Kendagor TechLegal centre Back to app →

Privacy Policy

What personal data we collect, why, how long we keep it and your rights.

Version 1.0 · Effective 9 October 2026

1. Who we are

Kendagor Tech operates the Service at kendagortech.online. This policy explains how we handle personal data in line with the Data Protection Act, 2019 of Kenya ("the Act") and the Data Protection (General) Regulations, 2021.

  • Data controller for the data of our own account holders (ISPs, their staff) and website visitors: Kendagor Tech.
  • Data processor for the data of an ISP's end customers (Hotspot and PPPoE users): we process it only on the ISP's instructions under the Data Processing Agreement. The ISP is the controller and you should contact them first about that data.

Data protection contact: kendagortech@gmail.com.

2. Data we collect

CategoryExamplesSource
Account dataName, company name, email, phone and WhatsApp number, country, password (stored only as a one-way hash), staff accountsYou
Billing dataSubscription plan, invoices, payment references and amounts. We do not store card numbers or M-PESA PINs.You, payment providers
Network dataRouter names, IP addresses, configuration, health metrics, logsYour routers
End-customer data (as processor)Phone numbers, names, device MAC and IP addresses, session times, data usage, payment receipts, vouchersThe ISP, its routers, payment providers
Security dataSign-in attempts, IP address, browser type, audit logs of account changesAutomatically
CommunicationsSupport tickets, bug reports, emails with usYou
Website analyticsAnonymous daily page-view counts (only with your consent; see the Cookie Policy)Automatically

We do not intentionally collect sensitive personal data (such as health, biometric or religious data) and ask you not to enter it in the Service. The Service is not directed at children under 18.

3. Why we use it and our lawful basis

PurposeLawful basis under section 30 of the Act
Creating and running your account, providing the Service, supportPerformance of our contract with you
Billing, invoicing, collecting fees, keeping financial recordsContract; compliance with legal obligations (e.g. tax law)
Security, fraud and abuse prevention, audit logsLegitimate interests in protecting users and the platform; legal obligations
Service emails (security alerts, invoices, policy changes)Contract; legal obligations
Product news and marketingYour consent, which you can withdraw at any time
Website analyticsYour consent via the cookie banner
Responding to lawful requests from authoritiesCompliance with legal obligations

We do not sell personal data, and we do not use it for advertising. We do not make decisions that produce legal or similarly significant effects on you based solely on automated processing.

4. Who we share it with

We share personal data only as needed to run the Service, with providers bound by confidentiality and data-protection obligations:

  • Hosting: DigitalOcean, which hosts our servers (see section 5).
  • Payments: Safaricom (M-PESA) and any other licensed payment provider an ISP chooses to enable, to process payments.
  • Email and messaging: our email delivery provider, and SMS or WhatsApp providers configured on the platform, to send messages you or your ISP request.
  • Sign-in and security: Google, if you choose "Continue with Google"; Cloudflare Turnstile, if bot protection is enabled on a form.
  • Your ISP: if you are an end customer, your ISP can see your data in its dashboard.
  • Authorities: when the law requires it, following the Legal Requests & Enforcement Policy.
  • Business transfer: a buyer or successor of our business, who must keep protecting the data under this policy.

5. Transfers outside Kenya

Our servers are hosted by DigitalOcean in its Sydney, Australia data centre, and some of our providers process data in other countries. Where personal data leaves Kenya we do so in line with Part VI of the Act: we transfer only what is needed, to providers that are contractually bound to protect it with appropriate safeguards, including encryption in transit, access controls and confidentiality obligations. You can ask us for more information about these safeguards.

6. How long we keep it

  • Account and network data: for as long as your account exists. When an account is closed or deleted (including automatic deletion after 15 days of inactivity, see the Terms), its data is deleted from our live systems.
  • Financial records we must keep: for the period required by Kenyan tax law (generally five years under the Tax Procedures Act, 2015).
  • Security and audit logs: for as long as needed to investigate and prevent abuse, then deleted.
  • Website analytics: anonymous daily visitor keys are deleted after 45 days; only aggregate counts are kept.
  • Backups: deleted data may remain in encrypted backups for a limited time until they are overwritten.

7. How we protect it

We use technical and organisational measures appropriate to the risk, including HTTPS encryption for all traffic, hashed passwords, role-based access, per-router RADIUS secrets, rate-limiting and lock-out of repeated failed sign-ins, audit logs, and restricted server access. No system is perfectly secure; if a personal-data breach creates a real risk of harm, we will notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it and inform affected people without undue delay, as required by section 43 of the Act.

8. Your rights

Under the Act you have the right to:

  • be informed of how your data is used (this policy);
  • access the personal data we hold about you;
  • have inaccurate data corrected, and have data deleted where there is no lawful reason to keep it;
  • object to processing, including to direct marketing at any time;
  • withdraw consent where we rely on it, without affecting earlier processing;
  • receive your data in a portable format;
  • not be subject to a decision based solely on automated processing that significantly affects you.

To exercise a right, email kendagortech@gmail.com from the address on your account. We may need to verify your identity. We respond within the time limits set by the Act and Regulations. If you are an ISP's end customer, contact your ISP first; we will help them respond.

You may also complain to the Office of the Data Protection Commissioner (www.odpc.go.ke). We would appreciate the chance to resolve your concern first.

9. Cookies

See the Cookie Policy. Optional cookies are off until you allow them.

10. Changes to this policy

We will post any update here with a new effective date and notify account holders of material changes by email or in the dashboard.