Skip to content
Upeo Africa Technologies

Privacy Policy

This policy explains what personal data Upeo Africa Technologies collects when you use our website or engage us for work, why we hold it, how we protect it, and the rights you can exercise over it at any time.

Effective 1 September 2026 · Last updated 23 August 2026

This Privacy Policy (“Policy”) describes how Upeo Africa Technologies Ltd (“Upeo Africa”, the “Company”, “we”, “us” or “our”), a limited liability company incorporated in the Republic of Kenya, collects, uses, stores, discloses, transfers and otherwise processes personal data. This Policy is issued in accordance with the Constitution of Kenya, 2010, the Data Protection Act, No. 24 of 2019 (the “Act”) and its subsidiary regulations, and, where applicable, Regulation (EU) 2016/679 (the General Data Protection Regulation or “GDPR”). By accessing our website or engaging our services, you acknowledge that you have read and understood this Policy.

1. Interpretation and definitions

1.1 In this Policy, unless the context otherwise requires, the following expressions bear the meanings assigned to them under the Act and the GDPR:

  • “Data Controller” means the natural or legal person who, alone or jointly with others, determines the purpose and means of processing personal data; in respect of this Policy, the Data Controller is the Company.
  • “Data Processor” means a natural or legal person who processes personal data on behalf of the Data Controller.
  • “Data Subject” means an identified or identifiable natural person who is the subject of personal data.
  • “Personal Data” means any information relating to an identified or identifiable natural person.
  • “Processing” means any operation performed on personal data, whether or not by automated means.
  • “Sensitive Personal Data” means data revealing a person’s race, health status, ethnic or social origin, conscience, belief, genetic or biometric data, property details, marital status, family details, sex or sexual orientation.
  • “ODPC” means the Office of the Data Protection Commissioner established under the Act.

1.2 Headings are for convenience only and do not affect the interpretation of this Policy. Words importing the singular include the plural and vice versa.

2. Data Controller and Data Protection Officer

2.1 The Data Controller responsible for your personal data is Upeo Africa Technologies Ltd, of Yunis Building, Moi Avenue, Mombasa, P.O. Box 88225-80100, Mombasa, Kenya.

2.2 Questions, requests, or complaints regarding this Policy or the processing of your personal data may be directed to our Data Protection Officer by email at hello@upeoafricatechnologies.co.ke or by writing to the address stated in clause 2.1.

3. Scope

3.1 This Policy applies to all personal data processed by the Company in connection with our website, our communications, and the provision of our software development, design, branding, and digital marketing services (the “Services”).

3.2 Where we process personal data on behalf of a client in the course of delivering the Services, we do so as a Data Processor, and such processing is governed by the data processing terms of the relevant client agreement rather than this Policy.

4. Personal data we collect

4.1 Depending on your interaction with us, we may collect and process the following categories of personal data:

  • Identity and contact data — your name, job title, employer, email address, telephone number and postal address.
  • Enquiry and engagement data — the contents of enquiry forms, proposals, correspondence, project requirements and instructions you provide.
  • Financial and transaction data — billing details and records of payments to and from you (we do not store full card numbers).
  • Technical and usage data — internet protocol (IP) address, browser type and version, device information, pages viewed, and the dates and times of your visits, collected through cookies and analytics.
  • Marketing and communications data — your preferences in receiving communications from us.

4.2 We do not intentionally collect Sensitive Personal Data through our website. Where such data is necessary for a specific engagement, we process it only with your explicit consent or another lawful basis under section 30 of the Act and Article 9 of the GDPR.

5. How we collect personal data

We collect personal data:

  1. directly from you, when you complete a form, request a proposal, correspond with us, or engage our Services;
  2. automatically, through cookies and similar technologies, when you interact with our website; and
  3. from third parties, such as our analytics providers and publicly available business sources, where lawful.

6. Purposes and lawful bases of processing

6.1 We process personal data only where the Act and the GDPR permit. The lawful bases on which we rely are: (a) your consent; (b) the performance of a contract with you or to take steps at your request prior to entering a contract; (c) compliance with a legal obligation; and (d) our legitimate interests, provided these are not overridden by your rights and freedoms.

