Legal

Privacy Policy

What we collect through this website, why we collect it, how long we keep it and what you can ask us to do with it.

Last updated: 24 August 2026

These policies are the standard basis on which we sell and engage clients. They are not legal advice, and they are not a substitute for advice on your own circumstances. Where you have signed an individual client agreement with us, that agreement takes precedence over anything on this page. We recommend you take your own advice before entering any significant commitment.

This policy explains how Streamedge Solutions Limited handles personal information collected through this website. It describes what the website actually does today, not what a template says a website might do. If we change what we collect, we change this page.

Your card details are never entered on this website. Where an online payment is available, it happens on the payment provider’s own page. Full card numbers, CVV codes and payment PINs do not reach our servers and are not stored by us at any point. See Payment information.

1. Who we are

Streamedge Solutions Limited sells digital products and remote technology services from Kenya. For the information collected through this website, we are the data controller — we decide what is collected and why.

You can reach us about anything in this policy at info@streamedgesolutions.com.

Where we handle personal data inside a client’s own systems as part of a project — migrating a customer database, configuring a CRM, connecting a mailing tool — we act as a processor on that client’s instructions, and the engagement terms govern it rather than this page.

2. What we collect

We collect the following, and nothing else:

  • Enquiry details. The contact form collects your name, email address, phone number (optional), subject and message.
  • Quote request details. Your name, company name (optional), email address, phone number (optional), country, the service required, budget range (optional), project description, preferred start date (optional) and anything else you choose to add.
  • Order details. See section 4.
  • Technical information sent by your browser when you submit a form: your IP address and user-agent string. We record these to detect and rate-limit automated or abusive submissions, and for no other purpose.
  • Anything you send us directly by email, or say to us during a call or a project.

We do not buy personal data from anyone, we do not build advertising or behavioural profiles, and we do not sell or rent what we hold.

Please do not put passwords, live API keys, card numbers or other credentials into a form field. If you need to send us access to something, we will tell you a safe way to do it.

3. Account information

This website has no customer accounts. You do not register, you do not set a password, and there is no customer login. Your cart is held in your own browser, not on our servers — see our Cookie Policy.

To look at an order after you have placed it, you enter the order number together with the email address the order was placed with. That pair is the only credential, which is why the order number is not something to forward on casually. There is nothing to deactivate and no password of yours for us to lose.

Staff access to the order records is protected separately by a single administrative login used only by us.

4. Order and billing information

When you place an order, we record:

  • Your name, company name (optional), email address, phone number and country.
  • A billing address where you give one. There is no delivery address, because nothing is shipped — see our Delivery & Fulfilment Policy.
  • What you ordered, the quantity, the add-ons chosen, the price, the currency and the order total.
  • The project information the checkout asks for, which varies by product — for example your existing website address, the systems to be connected, or the platform to be supported. We ask for it because we cannot start the work without it.
  • The status history of the order, and the payment reference, amount, date, method and status.

We need this to fulfil the order, to prove what was agreed if a question arises later, and to keep the accounting and tax records the law requires of us.

5. Payment information

We do not receive, process or store full card numbers, CVV codes or payment PINs. Card and mobile-money credentials are entered on the payment provider’s own systems, on their page, under their security arrangements. Our website never sees them.

No online payment is currently connected to this website. There is no card field, no stored card and no payment provider live on this site today. Orders are recorded as awaiting payment and settled against an invoice we issue separately.

When online payment is switched on, the position above still holds: the provider collects the payment details on its own page and returns only a reference, an amount, a date and a status to us.

We will never email or message you asking you to redirect a payment to different bank details. If you receive such a request, treat it as fraudulent and check with us at info@streamedgesolutions.com before paying.

6. Cookies

The short version: this site sets no cookie at all for ordinary visitors. It stores a cart in your browser’s own local storage, which never leaves your device, and it sets one login cookie for our own staff. Analytics scripts load only if an analytics ID has been configured.

The full detail, including how to clear what is stored, is in our Cookie Policy.

7. Analytics

No analytics or tracking script is loaded on this website. Nothing measures your visit. If analytics is added later, this section will name the provider, say what it collects and say whether it uses cookies — and the Cookie Policy will list it too.

8. Communications

We use your email address and phone number to reply to you, to send order confirmations and status updates, to ask the questions we need answered to do the work, and to send invoices and receipts. Those are service messages: they are part of what you asked us for, and you cannot opt out of them while an order or engagement is live.

We do not send marketing email to people who have only made an enquiry. If we ever run a mailing list you will have to ask to join it, and every message will carry a working unsubscribe link.

We keep correspondence about a project because it is the record of what was agreed.

9. How we use information

  • To answer enquiries and prepare quotations and proposals.
  • To take, confirm, deliver, support and invoice orders.
  • To ask for and chase the requirements we need before work can start.
  • To keep the accounting and tax records we are legally required to keep.
  • To detect, prevent and investigate abuse of our forms, checkout and systems.
  • To handle a complaint, a refund request or a dispute, and to defend our position if one is raised against us.

