Legal
Privacy Policy
Last updated 5 August 2026
This Privacy Policy explains how Koiva Technologies (“Koiva”, “we”, “us”) collects, uses, and protects personal data when you use Koiva CRM (the “Service”). We process personal data in accordance with the Kenya Data Protection Act, 2019 and other applicable law.
1. Who is responsible for your data
For data about your own account and use of the Service, Koiva is the data controller. For the Customer Data you load into your workspace — your contacts, deals, and communications — your organisation is the controller and Koiva is a data processor acting on your instructions.
2. What we collect
- Account data: your name, email address, organisation name, and password (stored only as a secure hash).
- Customer Data: the records you and your users create — contacts, deals, documents, and messages.
- Usage and technical data: log data, device and browser information, and IP address, used to operate and secure the Service.
- Cookies: strictly necessary cookies to keep you signed in and secure. We do not use advertising cookies.
3. How we use data
- to provide, maintain, and secure the Service;
- to authenticate you and protect against fraud and abuse;
- to communicate about your account, billing, and service changes;
- to comply with legal obligations and enforce our terms.
We do not sell your personal data, and we do not use your Customer Data to train third-party models.
4. Sharing
We share personal data only with service providers who help us run the Service (such as hosting and email delivery), under contracts that require them to protect it; where required by law; or to protect the rights and safety of Koiva and others. These providers act on our instructions and only for the purposes above.
5. Where data is stored
Your data is hosted on secured infrastructure. Each tenant’s data is isolated so that one organisation cannot access another’s. Where data is transferred outside Kenya, we take steps required by law to protect it.
6. Retention
We keep personal data for as long as your account is active and as needed to provide the Service. After termination we retain data for a limited period to allow export, then delete or anonymise it, subject to legal retention requirements.
7. Your rights
Subject to law, you have the right to access, correct, delete, or restrict the processing of your personal data, to object to processing, and to data portability. To exercise these rights over your own account data, contact us below. Where Koiva processes data on behalf of an organisation, please direct requests to that organisation.
8. Security
We use technical and organisational measures — encryption in transit, tenant isolation, access controls, and audit logging — to protect personal data. No system is perfectly secure, but we work to keep your data safe and to notify you of incidents as required by law.
9. Changes
We may update this Policy from time to time. Material changes will be notified by email or in the Service, and the “last updated” date above will change.
10. Contact
For privacy questions or to exercise your rights, email privacy@koiva.tech. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya.