Business Contacts Privacy Notice
Last updated 23 September 2026. Draft v0.1 issued for legal review and in force pending review. Questions: contact@laitigosystems.com.
1. Who we are and what this notice covers
Laitigo Systems Limited ("Laitigo", "we", "us") is a company registered in Kenya under number PVT-LRUM8JM. Our registered office is at LR No 1870/IX/8, Western Heights, Karuna Road, Westlands, Nairobi (P.O. Box 16679-00100, Nairobi).
This notice explains how we handle personal data about the people we deal with in business:
- contacts at our customers and prospective customers;
- contacts at our suppliers, subcontractors and service providers;
- billing, accounts and delivery contacts;
- people who use our customer and supplier portal; and
- people who register through forms on our website.
For this data we are the controller under the Kenya Data Protection Act, 2019 (the "Act") and the Data Protection (General) Regulations, 2021 (the "Regulations").
We develop software, build and host websites under annual maintenance contracts, and provide software-as-a-service (SaaS) platforms. This notice also covers the contact form on laitigosystems.com. Where we handle personal data on behalf of a customer, for example the users of a website we host or of a platform we operate for them, the customer is the controller and our Data Processing Addendum applies instead of this notice.
2. The personal data we handle
| Category | Examples |
|---|---|
| Identity and role | Name, job title, organisation, signature on signed terms |
| Contact details | Work email, telephone number, postal and physical address, delivery address |
| Verification (KYC) | Names of directors and shareholders shown on a CR12 or certificate of incorporation; KRA PIN certificate and national ID number where the supplier or customer is an individual or sole trader; bank confirmation letter |
| Financial | Bank account details for payments, payment history, credit terms, withholding tax certificates |
| Transactions | Requests for quotation (RFQs), quotations, purchase and sales orders, invoices, delivery notes, warranty and return claims |
| Communications | Emails, portal messages, files you upload, notes of calls (including bank-detail verification calls) |
| Portal and technical | Portal login email, access logs, IP address, browser type, time stamps of document views and electronic signatures |
| Form registrations | What you enter in the form, your consent and accuracy declaration, and the date and time you gave them |
We do not ask for sensitive personal data (such as health, ethnic origin or biometric data) about business contacts. Please do not send it to us or upload it to the portal. Where we need an ID number, for example from a sole trader, we ask only for what the law or the transaction requires.
3. Where the data comes from
Most of it comes from you or from your organisation. We may also check it against public sources, such as the Business Registration Service and the KRA PIN checker, and receive it from referees, partners or colleagues who introduce you to us.
4. Why we use it and our lawful basis
We process personal data only where section 30 of the Act gives us a lawful basis.
| Purpose | Lawful basis |
|---|---|
| Responding to a form registration or enquiry and setting up your organisation in our customer relationship management (CRM) system | Your consent, given on the form, and our legitimate interest in answering business enquiries |
| Preparing and sending RFQs, quotations, orders and invoices, and running the contract | Performance of a contract, or steps taken at your organisation's request before a contract |
| Verifying customers and suppliers, preventing fraud (including checking any change of bank details by call-back) | Our legitimate interest in protecting both parties from fraud; compliance with legal obligations |
| Keeping tax and accounting records and issuing electronic tax invoices through KRA eTIMS | Compliance with legal obligations, including the Tax Procedures Act, 2015 and the Value Added Tax Act, 2013 |
| Giving you access to the portal and collecting electronic signatures | Performance of a contract and our legitimate interest in keeping reliable records |
| Handling warranty claims, service quality and system security | Our legitimate interest in running and protecting our business |
| Sending occasional news about our services | Only with your express consent (section 37 of the Act). You can opt out at any time |
| Establishing or defending legal claims | Our legitimate interest and legal obligations |
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect anything we did lawfully before. Where we rely on legitimate interests, we have weighed them against your rights and you may object (see section 10).
5. Our ERP system, emails and portal
We run our business on Odoo, an enterprise resource planning (ERP) system provided as an online service by Odoo S.A. of Belgium. RFQs, quotations, orders, invoices, statements and reminders are sent to you by email directly from Odoo.
Most of these emails contain a private link to our portal. Through the portal you can view your documents, send us messages and upload files. Please note:
- anyone who has the link can open the document it points to, so do not forward it outside your organisation, and tell us straight away if you received it by mistake;
- messages and files you send through the portal become part of our business record for that transaction and are visible to our staff who handle it; and
- when you sign a document electronically through Odoo Sign, the system records your name, email address, IP address, the time and the signature image, and produces a signed certificate that both parties keep.
Some emails are sent automatically, such as order confirmations, delivery notices and payment reminders. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects (section 35 of the Act). Decisions about credit, supplier approval and disputes are made by a person.
6. Who we share it with
Service providers who process data for us (processors). Each works under written terms that require it to protect the data and use it only to provide its service.
| Provider | What it does for us | Where the data may be held |
|---|---|---|
| Odoo S.A. (Belgium) | ERP, CRM, portal, electronic signature, automated email | Odoo's cloud data centres |
| Google (Google Workspace) | Business email, calendar and documents | Google's data centres in several countries, including the United States and the European Union |
| Cloudflare, Inc. | Domain name system (DNS) and website security | Cloudflare's global network |
| Vercel Inc. | Website hosting and website forms | United States and Vercel's global network |
| Amazon Web Services | Cloud storage and hosting for specific services | South Africa (Cape Town); Ireland for some services |
| FormSubmit | Delivering the laitigosystems.com contact form to our mailbox | The provider's infrastructure |
Other organisations that receive data and decide for themselves how to use it (independent controllers): our banks and payment providers; Alibaba.com, where we source hardware overseas and pay through Trade Assurance, which receives supplier contact and order details under its own terms; the Kenya Revenue Authority (eTIMS and iTax); customs, clearing and forwarding agents and couriers; our auditors, advocates and insurers; and public authorities where the law requires.
