Skip to content
Legal

Privacy Policy

What we collect, why we collect it, how long we keep it, and what you can require of us. Written to be read rather than to be survived.

Last updated
27 July 2026
Controller
Enlobo Ltd
Governing law
Kenya · DPA 2019
Regulator
ODPC
01

Who we are

Enlobo Ltd ("Enlobo", "we", "us", "our") is a software engineering company registered in Kenya and based in Nairobi. We design, develop and deploy autonomous artificial intelligence systems and custom software architectures for enterprise clients.

For the purposes of the Data Protection Act, 2019 (Kenya) (the "DPA"), Enlobo is the data controller in respect of personal data collected through this website and in the course of our own business administration. Where we process personal data on behalf of a client as part of a system we have built for them, we act as a data processor and the client is the controller. Section 9 explains that distinction in more detail.

You can reach us about anything in this policy at hello@enlobo.com.

02

What this policy covers

This policy explains what personal data we collect through https://enlobo.com, why we collect it, the lawful basis on which we process it, how long we keep it, who it is shared with, and what rights you have. It applies to visitors to this website, people who contact us about work, and personnel at client and supplier organisations.

It does not apply to third-party websites we link to. Those sites have their own policies and we are not responsible for how they handle your data.

03

Personal data we collect

Information you send us directly

This website has no server-side contact form. The brief builder on our contact page runs entirely in your browser: it assembles a message from what you type and hands that draft to your own email application. Nothing you type into it is transmitted to us, or to anyone else, unless and until you choose to send that email yourself.

When you do email us, we receive whatever you have chosen to include. Typically that is your name, your email address, your organisation, and a description of the process or project you want to discuss. Please do not send us confidential or special-category information in a first email.

Information collected automatically

Our hosting provider processes standard server and network information in order to deliver the site and keep it secure. This includes your IP address, the pages requested, timestamps, referring page, and basic browser and device information. We use this only in aggregate and for security and reliability purposes.

Information stored on your device

This website sets no advertising or tracking cookies and runs no third-party analytics. We store a single value in your browser's local storage, under the key 'enlobo-theme', to remember whether you have chosen the light or dark appearance. It contains no identifier, is never transmitted to us, and you can clear it at any time through your browser settings.

Client and supplier records

In the course of an engagement we hold business contact details and correspondence for the individuals we work with at client and supplier organisations, together with the contractual and financial records required to run the relationship.

04

How we use personal data, and our lawful basis

Under section 30 of the DPA we must have a lawful basis for each processing purpose. Ours are set out below.

PurposeData usedLawful basis
Responding to an enquiry and discussing possible workName, email address, organisation, content of your messageLegitimate interests: replying to someone who has contacted us about our services; and steps taken at your request prior to entering a contract
Delivering an engagement and managing the client relationshipBusiness contact details, correspondence, project recordsPerformance of a contract
Invoicing, accounting and statutory recordsContact and transaction recordsCompliance with a legal obligation
Operating, securing and improving this websiteServer logs, IP address, request metadataLegitimate interests: keeping our systems available and protected from abuse
Establishing, exercising or defending legal claimsWhatever is relevant to the matterLegitimate interests, and compliance with a legal obligation

We do not sell personal data. We do not use it for automated decision-making that produces legal effects for you, and we do not build advertising profiles.

We do not send marketing email. If that ever changes we will ask for your consent first and every message will carry a working unsubscribe link.

05

Who we share it with

We keep the number of parties with access to personal data as small as the work allows. We share it only with:

  • Service providers who operate infrastructure on our behalf (principally our website host and our email provider) under contracts that restrict them to processing on our instructions.
  • Professional advisers such as accountants and lawyers, where they need it to advise us.
  • Regulators, courts or law enforcement, where we are legally required to disclose it or where disclosure is necessary to establish or defend a legal claim.
  • An acquirer or successor, in the event of a sale or reorganisation of our business, subject to the protections in this policy continuing to apply.

We do not disclose client project information to anyone outside the engagement without the client's instruction, other than where the law requires it.

06

Transfers outside Kenya

Some of the providers we rely on to host this website and carry our email operate infrastructure outside Kenya. Where personal data is transferred out of the country, section 48 of the DPA requires us to be satisfied that appropriate safeguards exist.

