Privacy Policy
How Quantec Insight collects, uses, discloses and safeguards your personal data, in compliance with the Kenya Data Protection Act, 2019.
Quantec Insight ("we," "our," or "us") is committed to protecting the privacy of our website visitors and clients. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website https://quantecinsight.co.ke/, in compliance with the Kenya Data Protection Act, 2019 (the "Act") and the regulations issued thereunder.
1. Introduction and Scope
This Privacy Policy describes our practices regarding the collection, use, storage, disclosure, transfer and protection of personal data belonging to visitors, prospective clients, clients, suppliers, partners and other individuals who interact with us through our website, electronic communications, or related digital services.
This Policy applies to:
- All pages hosted on or under https://quantecinsight.co.ke/.
- Contact forms, enquiry forms, registration pages, newsletter sign-ups and support channels.
- Any analytics, cookies or similar technologies deployed on our website.
- Any offline communications that reference this Policy.
By accessing or using our website, you acknowledge that you have read and understood this Privacy Policy. Where consent is the lawful basis for processing, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
This Policy does not apply to third-party websites, platforms or services that we may link to. We encourage you to review the privacy notices of any third party before providing your personal data to them.
2. Who We Are (Data Controller)
For the purposes of the Kenya Data Protection Act, 2019, Quantec Insight is the data controller in respect of the personal data described in this Policy. This means we determine the purpose and means of processing your personal data.
Where we engage service providers to process personal data on our behalf, those providers act as data processors and are contractually bound to process personal data only on our documented instructions and to apply appropriate technical and organisational safeguards.
3. Information We Collect
We may collect personal data that you voluntarily provide to us when you interact with our website, as well as certain data collected automatically. The categories of personal data we may process include:
3.1 Information You Provide Directly
- Contact Data: Name, email address, phone number, organisation, job title or professional details provided via contact forms, registration pages or direct correspondence.
- Enquiry and Service Data: The content of your messages, support requests, project briefs, feedback and any attachments you choose to send us.
- Account and Transaction Data: Where applicable, login credentials, preferences, billing details and records of services requested or delivered.
- Consent Records: Information about the consents you have given, the scope of those consents and the date and manner in which they were given.
3.2 Information Collected Automatically
- Technical Data: Internet Protocol (IP) address, browser type and version, operating system and platform, device type, screen resolution, language settings and referring URLs.
- Usage Data: Pages visited, time spent on pages, navigation paths, click patterns, session duration and other interactions with our website.
- Cookie and Analytics Data: Identifiers and tracking data collected through cookies, pixels, tags and similar technologies, as described in Section 8.
- Security and Log Data: Server logs, authentication events, error reports and records used to detect, prevent and investigate unauthorised access, fraud or abuse.
3.3 Information from Third Parties
- Business partners, referrers or service providers who introduce you to us.
- Publicly available sources, professional directories or public registers.
- Analytics and advertising providers that report aggregated or pseudonymised data.
3.4 Sensitive Personal Data
We do not intentionally request or process sensitive categories of personal data (such as data revealing health status, religious beliefs, political opinions, sexual orientation, or genetic and biometric data) through our website. Please do not submit such information to us through our forms or communication channels. If you believe we have inadvertently collected sensitive personal data, please contact us so that we can take appropriate action.
4. How We Collect Information
We collect personal data through the following methods:
- Direct interactions: When you complete a contact form, request a quote, subscribe to communications or correspond with us.
- Automated technologies: When your browser or device interacts with our website, cookies and similar tools may record technical and usage data.
- Server logging: Our hosting infrastructure automatically records connection and request data for security and operational purposes.
- Third-party sources: As described in Section 3.3 above.
5. Legal Basis for Processing
Under the Kenya Data Protection Act, 2019, we must have a lawful basis for processing your personal data. We rely on the following lawful bases:
- Consent: You have given clear, specific and informed consent to the processing of your personal data for one or more defined purposes, such as submitting an enquiry form, subscribing to updates or accepting non-essential cookies.