We never sell personal data. We do not disclose the identity of our customers to suppliers except where a supplier needs it to deliver or register an order and the customer has agreed. If Laitigo or its business is sold or restructured, data may pass to the new owner under confidentiality.
7. Transfers outside Kenya
Some of our providers hold data outside Kenya (see the table in section 6). Sections 48 to 50 of the Act allow this where appropriate safeguards are in place. Before we transfer data we:
- choose providers that give contractual data-protection commitments and hold recognised security certifications, such as ISO/IEC 27001 or SOC 2 reports;
- send only what the service needs;
- keep a record of the transfer, its basis and the safeguards, as the Act and the Regulations require; and
- do not transfer sensitive personal data outside Kenya without the consent of the person concerned and appropriate safeguards (section 49).
We do not currently handle any category of business-contact data that the Cabinet Secretary has required to be processed only in Kenya under section 50. If that changes, we will comply. You may ask us for a description of the safeguards that apply to a transfer.
8. How long we keep it
We keep personal data only for as long as the purpose needs it (section 39 of the Act), then delete or anonymise it.
| Record | Retention period |
|---|---|
| Invoices, bills, orders, payment and other tax and accounting records | 5 years after the end of the tax period they relate to (Tax Procedures Act, 2015, section 23) |
| Signed terms, data processing addenda and contracts | Life of the relationship plus 6 years (limitation period for contract claims) |
| Supplier and customer verification (KYC) documents and bank letters | Life of the relationship plus 5 years |
| Portal messages and uploaded files | Same period as the transaction they belong to |
| Business correspondence by email | 6 years after the last exchange on the matter |
| Form registrations and CRM leads that do not lead to business | 24 months after the last contact |
| Marketing consent and opt-out records | Consent for as long as it is valid; a minimal opt-out record is kept so that we do not contact you again |
| Portal and security logs | Up to 12 months, or as set by the provider |
9. How we protect it
We use multi-factor authentication and role-based access on our systems, so staff see only what their role needs. Data is encrypted in transit and our providers encrypt it at rest. Our ERP is backed up by the provider. Staff are bound by confidentiality. Bank details can be changed only after we verify the request by telephone on a number we already hold (see section 11). If a personal data breach occurs that is likely to harm you, we will notify the ODPC within 72 hours of becoming aware of it and tell you where section 43 of the Act requires.
10. Your rights
Under the Act (including section 26) you have the right to:
- be informed of how your personal data is used;
- have access to the personal data we hold about you;
- object to our processing of all or part of your data, including for direct marketing;
- have false or misleading data corrected, and have data deleted where we no longer have a lawful reason to keep it (section 40);
- ask us to restrict processing in the circumstances set out in section 34;
- receive data you gave us in a structured, commonly used, machine-readable format (section 38);
- withdraw consent at any time; and
- not be subject to a decision based solely on automated processing that significantly affects you.
To exercise a right, email contact@laitigosystems.com, or write to us at the address in section 1. We may ask you to confirm your identity. We will reply without undue delay and within the time the Regulations set. There is normally no charge. Some rights are limited by law; for example, we cannot delete invoices we must keep for tax purposes.
11. Accuracy of the information you give us
When you register, sign our terms or send us documents, you declare that the information is accurate and complete and that you are authorised to give it on behalf of your organisation. Please tell us promptly when it changes. We rely on this information to issue orders, invoices and payments, so we cannot accept responsibility for loss that results from inaccurate, incomplete or out-of-date information supplied to us, except where the loss is caused by our own negligence or where the law does not allow us to exclude liability.
Bank details. We will never ask you to change bank details by email alone, and we will never accept a change of your bank details by email alone. Any change must be confirmed by a letter from your bank and verified by our call-back to a number already on our records.
12. Complaints
If you are unhappy with how we have handled your personal data, please tell us first at contact@laitigosystems.com so that we can put it right. You also have the right to complain to the Office of the Data Protection Commissioner:
- email: info@odpc.go.ke
- address: Britam Tower, 12th Floor, Upper Hill, Nairobi
- website: www.odpc.go.ke
13. Contacts in the European Union
We are a Kenyan company dealing with other organisations. Where we handle personal data of individuals in the European Union, for example staff of research partners based there, the EU General Data Protection Regulation (GDPR) may also apply. In that case our lawful bases are those in Article 6(1) GDPR that match section 4 (contract, legal obligation, legitimate interests and, for marketing, consent). You have the rights in Articles 15 to 22 GDPR and may complain to the supervisory authority in your country. Kenya does not have an EU adequacy decision, so where an EU organisation transfers personal data to us we use the European Commission's standard contractual clauses.
14. Changes to this notice
We will update this notice when our practices change. The version and date appear at the top. If we make a significant change, we will tell current business contacts by email or through the portal.
15. Contact
Laitigo Systems Limited, LR No 1870/IX/8, Western Heights, Karuna Road, Westlands, Nairobi (P.O. Box 16679-00100, Nairobi). Email: contact@laitigosystems.com.