Legal

Privacy Policy

Last updated: June 1, 2025 · Compliant with GDPR (EU) 2016/679 and POPIA (Kenya)

1. Who We Are (Data Controller)

BazionWeb ("we", "our", "us"), based in Nairobi, Kenya, is the data controller for personal data collected via bazionweb.com and our client portal. Contact: [email protected]

2. Data We Collect (GDPR Art. 13)

DataPurposeBasis
Name, email, phoneAccount creation, service deliveryContract
Billing address, payment infoInvoice generation, payment processingContract
Usage data, logsSecurity monitoring, debuggingLegitimate interest
IP address, browser infoFraud prevention, uptime monitoringLegitimate interest
Support ticket contentService delivery, quality improvementContract
Email communicationsSupport, notifications, marketing (opt-in)Consent / Contract

3. Data Retention

Active client data is retained for the duration of the contract plus 7 years for tax/legal compliance. Support tickets: 3 years. Marketing data: until opt-out or 2 years of inactivity. Audit logs: 5 years (GDPR compliance requirement). Backup data: per plan retention schedule (30–365 days).

4. Third-Party Processors

We share data with these processors under DPA agreements:

  • Hetzner / Oracle Cloud — Infrastructure hosting (Germany / USA)
  • Cloudflare — CDN, DNS, DDoS protection (USA — EU SCCs in place)
  • Backblaze B2 — Encrypted backup storage (USA — EU SCCs in place)
  • Resend — Transactional email (USA — EU SCCs in place)
  • Sentry — Error monitoring (USA — EU SCCs in place)

We do not sell personal data to any third party.

5. Your Rights

Under GDPR and POPIA, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion (subject to legal retention obligations)
  • Portability — receive your data in machine-readable format
  • Object — opt out of legitimate-interest processing
  • Withdraw consent — at any time, for consent-based processing

Submit requests to: [email protected]. We respond within 30 days.

6. Data Breach Notification

In the event of a personal data breach, we will notify affected clients within 72 hours of discovery, in accordance with GDPR Article 33. Notification will include the nature of the breach, data affected, likely consequences, and remediation actions taken.

7. Cookies

We use strictly necessary cookies for portal authentication and session management. Analytics cookies (PostHog) require your consent. See our Cookie Policy for details.

8. Contact & Complaints

Data Protection contact: [email protected]
You have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya (ODPC).