6.2 We process personal data for the following purposes:

PurposeLawful basis
Responding to enquiries and providing requested informationConsent; steps prior to a contract
Providing, managing and delivering the ServicesPerformance of a contract
Invoicing, accounting and recovering sums dueContract; legal obligation; legitimate interests
Operating, securing and improving our websiteLegitimate interests
Sending relevant marketing communicationsConsent; legitimate interests
Meeting legal, tax, and regulatory obligationsLegal obligation

7. Cookies and similar technologies

7.1 Our website uses cookies and similar technologies to function correctly, to remember your preferences, and to measure performance. Cookies are small text files stored on your device.

7.2 You may accept or reject non-essential cookies and may configure your browser to refuse cookies. Disabling cookies may affect the functionality of the website. Where required by law, we obtain your consent before setting non-essential cookies.

8. Disclosure of personal data

8.1 We do not sell your personal data. We may disclose personal data to the following categories of recipients:

  • service providers and Data Processors who host our systems, deliver email, provide analytics, and support our operations, under written contracts imposing confidentiality and data protection obligations consistent with the Act and the GDPR;
  • professional advisers, including lawyers, auditors, and accountants;
  • public authorities, regulators or courts, where required by law or to establish, exercise, or defend legal claims; and
  • a successor entity in the event of a merger, acquisition, or reorganisation of the Company.

9. International transfers of personal data

9.1 Some of our service providers are located outside Kenya. Where we transfer personal data outside Kenya, we do so in accordance with section 48 and section 49 of the Act, and, in respect of data subject to the GDPR, only where an adequate level of protection is ensured, including through adequacy decisions, Standard Contractual Clauses, or your explicit consent.

10. Data retention

10.1 We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, contractual, or reporting requirements. Financial records are retained for a minimum of seven (7) years in accordance with applicable tax law.

10.2 When personal data is no longer required, we securely delete or anonymise it.

11. Data security

11.1 We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage, including access controls, encryption in transit, regular backups, and staff confidentiality obligations.

11.2 In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ODPC and, where required, affected data subjects without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach.

12. Your rights as a data subject

12.1 Subject to the Act and the GDPR, you have the right to:

  1. be informed of the use to which your personal data is put;
  2. access your personal data in our custody;
  3. request correction or rectification of inaccurate or incomplete data;
  4. request erasure or deletion of personal data that we are no longer authorised to retain;
  5. object to or restrict the processing of your personal data;
  6. data portability, where technically feasible;
  7. withdraw consent at any time, without affecting prior lawful processing; and
  8. not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

13. Exercising your rights

13.1 You may exercise any of the rights in clause 12 by contacting our Data Protection Officer using the details in clause 2. We will respond within the timelines prescribed by the Act and the GDPR, ordinarily within thirty (30) days. We may require verification of your identity before acting on a request.

14. Direct marketing

14.1 We send marketing communications only where you have consented or where permitted by law. You may opt out at any time by using the unsubscribe mechanism in our communications or by contacting us.

15. Children’s personal data

15.1 Our website and Services are not directed at children under the age of eighteen (18), and we do not knowingly collect their personal data without the consent of a parent or guardian.

16. Complaints

16.1 If you are dissatisfied with how we have handled your personal data, you may lodge a complaint with us in the first instance. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya, and, where the GDPR applies, with your local supervisory authority.

17. Changes to this Policy

17.1 We may amend this Policy from time to time. The revised Policy takes effect on the date it is published on this website, and the “Last updated” date will be revised accordingly.

18. Governing law

18.1 This Policy is governed by and construed in accordance with the laws of the Republic of Kenya, without prejudice to the additional protections afforded to data subjects under the GDPR where it applies.

19. Contact us

Any questions concerning this Policy may be addressed to the Data Protection Officer, Upeo Africa Technologies Ltd, Yunis Building, Moi Avenue, Mombasa, or by email to hello@upeoafricatechnologies.co.ke.

We're here to help