We do not use your information to make automated decisions that have a legal or similarly significant effect on you, and there is no profiling on this site.

10. Why we are allowed to (lawful basis)

In plain terms, we rely on one of four things:

  • You asked us to. Submitting the contact or quote form is your consent to be contacted about it. You can withdraw that at any time by telling us.
  • We have a contract with you. Once you place an order, we need your details to deliver it. Refusing to give them means the order cannot be fulfilled.
  • The law requires it. Accounting and tax records have to be kept for a set period, whether or not you would prefer them deleted.
  • We have a legitimate interest. Keeping the site secure, preventing fraud and abuse, and being able to evidence what was agreed. We use the least information that achieves this.

11. How long we keep it

  • Enquiries and quote requests that do not become orders — 24 months, then deleted.
  • Order and project records — for the life of the engagement, and afterwards for the period the applicable accounting, tax and limitation rules require. We do not keep them indefinitely.
  • Payment references — for the same period as the order they belong to, because they are part of the accounting record.
  • Technical logs used for abuse prevention — a short period only, then overwritten.
  • Correspondence — kept while it is relevant to a live or recent engagement.

You can ask us to delete an enquiry sooner than the period above, and we will, unless we are required to keep it — see Your rights.

12. How we protect it

The measures actually in place on this website are:

  • Encrypted connections (HTTPS) for every request.
  • Server-side validation of every submission, in addition to browser-side checks.
  • Rate limiting and automated-submission detection on the forms and the checkout.
  • Security headers, including a Content Security Policy.
  • Staff access to order records behind a signed, expiring, HttpOnly session cookie, over a login that is disabled entirely unless a strong password is configured.
  • Credentials held in server-side environment configuration, never in the website code and never in the browser bundle.
  • Access to stored submissions and orders limited to the people who need it.

No system can be guaranteed completely secure, and we do not claim otherwise. We hold no security certification and we do not claim to hold one. If we ever become aware of a breach affecting your personal data, we will tell you and the relevant authority within the time the law requires.

13. Who else handles it

We use third-party suppliers to run the business. They are described here by category rather than by name, because naming a supplier we have not actually contracted would be a false statement about our own operations. Each named supplier will be listed here once it is in place.

  • Our hosting and infrastructure provider — stores the website and its database on our behalf.
  • Our email delivery provider — sends order confirmations, enquiry notifications and invoices.
  • Our payment provider — takes payments and holds the card data we never see, under its own terms and security obligations.
  • Our analytics provider — only where analytics is configured, as described in section 7.
  • Our accountants and professional advisers — where they need a record to advise us.
  • Courts, regulators and law enforcement — where we are legally obliged to disclose something.

Each of these gets the minimum it needs to do its job, and none of them is permitted to use your data for its own marketing. A current list of the specific providers we rely on, with links to their own privacy terms, is available on request by emailing info@streamedgesolutions.com.

14. International transfers

Some of the suppliers above are likely to operate outside Kenya, which means your information may be stored or processed in another country. Where that happens, we choose suppliers that commit contractually to protecting the data to a standard comparable to that required at home, and we transfer only what the supplier needs.

We will name the countries involved here once the suppliers in section 13 are confirmed.

15. Your rights

Under the Data Protection Act, 2019 of Kenya — and under comparable laws where they apply to you — you have the right to:

  • Be told how your data is used, which is what this page is for.
  • Get a copy of the personal data we hold about you.
  • Have inaccurate or incomplete data corrected.
  • Have your data deleted where we have no continuing need or legal duty to keep it.
  • Object to, or ask us to restrict, particular processing.
  • Receive data you gave us in a portable form, or have it sent to another provider, where that is technically feasible.
  • Withdraw consent at any time. That stops future processing based on consent; it does not undo what was lawfully done before.

How to exercise them: email info@streamedgesolutions.com saying which right you are exercising and what it relates to. We may ask you to confirm your identity first — usually by replying from the address the data was submitted from — so that we do not hand your information to someone else. We respond within the period the law allows, and we do not charge for a reasonable request.

If we cannot do what you have asked, we will tell you why in writing rather than simply declining.

16. How to complain

Please raise it with us first — email info@streamedgesolutions.com, or follow the full procedure in our Contact & Complaints page, which sets out how a complaint is acknowledged, handled and escalated.

If you are not satisfied with our response, you have the right to complain to the data protection authority in Kenya — the Office of the Data Protection Commissioner — or to the equivalent authority where you live. Doing so does not require you to come to us first, though it usually resolves things faster.

17. Children

We sell to businesses and organisations. This website is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has submitted information to us, tell us and we will delete it.

18. Changes to this policy

We update this page when the website changes or when the law does. The date of the current version is shown at the top. Material changes will be described here rather than slipped in, and the version in force when you submitted information is the version that governed it.

19. Contact

Questions about this policy, or about the data we hold on you:

Streamedge Solutions Limited
info@streamedgesolutions.com
+254 719 771839
12th Floor, One Padmore Place, George Padmore Road, P.O Box 856-00606, Nairobi
Kenya

Contact us