Who we are
Trustline Cyber & Cloud Group ("Trustline", "we") is an IT governance, cybersecurity and cloud services company based in Nairobi, Kenya. We operate this website, an online equipment shop, and a client platform used by organisations we work with.
For questions about this policy or about data we hold, contact info@trustlinecyber.co.ke.
Two different roles
We handle personal data in two distinct capacities, and the difference matters because it determines who is responsible for what.
For data you give us directly — enquiries, quotation requests, orders and platform accounts. We decide how that data is used, and this policy governs it.
For data our clients upload, such as contact lists used to send SMS. That data belongs to the client organisation. They decide what happens to it; we act only on their instructions.
If your details were used in a message sent through our platform, the organisation that sent it is your first point of contact.
What we collect
When you contact us or request a quotation
- Your name, email address and phone number
- Your organisation, where you provide it
- Your KRA PIN, where you provide it for invoicing
- A delivery address, for equipment orders
- The content of your enquiry, and the items you asked us to quote
When you hold an account on our platform
- Your name, work email address and phone number
- The organisation you belong to and your role within it
- A record of significant actions taken in the system
Automatically
- A cookie that keeps you signed in
- A cookie holding items you add to a shopping list, for fourteen days
- Standard server logs, including IP address and browser type
Why we hold it
| Purpose | Data used |
|---|---|
| Responding to an enquiry | Contact details and your message |
| Preparing a quotation or invoice | Contact details, KRA PIN, delivery address, items |
| Delivering equipment | Delivery address and contact details |
| Providing platform access | Account details and access permissions |
| Meeting tax obligations | Invoice and payment records |
| Keeping the platform secure | Login records and server logs |
Who else sees it
We share personal data only where it is necessary to provide our services.
- Our SMS and airtime gateway — recipient numbers and message content, to deliver them
- Our email provider — addresses and content, to send quotations, invoices and notifications
- Our hosting provider — data stored on servers we operate
- KRA and our accountants — invoice records, where required by law
We do not sell, rent or trade personal data, and we do not share it for marketing purposes.
How long we keep it
| Record | Kept for |
|---|---|
| Website enquiries | Two years from last contact |
| Quotations that did not proceed | Two years |
| Invoices and payment records | Seven years, for tax purposes |
| Platform accounts | While active, then twelve months |
| Client-uploaded contact lists | Until deleted by the client |
Your rights
Under the Data Protection Act 2019, you have the right to:
- Ask what personal data we hold about you
- Ask us to correct anything inaccurate
- Ask us to delete data, where we have no legal obligation to keep it
- Object to how we use it
- Ask for a copy in a portable format
Write to info@trustlinecyber.co.ke and we will respond within thirty days. If we have not resolved your concern, you may complain to the Office of the Data Protection Commissioner.
Security
Access to client data is restricted to staff who need it. Passwords are stored hashed and never in readable form. Traffic to our platform is encrypted. Support access to a client account is logged with a record of who accessed it and when.
No system is perfectly secure. If a breach occurs that puts your data at risk, we will tell you and the Data Protection Commissioner as required.
Changes
We will update this page when our practices change, and revise the date at the top. Material changes affecting platform clients will be notified by email.