Legal Center

Data protection

Privacy Policy

This policy explains what personal data ZIAM may collect, why it is used, how it is protected, and the choices available to each person.

Effective: 2 August 2026

1. Scope and responsibility

This Privacy Policy applies to ziam.co.ke and to ZIAM digital services that expressly link to it. It does not apply to an independent third-party service simply because ZIAM links to that service.

ZIAM determines the purpose and means of processing personal data for the services it operates. Product-specific notices may provide additional detail where a service handles specialised information.

2. Data we may collect

We limit collection to information that is relevant to a defined service purpose.

  • Identity and contact data, such as a name, email address, telephone number, and account identifier.
  • Account and security data, such as password hashes, authentication events, device information, and session records.
  • Transaction and service data, such as selected products, orders, support requests, and service history.
  • Technical data, such as browser type, approximate network information, error logs, security events, and service performance data.
  • Information supplied voluntarily through enquiries, research participation, applications, surveys, or community programmes.

3. Why we process data

Personal data may be processed to provide a requested service, comply with law, protect systems, or pursue a legitimate operational purpose that does not override individual rights.

  • Create and administer accounts, products, subscriptions, orders, and support requests.
  • Authenticate users, prevent fraud and abuse, investigate security events, and maintain service integrity.
  • Communicate service notices, requested information, policy updates, and optional product news.
  • Improve accessibility, reliability, performance, documentation, and user experience.
  • Meet legal, regulatory, accounting, dispute-resolution, and public-interest obligations.

4. Our processing principles

ZIAM aims to process personal data lawfully, fairly, transparently, and only for explicit purposes. Collection should be adequate and relevant, records should be accurate, retention should be limited, and appropriate technical and organisational safeguards should protect confidentiality and integrity.

5. Sharing and service providers

ZIAM does not sell personal data. Information may be shared with contracted infrastructure, payment, communication, professional, or support providers only where necessary for a defined service and subject to appropriate safeguards.

Information may also be disclosed where required by Kenyan law, a valid legal process, protection of rights and safety, or the investigation of fraud, abuse, or a security incident.

6. Retention and security

Records are retained only for the service, security, legal, accounting, research, or dispute period that applies to them, after which they should be deleted, anonymised, or securely archived.

Safeguards may include access controls, encryption in transit, password hashing, audit records, secure development practices, backups, monitoring, and incident-response procedures. No internet service can guarantee absolute security.

7. Your data rights

Subject to applicable law, a person may request information about processing and exercise available data-subject rights.

  • Be informed about how personal data is used.
  • Access personal data held about you and request correction of inaccurate or misleading information.
  • Object to processing or request restriction where the legal conditions are met.
  • Request deletion of false, misleading, or unlawfully held data where applicable.
  • Withdraw consent for future processing when consent is the legal basis.
  • Raise a concern with ZIAM or lodge a complaint with Kenya's Office of the Data Protection Commissioner.

8. Children and young users

ZIAM services are not designed to collect a child's personal data without an appropriate legal basis and the involvement of a parent or guardian where required. Product-specific age requirements will be displayed before collection begins.

9. Questions and requests

Privacy questions, access requests, corrections, objections, or deletion requests can be submitted through the ZIAM Help Center. ZIAM may need to verify identity before acting on a request and will respond within the period required by applicable law.

The current public account forms are interface previews and do not transmit credentials until the ZIAM identity service is activated.

Need clarification?

Use the ZIAM Help Center for policy questions, data requests, or account concerns.

Open Help Center