Privacy Policy for Uwazo

Last updated: November 2, 2025

This Privacy Policy describes how Uwazo ("we", "us", "our") collects, uses, and discloses Personal Data when you use the Uwazo Service (the "Service"), and explains your privacy rights.

We use your Personal Data to operate and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

1. Interpretation and Definitions

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

2. Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using Our Service, We collect the following types of Personal Data:

Information from Social Authentication:
Information You Provide Directly:
Information for Payments:

You are responsible for the accuracy of the information You provide to Us and for ensuring You have the right to upload any User Documents.

Usage Data

Usage Data is collected automatically when using the Service. This may include information such as your device's Internet Protocol address (e.g., IP address), browser type, browser version, the pages of our Service you visit, the time spent on those pages, unique device identifiers, and other diagnostic data. We also receive anti-bot signals from Vercel Bot Protection.

Use of Your Personal Data

The Company may use Personal Data for the following purposes:

We process Personal Data under the legal bases available under the Kenya Data Protection Act, including contract necessity (providing the Service), legitimate interests (security, fraud prevention, service improvement), consent (where required, e.g., marketing communications), and compliance with legal obligations.

Sharing of Your Personal Data

We may share Your personal information in the following situations:

Retention of Your Personal Data

The Company will retain your Personal Data, including Account information, Customer Content, and workspace metadata, only for as long as your account remains active or as necessary for the purposes set out in this Privacy Policy.

Upon deletion of your Account, we will take commercially reasonable steps to delete Personal Data associated with your Account from our active systems. Some data may persist in backups for a limited period or as required by law, to resolve disputes, or enforce agreements.

Usage Data is generally retained for a shorter period for internal analysis, unless needed to strengthen security, improve Service functionality, or if legally required to be retained longer. For BYOB deployments, the Organization controls retention within its Supabase instance.

Security of Your Personal Data

The security of your Personal Data is important to us. We encrypt data in transit, rely on Supabase and our hosting providers for encryption at rest, apply access controls, and follow secure development practices. Access to Customer Content is limited to personnel who require it to operate or support the Service.

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security. We will notify you without undue delay of any personal data breach that is likely to result in a high risk to your rights and freedoms.

3. Children's Privacy

Our Service is not intended for use by individuals under the age of 18 (the age of majority as defined under Kenyan law for data protection purposes). We do not knowingly collect personally identifiable information from anyone under the age of 18. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 18 without verification of parental consent, We take steps to remove that information from Our servers.

4. Links to Other Websites

Our Service may contain links to other websites that are not operated by us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third party sites or services.

5. Data Subject Rights and International Transfers

Depending on your location and applicable law (including the Kenya Data Protection Act), you may have the right to access, correct, delete, object to, or restrict processing of your Personal Data, and to request data portability. You may also withdraw consent where processing is based on consent. To exercise these rights, contact us at support@uwazo.com. We will respond within the timelines required by law.

You may lodge a complaint with the Office of the Data Protection Commissioner (ODPC) in Kenya or your local data protection authority if you believe we have not complied with applicable data protection laws.

We may transfer Personal Data outside Kenya to our service providers. Where we do so, we ensure appropriate safeguards such as contractual clauses and access controls. For BYOB deployments, the Organization controls the geographic location of its Supabase instance and related data residency.

For Organization accounts, the Organization is the data controller of Customer Content. We act as a data processor and process Customer Content only on the Organization’s instructions and in accordance with a Data Processing Addendum (available on request). For individual accounts, we are the data controller.

6. Changes to this Privacy Policy

We may update this Privacy Policy from time to time as we introduce new features or as legal requirements change. We will notify you of any material changes by posting the new Privacy Policy on this page and, where feasible, by email or a prominent notice on our Service prior to the change becoming effective. We will also update the "Last updated" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

7. Contact Us

If you have any questions about this Privacy Policy or our data practices, you can contact us: