Back to Home
Statutory Compliance: KDPA (2019) & TPDPA (2022)

Privacy Policy & Data Governance Charter

Last Updated: September 2026 • Oduk Tech Limited (Kenya & Tanzania Operations)

Our Institutional Privacy Commitments

Zero Data MonetizationWe do not sell, rent, broker, or trade enterprise databases, clinical files, or member records to any third party.
Banking-Grade CryptographyEnd-to-end TLS 1.3 encryption in transit and AES-256 volume encryption at rest for all database backups.
72-Hour Breach NotificationStrict adherence to mandatory incident notification windows required by Kenyan and Tanzanian data authorities.
1.0

Legislative & Regulatory Framework

Oduk Tech Limited ("we", "our", or "us") operates as a premier software development, cloud systems, and ERP consulting firm across the East African Community. This Privacy Policy sets forth our operational policies and technological controls regarding the collection, processing, protection, and retention of personal and enterprise information, in strict adherence to:

  • Republic of Kenya: The Data Protection Act (No. 24 of 2019) ("KDPA") and statutory guidelines enacted by the Office of the Data Protection Commissioner (ODPC).
  • United Republic of Tanzania: The Personal Data Protection Act (No. 11 of 2022) ("TPDPA") and regulations promulgated by the Personal Data Protection Commission (PDPC).
  • Regional Standards: The East African Community (EAC) e-Commerce and cyber security protocols governing cross-border technology transactions.
2.0

Dual Roles: Data Controller vs. Data Processor

To guarantee transparency, Oduk Tech Limited maintains clear legal boundaries between its responsibilities:

2.1 Oduk Tech as a Data Controller

We act as a Data Controller in respect of personal information collected directly through our website (e.g. contact forms, consultation booking requests, demo requests, and corporate recruitment). We determine the purposes and legal grounds for processing this information.

2.2 Oduk Tech as a Data Processor

In our enterprise SaaS hosting, ERPNext implementations, SACCO core banking modules, and Hospital Information Systems (HIMS), our enterprise Client is the Data Controller. Oduk Tech acts strictly as a Data Processor, processing customer records, patient files, and financial entries solely upon documented instructions and within the bounds of a signed Service Contract and Data Processing Addendum (DPA).

3.0

Categories of Data Processed

We process data strictly proportionate to providing reliable, mission-critical enterprise software:

Inquiry & Business Contact Data:Full Name, business email, telephone number, WhatsApp contact, job title, institutional organization name, and country of operational deployment (Kenya, Tanzania, Other).
SACCO & Financial Records:Member IDs, share capital, savings deposits, loan schedules, national identity numbers, and M-PESA/bank transaction reference identifiers (processed under strict bank secrecy protocols).
Healthcare & Clinical Records (HIMS):Patient demographics, triage vital signs, physician diagnosis notes, pharmaceutical prescriptions, and health insurance authorization codes (governed by medical confidentiality standards).
Technical Audit & Telemetry Data:IP addresses, user agent strings, authentication timestamps, role-based activity audit logs, and diagnostic error traces required for SLA uptime monitoring.
4.0

Lawful Grounds for Processing

In accordance with Section 30 of the Kenya Data Protection Act and Section 23 of the Tanzania Personal Data Protection Act, our data processing is grounded upon:

  • Contractual Performance: Processing necessary for configuring, delivering, hosting, and supporting enterprise ERP software agreed upon under a signed contract.
  • Legal & Statutory Compliance: Processing required to interface with revenue bodies (KRA eTIMS, TRA EFDMS) and satisfy anti-money laundering (AML/CFT) regulatory reporting.
  • Legitimate Institutional Interests: Ensuring enterprise network security, fraud detection, server failover, and proactive incident triage.
  • Explicit Consent: Provided voluntarily by prospective clients when submitting demo requests, consultation bookings, or newsletter subscriptions.
5.0

Fiscal Authorities & Telecommunications Gateways

Our automated ERP engines interface with statutory and financial gateways. We implement strict safeguards around all third-party transmissions:

Kenya Revenue Authority (KRA eTIMS): Invoicing DocTypes communicate directly with KRA eTIMS middleware over TLS-encrypted mutual authentication to sign tax invoices and return statutory QR codes. No secondary marketing data is ever attached to fiscal transmissions.
Tanzania Revenue Authority (TRA EFDMS/VFD): Retail and wholesale fiscal transmissions connect to the TRA VFD server using authorized digital certificates and RSA signature keys.
Telco Mobile Money Connectors: Safaricom M-PESA Daraja API, Airtel Money, Vodacom M-Pesa Tanzania, and Tigo Pesa callbacks are received securely via webhook endpoints protected by IP whitelisting and HMAC cryptographic signatures.
6.0

