Effective Date: 8th September 2026 Last Updated: 8 September 2026

1. Introduction

SIMI Technologies (“we”, “us”, “our” or the “Company”) is committed to protecting the privacy, confidentiality and security of personal data entrusted to us. We provide enterprise resource planning (ERP) software, business management systems, software development, implementation, hosting, support, consulting and related technology services.

This Privacy Policy explains how we collect, receive, use, store, disclose, protect and otherwise process personal data when you:

  • Visit or use our website;
  • Contact us;
  • Request or purchase our products or services;
  • Communicate with our employees or representatives;
  • Register for an account, demonstration, training or event; or
  • Otherwise interact with us in the course of business.
This Privacy Policy is intended to comply with the Kenya Data Protection Act, 2019 (“DPA”), applicable regulations and other applicable data protection requirements. The DPA establishes principles governing the lawful, fair and transparent processing of personal data and provides individuals with rights regarding their personal data.

2. Who We Are

SIMI Technologies is a technology company providing ERP and business software solutions. For personal data that we collect and determine the purposes and means of processing ourselves, we may act as a Data Controller. Where we process personal data on behalf of one of our customers through our ERP, hosting, implementation, support or related services, we may act as a Data Processor, processing such information primarily in accordance with the customer's instructions and applicable contractual arrangements. Where appropriate, our customers remain responsible for determining the lawful purposes for which information entered into their ERP systems is collected and used.
Company Name: SIMI Technologies
Registered Address: JD Neno Plaza
Email: privacy@simitechnologies.ke
Telephone: +254 701 378 573
Website: https://simitechnologies.ke

3. Personal Data We May Collect

Depending on how you interact with us, we may collect and process the following categories of personal data:

3.1 Identification Information

This may include:

  • name;
  • username;
  • employee or staff identification information;
  • company or organisation;
  • job title or position; and
  • other information necessary to identify or authenticate an authorised user.

3.2 Contact information

This may include:

  • email address;
  • telephone number;
  • postal or physical address;
  • business address; and
  • other contact information provided to us.

3.3 Account and authentication information

Where applicable, this may include:

  • account usernames;
  • authentication information;
  • account preferences;
  • user roles and permissions;
  • login records; and
  • security and audit information.
  • We do not intend to collect passwords in plain text.

3.4 Transaction and business information

Depending on the services provided, this may include information relating to:

  • purchases;
  • subscriptions;
  • invoices;
  • payments;
  • quotations;
  • contracts;
  • customer and supplier relationships;
  • support requests;
  • service history; and
  • other business transactions.

3.5 Technical and usage information

We may collect information such as:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • application version;
  • login and access times;
  • system logs;
  • security events;
  • diagnostic information; and
  • information about how our websites and applications are used.

3.6 Information provided voluntarily

We may process any personal information that you voluntarily provide when communicating with us, requesting support, submitting enquiries, participating in demonstrations or training, or otherwise interacting with our Company.

4. Personal Data Contained in Customer ERP Systems

Our ERP systems may allow our customers to store and process substantial amounts of business information. Such information may include personal data relating to a customer's:

  • employees;
  • customers;
  • suppliers;
  • contractors;
  • business partners;
  • patients or clients, where applicable;
  • contacts; and
  • other individuals whose information the customer enters into the system.
Where we process such personal data solely on behalf of the customer, the customer generally determines the purposes and means of processing and may act as the Data Controller, while we may act as the Data Processor. In such circumstances, we process the information primarily to provide, maintain, secure, support and improve the contracted services and in accordance with the customer's lawful instructions and applicable agreements. Customers using our ERP systems are responsible for ensuring that they have an appropriate lawful basis for collecting and processing personal data and that their use of the ERP complies with applicable data protection laws.