- Contractual Necessity: Processing is necessary to enter into or perform a contract with you, for example to deliver services you have requested or to respond to service requests.
- Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, provided your rights and freedoms are not overridden — for example, maintaining and securing website infrastructure, preventing fraud, improving services and internal reporting.
- Legal Obligation: Processing is necessary to comply with a legal or regulatory obligation to which we are subject, such as record-keeping, tax and accounting obligations, or responding to lawful requests from authorities.
- Vital Interests: Processing is necessary to protect your vital interests or those of another person, for example in an emergency situation where safety is at risk.
Where we rely on legitimate interests, we carry out a balancing assessment to ensure that our interests do not unfairly prejudice your rights and freedoms. You may object to processing based on legitimate interests as described in Section 12.
6. How We Use Your Information
We use the collected data to:
- Provide, operate, maintain and improve our digital services and website functionality.
- Respond to your inquiries, support tickets and service requests.
- Prepare and deliver proposals, quotes, reports and contracted deliverables.
- Communicate with you about your account, transactions or ongoing engagements.
- Monitor website traffic patterns and usage trends to improve user experience.
- Personalise content and remember your preferences.
- Prevent unauthorised access, fraud, abuse or cybersecurity breaches.
- Conduct internal analysis, research and service quality assessments.
- Comply with legal, regulatory, tax and accounting obligations.
- Establish, exercise or defend legal claims.
- Send you marketing communications where you have consented or where otherwise permitted by law.
We will not use your personal data for purposes that are incompatible with those described in this Policy unless we have a lawful basis to do so and, where required, we have provided you with updated information.
7. Disclosure and Sharing of Data
We do not sell, rent or trade your personal data. We may disclose personal data in the following limited circumstances:
7.1 Service Providers and Processors
- Hosting providers, cloud infrastructure and content delivery networks.
- IT support, security and website maintenance providers.
- Analytics and performance measurement providers.
- Communication, email delivery and customer support platforms.
- Professional advisers, including auditors, accountants and legal counsel.
All processors are engaged under written agreements requiring confidentiality, appropriate security measures and processing only on our documented instructions.
7.2 Legal and Regulatory Disclosures
- To comply with applicable law, regulation, court order or legal process.
- To respond to lawful requests from public authorities, including the Office of the Data Protection Commissioner.
- To enforce our agreements, protect our rights and property, or investigate suspected wrongdoing.
- To protect the safety, rights or property of our users, the public or our personnel.
7.3 Business Transfers
If we are involved in a merger, acquisition, restructuring, financing or sale of assets, your personal data may be transferred as part of that transaction. We will notify you where required by law, and any successor will be bound by this Policy or a policy offering comparable protection.
7.4 With Your Consent
We may share your personal data with other parties where you have given us explicit consent to do so.
7.5 Aggregated and De-Identified Data
We may create and share aggregated or de-identified information that cannot reasonably be used to identify you, for analytics, benchmarking, research and service improvement purposes.
8. Cookie Policy and Tracking Technologies
Our website uses cookies and similar technologies to enhance browsing functionality, remember preferences, measure site performance and improve your overall experience. Cookies are small text files placed on your device that allow a website to recognise your browser.
8.1 Categories of Cookies We May Use
- Strictly Necessary Cookies: Required for the website to function, including security, session management and accessibility features. These cannot be disabled through our site.
- Performance and Analytics Cookies: Help us understand how visitors use the website, which pages are most visited and how users navigate the site.
- Functionality Cookies: Remember your preferences, such as language, region or display settings.
- Targeting or Advertising Cookies: Where applicable, used to deliver relevant content or measure the effectiveness of campaigns. These are used only where a lawful basis exists.
8.2 Managing Cookies
You can adjust your browser settings to refuse cookies, delete existing cookies, or alert you when cookies are being set. Please note that disabling certain cookies may cause some features of the site to cease to function correctly. Where required, we will present a cookie banner or consent mechanism allowing you to accept or reject non-essential cookies.
8.3 Third-Party Cookies
Some cookies may be set by third-party services embedded in our website, such as analytics providers or content delivery networks. These third parties have their own privacy and cookie policies, which we encourage you to review.
8.4 Do Not Track Signals
Some browsers offer a "Do Not Track" (DNT) feature. There is currently no industry-wide standard for how websites should respond to DNT signals. We do not currently respond to DNT signals, but you may use cookie controls and browser settings to limit tracking.
9. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, reporting or contractual requirements. Retention periods vary depending on the nature of the data and the purpose of processing.
- Contact and enquiry data: Up to 24 months from last interaction, unless a contractual relationship arises.
- Client and contractual records: Duration of the engagement plus up to 7 years for legal and accounting purposes.
- Technical, log and security data: Typically up to 12 months, unless required longer for security investigations.
- Analytics and usage data: Typically up to 26 months, depending on the analytics provider configuration.
- Marketing consent records: Until consent is withdrawn, plus a reasonable period to evidence the withdrawal.
When personal data is no longer required, we will securely delete it, anonymise it, or, where deletion is not immediately possible (for example, because data is stored in backup archives), isolate it from further processing until deletion becomes feasible.
10. Data Security
We implement strict organisational and technical security measures to protect your data from unauthorised access, loss, misuse or alteration. These measures include, where appropriate:
- Encryption of data in transit using industry-standard protocols such as TLS/HTTPS.
- Access controls, authentication requirements and the principle of least privilege.
- Regular software updates, patching and vulnerability management.
- Network security controls, firewalls and monitoring for suspicious activity.
- Secure configuration of hosting and cloud infrastructure.
- Staff awareness, confidentiality obligations and data protection training.
- Incident response procedures for detecting, containing and remediating breaches.
- Periodic review of security practices and service provider assurances.
No system is completely secure. While we take reasonable and appropriate steps to protect your personal data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of any credentials you use in connection with our services.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Office of the Data Protection Commissioner and, where required, affected data subjects, in accordance with the Act.
11. International Data Transfers
Some of our service providers, hosting infrastructure or analytics tools may store or process personal data outside Kenya. Where we transfer personal data outside Kenya, we will ensure that the transfer is carried out in accordance with the Kenya Data Protection Act, 2019 and applicable regulations. Appropriate safeguards may include:
- Transferring to jurisdictions that provide an adequate level of data protection.
- Putting in place contractual clauses that require the recipient to protect personal data to a standard comparable to Kenyan law.
- Obtaining your consent where required, after informing you of the possible risks.
- Ensuring transfers are necessary for the performance of a contract with you or for other lawful purposes recognised under the Act.
You may contact us for more information about the safeguards applied to any international transfer of your personal data.
12. Your Data Protection Rights
As a data subject in Kenya, you possess specific legal rights under the Office of the Data Protection Commissioner (ODPC). Subject to the conditions and limitations set out in the Act, these rights include:
- Right to be Informed: You have the right to know what personal data we collect, why we collect it, and how it is used and shared.
- Right to Access: You can request confirmation of whether we process your personal data and request a copy of the personal data we hold about you.
- Right to Rectification: You can request that we correct inaccurate, incomplete or misleading personal data.
- Right to Erasure: You can request the deletion of your personal data under certain conditions, for example where it is no longer necessary for the purposes for which it was collected.
- Right to Restriction of Processing: You can request that we limit the processing of your personal data in specified circumstances.
- Right to Object: You can object to the processing of your personal data, including processing for direct marketing purposes.
- Right to Data Portability: You can request to receive your personal data in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right Not to be Subject to Automated Decisions: You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to the exceptions in the Act.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Office of the Data Protection Commissioner.
- Right to Compensation: You may be entitled to compensation for material or non-material damage suffered as a result of a contravention of the Act.
These rights are not absolute. Certain exemptions and limitations may apply, including where processing is necessary for compliance with a legal obligation, for the establishment or defence of legal claims, or to protect the rights of others.