We rely on a combination of contractual safeguards with the provider, an assessment of the protections available in the destination jurisdiction, and, where relevant, your consent or the necessity of the transfer for the performance of a contract. You may ask us for details of the safeguards applying to a particular transfer.

Where a client requires that processing of their data stays within a particular jurisdiction, we design the deployment to meet that requirement and record it in the engagement contract.

07

How long we keep it

We keep personal data only as long as we have a reason to, and then delete it.

RecordRetention period
Enquiries that do not become an engagement24 months from our last exchange, then deleted
Client correspondence and project recordsFor the duration of the engagement and 7 years afterwards, to cover contractual and statutory limitation periods
Accounting and tax records7 years, as required by Kenyan tax law
Website server logsRolling period of up to 90 days

Where we hold data as a processor for a client, retention is governed by our contract with that client and we delete or return the data on their instruction at the end of the engagement.

08

How we protect it

We apply technical and organisational measures appropriate to the risk, including:

  • Encryption in transit for this website and for our email, and encryption at rest for stored records.
  • Access on a least-privilege basis, with multi-factor authentication on the accounts that hold client information.
  • Separation of client environments, so that one engagement's data is not reachable from another.
  • Logging and monitoring of access to production systems we operate.
  • Confidentiality obligations on everyone who works on an engagement.

No system is perfectly secure. If a breach occurs that is likely to result in a real risk to your rights and freedoms, we will notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it where the DPA requires, and we will notify you without undue delay where the risk to you is high.

09

Your rights

Under Part V of the DPA you have the right to:

  • Be informed of the use to which your personal data is being put, which is what this policy is for.
  • Access the personal data we hold about you, and obtain a copy of it.
  • Have inaccurate or misleading data corrected without delay.
  • Have your data deleted where we no longer have a lawful reason to hold it.
  • Object to processing based on our legitimate interests, on grounds relating to your particular situation.
  • Restrict our processing while an accuracy dispute or an objection is being resolved.
  • Receive the personal data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
  • Withdraw consent at any time, where we relied on consent. Withdrawal does not affect processing carried out before you withdrew.

To exercise any of these, email hello@enlobo.com. We will respond within the timeframe set by the DPA and will not charge a fee unless a request is manifestly unfounded or excessive. We may ask you for information to confirm your identity before we act.

If your request concerns data we hold as a processor for one of our clients, we will pass it to that client, who is the controller, and support them in responding.

10

When we act as a processor

Much of our work involves building systems that handle personal data belonging to our clients: their customers, staff or suppliers. In that context the client decides why and how that data is processed, and is therefore the data controller. We act as their processor.

Where that is the case:

  • We process the data only on the client's documented instructions.
  • We enter a written data processing agreement covering the subject matter, duration, nature and purpose of the processing, the categories of data and data subjects, and each party's obligations.
  • We do not engage a sub-processor without the client's authorisation, and we impose equivalent obligations on any we do engage.
  • We assist the client with data subject requests, security obligations, breach notification and impact assessments.
  • We delete or return the data at the end of the engagement, as the client directs.

If you are a customer or employee of one of our clients and want to exercise your rights over data held in a system we built, contact that organisation directly. They will know what they hold and why, and we will assist them.

11

Children

This website and our services are directed at businesses and are not intended for children. We do not knowingly collect personal data relating to a child. If you believe a child has provided us with personal data, contact us and we will delete it.

12

Complaints

If you are unhappy with how we have handled your personal data, please tell us first at hello@enlobo.com. We would rather fix it directly and quickly.

You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC), the supervisory authority for data protection in Kenya. You can find their current contact details and complaint procedure at odpc.go.ke.

13

Changes to this policy

We review this policy periodically and will update it when our practices change or the law does. The date at the top of this page shows when it was last revised. Where a change materially affects how we handle your personal data, we will take reasonable steps to bring it to your attention rather than relying on a silent update. This version is effective from 27 July 2026.

14

Contact

Enlobo Ltd, Nairobi, Kenya. Questions, requests and complaints about this policy: hello@enlobo.com.