Privacy Policy

Smart. Safe. Seamless.

At Safiri by Citrus, we're committed to transparency in our data practices, safeguarding the privacy of our Platform Administrator users, and ensuring compliance with Kenyan data protection laws.

1

Introduction & Overview

This Privacy Policy explains how Safiri by Citrus ("the Platform") collects, processes, stores, and protects personal data from Platform Administrator account users. The purpose of this Policy is to ensure transparency in our data practices, safeguard the privacy of our users, and comply with Kenyan data protection laws, including the Data Protection Act (2025), along with any other applicable regulations. This Policy applies solely to Platform Administrator account users, who use the Platform to manage and oversee the entire school transport system, including school registrations, user account management, system performance monitoring, revenue and payment configuration, and security enforcement.

Compliance with Kenyan Data Protection laws
Applies to Platform Administrators overseeing school transport system
2

Definitions

For the purposes of this Privacy Policy, the following terms are defined as:

Personal Data

Any information relating to an identified or identifiable natural person, including names, contact details, and other identifying information.

Processing

Any operation performed on personal data, whether automated or manual, such as collection, storage, retrieval, use, alteration, or deletion.

Data Subject

Any individual whose personal data is processed by the Platform.

Data Controller

Citrus Labs Limited, which determines the purposes and means of processing personal data.

Data Processor

Any third party engaged by Citrus Labs Limited to process personal data on its behalf.

Sensitive Data

Personal data that requires special protection under Kenyan law, including any information classified as sensitive by applicable regulations.

Cookies

Small data files placed on a user's device to enhance user experience and track usage patterns.

3

Data Collection

Safiri by Citrus collects the following types of data from Platform Administrator account users:

Personal Information

Data provided during registration including full name, email address, phone number, job title, and organizational details.

Usage Data

Information about how users interact with the Platform, such as login timestamps, session durations, and activity logs.

Device Information

Details about the devices used to access the Platform, including IP address, device type, operating system, and browser.

Cookies and Tracking Data

Data collected via cookies and similar technologies to optimize the user experience and analyze usage trends.

Sensitive Data

Any sensitive personal information, if provided, will be subject to enhanced security measures in compliance with Kenyan law.

Data may be collected directly from users during registration and via automated collection tools integrated within the Platform.

5

Purpose & Use of Data

Data collected from Platform Administrator account users is used for:

Service Delivery

Facilitating the management of school registrations, user account administration, system performance monitoring, revenue and payment configuration, and security protocol enforcement.

Customer Support

Providing technical support and addressing user inquiries effectively.

System Improvement

Analyzing usage data to improve Platform functionality, enhance user experience, and develop new features.

Security

Ensuring the integrity and security of the Platform through monitoring, fraud prevention, and incident response.

Marketing & Communication

Informing users about Platform updates, new features, and relevant promotional information, provided users have consented to such communications.

Compliance

Meeting legal and regulatory obligations under Kenyan law.

6

Data Storage & Security Measures

Data Storage

Personal data is securely stored on cloud-based servers managed by reputable third-party service providers that comply with industry-standard security practices. Data retention periods are determined based on legal requirements and operational needs.

Security Measures

The Platform implements robust security protocols including:

  • Encryption: Data is encrypted during transmission and while at rest
  • Access Controls: Strict access controls and multi-factor authentication safeguard user data
  • Regular Audits: Routine security audits and vulnerability assessments are conducted to ensure system integrity
  • Backup & Recovery: Comprehensive backup and disaster recovery procedures are in place to prevent data loss
7

Data Sharing & Third-Party Disclosures

8

User Rights

Platform Administrator account users have the following rights regarding their personal data:

Right to Access

Request access to the personal data held by Citrus Labs Limited.

Right to Rectification

Request correction of any inaccurate or incomplete personal data.

Right to Erasure

Request deletion of personal data, subject to legal and contractual constraints.

Right to Restrict Processing

Request limitations on the processing of personal data under certain circumstances.

Right to Data Portability

Obtain personal data in a structured, commonly used, and machine-readable format.

Right to Object

Object to the processing of personal data for reasons related to legitimate interests or direct marketing.

Users may exercise these rights by contacting us using the details provided in Section 13.

9

Data Retention and Deletion

Retention Period

Personal data is retained for as long as necessary to fulfill the purposes for which it was collected or as required by law. Retention periods vary depending on the type of data and applicable legal obligations.

Deletion Process

Once personal data is no longer required, it will be securely deleted or anonymized in accordance with Citrus Labs Limited's data retention policies.

10

Data Breach Notification

1

Detection and Response

The Platform employs monitoring systems to detect any data breaches promptly. In the event of a breach, Citrus Labs Limited will investigate the incident and take immediate remedial action.

2

Notification

Affected users will be notified of a data breach affecting their personal data within a reasonable timeframe, and relevant regulatory authorities will be informed in accordance with Kenyan law.

3

Response Plan

A comprehensive response plan is in place to address breaches, mitigate risks, and prevent future incidents.

11

Cookies & Tracking Technologies

12

Policy Updates

Amendments

Citrus Labs Limited reserves the right to update this Privacy Policy as necessary. Users will be notified of material changes via email or through prominent notices on the Platform.

Acceptance

Continued use of the Platform after the effective date of any updated Privacy Policy constitutes acceptance of the changes.

13

Contact Information and Complaints

For any questions, clarifications, or complaints regarding this Privacy Policy, please contact:

Email

legal@citruslabs.co.ke

Mailing Address

P.O. Box 23983 - 00100

Phone

+254 112 400 000

If you believe that your personal data has been mishandled or wish to escalate a complaint, you may also contact the relevant data protection authority in Kenya.

14

Governing Law & Jurisdiction

Governed by laws of Kenya

This Privacy Policy is governed by and construed in accordance with the laws of Kenya.

Exclusive jurisdiction of courts in Nairobi

Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts in Nairobi, Kenya.

Administrator Platform Functions

As a Platform Administrator, you have access to powerful system-wide functions:

School Registration Management

Add, edit, and manage school profiles and their associated transport services.

User Account Administration

Create and manage accounts for schools, drivers, and parents across the platform.

System Performance Monitoring

Track and optimize platform performance with comprehensive analytics tools.

Revenue & Payment Configuration

Set up and manage payment systems, transaction fees, and financial reporting.

Security Protocol Enforcement

Implement and maintain platform-wide security standards and compliance measures.

Administrator Privacy Responsibilities

With great access comes great responsibility:

Ensuring Proper Data Handling

Maintain data integrity and follow best practices for all personal data accessible to you.

Respecting User Privacy Rights

Honor privacy requests from users and ensure timely responses to privacy-related inquiries.

Managing Data Access Privileges

Assign appropriate access permissions and regularly review user privileges across the platform.

Reporting Privacy Incidents

Immediately report any data breaches or security concerns following established protocols.

Maintaining Privacy Compliance

Stay informed about privacy regulations and ensure the platform remains compliant with current laws.

By using the Safiri by Citrus Platform as a Platform Administrator account user, you acknowledge that you have read, understood, and agree to the collection, processing, storage, and use of your personal data as described in this Privacy Policy.

Ready to Experience Safiri by Citrus?

Join our platform and be part of a smart, safe, and seamless school transport management system. Get started today!