Your Data. Our Responsibility.
Kendaall Tracking is built on operational trust. This Privacy Policy sets out, in plain language, precisely what personal and operational data we collect, why we collect it, how we protect it, and the rights you hold over every piece of information you entrust to our platform.
Data Protection Officer
Amara Osei
Data Protection Officer
Certified privacy professional with 11 years’ experience in industrial IoT data governance and cross-border data transfer compliance across African regulatory frameworks.
This Privacy Policy governs the collection, use, storage, disclosure, and protection of personal data by Kendaall Tracking Limited, a company registered in Kenya and operating the asset intelligence platform available at kendaalltracking.co.ke. It applies to all users of our platform, visitors to our website, clients who deploy our hardware devices and IoT telemetry infrastructure, and any individual whose personal data we process in connection with delivering our services.
Kendaall Tracking is committed to responsible data stewardship. We process only the minimum personal data necessary to deliver our services, protect that data to ISO 27001-certified standards, and provide clear, enforceable rights to every data subject covered by this policy. Questions should be directed to our Data Protection Officer at privacy@kendaalltracking.co.ke.
Data Controller Identity
Who We Are
Kendaall Tracking Limited is the data controller for all personal information collected through our website, platform, and IoT device network. We are registered under the laws of Kenya and operate under the regulatory oversight of the Office of the Data Protection Commissioner (ODPC) established by the Kenya Data Protection Act 2019 (DPA 2019).
Our primary place of business is located at 35644 Kasarani Mwiki Road, Nairobi, Kenya 00100. Our company specialises in next-generation asset management for logistics and heavy industry — specifically the real-time monitoring of locomotives, freight wagons, mining equipment, port machinery, and industrial assets in operational service. The platform we operate collects telemetry data from physical IoT devices installed on these assets. While the primary subject of that telemetry is the asset itself, some telemetry — such as operator identification, access event records, and driver behaviour scoring — may constitute personal data where it is linked to an identifiable natural person.
Our registered Data Protection Officer (DPO) is Amara Osei, reachable at privacy@kendaalltracking.co.ke. For enterprise clients who have signed a Data Processing Agreement (DPA) with Kendaall Tracking, the DPA takes precedence over this general Privacy Policy where the two documents address the same subject matter.
Kendaall Tracking acts as a data controller for personal data collected through our website and platform accounts, and as a data processor for operational telemetry data collected on behalf of our enterprise clients. Where we act as processor, the controller (our client) retains ultimate responsibility for the lawfulness of processing, and our obligations are defined in the relevant Data Processing Agreement.
Applicability & Entities Covered
Scope of This Privacy Policy
This Privacy Policy applies to all personal data processing activities conducted by Kendaall Tracking in connection with the following interactions and relationships.
- Platform Users: Any individual who creates or uses a Kendaall Tracking platform account, including operations managers, fleet supervisors, maintenance engineers, and system administrators employed by or contracted to a Kendaall Tracking client organisation.
- Website Visitors: All individuals who visit kendaalltracking.co.ke or any subdomain operated by Kendaall Tracking, regardless of whether they register for or use the platform.
- Field Personnel: Equipment operators, locomotive drivers, site supervisors, and maintenance technicians who interact with Kendaall hardware devices or the Kendaall mobile application, where such interaction generates personal data such as operator identification events, mobile app login records, or geotagged inspection submissions.
- Contact & Prospect Records: Individuals who contact Kendaall Tracking via email, telephone, or contact form for sales enquiries, support requests, or partnership discussions, whose contact details and communication records are held in our CRM system.
- Third-Party API Integrators: Developer or enterprise technical contacts who register for Kendaall API credentials and whose account registration, API key management, and access log data is processed by our platform.
This policy does not apply to personal data processed by our clients in their own systems, even where that data may have originated from Kendaall telemetry feeds. Clients are responsible for their own compliance with applicable data protection legislation in respect of data held within their own operational systems.
Personal Data Categories & Collection Methods
What Data We Collect
Kendaall Tracking collects personal data through three primary mechanisms: data you provide directly when registering for and using the platform, data generated automatically through your use of our technology, and data received from our enterprise clients in connection with deploying the platform in their operational environment.
Account Registration Data
Full name, work email, job title, employing organisation, telephone number, and account password (stored as a salted cryptographic hash, never in plaintext). Collected when you create or are provisioned a Kendaall account.
RequiredPlatform Usage Data
Login timestamps, IP addresses, session duration, pages and features accessed, alert acknowledgements, dashboard preferences, and report generation histories. Collected automatically as you use the platform.
TechnicalOperator & Field Personnel Data
Where asset monitoring tracks equipment access by named personnel — RFID tag associations, NFC scan records, mobile app login events, operator ID at asset start-up — the resulting records are personal data.
OperationalCommunication Records
Emails, chat transcripts, support ticket contents, and call notes generated during support, sales, or account management interactions, retained in our CRM with access limited to authorised personnel.
RequiredMobile Application Data
Device identifier, OS version, app version, push notification tokens, offline sync timestamps, geotagged inspection metadata, and NFC/QR scan event logs from our field apps.
TechnicalWebsite Analytics Data
Browser type, referring URL, pages visited, session duration, approximate geographic region. IP addresses anonymised before retention beyond 30 days.
OptionalWhat we do not collect: Kendaall Tracking does not collect payment card numbers, bank account details, national identification numbers, biometric templates, medical or health records, or any special categories of sensitive personal data as defined in Section 30 of the Kenya Data Protection Act 2019, except where explicitly required by a specific contracted service and covered by a separate data processing agreement with enhanced safeguards.
The vast majority of data processed by our platform — vibration signatures, temperature readings, pressure measurements, GPS coordinates, fuel consumption metrics, and mechanical cycle counts — relates to physical assets, not to individuals, and does not constitute personal data under the DPA 2019 unless it is linked to a named or identifiable person.
Lawfulness, Fairness & Transparency
Legal Basis for Processing Your Data
Every processing activity conducted by Kendaall Tracking must rest on a valid legal basis under Section 30 of the Kenya Data Protection Act 2019 and, for clients operating in the European Economic Area, under Article 6 of the GDPR. We do not use a single legal basis as a catch-all; we assess the appropriate basis for each specific processing purpose separately.
- Contractual Necessity: Processing your account registration data, platform access credentials, billing contact records, and integration configuration data is necessary for us to fulfil our contract with you or your organisation.
- Legitimate Interests: Processing platform usage analytics, session data, support interaction records, and internal security monitoring to improve service performance, detect and prevent fraud, and develop new platform features — balanced against and never overriding individual data subject rights.
- Consent: Processing website analytics cookies beyond strictly necessary session management, sending optional marketing communications, and collecting optional profile information beyond core account fields. Consent may be withdrawn at any time without penalty to service delivery.
- Legal Obligation: Retaining financial transaction records, processing data required by a valid court order or regulatory demand, and maintaining compliance documentation for our own regulatory obligations.
Where Kendaall Tracking acts as a data processor for enterprise clients, the client as data controller determines and is responsible for the legal basis for that processing. Kendaall acts only on the documented instructions of the controller.
Purposes of Processing
How We Use Your Personal Data
Personal data collected by Kendaall Tracking is used exclusively for purposes directly connected to delivering, maintaining, improving, and protecting our platform. We do not use personal data for profiling, automated decision-making with legal effects, advertising targeting, or any incompatible purpose.
- Platform Service Delivery: Provisioning and authenticating accounts; routing alert notifications; processing maintenance work order triggers; generating compliance documentation; syncing data with connected enterprise systems.
- Customer Support and Account Management: Responding to support tickets, troubleshooting integrations, onboarding guidance, and periodic account health reviews. Retained for 24 months for quality assurance.
- Platform Performance Improvement: Analysing aggregated and pseudonymised usage patterns to identify feature demand and UX friction points. Analysis is conducted at aggregate level.
- Security Monitoring and Fraud Prevention: Analysing access logs and session patterns to detect unauthorised access, API key abuse, and data exfiltration indicators, on a risk-triggered basis.
- Legal and Regulatory Compliance: Meeting our obligations under Kenyan law, contractual obligations, and standards including ISO 27001.
- Marketing Communications (with Consent): Newsletters, product updates, and event invitations to contacts who have opted in. All marketing emails contain a one-click unsubscribe processed within 24 hours.
No Selling. No Profiling for Advertising. Kendaall Tracking does not sell personal data. We do not build advertising profiles or allow third parties to use our data for their own marketing. Our revenue model is based entirely on platform subscriptions and services.
Third-Party Disclosure & Sub-Processors
Data Sharing and Third-Party Processors
Kendaall Tracking shares personal data with third parties only where strictly necessary to deliver our platform services, required by law, or expressly authorised by the data subject.
Sub-Processors we engage include: cloud infrastructure and hosting providers (ISO 27001-certified data centres); email service providers (notification and alert delivery); customer support platform providers; payment processing providers (billing contact and transaction confirmation only, not full card data); and security monitoring providers (access log data for platform security).
All sub-processors are bound by Data Processing Agreements requiring them to process data only on our documented instructions, implement equivalent security measures, notify us promptly of any breach, and return or securely delete data on termination. A current sub-processor list is available on request from our DPO.