Cross-Border Transfers & Regional Data Sovereignty

For multinational enterprise clients operating across Kenya and Tanzania:

  • Local Data Center Preference: Production databases for Kenyan institutions are hosted within local or regional certified Tier-III/IV facilities (such as IXAfrica Nairobi, Safaricom Cloud, or localized AWS Africa zones).
  • Cross-Border Safeguards: Any transfer of personal or operational data across the Kenya-Tanzania border is executed in compliance with Section 48 of the Kenya Data Protection Act and Part VI of the Tanzania Personal Data Protection Act, supported by enforceable contractual clauses guaranteeing equivalent security protections.
7.0

Technical & Organizational Security Safeguards (TOMs)

Oduk Tech implements state-of-the-art technical and organizational security controls to protect client information against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure:

Cryptographic Controls:TLS 1.3 protocol for all browser and API traffic with Perfect Forward Secrecy; AES-256 encryption applied to all database tablespaces and offsite automated snapshots.
Role-Based Access (RBAC):Strict least-privilege role permissions, multi-factor authentication (MFA) enforcement for administrative cockpits, and full immutable audit trails.
Mandatory Staff NDAs:All developers, DevOps engineers, and support personnel are bound by rigorous non-disclosure agreements prior to obtaining access to client staging or production environments.
Vulnerability Management:Routine vulnerability assessments, container isolation, automated patch deployment, and DDoS mitigation proxies.
8.0

Data Retention & Sanitization Schedules

Personal and enterprise data is retained only for as long as necessary to fulfill the purposes for which it was collected or to satisfy statutory retention obligations:

  • Financial, Tax & SACCO Records: Maintained for seven (7) years in accordance with the Kenya Tax Procedures Act, National Payment System regulations, and Tanzania Tax Administration Act.
  • Clinical & Patient Records: Maintained in compliance with Ministry of Health and KMPDC guidelines.
  • Prospective Inquiries: Retained for a maximum of twenty-four (24) months from date of inquiry, unless an earlier erasure request is submitted.
  • Secure Disposal: Data scheduled for deletion is sanitized using cryptographic erasure and DoD 5220.22-M sanitization protocols.
9.0

Your Statutory Data Subject Rights

Under Kenyan and Tanzanian data protection legislation, you possess enforceable rights regarding your personal information:

Right of Access & Portability: You may request a verified copy of all personal records held about you in a structured, commonly used, machine-readable format (JSON/CSV).
Right to Rectification: You hold the right to require correction or completion of inaccurate, outdated, or misleading records without undue delay.
Right to Erasure ("Right to be Forgotten"): You may request the deletion of your personal data where retention is no longer justified by law or contract.
Right to Object & Restrict: You hold the right to object to processing for direct marketing or request temporary restriction of processing during verification.
10.0

Security Incident & Breach Notification Protocol

Oduk Tech maintains an incident response protocol aligned with international security best practices:

  • In the event of a confirmed security incident or unauthorized breach affecting personal or confidential client data, Oduk Tech will notify impacted client Data Controllers within twenty-four (24) hours of confirmation.
  • Oduk Tech complies with the mandatory 72-hour notification threshold to the Office of the Data Protection Commissioner (ODPC Kenya) and the Personal Data Protection Commission (PDPC Tanzania) as prescribed by law.
  • Notifications include details on the nature of the breach, affected record counts, potential ramifications, and immediate forensic mitigation measures implemented.
11.0

Data Protection Officer (DPO) & Inquiries

If you have any questions, wish to exercise your data subject rights, or require an executed Data Processing Addendum (DPA), contact our appointed Data Protection Officer:

Oduk Tech Limited — Office of the Data Protection Officer

Nairobi Headquarters: Valley View Park, Parklands, Nairobi, Kenya

Tanzania Operations: Dar es Salaam, Tanzania (Contact: Emmanuel Majwala • +255 754 710 459)

Telephone (Direct): +254 726 444 005 / +254 702 568 824

Dedicated Privacy Email: privacy@oduktech.com / dpo@oduktech.com