Statum website privacy policy
This policy explains what information we collect through the website, why we use it, and how to contact us about it.
Effective date: April 6, 2025
Statum Company Ltd respects the privacy of people who use this website or contact us about our services. This policy describes the information we may collect, how we use it, and the choices available to you under applicable data protection law, including Kenya's Data Protection Act, 2019.
1. Information We Collect
- Personal Information: Includes your full name, email address, phone number, company name, and service preferences.
- Technical Information: IP address, browser type, device type, operating system.
- Usage Information: Pages visited, time spent, interaction data.
- Cookies: To enhance user experience.
2. How we receive information
- Through secure forms on our website.
- Automatically through website logs, cookies, or analytics tools where enabled.
- Through direct communication, such as email or a project enquiry.
3. Why we use it
- To respond to enquiries and provide information requested through the website.
- To discuss, deliver, and support services where we have an engagement with you.
- To understand website use and improve our content and services.
- To meet legal, security, and operational obligations.
4. Lawful basis
We process your data based on consent, steps taken at your request, performance of a contract, legitimate interests, or compliance with a legal obligation, as applicable to the activity.
5. Sharing
We do not sell personal information. We may share it with service providers that help us operate the website or deliver an agreed service, and where disclosure is required or permitted by law.
6. Security
We use reasonable technical and organisational measures to protect information against unauthorised access, loss, misuse, or disclosure. No internet service can guarantee absolute security.
7. Storage and transfers
Information may be processed by us or by service providers in the locations needed to run the website or deliver a service. Where a project has specific storage, transfer, or data residency requirements, those requirements should be recorded in the relevant agreement.
8. Project-specific security
Security controls depend on the service, information, users, and hosting environment. Where a client project needs particular controls, they are agreed as part of that project. Examples may include:
- Access control and least-privilege permissions.
- Secure transport and careful handling of credentials.
- Input validation, logging, backups, and release checks where appropriate.
- Additional testing or assessment where the project scope requires it.
9. Retention and deletion
We keep information only for as long as it is needed for the purpose collected, an agreed service, security, record-keeping, or a legal obligation. Deletion requests are handled subject to applicable law and any information we are required to retain.
10. Your rights
You hold the right to access, correct, delete, or object to the processing of your data under the Data Protection Act, 2019, subject to the limits and procedures in applicable law. To make a request, contact us using the details below.