Legal

Privacy Policy

Last updated: September 2026  ·  SecureZaidi Ltd, Nairobi, Kenya

1. Who We Are

SecureZaidi Ltd ("SecureZaidi", "we", "us", "our") is a cybersecurity and data protection compliance consultancy based in Nairobi, Kenya. We help small and medium-sized enterprises achieve compliance with the Data Protection Act, 2019 (the "DPA"), reduce risk, and build resilient security cultures.

For the personal data described in this notice, SecureZaidi is the data controller within the meaning of the DPA. You can reach us about anything in this notice at [email protected].

2. Scope of This Notice

This notice explains how we handle personal data belonging to visitors to our website, people who contact us or subscribe to our updates, representatives of our clients and prospective clients, and our suppliers. It does not cover personal data we process on behalf of our clients in the course of delivering our services — see section 4 below.

3. Personal Data We Collect

We collect most of this data directly from you. The exception is prospect data, which we collect indirectly from public business listings (including Google Maps listings, via our research provider) and from the organisation's own public website. Where we hold prospect data and contact you, we tell you where we found the address in that first message, and you can ask us to stop or to delete it at any time.

We do not collect sensitive personal data (as defined in section 2 of the DPA) through our website, and we ask that you do not send it to us unsolicited.

4. Data We Process on Behalf of Clients

In delivering compliance and security services, we may handle personal data contained in client systems and documents (for example, during a compliance gap assessment). For that data, our client is the data controller and SecureZaidi acts as a data processor on the client's documented instructions, under a written engagement agreement with appropriate confidentiality and security obligations. Questions about that data should be directed to the relevant client; we will assist them in responding.

5. How and Why We Use Your Data

We process personal data only where the DPA permits it, namely:

Business-to-business outreach. We sometimes approach organisations we have not dealt with before. We do this only at a general or role-based address published by the organisation itself — an address that identifies a business rather than a person — and we do not send marketing to an individual's personal or named work address without their consent, as section 37 of the DPA requires. Every such message tells you where we found the address, links to this notice, and carries a one-click unsubscribe as well as a reply-to-stop option. We act on either immediately, and we keep a permanent do-not-contact record so that it cannot be undone by a later campaign.

6. Sharing Your Data

We do not sell personal data, and we do not share it with third parties for their own marketing. We share personal data only with:

7. International Transfers

Some of our service providers store data outside Kenya — for example, our email is hosted in the European Union. Where personal data is transferred outside Kenya, we do so in accordance with sections 48 and 49 of the DPA, ensuring the recipient is subject to appropriate safeguards for the security and protection of the data.

8. How Long We Keep Your Data

When data is no longer required, we delete or anonymise it securely.

9. How We Protect Your Data

Security is our trade, and we apply the same standards to ourselves that we recommend to clients. Our measures include encryption of data in transit, multi-factor authentication and access controls on our systems, email authentication (SPF, DKIM, DMARC), vendor due diligence, and documented breach response procedures. In the unlikely event of a personal data breach affecting your rights, we will notify the ODPC and affected individuals as required by section 43 of the DPA.

10. Your Rights

Under the DPA you have the right to:

To exercise any of these rights, email [email protected]. We will respond within a reasonable time and in any event within the periods required by the DPA. We may need to verify your identity before acting on a request.

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner: www.odpc.go.ke, [email protected], Britam Towers, 12th Floor, Hospital Road, Upperhill, Nairobi.

11. Automated Decision-Making and Children

We do not make decisions about you based solely on automated processing, and nothing we do produces legal effects for you or otherwise significantly affects you within the meaning of section 35 of the DPA. To be clear about what we do do: when you send us an enquiry, an automated step summarises it and suggests how urgent it looks, so that we can prioritise our replies. A person reviews every one and decides what happens next, and no reply is sent without one. Our services and website are directed at businesses; we do not knowingly collect personal data from children.

12. Changes to This Notice

We may update this notice from time to time. The "last updated" date at the top reflects the current version, and material changes will be highlighted on this page.

13. Contact

For any privacy-related questions or to exercise your rights, contact us at [email protected] or write to SecureZaidi Ltd, Nairobi, Kenya.