Privacy Policy
How Nexis Digital Systems processes personal data under the Kenya Data Protection Act 2019.
Updated: 2026-03-12
Overview
This Privacy Policy explains how Nexis Digital Systems (“Nexis”, “we”, “us”) collects, uses, discloses, and protects personal data when you:
- Visit our website
- Contact us via forms, email, phone, or WhatsApp
- Request a quotation or submit a project brief
- Subscribe to updates (newsletter)
We follow privacy-by-design principles and align our practices with the Kenya Data Protection Act, 2019 and guidance from the Office of the Data Protection Commissioner (ODPC).
Data Controller
- Controller: Nexis Digital Systems
- Email: support@nexis.example (sample)
- Phone/WhatsApp: +254 700 000 000 (sample)
- Location: Nairobi, Kenya (sample)
What personal data we collect
Depending on how you interact with us, we may collect:
- Contact details: name, email address, phone number, company name
- Project details: requirements you submit (e.g., M‑Pesa/eTIMS scope, timelines, budget ranges)
- Technical data: IP address, device/browser data, approximate location (city/country), and cookies
- Communications: messages sent to us (email, WhatsApp, contact forms)
We do not intentionally collect sensitive categories of personal data unless you voluntarily include them in your message.
Why we process your data (purposes)
We process personal data to:
- Respond to enquiries and provide quotations
- Deliver requested services and support
- Improve website performance, reliability, and content
- Measure marketing effectiveness (where consent is provided)
- Maintain security, prevent abuse, and troubleshoot issues
Legal basis for processing
We rely on one or more of the following, depending on context:
- Consent: for optional cookies (analytics/marketing) and newsletters
- Steps prior to contract / performance of contract: to respond to requests and deliver services
- Legitimate interests: security monitoring, fraud prevention, and service improvement
- Legal obligations: where records are required by law (e.g., accounting)
Cookies and similar technologies
We use:
- Essential cookies: required for core site functionality and security
- Analytics cookies (optional): to understand usage and improve the site
- Marketing cookies (optional): to measure campaign performance
You can manage choices in the cookie banner or via our Cookie Policy.
Sharing and processors
We may share your data with service providers who help us operate (for example: hosting, email delivery, analytics, or customer support tooling). We only share what is necessary and expect processors to apply appropriate safeguards.
International transfers
Some providers may process data outside Kenya. Where applicable, we apply safeguards such as contractual protections and data minimization.
Data retention
We keep data only as long as necessary for the purposes described above. Typical retention periods (samples):
- Enquiries/quotes: 12–24 months
- Project records: duration of the engagement plus a reasonable period for support
- Security logs: short retention, unless needed for investigations
Your rights (Kenya Data Protection Act 2019)
You may have rights to:
- Access and obtain a copy of your personal data
- Request correction of inaccurate data
- Request deletion (where applicable)
- Object to processing in certain circumstances
- Withdraw consent for optional processing
- Lodge a complaint with the ODPC
Security
We implement reasonable technical and organizational measures such as access controls, encryption in transit, and least-privilege practices. No method of transmission is 100% secure, but we work to reduce risk.
Contact
To exercise your rights or ask questions, contact:
- Email: support@nexis.example (sample)
- WhatsApp: +254 700 000 000 (sample)