Microstation — Since 1995

Privacy Policy

How Microstation collects, uses, stores, shares and protects your personal data in line with Kenya's Data Protection Act, 2019 and ODPC requirements.

🛡️Data Protection Act 2019
🇰🇪ODPC Compliant
🔒Secure by Design
Governing lawData Protection Act, 2019
RegulatorODPC — Kenya
Lawful basesConsent & contract
1

Introduction

This Privacy Policy explains how Microstation ("we", "us", "our") collects, uses, stores, shares and protects personal data when you visit microstation.co.ke, engage our IT, software, ERP and digital services, or otherwise interact with us. Protecting your personal data is a core part of the trust you place in us.

This policy is issued in compliance with Article 31 of the Constitution of Kenya, 2010 and the Data Protection Act, 2019 (Act No. 24 of 2019), together with the Data Protection (General) Regulations, 2021, the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, and the Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021. We process personal data as a data controller and, in some cases, as a data processor.

The Data Protection Act, 2019 defines "personal data" as any information relating to an identified or identifiable natural person. By using our website or services, you acknowledge that you have read and understood this Privacy Policy. Where we rely on your consent as a lawful basis, you may withdraw it at any time.

2

Who We Are (Data Controller)

Microstation is an information technology solutions provider in Nairobi, Kenya, offering web development, IT support, ERP systems, custom software development, digital marketing and related technology services. For the purposes of the Data Protection Act, 2019, Microstation is the data controller responsible for the personal data described in this policy.

Our details

  • Registered name / trading name: Microstation
  • Physical address: Westlands, Nairobi, Kenya
  • Email: kiarie@microstation.co.ke
  • Telephone: +254 722 711 162 / +254 731 822 629
  • Data protection contact: the person responsible for data protection matters can be reached using the email address above.
3

Personal Data We Collect

We only collect personal data that is adequate, relevant and limited to what is necessary for the purposes described in this policy (the principle of data minimisation under Section 25 of the Data Protection Act, 2019).

Information you provide directly

  • Identity and contact details such as your name, company name, email address and telephone number.
  • Enquiry, quotation and support information you share with us by email, telephone, or our contact forms.
  • Account and registration details for our products and platforms, including saloPoint and our Hotel Management App.
  • Billing, invoicing and payment information required to deliver our services.
  • Records of correspondence, meetings, contracts and agreements.

Information collected automatically

  • Technical data such as IP address, browser type and version, device type, operating system and screen resolution.
  • Usage data such as the pages you visit, the time and date of your visit, time spent and referring URL.
  • Approximate geographic location derived from your IP address.
  • Data collected through cookies and similar technologies as described in Section 7 below.

Sensitive personal data

We do not intentionally collect sensitive personal data (as defined in Section 2 of the Data Protection Act, 2019) unless it is necessary for a specific purpose, you have given explicit consent, or the law requires it. Where we process such data, we apply additional safeguards in line with Sections 44 to 47 of the Act.

4

How We Collect Your Data

We collect personal data in the following ways:

  • Directly from you when you submit a form, send us an email, call us, request a quotation, or enter into a contract with us.
  • Automatically when you browse our website, through cookies, log files and analytics technologies.
  • From third parties such as business partners, resellers, payment providers and hosting providers, where this is lawful.
  • From publicly available sources, such as company registries and professional networks, where relevant to our business relationship.
5

Lawful Basis for Processing

Under Section 30 of the Data Protection Act, 2019 we may process personal data on one or more of the following lawful bases. We identify and document the applicable basis before processing:

  • Consent — where you have given clear, specific and informed consent, for example to receive our newsletter or marketing communications.
  • Performance of a contract — where processing is necessary to provide the services or products you have requested.
  • Compliance with a legal obligation — for example, maintaining accounting, tax and statutory records.
  • Vital interests — where processing is necessary to protect your life or health, or that of another person.
  • Public interest — where processing is necessary for the performance of a task carried out in the public interest.
  • Legitimate interests — for our legitimate business interests such as network security, service improvement and fraud prevention, provided your rights and freedoms are not overridden.
6

How We Use Your Personal Data

We use personal data only for the purposes for which it was collected or for compatible purposes permitted by law. These purposes include:

  • Responding to your enquiries, requests and providing quotations.
  • Delivering, maintaining, supporting and improving our services, software and platforms.
  • Managing your account, processing payments, invoicing and debt recovery.
  • Sending service and transactional messages, such as updates, reminders and confirmations.
  • Sending marketing communications where you have consented, with an easy option to unsubscribe at any time.
  • Analysing and improving our website, products and services.
  • Complying with legal, regulatory, tax and accounting obligations.
  • Detecting, preventing and investigating fraud, abuse, misuse and security incidents.
  • Establishing, exercising or defending legal claims and enforcing our agreements.
7

Cookies and Similar Technologies

We use cookies and similar technologies to operate our website, remember your preferences, measure traffic and improve performance. Cookies are small text files stored on your device.

