Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your information.
Quick Navigation
Welcome to Silicon Savannah Technologies's Privacy Policy. This document outlines how we collect, use, disclose, and safeguard your information when you visit our website siliconsavannahtechnologies.com or make a purchase from us. We respect your privacy and are committed to protecting your personal data.
1. Information We Collect
Personal Information
- Contact Details: Name, email address, phone number, shipping and billing addresses
- Account Information: Username, password, purchase history, preferences
- Payment Information: Credit/debit card details, M-Pesa numbers (processed securely through payment gateways)
- Communication Data: Messages, emails, and any other correspondence with us
Automatically Collected Information
- Technical Data: IP address, browser type and version, time zone setting, operating system
- Usage Data: Pages visited, time spent on pages, click patterns, search queries
- Device Information: Device type, unique device identifiers, mobile network information
2. How We Use Your Information
Order Processing
Process your orders, manage payments, and arrange deliveries
Customer Service
Respond to your inquiries, provide support, and handle complaints
Personalization
Tailor our website content and product recommendations to your preferences
Marketing
Send promotional offers, newsletters, and updates (with your consent)
Improvement
Analyze website usage to improve our products and services
Security
Detect and prevent fraudulent activities and security breaches
Legal Compliance
Comply with legal obligations and regulatory requirements
Account Management
Manage your account registration and provide access to features
Legal Basis for Processing
Contract Performance
Processing necessary to fulfill orders and provide services
Legitimate Interests
Improving our services and preventing fraud
Consent
For marketing communications and optional features
3. Data Security Measures
Encryption & Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. This includes SSL encryption and secure payment gateways.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. Order and transaction records are generally retained for 7 years for tax and legal purposes. Upon expiry of the retention period, data is securely deleted or anonymised.
Third-Party Processors
We work with trusted third-party service providers who process data on our behalf (e.g., payment processors, delivery services). These providers are carefully vetted and bound by data processing agreements to ensure your data is protected.
4. Payment Security & M-Pesa Handling
We Never Store Your Payment Details
Silicon Savannah Technologies does not store credit/debit card numbers, CVV codes, or full M-Pesa phone numbers linked to transactions on our servers. All card payments are processed through third-party payment gateways. M-Pesa transactions are processed through Safaricom's Daraja API using server-side API keys that are never exposed to the client.
Third-Party Payment Processors
Card payments on this platform are handled by third-party payment processors. By routing card processing through these providers, cardholder data does not pass through or reside on our own systems.
Payment Data Retention
We retain transaction metadata (order ID, amount, M-Pesa reference, masked phone number, timestamp) for 7 years as required by Kenyan tax law and the Kenya Revenue Authority (KRA). This metadata does not include full payment credentials. All retained data is encrypted at rest.
5. Our Data Protection Approach
Silicon Savannah Technologies is committed to handling personal data responsibly and transparently. We aim to be consistent with applicable data protection principles, including collecting only what we need, keeping it secure, and not retaining it longer than necessary.
Why We Process Your Data
Consent
Marketing communications, optional account features, analytics. You may withdraw consent at any time without penalty.
Contract Performance
Order processing, delivery coordination, payment verification, customer support related to active orders.
Legal Obligation
KRA tax records (7 years), anti-fraud records, court orders, and regulatory reporting to relevant Kenyan authorities.
Data Retention Schedule
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Order & transaction records | 7 years | KRA / Tax Act |
| Account & profile data | Duration of account + 2 years post-closure | Contract / Legitimate interest |
| M-Pesa transaction metadata | 7 years | KRA / Tax Act |
| Customer support communications | 3 years | Legitimate interest / Legal claims |
| Marketing preferences & consent records | Until withdrawal + 1 year | Consent |
| Website analytics (anonymised) | 26 months | Legitimate interest |
| Security & fraud logs | 2 years | Legal obligation / Legitimate interest |
After the applicable retention period, personal data is securely deleted or anonymised. Data subjects may request early erasure where no overriding legal obligation applies.
6. Your Data Protection Rights
Right to Access
Request copies of your personal data
Right to Rectification
Request correction of inaccurate or incomplete data
Right to Erasure
Request deletion of your personal data under certain conditions
Right to Restrict Processing
Request restriction of processing your personal data
Right to Data Portability
Request transfer of your data to another organization
Right to Object
Object to our processing of your personal data
Right to Withdraw Consent
Withdraw consent at any time where we rely on consent
Right to Lodge a Complaint
If you believe your data has been mishandled, contact us directly so we can investigate and resolve your concern.
Third-Party Links
Our website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.
Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us. If we become aware that we have collected personal information from children without verification of parental consent, we take steps to remove that information from our servers.
Policy Updates
We may update this privacy policy from time to time to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically for any changes.
Notification: Significant changes will be communicated via email or prominent notice on our website at least 30 days before they take effect.
8. Contact Us
Phone
+254 768 468747Data Protection Officer
For privacy-related inquiries, contact our DPO at the email above
We typically respond to privacy inquiries within 7 business days.
