1. Who we are
Kendagor Tech operates the Service at kendagortech.online. This policy explains how we handle personal data in line with the Data Protection Act, 2019 of Kenya ("the Act") and the Data Protection (General) Regulations, 2021.
- Data controller for the data of our own account holders (ISPs, their staff) and website visitors: Kendagor Tech.
- Data processor for the data of an ISP's end customers (Hotspot and PPPoE users): we process it only on the ISP's instructions under the Data Processing Agreement. The ISP is the controller and you should contact them first about that data.
Data protection contact: kendagortech@gmail.com.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, company name, email, phone and WhatsApp number, country, password (stored only as a one-way hash), staff accounts | You |
| Billing data | Subscription plan, invoices, payment references and amounts. We do not store card numbers or M-PESA PINs. | You, payment providers |
| Network data | Router names, IP addresses, configuration, health metrics, logs | Your routers |
| End-customer data (as processor) | Phone numbers, names, device MAC and IP addresses, session times, data usage, payment receipts, vouchers | The ISP, its routers, payment providers |
| Security data | Sign-in attempts, IP address, browser type, audit logs of account changes | Automatically |
| Communications | Support tickets, bug reports, emails with us | You |
| Website analytics | Anonymous daily page-view counts (only with your consent; see the Cookie Policy) | Automatically |
We do not intentionally collect sensitive personal data (such as health, biometric or religious data) and ask you not to enter it in the Service. The Service is not directed at children under 18.
3. Why we use it and our lawful basis
| Purpose | Lawful basis under section 30 of the Act |
|---|---|
| Creating and running your account, providing the Service, support | Performance of our contract with you |
| Billing, invoicing, collecting fees, keeping financial records | Contract; compliance with legal obligations (e.g. tax law) |
| Security, fraud and abuse prevention, audit logs | Legitimate interests in protecting users and the platform; legal obligations |
| Service emails (security alerts, invoices, policy changes) | Contract; legal obligations |
| Product news and marketing | Your consent, which you can withdraw at any time |
| Website analytics | Your consent via the cookie banner |
| Responding to lawful requests from authorities | Compliance with legal obligations |
We do not sell personal data, and we do not use it for advertising. We do not make decisions that produce legal or similarly significant effects on you based solely on automated processing.
5. Transfers outside Kenya
Our servers are hosted by DigitalOcean in its Sydney, Australia data centre, and some of our providers process data in other countries. Where personal data leaves Kenya we do so in line with Part VI of the Act: we transfer only what is needed, to providers that are contractually bound to protect it with appropriate safeguards, including encryption in transit, access controls and confidentiality obligations. You can ask us for more information about these safeguards.
6. How long we keep it
- Account and network data: for as long as your account exists. When an account is closed or deleted (including automatic deletion after 15 days of inactivity, see the Terms), its data is deleted from our live systems.
- Financial records we must keep: for the period required by Kenyan tax law (generally five years under the Tax Procedures Act, 2015).
- Security and audit logs: for as long as needed to investigate and prevent abuse, then deleted.
- Website analytics: anonymous daily visitor keys are deleted after 45 days; only aggregate counts are kept.
- Backups: deleted data may remain in encrypted backups for a limited time until they are overwritten.
7. How we protect it
We use technical and organisational measures appropriate to the risk, including HTTPS encryption for all traffic, hashed passwords, role-based access, per-router RADIUS secrets, rate-limiting and lock-out of repeated failed sign-ins, audit logs, and restricted server access. No system is perfectly secure; if a personal-data breach creates a real risk of harm, we will notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it and inform affected people without undue delay, as required by section 43 of the Act.
8. Your rights
Under the Act you have the right to:
- be informed of how your data is used (this policy);
- access the personal data we hold about you;
- have inaccurate data corrected, and have data deleted where there is no lawful reason to keep it;
- object to processing, including to direct marketing at any time;
- withdraw consent where we rely on it, without affecting earlier processing;
- receive your data in a portable format;
- not be subject to a decision based solely on automated processing that significantly affects you.
To exercise a right, email kendagortech@gmail.com from the address on your account. We may need to verify your identity. We respond within the time limits set by the Act and Regulations. If you are an ISP's end customer, contact your ISP first; we will help them respond.
You may also complain to the Office of the Data Protection Commissioner (www.odpc.go.ke). We would appreciate the chance to resolve your concern first.
10. Changes to this policy
We will post any update here with a new effective date and notify account holders of material changes by email or in the dashboard.