  • Strictly necessary cookies — required for the website to function securely and correctly.
  • Preference cookies — remember choices such as language or display settings.
  • Analytics and performance cookies — help us understand how visitors use the website so we can improve it.
  • Marketing cookies (optional) — used only where you have consented, to measure the effectiveness of campaigns.

You can control, block or delete cookies through your browser settings. Please note that disabling certain cookies may affect the functionality and performance of our website.

8

Sharing and Disclosure of Personal Data

We do not sell your personal data. We only share it in accordance with the Data Protection Act, 2019 and, where required, under written data processing agreements. We may share personal data with:

  • Service providers and data processors such as hosting, cloud, analytics, payment and communication providers.
  • Professional advisers including lawyers, auditors and accountants.
  • Government and regulatory authorities where we are legally required, such as the Kenya Revenue Authority, the Office of the Data Protection Commissioner, or the courts.
  • A successor entity in the event of a merger, acquisition, restructuring or sale of assets.
  • Third parties where you have given your consent or requested us to do so.

Where we engage a data processor, we ensure that it provides sufficient guarantees to implement appropriate technical and organisational measures, as required under Section 42 of the Data Protection Act, 2019.

9

Cross-Border Transfers of Personal Data

Some of our service providers operate outside Kenya. Where personal data is transferred out of the country, we ensure that the transfer complies with Sections 48, 49 and 50 of the Data Protection Act, 2019. This means the transfer is only carried out where one of the following applies:

  • The destination country has adequate data protection laws, as determined by the Office of the Data Protection Commissioner.
  • There are appropriate safeguards in place, such as contractual clauses or binding corporate rules.
  • You have given your consent to the transfer after being informed of the possible risks.
  • The transfer is necessary for the performance of a contract between you and us, or for a legal claim or other ground permitted by the Act.
10

Data Retention

We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected and to comply with legal, regulatory, tax and accounting requirements, in line with Section 39 of the Data Protection Act, 2019.

  • Enquiries and quotations: retained for as long as needed to respond and for a reasonable follow-up period.
  • Customer and service records: retained for the duration of the relationship and any applicable warranty or support period.
  • Financial, tax and accounting records: retained for the period required by Kenyan law, generally up to seven (7) years.
  • Website analytics: retained in aggregated or anonymised form wherever possible, for a limited period.

When personal data is no longer needed, we securely delete, destroy or anonymise it so that it can no longer be associated with you.

11

How We Protect Your Data

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration or disclosure, as required by Sections 41 and 42 of the Data Protection Act, 2019. These measures include:

  • Encryption of data in transit using secure protocols such as HTTPS/TLS.
  • Access controls, strong authentication and role-based permissions, so staff only access data they need.
  • Firewalls, monitoring, and regular security updates and patching.
  • Confidentiality obligations and ongoing data protection training for our staff and contractors.
  • Secure backup, disaster recovery and business continuity procedures.
  • Documented incident response procedures, including notifying the Office of the Data Protection Commissioner and affected data subjects where a personal data breach occurs, as required by Section 43 of the Act.

While we take reasonable steps to protect your data, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

12

Your Rights as a Data Subject

Under Sections 26 to 40 of the Data Protection Act, 2019, you have the following rights in relation to your personal data:

  • The right to be informed of how your personal data is being used.
  • The right to access your personal data and to obtain a copy of it.
  • The right to request correction or rectification of inaccurate or incomplete data.
  • The right to request erasure or deletion of your personal data.
  • The right to restrict or object to the processing of your personal data.
  • The right to data portability — to receive your data in a structured, commonly used and machine-readable format and to have it transmitted to another controller.
  • The right to object to direct marketing.
  • The right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects.
  • The right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • The right to lodge a complaint with the Office of the Data Protection Commissioner.

To exercise any of these rights, please contact us at kiarie@microstation.co.ke. We may ask you to verify your identity, and we will respond within the timelines set out in the Act, generally within thirty (30) days.

13

Children's Personal Data

Our website and services are intended for businesses and adults. We do not knowingly collect or process personal data from children. Where a child's personal data must be processed, we obtain verifiable parental or guardian consent as required by Section 33 of the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021.

If we become aware that we have collected personal data from a child without the required consent, we will take reasonable steps to delete it promptly.

14

Automated Decision-Making and Profiling

We do not use your personal data to make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. Where any automated processing is used, we implement appropriate safeguards and, where required by law, obtain your consent.

16

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the law, regulation, or our practices. The "Last Updated" date at the top of this page shows when the latest revision took effect. Where changes are material, we will take reasonable steps to bring them to your attention.

17

How to Contact Us and Lodge a Complaint

If you have any questions, requests or concerns about this Privacy Policy or about how we handle your personal data, please contact us:

  • Email: kiarie@microstation.co.ke
  • Telephone: +254 722 711 162 / +254 731 822 629
  • Address: Westlands, Nairobi, Kenya

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC), the supervisory authority established under the Data Protection Act, 2019:

  • Website: www.odpc.go.ke
  • Email: complaints@odpc.go.ke
  • Telephone: +254 (0)20 267 1999
  • Address: Nairobi, Kenya

Questions about your data?

Our team is ready to help you exercise your data subject rights.

Contact Us