13. How to Exercise Your Rights
To exercise any of the rights described in Section 12, please submit a request through our official domain communication channels. To help us process your request efficiently and securely, please include:
- Your full name and contact details.
- A clear description of the right you wish to exercise and the request you are making.
- Sufficient information to allow us to verify your identity and locate the relevant data.
- Any supporting documentation, where relevant.
We will acknowledge receipt of your request and respond within the timeframe required by the Kenya Data Protection Act, 2019. Where a request is complex or numerous, we may extend the response period and will inform you accordingly.
We may need to verify your identity before acting on a request in order to prevent unauthorised disclosure or modification of personal data. Where we cannot comply with a request, we will explain the reasons, subject to any legal restrictions.
Exercising your rights is generally free of charge. However, where a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline to act, in accordance with the Act.
14. Children's Privacy
Our website and services are not directed at children, and we do not knowingly collect personal data from children without the appropriate consent of a parent or guardian as required under the Kenya Data Protection Act, 2019.
If you are a parent or guardian and believe that a child has provided us with personal data without your consent, please contact us. We will take reasonable steps to delete such data from our systems promptly.
15. Automated Decision-Making and Profiling
We do not generally use your personal data to make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. Where we use automated tools, such as analytics or spam filtering, these are used to support operational and security functions rather than to make significant decisions about individuals.
If we ever introduce automated decision-making that falls within the scope of the Act, we will update this Policy, provide appropriate information, and implement safeguards, including the ability to request human intervention and to contest the decision.
16. Direct Marketing
Where you have provided your consent, or where we have another lawful basis to do so, we may send you updates, newsletters, service announcements or promotional communications.
You can opt out of receiving marketing communications at any time by using the unsubscribe mechanism included in our communications or by contacting us directly. We will honour your opt-out request promptly. Please note that we may still send you non-promotional messages relating to your account, transactions or legal obligations.
17. Third-Party Links and Services
Our website may contain links to third-party websites, plugins, social media platforms or embedded content. We do not control these third parties and are not responsible for their privacy practices, security measures or content.
When you interact with a third-party service, that provider may collect information about you in accordance with its own privacy policy. We encourage you to review the privacy notices of any third-party services you use.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or regulatory guidance. When we make changes, we will:
- Revise the "Last updated" date at the top of this page.
- Post the updated Policy on our website.
- Where changes are material, provide additional notice, such as a prominent website notice or direct communication where appropriate.
Your continued use of our website after the effective date of an updated Policy constitutes your acknowledgement of the changes. We encourage you to review this page periodically to stay informed about how we protect your personal data.
19. Complaints and the ODPC
If you have concerns about how we have handled your personal data, we encourage you to contact us first so that we can investigate and attempt to resolve the matter.
If you are not satisfied with our response, or if you believe we have contravened the Kenya Data Protection Act, 2019, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC), the supervisory authority responsible for enforcing data protection law in Kenya. Complaints may be lodged through the channels and procedures published by the ODPC.
20. Definitions
Personal Data: Any information relating to an identified or identifiable natural person, as defined in the Kenya Data Protection Act, 2019.
Data Subject: The individual to whom personal data relates.
Data Controller: A person, entity or public authority that alone or jointly with others determines the purpose and means of processing personal data.
Data Processor: A natural or legal person, public authority or other body that processes personal data on behalf of the data controller.
Processing: Any operation performed on personal data, including collection, recording, storage, retrieval, use, disclosure, transmission, alteration and deletion.
Consent: Any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or clear affirmative action, signify agreement to the processing of their personal data.
Cookies: Small text files stored on a user's device by a website to remember information about the user, their preferences or their browsing activity.
ODPC: The Office of the Data Protection Commissioner, the supervisory authority established under the Kenya Data Protection Act, 2019.
21. Contact Us
For any inquiries regarding this Privacy Policy or to exercise your data rights, please contact us at [email protected], or through the details on our contact page.
When contacting us about a privacy matter, please provide sufficient detail for us to identify you and understand your request, so that we can respond as efficiently as possible.