Legal

Privacy Policy

How we handle personal data across our website, shop and client platform.

Last updated August 2026
On this page
Who we are Two different roles What we collect Why we hold it Who else sees it How long we keep it Your rights Security Changes
Draft for review. This policy is a working draft and has not been reviewed by legal counsel. It describes our intended practice. Contact us with any question about how your data is handled.

Who we are

Trustline Cyber & Cloud Group ("Trustline", "we") is an IT governance, cybersecurity and cloud services company based in Nairobi, Kenya. We operate this website, an online equipment shop, and a client platform used by organisations we work with.

For questions about this policy or about data we hold, contact info@trustlinecyber.co.ke.

Two different roles

We handle personal data in two distinct capacities, and the difference matters because it determines who is responsible for what.

As a controller

For data you give us directly — enquiries, quotation requests, orders and platform accounts. We decide how that data is used, and this policy governs it.

As a processor

For data our clients upload, such as contact lists used to send SMS. That data belongs to the client organisation. They decide what happens to it; we act only on their instructions.

If your details were used in a message sent through our platform, the organisation that sent it is your first point of contact.

What we collect

When you contact us or request a quotation

  • Your name, email address and phone number
  • Your organisation, where you provide it
  • Your KRA PIN, where you provide it for invoicing
  • A delivery address, for equipment orders
  • The content of your enquiry, and the items you asked us to quote

When you hold an account on our platform

  • Your name, work email address and phone number
  • The organisation you belong to and your role within it
  • A record of significant actions taken in the system

Automatically

  • A cookie that keeps you signed in
  • A cookie holding items you add to a shopping list, for fourteen days
  • Standard server logs, including IP address and browser type
We do not use advertising or tracking cookies, and we do not sell personal data to anyone.

Why we hold it

PurposeData used
Responding to an enquiryContact details and your message
Preparing a quotation or invoiceContact details, KRA PIN, delivery address, items
Delivering equipmentDelivery address and contact details
Providing platform accessAccount details and access permissions
Meeting tax obligationsInvoice and payment records
Keeping the platform secureLogin records and server logs

Who else sees it

We share personal data only where it is necessary to provide our services.

  • Our SMS and airtime gateway — recipient numbers and message content, to deliver them
  • Our email provider — addresses and content, to send quotations, invoices and notifications
  • Our hosting provider — data stored on servers we operate
  • KRA and our accountants — invoice records, where required by law

We do not sell, rent or trade personal data, and we do not share it for marketing purposes.

How long we keep it

RecordKept for
Website enquiriesTwo years from last contact
Quotations that did not proceedTwo years
Invoices and payment recordsSeven years, for tax purposes
Platform accountsWhile active, then twelve months
Client-uploaded contact listsUntil deleted by the client

Your rights

Under the Data Protection Act 2019, you have the right to:

  • Ask what personal data we hold about you
  • Ask us to correct anything inaccurate
  • Ask us to delete data, where we have no legal obligation to keep it
  • Object to how we use it
  • Ask for a copy in a portable format

Write to info@trustlinecyber.co.ke and we will respond within thirty days. If we have not resolved your concern, you may complain to the Office of the Data Protection Commissioner.

Security

Access to client data is restricted to staff who need it. Passwords are stored hashed and never in readable form. Traffic to our platform is encrypted. Support access to a client account is logged with a record of who accessed it and when.

No system is perfectly secure. If a breach occurs that puts your data at risk, we will tell you and the Data Protection Commissioner as required.

Changes

We will update this page when our practices change, and revise the date at the top. Material changes affecting platform clients will be notified by email.

Questions about this policy? We would rather you asked than wondered.
Contact us

Trustline Cyber & Cloud Group

IT governance, cloud services, cybersecurity and AI-enabled enterprise technology for organisations and the public institutions their communities depend on.

Navigate

Solutions Cloud Shop Impact Program Contact Us

Contact

info@trustlinecybercloud.com
Nairobi, Kenya

© 2026 Trustline Cyber & Cloud Group. All Rights Reserved.