Disclosure Required by Law: Where we receive a valid legal demand, we will comply with our obligations, notify the affected data subject where legally permitted, disclose only the minimum data responsive to the demand, and challenge overreaching demands through appropriate legal channels.
Merger, Acquisition, or Business Transfer: Personal data may be transferred to an acquiring entity. We will provide at least 30 days’ notice to affected users, and the incoming entity must honour this policy’s commitments or obtain fresh consent for materially different processing.
Cross-Border Data Flows
International Data Transfers
Kendaall Tracking’s primary data infrastructure is located within the African region. However, sub-processor relationships, satellite communication providers, and multinational client operations mean personal data may, in certain circumstances, be transferred to or accessed from countries outside Kenya.
Where personal data is transferred to a country not designated as providing adequate protection, we implement appropriate safeguards before transfer, including Standard Contractual Clauses (SCCs), Binding Corporate Rules where applicable, and case-by-case Transfer Impact Assessments (TIAs).
Clients operating under GDPR may request a copy of the SCCs and TIAs governing any transfer of their employees’ personal data to non-EEA sub-processors. Requests should be directed to privacy@kendaalltracking.co.ke.
Storage Periods & Deletion Schedules
How Long We Retain Your Data
Kendaall Tracking retains personal data for the minimum period necessary to fulfil its collection purpose, meet contractual obligations, and comply with legal retention requirements.
| Data Category | Retention Period | Basis for Retention Period |
|---|---|---|
| Active Platform Account Data | Duration of contract + 90 days | Contractual necessity; post-termination recovery buffer |
| Platform Usage Logs (IP, session) | 12 months | Security monitoring and fraud investigation |
| Operator / Field Personnel Records | Contract duration + 12 months | As directed by client data controller |
| Support Communication Records | 24 months | Service quality improvement; dispute limitation period |
| Asset Telemetry Data (operational) | 5 years minimum | Regulatory compliance, insurance audit requirements |
| Financial & Billing Records | 7 years | Kenya Revenue Authority — Tax Procedures Act 2015 |
| Marketing Consent Records | Until withdrawn + 3 years | Proof of consent for compliance defence |
| Website Analytics (anonymised) | 26 months | Industry standard; IP anonymised after 30 days |
| Deleted Account Data | 30 days post-request | Recovery period before irreversible deletion |
Upon expiry of the retention period, data is securely deleted or physically destroyed per ISO 27001 disposal procedures. Deletion events are logged with a certificate available to enterprise clients on request. Backups are purged within 90 days of the scheduled production deletion date.
Technical & Organisational Measures
How We Protect Your Data
Data security is an engineering priority at Kendaall Tracking. We hold ISO 27001 certification across our information security management system, independently audited annually.
- Encryption at Rest and in Transit: AES-256 at rest; TLS 1.3 minimum in transit with certificate pinning on mobile apps. Satellite and LoRaWAN transmissions use end-to-end application-layer encryption.
- Access Controls: Role-based access control with asset-level granularity; mandatory MFA for staff; Privileged Access Management with full audit logging.
- Security Monitoring and Incident Response: 24/7 Security Operations Centre monitoring; critical incidents escalated within 15 minutes; affected data subjects notified within 72 hours of a confirmed breach.
- Penetration Testing and Vulnerability Management: Independent tests biannually; critical/high findings remediated within 14 days.
- Staff Training and Data Minimisation: Mandatory data protection training on joining and annually thereafter; staff access limited to role-necessary minimum data.
Reporting a Security Concern: Contact security@kendaalltracking.co.ke immediately. We operate a responsible disclosure programme, acknowledge reports within 24 hours, and do not pursue legal action against good-faith researchers.
Data Subject Rights Under the DPA 2019
Your Rights Over Your Personal Data
The Kenya Data Protection Act 2019 grants specific, enforceable rights to individuals whose personal data Kendaall Tracking processes.
Right of Access
Request a copy of all personal data we hold about you and how it is processed, provided within 30 days free of charge.
Right of Rectification
Request correction of inaccurate data or completion of incomplete records, processed within 14 days.
Right to Erasure
Request deletion where processing is no longer necessary or consent is withdrawn, subject to statutory retention requirements.
Right to Portability
Receive your data in a structured, machine-readable format (JSON or CSV) for transfer elsewhere.
Right to Object
Object to processing based on legitimate interests, including direct marketing, which stops immediately on objection.
Right to Restrict
Request restricted processing while a rectification or objection request is assessed.
To exercise any right above, contact our DPO at privacy@kendaalltracking.co.ke identifying the right you wish to exercise. We verify identity, confirm receipt within 72 hours, and aim to complete requests within 30 calendar days (extendable to 60 days for complex requests, with notice).
