Legal

Privacy Policy

Effective date: 1 June 2025  ·  Last updated: 1 June 2025

1. Who We Are

AfriProtec Ltd ("AfriProtec", "we", "us", "our") is a cybersecurity company incorporated in Kenya. We operate the AfriProtec security intelligence platform accessible at afriprotec.com and associated subdomains.

As the data controller, we are responsible for how your personal data is collected, stored, and used. This Privacy Policy explains our practices in compliance with the Kenya Data Protection Act 2019 (DPA 2019) and, where applicable, South Africa's Protection of Personal Information Act (POPIA).

2. Data We Collect

We collect information you provide directly and information generated by your use of the Service.

Account data:

  • Email address (required for account creation and login)
  • Full name (optional, used for personalisation)
  • Password (stored as a salted cryptographic hash — never in plain text)
  • Organisation name and role (optional, collected during onboarding)

Scan and operational data:

  • Scan targets you submit (domain names, IP addresses, URLs)
  • Vulnerability findings and security recommendations generated by scans
  • Scan configuration and history
  • AI assistant conversation logs within your session

Technical data:

  • IP address and approximate geolocation at login
  • Browser type, device type, and operating system
  • Pages visited and features used within the platform (analytics)
  • Error logs and performance metrics

3. How Data Is Stored

Your data is stored on Supabase, a cloud database platform hosted on infrastructure within or accessible from the European Union and United States. We have Data Processing Agreements in place with Supabase consistent with international data transfer requirements.

  • Data in transit: All connections between your browser and our servers use TLS 1.2 or higher. All API traffic is encrypted.
  • Data at rest: Database storage is encrypted at rest using AES-256 encryption provided by Supabase's underlying cloud infrastructure.
  • Passwords: Stored using bcrypt hashing. AfriProtec staff cannot read your password.
  • Scan results: Retained for 90 days from the scan date, then permanently and automatically deleted.
  • Account data: Retained for the lifetime of your account, and for up to 30 days after account deletion to allow for dispute resolution.

4. Who Can Access Your Data

Access to your personal data is restricted on a need-to-know basis.

  • You: You can access, export, and delete your data through the platform at any time.
  • AfriProtec engineering and support staff: Limited access for troubleshooting and support, subject to internal access controls and audit logging.
  • Supabase: Infrastructure-level access as our data processor. Supabase does not use your data for its own purposes.
  • Payment processors: Payment card data is handled directly by our payment processor. AfriProtec only receives a transaction confirmation and anonymised billing reference.

We do not sell, rent, or trade your personal data to any third party. We do not share scan findings with other AfriProtec customers.

5. Kenya Data Protection Act 2019 (DPA 2019)

AfriProtec processes your personal data in accordance with the Kenya Data Protection Act 2019 and the regulations made under it.

Our lawful bases for processing are:

  • Contract performance: Processing necessary to provide the Service you signed up for (account management, scan execution, results delivery)
  • Legitimate interests: Fraud prevention, security monitoring of our own systems, and platform improvement through aggregate analytics
  • Consent: Where we send you marketing communications — you can withdraw consent at any time
  • Legal obligation: Where we are required to retain or disclose data by Kenyan law

We are registered with the Office of the Data Protection Commissioner (ODPC) in Kenya as required by the DPA 2019.

6. POPIA Compliance (South Africa)

For users in South Africa, AfriProtec processes personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).

  • We process only the minimum personal information necessary for the stated purpose (data minimisation)
  • We maintain reasonable technical and organisational safeguards to protect personal information from unauthorised access or loss
  • You have the right to object to processing, request correction, and request deletion of your personal information
  • If a security incident affects your personal information, we will notify you and, where required, the Information Regulator of South Africa within the timelines prescribed by POPIA

7. Data Retention

Scan results and findings: 90 days from scan completion, then permanently deleted.
Account and profile data: Duration of your account, plus 30 days after deletion.
Payment records: 7 years, as required by Kenyan tax law.
Security and access logs: 12 months, then deleted.

You can export your scan findings at any time from the dashboard before the 90-day retention window closes.

8. Your Rights

Under the Kenya DPA 2019 and, where applicable, POPIA, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Ask us to correct inaccurate or incomplete data
  • Right to erasure: Request deletion of your account and associated data
  • Right to data portability: Export your scan results and account data in a machine-readable format
  • Right to object: Object to processing based on legitimate interests, including profiling
  • Right to withdraw consent: Withdraw marketing consent at any time without affecting the lawfulness of prior processing

To exercise any of these rights, email us at hello@afriprotec.com. We will respond within 21 days as required by the DPA 2019.

9. Cookies and Tracking

AfriProtec uses strictly necessary session cookies to keep you authenticated. We do not use third-party advertising trackers or cross-site tracking cookies.

We use anonymised, aggregated analytics to understand how the platform is used. No personal identifiers are shared with analytics providers.

10. Security Incident Notification

In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify you without undue delay and, where legally required, notify the relevant data protection authority (ODPC Kenya and/or the Information Regulator of South Africa).

11. Children's Privacy

AfriProtec is intended for business use by individuals aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you by email and by posting a notice in the platform dashboard at least 14 days before material changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact and Complaints

For privacy questions, data subject requests, or concerns about how we handle your data, contact our Data Protection Officer:

AfriProtec Ltd — Data Protection Officer
Email: hello@afriprotec.com
Location: Nairobi, Kenya

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) in Kenya, or if you are in South Africa, with the Information Regulator.