process personal data on our behalf to apply appropriate confidentiality and security measures and to process the data only for authorised purposes.
We may also disclose personal data where disclosure is:
- Required by law
- Required by a court order
- Requested by a regulatory authority
- Necessary for law enforcement purposes
- Necessary to investigate fraud, abuse or a security incident
- Necessary to establish, exercise or defend legal rights
- Necessary to protect the safety, property or rights of any person
- Authorised by the relevant data subject or client
International Data Transfers
Some technology, hosting, cloud, communication and infrastructure providers used by Amigo Digital Hub or by our clients may operate servers or provide services outside Kenya.
As a result, personal data may in some circumstances be transferred to, processed in or stored in another country.
Where applicable, we will take reasonable steps to ensure that international processing is carried out in accordance with applicable data protection requirements and that appropriate safeguards are considered. Such safeguards may include contractual protections, security controls, confidentiality obligations, access restrictions and assessment of the receiving service provider.
By providing personal data to us, you acknowledge that authorised service providers supporting our operations or the relevant project may process that data outside Kenya where permitted by applicable law and the relevant contractual arrangements.
Cookies and Similar Technologies
Our website may use cookies and similar technologies to support functionality, security, performance and analytics.
Cookies may allow the website to:
- Remember certain preferences
- Maintain website functionality
- Support secure access
- Understand how visitors interact with the website
- Measure website performance
- Improve user experience
- Detect technical problems
- Identify and address security issues
You may control or restrict cookies through your browser settings. You may also be able to delete cookies that have already been stored on your device.
Disabling certain cookies may affect the availability, performance or functionality of parts of the website.
Where the website uses non-essential cookies that require consent, we will provide an appropriate consent mechanism where required by law.
Data Security
We take reasonable technical and organisational measures to protect personal data against:
- Unauthorised access
- Unauthorised disclosure
- Accidental loss
- Destruction
- Alteration
- Misuse
- Unauthorised processing
- Unlawful disclosure
- System compromise
Depending on the nature of the information and the services provided, security measures may include:
- Access controls
- Authentication requirements
- Restricted administrative access
- Secure communications
- Password and credential management
- Role-based permissions
- System monitoring
- Security logging
- Backups
- Malware and intrusion protection
- Incident response procedures
- Confidentiality obligations
- Staff and contractor access restrictions
- Secure disposal procedures
No internet-based system, website, server, application, database or electronic transmission can be guaranteed to be completely secure. You should therefore take reasonable steps to protect your own devices, passwords, accounts and access credentials.
Where you provide us with access credentials for purposes of delivering a service, you remain responsible for ensuring that the credentials are supplied through a reasonably secure method and are changed or revoked when they are no longer required.
Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected.
The applicable retention period may depend on:
- The nature of the personal data
- The purpose for which the data was collected
- The duration of our relationship with you
- The terms of the relevant contract
- Accounting and tax requirements
- Legal and regulatory obligations
- Dispute resolution requirements
- Security and audit requirements
- The establishment, exercise or defence of legal claims
Where we act as a data processor, we will retain, return or delete client data in accordance with the client’s lawful instructions and the applicable service agreement or data processing agreement.
When personal data is no longer reasonably required, we may securely delete, anonymise, archive or otherwise dispose of it in accordance with applicable legal, contractual and security requirements.
Your Privacy Rights
Subject to applicable law and any lawful limitations, you may have the following rights concerning your personal data:
- The right to request access to personal data that we hold about you
- The right to request correction of inaccurate, outdated or incomplete personal data
- The right to request deletion of personal data where legally applicable
- The right to object to certain forms of processing
- The right to request restriction of processing in appropriate circumstances
- The right to withdraw consent where processing is based on consent
- The right to request information about how your personal data is being processed
- The right to request transfer of personal data where applicable
- The right to raise a complaint regarding our handling of personal data
- The right not to be subjected to a decision based solely on automated processing where applicable under law
Some rights may be subject to legal, contractual, security, regulatory or other legitimate limitations. For example, we may be unable to delete information that we are required to retain by law or that is necessary to establish, exercise or defend a legal claim.
To exercise a privacy right, please contact us using the contact details published on our website. We may request sufficient information to verify your identity and clarify the scope of your request.
We will respond to a valid request within the period required by applicable law. Where a request cannot be fully met, we will provide an explanation subject to any lawful restriction on disclosure.
Complaints
If you have a concern about our handling of personal data, we encourage you to contact us first so that we may investigate and attempt to resolve the concern.
A data subject or any person aggrieved by a matter arising under the Data Protection Act, 2019 may lodge a complaint with the Data Commissioner in accordance with the Data Protection Act, 2019 and the Data Protection Complaints Handling Procedure and Enforcement Regulations.
A complaint may be lodged in person, through electronic means, by an authorised representative or through another appropriate lawful method. Complaints may be submitted to the Office of the Data Protection Commissioner through its official contact channels.
