Privacy notice
This notice explains what personal data we collect through this website, why we collect it, how long we keep it and what you can do about it. If anything is unclear, email us at info@wearedeefrent.com.
Who we are
Deefrent Collective Limited (“Deefrent”, “we”) is the data controller for the personal data collected through this website. That means we decide why and how it is used, and we are responsible for it under Kenya’s Data Protection Act, 2019.
Our office is at Ikigai, Westlands, Nairobi, Kenya.
What we collect
When you send us a form. Your name, company, phone or WhatsApp number, email address, what you are interested in, your company size and your message. We also record whether you ticked the box to hear from us, the page you sent the form from, any campaign tags in the link that brought you here, and your eTIMS readiness score if you used the readiness check. With each enquiry we store the time it arrived and your IP address.
What happens when you send it. Your enquiry is saved to our enquiry log and emailed to our team straight away. When our customer records system (CRM) is connected, it is also recorded there at the same moment.
Do you have to give us this? No, giving us your details is voluntary. But we need your name and a phone number or email address to reply to an enquiry. Without them we cannot respond.
When you visit any page. Like every website, ours keeps server logs of requests: your IP address, the page requested, the date and time, and details of your browser. We use your IP address to keep the site secure and to limit how many enquiries one address can send in an hour.
Analytics. We use Umami to count visits and actions such as button clicks and form submissions. Umami does not use cookies and does not tell us who you are. We use it for figures such as how many people viewed a page.
No cookies or trackers. This website does not set cookies, and it has no advertising tags or tracking pixels.
WhatsApp and email. If you contact us on WhatsApp, you leave this website. WhatsApp (Meta) handles that conversation under its own privacy policy, and we receive your number and your messages. If you email us, we receive your email address and what you write.
Why we use it, and our lawful basis
The Data Protection Act lets us use personal data only for a stated purpose and on a lawful basis. Ours are:
- Replying to your enquiry and preparing a proposal. We rely on the steps you asked us to take before a possible contract, and on our legitimate interest in answering business enquiries.
- Sending you news and insights. We rely on your consent, given by ticking the box on our form. You can withdraw it at any time, and we will stop.
- Keeping the website and the form secure. We rely on our legitimate interest in protecting the site and stopping abuse, such as spam.
- Understanding how the website is used. We rely on our legitimate interest in improving it. Umami does not tell us who you are.
- Keeping records the law requires. If you become a client, we keep contract and tax records because the law requires us to.
We do not sell your data, and we do not use it to make automated decisions about you.
How long we keep it
- Enquiry log. Each enquiry is saved to a log on our server, which deletes it after 90 days. Copies in our hosting provider’s backups may be kept for a short period beyond that.
- Email and customer records. Your enquiry is emailed to our team and, when our CRM is connected, recorded in our customer records as soon as you send it. We keep your enquiry, your details and our correspondence with you for up to 24 months after our last contact, then delete them.
- Client records. If you become a client, we keep contract and invoice records for as long as Kenyan tax law requires.
- Form protection. The record we use to limit enquiries from one IP address is held only in the server’s memory, never written to disk, and discarded when the server restarts or the record is no longer needed.
Who we share it with
We share personal data only with service providers that process it on our behalf and under contract:
- Hostinger hosts this website and our email. Your enquiries, our server logs and our emails are stored on its servers.
- The provider that hosts our customer records (CRM) stores your enquiry and our notes about it, when our CRM is connected.
- Umami provides our cookieless website analytics.
These providers may store data in data centres outside Kenya. Where they do, the safeguard we rely on is each provider’s contractual commitment to protect personal data. We use them only for the purposes in this notice.
We may also disclose personal data when the law requires it, for example to a court or a regulator.
Your rights
Under the Data Protection Act you can ask us to:
- tell you what personal data we hold about you, and give you a copy;
- correct data that is wrong or misleading;
- delete your data;
- stop or limit how we use it, or object to our use of it;
- give you your data in a format you can take elsewhere;
- stop sending you news and insights, at any time.
To make a request, email info@wearedeefrent.com. We may need to confirm your identity before we act on it.
How we protect it
Every page and form on this website is served over an encrypted connection (HTTPS). The enquiry log is kept outside the public website files, and only our team can read it. Access to our email and customer records is limited to the people who need it.
Complaints
If you are unhappy with how we have handled your data, please tell us first at info@wearedeefrent.com so we can put it right. You also have the right to complain to the Office of the Data Protection Commissioner (ODPC) at odpc.go.ke.
Changes to this notice
We update this notice when the way we handle personal data changes. The date of the latest version is shown on this page.
Find out what your systems could run on their own
Start with a free 30-minute automation audit. We look at how your team works across WhatsApp, M-Pesa and other mobile money, your bank, Odoo and eTIMS, and you leave with a one-page map of what to automate first.