Legal

Privacy Policy

How Steff Cloud Limited collects, uses and protects your personal data — written to be read, not to be survived.

Last updated

Who is responsible for your data

Steff Cloud Limited (“Steff Cloud”, “we”) is the data controller for personal data collected through steffcloud.co.ke. We are a company registered in Kenya, registration number PVT-RQ13VMZZ, based at Nakuru–Solai Road, opposite Emboita, Nakuru, Kenya.

For anything in this policy, contact us at info@steffcloud.co.ke or +254 118 407 026.

What we collect, and why

When you contact us or request a quote

Your name, phone number, email address, and whatever you tell us about your business and what you need. We collect this because you asked us to get in touch — the lawful basis is your consent, and performance of steps taken at your request before entering a contract.

When you become a client

Project details, billing information and payment records, including M-Pesa transaction references. We need these to deliver the work and to meet our tax and record-keeping obligations under Kenyan law.

When you browse the site

Standard technical information your browser sends — IP address, browser type, pages visited. If, and only if, you have accepted analytics cookies, we also collect aggregate statistics about which pages get read and how visitors arrive.

We do not collect sensitive personal data as defined in the Data Protection Act, and we do not buy contact lists.

Cookies and tracking

Nothing beyond strictly necessary cookies is set until you choose. There are no pre-ticked boxes, and rejecting is one click, exactly like accepting.

  • Strictly necessary. Keeps the site working — page security, form submissions and remembering this choice. These cannot be switched off.
  • Analytics. Anonymous counts of which pages get read and how people arrive. Helps us write about what you actually want.
  • Marketing. Lets us show relevant ads on other platforms and measure whether they worked. Off unless you turn it on.

Your choice is stored for 365 days, after which we ask again. You can change or withdraw it at any time using the Cookie settings link at the bottom of any page.

Who we share it with

We do not sell your personal data. We share it only with service providers who help us operate, and only as far as they need it:

  • Hosting and infrastructure — Cloudflare and Supabase.
  • Messaging — the WhatsApp Business Platform, operated by Meta, when we reply to you there.
  • Payments — M-Pesa (Safaricom) and our bank, for processing payments.
  • Where the law requires it, such as a valid request from a regulator or court.

Some of these providers process data outside Kenya. Where that happens we rely on the provider’s contractual data-protection commitments, consistent with the transfer conditions in Part VI of the Data Protection Act.

How long we keep it

Enquiries that do not become projects are deleted after 24 months. Client and financial records are kept for seven years, as required by Kenyan tax law. Analytics data is retained in aggregate for 26 months. Consent records are kept for as long as the consent is current, so we can demonstrate it was given.

Your rights

Under the Data Protection Act, 2019 you have the right to:

  • Be told how your data is being used — that is what this page is for.
  • Ask for a copy of the personal data we hold about you.
  • Have inaccurate or incomplete data corrected.
  • Ask us to delete your data, where we have no overriding legal obligation to keep it.
  • Object to processing, or ask us to restrict it.
  • Receive your data in a portable format.
  • Withdraw consent at any time — as easily as you gave it.

Email info@steffcloud.co.ke and we will respond within 30 days. There is no charge.

If you are not satisfied with how we handle it, you can complain to the Office of the Data Protection Commissioner (ODPC). You do not need our permission to do that.

How we protect it

Data is transmitted over HTTPS and stored in access-controlled systems. Access is limited to people who need it to do their work, and administrative access requires authentication. No system is perfectly secure, but if a breach ever put your rights at risk we will notify you and the ODPC as the Act requires.

Children

This site is intended for businesses and is not directed at children under 18. We do not knowingly collect their data. If you believe we have, contact us and we will delete it.

Changes to this policy

When we change how we handle data, we update this page and the date at the top. If a change is significant, we will reset cookie consent so you are asked again rather than carried over on a decision you made about something else. See also our Terms of Service.