Legal

Privacy policy.

Last updated: 25 June 2026

Kemobi Technologies Limited ("we", "us", "our") is committed to protecting your privacy and complying with the Kenya Data Protection Act 2019 ("KDPA") and, where applicable, the EU General Data Protection Regulation ("GDPR").

1. Who we are

Kemobi Technologies Limited is incorporated in Kenya. Our registered address is Kony House, Ngong Road, Ngong, Kajiado County, Kenya. For any privacy enquiries contact info@kemobitech.com.

2. What we collect and why

2.1 Data you provide

When you submit a contact or enquiry form, we collect your name, email address, phone number, company name, and message. This data is used solely to respond to your enquiry or to deliver the services you have requested.

2.2 Anonymised analytics — no cookies, no consent required

We run our own cookieless, server-side analytics. When you visit the site our server records:

  • A one-way hash of your IP address (SHA-256, salted — the raw IP is never stored)
  • Your approximate location (country, region, city — derived from the hashed IP via IPinfo)
  • Device type, operating system, and browser (parsed from your User-Agent header; the raw string is discarded)
  • The URL path visited and your referring URL (if any)

No cookie is set. No cross-site or advertising identifier is used. No personal data is retained. Because no cookie is involved, no consent banner is required under the KDPA, GDPR, or the ePrivacy Directive.

2.3 Essential cookies

The only cookies we ever set are strictly necessary:

  • Authentication session cookie — if you sign in to a protected area (expiry: session or short-lived JWT)
  • Theme preference — if you switch between light and dark mode (key: theme; expiry: 1 year)

No advertising, analytics, or third-party tracking cookies are set.

3. Legal basis for processing

  • Enquiry / contract data — necessary to respond to a pre-contractual enquiry or to perform a contract (KDPA s.30(1)(b); GDPR Art. 6(1)(b)).
  • Anonymised analytics — legitimate interests in understanding site usage to improve our service (KDPA s.30(1)(f); GDPR Art. 6(1)(f)). As the data is fully anonymised and cookieless, this processing does not require consent.
  • Essential cookies — strictly necessary to provide the service you have requested; no legal basis beyond necessity is required.

4. Data sharing

We do not sell, rent, or trade your personal data. We share data only with:

  • IPinfo.io — geolocation look-up of hashed IP addresses (country, region, city). IPinfo processes IP addresses under their own privacy policy.
  • Neon (PostgreSQL hosting) — encrypted at rest, SOC 2 Type II certified.
  • Resend / Zoho Mail — to deliver email replies to enquiries.

5. Retention

  • Enquiry data — retained for the duration of the business relationship plus 3 years, then deleted.
  • Anonymised analytics — retained indefinitely (no personal data is stored).
  • Session cookies — deleted when you close your browser or after a short expiry.

6. International transfers

Our servers are located in the United States (Neon / cloud infrastructure). Transfers outside Kenya are safeguarded by our sub-processors' compliance with applicable data-transfer mechanisms.

7. Your rights

Under the KDPA and GDPR you have the right to:

  • Access personal data we hold about you
  • Correct inaccurate data
  • Request erasure ("right to be forgotten")
  • Object to processing based on legitimate interests
  • Data portability (where technically feasible)

Because our analytics are fully anonymous we cannot identify individual visitors from analytics records. Rights requests relating to identifiable data (contact form submissions) should be sent to info@kemobitech.com.

8. Changes to this policy

We will update this policy when our practices change. Material changes will be noted with a new "Last updated" date at the top of this page.

9. Contact

Kemobi Technologies Limited
Kony House, Ngong Road, Ngong
Kajiado County, Kenya
info@kemobitech.com