5. How We Use Personal Data

We may process personal data for legitimate and specified purposes, including:

  1. providing, operating and maintaining our ERP software and other services;
  2. creating and administering user accounts;
  3. authenticating users and managing access permissions;
  4. providing customer and technical support;
  5. implementing, configuring and customising ERP systems;
  6. communicating with customers and users;
  7. processing subscriptions, invoices and payments;
  8. fulfilling contractual obligations;
  9. maintaining system security and preventing unauthorised access;
  10. detecting, investigating and preventing fraud, abuse or security incidents;
  11. monitoring system performance and reliability;
  12. troubleshooting technical problems;
  13. maintaining backups and business continuity systems;
  14. complying with legal, regulatory, tax, accounting or other lawful obligations;
  15. enforcing our agreements and protecting our legal rights;
  16. conducting internal analysis, statistics, quality assurance and service improvement;
  17. developing and improving our software, products and services;
  18. understanding how our services are used so that we can improve functionality, reliability, usability and security; and
  19. communicating information about our services where such communication is lawful and appropriate.
We may use information internally for purposes reasonably related to the purposes for which it was collected, provided that such processing is lawful, proportionate and consistent with applicable data protection requirements. We do not use personal data for unlimited or unrelated purposes merely because it has been provided to us.

6. Lawful Basis for Processing

Depending on the circumstances, we may rely on one or more lawful bases recognised under the Kenya Data Protection Act, including:

6.1 Performance of a contract

Where processing is necessary to enter into or perform a contract with you or your organisation.

6.2 Legal obligation

Where processing is necessary for us to comply with an obligation imposed by law.

6.3 Legitimate interests

Where processing is necessary for legitimate business interests, provided those interests do not override the rights and freedoms of the relevant data subject. Examples may include:

  1. maintaining information security;
  2. preventing fraud and abuse;
  3. protecting our systems;
  4. improving service reliability;
  5. managing business relationships; and
  6. maintaining appropriate business records.

6.4 Consent

Where consent is required by law or is the appropriate lawful basis, we will seek consent before processing the relevant personal data. Where processing is based on consent, the data subject may withdraw consent, subject to applicable legal or contractual limitations.

6.5 Other lawful grounds

We may process personal data where another lawful basis recognised under applicable Kenyan data protection law applies. The DPA recognises several lawful grounds for processing, including consent, contractual necessity, legal obligations and legitimate interests, among others.

7. We Do Not Sell Personal Data

We do not sell, rent or trade personal data to third parties for their own commercial purposes. We do not operate a business model based on selling personal information. However, this does not prevent us from sharing or providing access to personal data where such disclosure or processing is necessary and lawful for purposes such as:

  1. providing our services;
  2. hosting and maintaining systems;
  3. technical support;
  4. payment processing;
  5. cybersecurity;
  6. infrastructure management;
  7. professional services;
  8. compliance with legal obligations;
  9. responding to lawful requests from authorities;
  10. protecting our rights, property or security; or
  11. carrying out other legitimate and disclosed business purposes.
Where we use third-party service providers to process personal data on our behalf, we take reasonable steps to require appropriate confidentiality, security and data protection obligations.

8. Service Providers and Third Parties

We may use carefully selected third-party service providers to support our operations. These may include providers of:

  1. cloud and server infrastructure;
  2. data storage and backup;
  3. email and communications;
  4. cybersecurity;
  5. payment processing;
  6. domain and hosting services;
  7. analytics and monitoring;
  8. customer support systems;
  9. software development and deployment infrastructure; and
  10. professional, legal, accounting or auditing services.
Such providers may have access to personal data only to the extent reasonably necessary to provide their services or fulfil a lawful purpose. We require appropriate contractual, organisational and technical safeguards where third parties process personal data on our behalf.

9. International Data Transfers

Where personal data is stored, accessed or processed outside Kenya, we will take reasonable steps to ensure that the transfer or processing complies with applicable Kenyan data protection requirements. Where required by law, we will ensure that appropriate safeguards, contractual protections, adequacy mechanisms or other lawful mechanisms are in place before transferring personal data outside Kenya. We will not knowingly transfer personal data internationally in a manner that violates applicable data protection requirements.

10. Data Security

We take reasonable technical and organisational measures designed to protect personal data against:

  1. unauthorised access;
  2. unauthorised disclosure;
  3. alteration;
  4. accidental loss;
  5. destruction;
  6. misuse; and
  7. other unlawful or unauthorised processing.
Depending on the nature of the information and services involved, security measures may include:
  1. user authentication;
  2. role-based access controls;
  3. access restrictions;
  4. encryption where appropriate;
  5. secure communications;
  6. system monitoring;
  7. audit logs;
  8. backups;
  9. vulnerability management;
  10. security updates;
  11. incident response procedures;
  12. confidentiality obligations for personnel; and
  13. physical and infrastructure security controls.
No electronic system can be guaranteed to be completely secure. However, we continually assess and improve our security measures based on the nature and risks associated with the personal data we process.