Managed & Operated by: Siscom Technology
Effective Date: [Insert Date]
This Data Handling Policy outlines the internal procedures, technical safeguards, and governance frameworks used to manage personal data collected via the Ravora Systems platform. This policy ensures compliance with the Data Protection Act (2019) and the Data Protection (General) Regulations (2021) of Kenya.
For the purposes of this policy and all operations conducted under the Ravora Systems brand:
Siscom Technology adheres to the principle of Data Minimization. We only collect data that is strictly necessary for the fulfillment of e-commerce transactions, including:
Unless specifically required by law for high-value transactions (Anti-Money Laundering protocols), Siscom Technology does not collect or store sensitive personal data such as religious beliefs, political affiliations, or biometric data.
As the technical lead, Siscom Technology implements "Security by Design" through the following:
In compliance with the Data Protection (General) Regulations, Siscom Technology ensures that all data related to the strategic interests of Kenya or critical infrastructure is processed and stored on servers located within the Republic of Kenya unless otherwise authorized by the Data Commissioner.
Automated backups are performed daily to ensure data availability and resilience. These backups are stored in secure, off-site locations within Siscom Technology's private cloud infrastructure.
Data may be shared with third-party couriers. Siscom Technology ensures that these partners are bound by Data Processing Agreements (DPAs) that prevent them from using customer data for any purpose other than delivery.
Siscom Technology will only disclose personal data to Kenyan government authorities upon receipt of a valid court order or a formal request that meets the threshold of the Criminal Procedure Code and the Data Protection Act.
In the event of a security breach, Siscom Technology—as the Data Controller—assumes responsibility for:
Siscom Technology shall conduct periodic Data Protection Impact Assessments (DPIAs) for any new technology or process introduced to the Ravora Systems platform that may pose a high risk to the rights and freedoms of data subjects.
For all data-related inquiries, Ravora Systems can be reached at:
The Data Protection Officer
Ravora Systems
Email: info@ravorasystems.com
Tel: 0116 045 045
Address: Nairobi, Kenya