Privacy Policy
Last updated: June 1, 2025 · Compliant with GDPR (EU) 2016/679 and POPIA (Kenya)
1. Who We Are (Data Controller)
BazionWeb ("we", "our", "us"), based in Nairobi, Kenya, is the data controller for personal data collected via bazionweb.com and our client portal. Contact: [email protected]
2. Data We Collect (GDPR Art. 13)
| Data | Purpose | Basis |
|---|---|---|
| Name, email, phone | Account creation, service delivery | Contract |
| Billing address, payment info | Invoice generation, payment processing | Contract |
| Usage data, logs | Security monitoring, debugging | Legitimate interest |
| IP address, browser info | Fraud prevention, uptime monitoring | Legitimate interest |
| Support ticket content | Service delivery, quality improvement | Contract |
| Email communications | Support, notifications, marketing (opt-in) | Consent / Contract |
3. Data Retention
Active client data is retained for the duration of the contract plus 7 years for tax/legal compliance. Support tickets: 3 years. Marketing data: until opt-out or 2 years of inactivity. Audit logs: 5 years (GDPR compliance requirement). Backup data: per plan retention schedule (30–365 days).
4. Third-Party Processors
We share data with these processors under DPA agreements:
- Hetzner / Oracle Cloud — Infrastructure hosting (Germany / USA)
- Cloudflare — CDN, DNS, DDoS protection (USA — EU SCCs in place)
- Backblaze B2 — Encrypted backup storage (USA — EU SCCs in place)
- Resend — Transactional email (USA — EU SCCs in place)
- Sentry — Error monitoring (USA — EU SCCs in place)
We do not sell personal data to any third party.
5. Your Rights
Under GDPR and POPIA, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion (subject to legal retention obligations)
- Portability — receive your data in machine-readable format
- Object — opt out of legitimate-interest processing
- Withdraw consent — at any time, for consent-based processing
Submit requests to: [email protected]. We respond within 30 days.
6. Data Breach Notification
In the event of a personal data breach, we will notify affected clients within 72 hours of discovery, in accordance with GDPR Article 33. Notification will include the nature of the breach, data affected, likely consequences, and remediation actions taken.
7. Cookies
We use strictly necessary cookies for portal authentication and session management. Analytics cookies (PostHog) require your consent. See our Cookie Policy for details.
8. Contact & Complaints
Data Protection contact: [email protected]
You have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya (ODPC).