1. Scope and responsibility
This Privacy Policy applies to ziam.co.ke and to ZIAM digital services that expressly link to it. It does not apply to an independent third-party service simply because ZIAM links to that service.
ZIAM determines the purpose and means of processing personal data for the services it operates. Product-specific notices may provide additional detail where a service handles specialised information.
2. Data we may collect
We limit collection to information that is relevant to a defined service purpose.
- Identity and contact data, such as a name, email address, telephone number, and account identifier.
- Account and security data, such as password hashes, authentication events, device information, and session records.
- Transaction and service data, such as selected products, orders, support requests, and service history.
- Technical data, such as browser type, approximate network information, error logs, security events, and service performance data.
- Information supplied voluntarily through enquiries, research participation, applications, surveys, or community programmes.
3. Why we process data
Personal data may be processed to provide a requested service, comply with law, protect systems, or pursue a legitimate operational purpose that does not override individual rights.
- Create and administer accounts, products, subscriptions, orders, and support requests.
- Authenticate users, prevent fraud and abuse, investigate security events, and maintain service integrity.
- Communicate service notices, requested information, policy updates, and optional product news.
- Improve accessibility, reliability, performance, documentation, and user experience.
- Meet legal, regulatory, accounting, dispute-resolution, and public-interest obligations.
4. Our processing principles
ZIAM aims to process personal data lawfully, fairly, transparently, and only for explicit purposes. Collection should be adequate and relevant, records should be accurate, retention should be limited, and appropriate technical and organisational safeguards should protect confidentiality and integrity.
6. Retention and security
Records are retained only for the service, security, legal, accounting, research, or dispute period that applies to them, after which they should be deleted, anonymised, or securely archived.
Safeguards may include access controls, encryption in transit, password hashing, audit records, secure development practices, backups, monitoring, and incident-response procedures. No internet service can guarantee absolute security.
7. Your data rights
Subject to applicable law, a person may request information about processing and exercise available data-subject rights.
- Be informed about how personal data is used.
- Access personal data held about you and request correction of inaccurate or misleading information.
- Object to processing or request restriction where the legal conditions are met.
- Request deletion of false, misleading, or unlawfully held data where applicable.
- Withdraw consent for future processing when consent is the legal basis.
- Raise a concern with ZIAM or lodge a complaint with Kenya's Office of the Data Protection Commissioner.
8. Children and young users
ZIAM services are not designed to collect a child's personal data without an appropriate legal basis and the involvement of a parent or guardian where required. Product-specific age requirements will be displayed before collection begins.
9. Questions and requests
Privacy questions, access requests, corrections, objections, or deletion requests can be submitted through the ZIAM Help Center. ZIAM may need to verify identity before acting on a request and will respond within the period required by applicable law.
The current public account forms are interface previews and do not transmit credentials until the ZIAM identity service is activated.
Need clarification?
Use the ZIAM Help Center for policy questions, data requests, or account concerns.
Open Help Center