Privacy Policy
1. Introduction
SIMI Technologies (“we”, “us”, “our” or the “Company”) is committed to protecting the privacy, confidentiality and security of personal data entrusted to us. We provide enterprise resource planning (ERP) software, business management systems, software development, implementation, hosting, support, consulting and related technology services.
This Privacy Policy explains how we collect, receive, use, store, disclose, protect and otherwise process personal data when you:
- Visit or use our website;
- Contact us;
- Request or purchase our products or services;
- Communicate with our employees or representatives;
- Register for an account, demonstration, training or event; or
- Otherwise interact with us in the course of business.
2. Who We Are
SIMI Technologies is a technology company providing ERP and business software solutions.
For personal data that we collect and determine the purposes and means of processing ourselves, we may act as a Data Controller.
Where we process personal data on behalf of one of our customers through our ERP, hosting, implementation, support or related services, we may act as a Data Processor, processing such information primarily in accordance with the customer's instructions and applicable contractual arrangements.
Where appropriate, our customers remain responsible for determining the lawful purposes for which information entered into their ERP systems is collected and used.
Company Name: SIMI Technologies
Registered Address: JD Neno Plaza
Email: privacy@simitechnologies.ke
Telephone: +254 701 378 573
Website: https://simitechnologies.ke
3. Personal Data We May Collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
3.1 Identification Information
This may include:
- name;
- username;
- employee or staff identification information;
- company or organisation;
- job title or position; and
- other information necessary to identify or authenticate an authorised user.
3.2 Contact information
This may include:
- email address;
- telephone number;
- postal or physical address;
- business address; and
- other contact information provided to us.
3.3 Account and authentication information
Where applicable, this may include:
- account usernames;
- authentication information;
- account preferences;
- user roles and permissions;
- login records; and
- security and audit information.
- We do not intend to collect passwords in plain text.
3.4 Transaction and business information
Depending on the services provided, this may include information relating to:
- purchases;
- subscriptions;
- invoices;
- payments;
- quotations;
- contracts;
- customer and supplier relationships;
- support requests;
- service history; and
- other business transactions.
3.5 Technical and usage information
We may collect information such as:
- IP address;
- browser type;
- device type;
- operating system;
- application version;
- login and access times;
- system logs;
- security events;
- diagnostic information; and
- information about how our websites and applications are used.
3.6 Information provided voluntarily
We may process any personal information that you voluntarily provide when communicating with us, requesting support, submitting enquiries, participating in demonstrations or training, or otherwise interacting with our Company.
4. Personal Data Contained in Customer ERP Systems
Our ERP systems may allow our customers to store and process substantial amounts of business information. Such information may include personal data relating to a customer's:
- employees;
- customers;
- suppliers;
- contractors;
- business partners;
- patients or clients, where applicable;
- contacts; and
- other individuals whose information the customer enters into the system.
5. How We Use Personal Data
We may process personal data for legitimate and specified purposes, including:
- providing, operating and maintaining our ERP software and other services;
- creating and administering user accounts;
- authenticating users and managing access permissions;
- providing customer and technical support;
- implementing, configuring and customising ERP systems;
- communicating with customers and users;
- processing subscriptions, invoices and payments;
- fulfilling contractual obligations;
- maintaining system security and preventing unauthorised access;
- detecting, investigating and preventing fraud, abuse or security incidents;
- monitoring system performance and reliability;
- troubleshooting technical problems;
- maintaining backups and business continuity systems;
- complying with legal, regulatory, tax, accounting or other lawful obligations;
- enforcing our agreements and protecting our legal rights;
- conducting internal analysis, statistics, quality assurance and service improvement;
- developing and improving our software, products and services;
- understanding how our services are used so that we can improve functionality, reliability, usability and security; and
- communicating information about our services where such communication is lawful and appropriate.
6. Lawful Basis for Processing
Depending on the circumstances, we may rely on one or more lawful bases recognised under the Kenya Data Protection Act, including:
6.1 Performance of a contract
Where processing is necessary to enter into or perform a contract with you or your organisation.
6.2 Legal obligation
Where processing is necessary for us to comply with an obligation imposed by law.
6.3 Legitimate interests
Where processing is necessary for legitimate business interests, provided those interests do not override the rights and freedoms of the relevant data subject. Examples may include:
- maintaining information security;
- preventing fraud and abuse;
- protecting our systems;
- improving service reliability;
- managing business relationships; and
- maintaining appropriate business records.
6.4 Consent
Where consent is required by law or is the appropriate lawful basis, we will seek consent before processing the relevant personal data. Where processing is based on consent, the data subject may withdraw consent, subject to applicable legal or contractual limitations.
6.5 Other lawful grounds
We may process personal data where another lawful basis recognised under applicable Kenyan data protection law applies. The DPA recognises several lawful grounds for processing, including consent, contractual necessity, legal obligations and legitimate interests, among others.
7. We Do Not Sell Personal Data
We do not sell, rent or trade personal data to third parties for their own commercial purposes. We do not operate a business model based on selling personal information. However, this does not prevent us from sharing or providing access to personal data where such disclosure or processing is necessary and lawful for purposes such as:
- providing our services;
- hosting and maintaining systems;
- technical support;
- payment processing;
- cybersecurity;
- infrastructure management;
- professional services;
- compliance with legal obligations;
- responding to lawful requests from authorities;
- protecting our rights, property or security; or
- carrying out other legitimate and disclosed business purposes.
8. Service Providers and Third Parties
We may use carefully selected third-party service providers to support our operations. These may include providers of:
- cloud and server infrastructure;
- data storage and backup;
- email and communications;
- cybersecurity;
- payment processing;
- domain and hosting services;
- analytics and monitoring;
- customer support systems;
- software development and deployment infrastructure; and
- professional, legal, accounting or auditing services.
9. International Data Transfers
Where personal data is stored, accessed or processed outside Kenya, we will take reasonable steps to ensure that the transfer or processing complies with applicable Kenyan data protection requirements. Where required by law, we will ensure that appropriate safeguards, contractual protections, adequacy mechanisms or other lawful mechanisms are in place before transferring personal data outside Kenya. We will not knowingly transfer personal data internationally in a manner that violates applicable data protection requirements.
10. Data Security
We take reasonable technical and organisational measures designed to protect personal data against:
- unauthorised access;
- unauthorised disclosure;
- alteration;
- accidental loss;
- destruction;
- misuse; and
- other unlawful or unauthorised processing.
- user authentication;
- role-based access controls;
- access restrictions;
- encryption where appropriate;
- secure communications;
- system monitoring;
- audit logs;
- backups;
- vulnerability management;
- security updates;
- incident response procedures;
- confidentiality obligations for personnel; and
- physical and infrastructure security controls.