For field personnel whose data Kendaall processes as a data processor, rights requests should be directed first to the employer (the data controller); Kendaall cooperates fully with any controller-initiated rights process.
Cookies, Web Beacons & Local Storage
Cookies and Tracking Technologies
Our website uses cookies to enable core functionality, remember preferences, and — with consent — measure audience behaviour.
Strictly Necessary Cookies
Session management, CSRF protection, and load-balancing cookies. Cannot be disabled without breaking platform functionality. Contain no personally identifying information beyond a session ID.
Always ActiveFunctional Preference Cookies
Remember language, dashboard layout, notification settings, and onboarding dismissal. Retained for subscription duration plus 30 days.
OptionalAnalytics Cookies
First-party anonymised page visit and navigation data. IP addresses anonymised before storage. Set only with explicit consent.
Consent RequiredMarketing Cookies
We do not use marketing, retargeting, or cross-site tracking cookies. No social tracking pixels or advertising network scripts on our site.
Not UsedManage cookie preferences via the Cookie Preference Centre linked in our footer, or through your browser settings — noting that blocking strictly necessary cookies will impair platform login.
Minors & Age Restrictions
Children’s Privacy
The Kendaall platform is a professional industrial operations tool for adults in commercial and enterprise contexts. We do not knowingly collect personal data from children or minors under 18.
If you believe we have inadvertently collected data relating to a person under 18, contact our DPO at privacy@kendaalltracking.co.ke immediately. Confirmed data will be deleted within 14 days.
Policy Amendments & Version Control
Changes to This Privacy Policy
We review this Privacy Policy at minimum annually and whenever a material change occurs to processing activities, sub-processor categories, applicable law, or business structure.
Where a revision is material, we notify all active account holders by email at least 30 days before it takes effect, describing the changes and linking both new and previous versions. Continued use after the effective date constitutes acceptance for processing covered by contractual necessity; new purposes previously requiring consent will need fresh consent.
Previous versions are archived and available on request from our DPO.
Supervisory Authority & Escalation
Contacting Us and Making a Complaint
If you have a question about this policy, wish to exercise a right, or have a concern about how your data has been handled, your first point of contact should always be our DPO.
Data Protection Officer
General & Registered Office
If dissatisfied with our response, you may lodge a complaint with the Office of the Data Protection Commissioner of Kenya (ODPC), the independent supervisory authority under the DPA 2019 with powers to investigate complaints and impose penalties.
ODPC contact: www.odpc.go.ke · +254 20 628 4000 · Teleposta Towers, Kenyatta Avenue, Nairobi, Kenya.
Data subjects in the European Economic Area retain the right to lodge a complaint with a supervisory authority in their country of residence regardless of where Kendaall Tracking is established.
We encourage you to contact us directly before escalating to a supervisory authority. Concerns brought to us directly are typically resolved more quickly and satisfactorily than those routed through formal regulatory channels.
The Questions We Hear Most Often
Privacy decisions at enterprise level involve real operational and legal considerations. Here are the answers to the questions logistics directors, IT procurement teams, and legal counsel ask most frequently before signing a Kendaall Tracking agreement.
What personal data does Kendaall Tracking collect?
Kendaall Tracking collects account registration data (name, email, job title, organisation), platform usage data, device telemetry linked to named asset operators where applicable, and communication records from support interactions. We do not collect biometric data, payment card details, or sensitive personal categories beyond what is necessary for contractual service delivery.
Does Kendaall Tracking sell personal data to third parties?
No. We do not sell, rent, or exchange personal data with any third party for commercial or marketing purposes. Our revenue model is built entirely on platform subscriptions and professional services. Sub-processor arrangements are reviewed annually for continued necessity and compliance.
Where is Kendaall Tracking data stored?
Platform data is stored in ISO 27001-certified data centres, with primary storage using African regional infrastructure where technically viable. Enterprise clients with residency requirements (e.g. EU GDPR) can request dedicated regional storage under a Data Processing Agreement with documented transfer safeguards.
How can I request deletion of my personal data?
Email privacy@kendaalltracking.co.ke with subject “Data Deletion Request” and identifying information. We acknowledge within 72 hours, verify identity, and complete verified deletion within 30 calendar days, subject to statutory retention obligations which we’ll flag clearly if applicable.
What legal basis does Kendaall Tracking use to process personal data?
We rely on contractual necessity, legitimate interests (documented in a Legitimate Interests Assessment), legal obligation, and consent where separately obtained — assessed individually per processing purpose and recorded in our processing register, available to enterprise clients on request.
Questions About Your Data?
Our Data Protection Officer responds to all privacy queries within 72 hours. Whether you need to exercise a data right, review our processing register, or discuss a Data Processing Agreement for your enterprise deployment — we are ready to help.