The applicable complaint handling framework provides for the lodging, admission, investigation and determination of complaints, as well as possible mediation, conciliation, negotiation, enforcement notices and other remedies.
The Data Protection Complaints Handling Procedure and Enforcement Regulations, Legal Notice 264 of 2021, are available at: Legal Notice 264 of 2021
Marketing Communications
Where permitted by law, we may communicate with existing or prospective clients regarding:
- Our services
- Technology solutions
- Product developments
- Website updates
- Industry information
- Events
- Business opportunities
- Service-related announcements
You may request that we stop sending you non-essential marketing communications at any time by contacting us or using the unsubscribe mechanism included in the relevant communication.
Transactional, security, contractual, administrative and service-related communications may still be sent where reasonably necessary.
Third-Party Websites and Services
Our website or digital communications may contain links to third-party websites, platforms or services.
Third parties operate under their own privacy policies, terms and security arrangements. Amigo Digital Hub does not control and is not responsible for the privacy practices, content, security or policies of third-party websites or services.
You should review the privacy policy and terms applicable to any third-party website, platform or service before providing personal data or using that service.
Children’s Privacy
Our services are primarily intended for businesses, organisations and general adult users.
We do not knowingly seek to collect personal data from children where the collection is inappropriate or not legally permitted. If you believe that a child has provided personal data to us without appropriate authorisation, please contact us so that we may assess and take appropriate action.
Artificial Intelligence and Automated Technologies
As part of our technology services, Amigo Digital Hub may develop, integrate, test or use artificial intelligence and other automated technologies.
Where personal data is processed through an artificial intelligence service or third-party artificial intelligence platform, the processing may also be subject to the terms, privacy practices, security controls and data handling arrangements of that service.
We take reasonable steps to ensure that personal data is not knowingly submitted to an artificial intelligence service for purposes unrelated to the relevant business, operational or project requirement.
Where appropriate, we may apply access controls, data minimisation, anonymisation, pseudonymisation or other safeguards before using personal data with artificial intelligence or automated technologies.
Clients remain responsible for providing lawful instructions concerning personal data submitted for artificial intelligence development, integration, testing or deployment. Clients should not provide sensitive or confidential personal data unless the relevant processing is necessary, lawful and appropriately safeguarded.
Where applicable law requires human review, notice, consent or other safeguards in relation to automated decision-making, we will consider and apply those requirements to the relevant processing activity.
Data Breaches and Security Incidents
If we become aware of a security incident involving personal data under our control, we will assess the incident and take reasonable steps to contain, investigate and address it.
Our response may include:
- Identifying and containing the incident
- Assessing the nature and extent of the incident
- Taking steps to prevent further unauthorised access
- Restoring the security of affected systems
- Documenting the incident and remedial measures
- Notifying affected clients or data subjects where appropriate
- Notifying the Data Commissioner or another competent authority where required by law
- Cooperating with relevant clients, authorities and service providers
Where Amigo Digital Hub acts as a data processor, we will notify the relevant client in accordance with the applicable service agreement or data processing agreement and provide reasonable assistance in relation to the incident.
Notifications will be made within the applicable legal or contractual timelines, subject to the circumstances of the incident and any lawful restrictions.
Accuracy of Personal Data
We rely on information provided by users and clients to deliver our services effectively.
You are encouraged to provide accurate, complete and current information and to notify us where relevant information changes.
Where we act as a data processor, the relevant client is responsible for ensuring the accuracy and currency of the personal data supplied to us, unless otherwise agreed in writing.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to:
- Our services
- Our technology
- Our data processing practices
- Our service providers
- Applicable laws
- Regulatory requirements
- Security practices
- Business operations
When we update this Privacy Policy, we will revise the “Last Updated” date displayed at the beginning of the document.
Where a change materially affects your rights or our data processing practices, we may provide an additional notice or take any other step required by applicable law.
Contact Us
If you have questions about this Privacy Policy, wish to exercise a privacy right, or have a concern regarding how your personal data is handled, please contact us using the contact details published on our website.
Amigo Digital Hub
Technology that helps businesses grow.
Kenya
Email: the email address published on our website
Telephone: the telephone number published on our website
Website: the website operated by Amigo Digital Hub
Governing Framework
This Privacy Policy is intended to operate in accordance with applicable data protection and privacy laws, including the Data Protection Act, 2019 of Kenya, applicable regulations, guidelines and other legal requirements.
Where mandatory privacy or data protection requirements in another jurisdiction apply to a particular individual, client, project or processing activity, those requirements may also apply to the extent required by law.
This Privacy Policy does not replace any specific data processing agreement, confidentiality agreement, service agreement, terms of use, statement of work or other contractual terms that may apply to a particular client or project.
Where there is a conflict between this Privacy Policy and a specific written data processing agreement or service agreement, the specific agreement will govern to the extent of the conflict.