Privacy Policy
Intellinks East Africa Limited (“Intellinks”) - how we collect, use, disclose, store and protect personal data when you visit intellinksea.com.
1. Introduction
Intellinks East Africa Limited (“Intellinks,” “we,” “us,” or “our”) provides enterprise IT, cybersecurity, backup and disaster recovery, infrastructure, virtualization, and software solutions across Kenya and East Africa. This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you visit intellinksea.com (the “Site”), submit an enquiry or quote request, apply for a role with us, or otherwise interact with us.
We process personal data in accordance with the Data Protection Act, 2019 (Kenya), its subsidiary regulations, and — where applicable to visitors or data subjects outside Kenya — internationally recognized data protection standards including the EU/UK GDPR.
By using the Site, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Site or submit personal data to us.
2. Who We Are (Data Controller)
Intellinks East Africa Limited is the data controller responsible for your personal data collected through the Site.
- Registered office/place of business: Vision Plaza, 5th Floor, Suite 18, Mombasa Road, Nairobi, Kenya
- Company registration number: CPR/2009/7331
- ODPC registration number: 323-888B-1461
- Data Protection Officer/privacy contact: Data Manager — privacy@intellinksea.com
- General contact: info@intellinksea.com · +254 (0) 242-7834 | +254701125923
If we act as a data processor on behalf of a client (for example, when configuring or managing security tooling on a client’s own systems), that client’s own privacy policy governs the personal data processed within their environment, and the terms of our separate service/data processing agreement with that client apply — not this Policy.
3. What Personal Data We Collect
3.1 Information you provide directly
- Contact and enquiry forms (Contact page, Security “Request a quote” form): full name, email address, phone number, company name, job title, and the content of your message or stated “service of interest.”
- Careers page/job applications: name, contact details, CV/resume content, and any other information you choose to submit, sent to careers@intellinksea.com.
- Newsletter or resource downloads (e.g., datasheets), if applicable: name and email address.
- Correspondence: any information you provide when you call, email, or message us.
3.2 Information collected automatically
- Technical and usage data: IP address, browser type and version, device type, operating system, referring URL, pages visited, time spent on pages, and general location inferred from IP address.
- Cookies and similar technologies: see our separate Cookie Policy, which forms part of, and should be read alongside, this Privacy Policy.
3.3 Information from third parties
- Where relevant, information from business partners, vendors, or publicly available sources (for example, to verify a company’s identity in a procurement or partnership context).
We do not knowingly collect special categories of personal data (e.g., health data, biometric data) through the Site. Please do not submit such information via our web forms.
4. Why We Process Your Personal Data (Purposes and Legal Basis)
Under section 30 of the DPA, we rely on the following legal bases:
| Purpose | Examples | Legal basis |
|---|---|---|
| Responding to enquiries and quote requests | Replying to Contact/Security form submissions | Consent (submission of the form) and/or steps prior to entering a contract |
| Delivering and managing services | Fulfilling engagements with clients | Performance of a contract |
| Marketing communications | Sending updates about services, where you have opted in | Consent |
| Recruitment | Reviewing job applications | Consent/steps prior to entering a contract |
| Site security and fraud prevention | Detecting abuse, spam, unauthorized access attempts | Legitimate interest |
| Analytics and site improvement | Understanding how the Site is used | Legitimate interest / consent (via cookie settings) |
| Legal and regulatory compliance | Responding to lawful requests from regulators or courts | Legal obligation |
Where we rely on consent, you may withdraw it at any time (see Section 8). Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
5. How We Share Personal Data
We do not sell personal data. We may share personal data with:
- Service providers and sub-processors who support our operations — for example, website hosting providers, email delivery platforms, spam/abuse-prevention services, and analytics providers — under contractual confidentiality and data protection obligations.
- Technology vendors and partners named on the Site (e.g., Fortinet, CrowdStrike, Mimecast, Red Hat, Dell, AWS, Microsoft), only where necessary to process a specific quote request you have directed to that product line, and only to the extent needed to respond to you.
- Professional advisers (lawyers, auditors) where necessary for our legitimate business purposes.
- Regulators, law enforcement, or courts, where required by Kenyan law or a valid legal process.
- A successor entity, in the event of a merger, acquisition, or sale of business assets, subject to equivalent protections for your data.
Any third party processing personal data on our behalf is required to do so under a written agreement consistent with section 41 of the DPA (or equivalent international standards for processors outside Kenya).
6. International Data Transfers
Some of our service providers (e.g., cloud hosting, email, or analytics platforms) may process data outside Kenya. Where we transfer personal data outside Kenya, we do so in accordance with section 48 of the DPA, which requires that the recipient country, territory, or organization ensures an adequate level of data protection, or that appropriate safeguards are in place (such as contractual clauses providing equivalent protection). Where relevant, we also have regard to internationally recognized transfer mechanisms such as GDPR Standard Contractual Clauses.
7. Data Retention
We retain personal data for seven (7) years from the date of collection or last contact, unless a shorter period is stated for a specific category below, or a longer period is required to satisfy a legal, regulatory, contractual, or accounting obligation (for example, records connected to a public-sector or regulated-industry engagement).
- Enquiry/quote request data: retained for 7 years from last contact.
- Job application data: retained for 7 years, unless you consent to longer retention for future opportunities.
- Technical/analytics data: retained per the retention settings of the relevant analytics tool, capped at 7 years.
At the end of the applicable retention period, personal data is securely deleted or anonymized.
8. Your Rights
Under Part IV of the DPA, and consistent with internationally recognized data subject rights, you have the right to:
- Be informed of the use to which your personal data is to be put (this Policy).
- Access the personal data we hold about you.
- Request correction or rectification of inaccurate or outdated personal data.
- Request deletion of personal data we no longer have a lawful basis to hold.
- Object to processing of your personal data, including for direct marketing purposes.
- Restrict processing in certain circumstances.
- Data portability, i.e., receive your data in a structured, commonly used format, where technically feasible.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with the Office of the Data Protection Commissioner, Kenya (ODPC) if you believe your rights have been infringed: www.odpc.go.ke.
To exercise any of these rights, contact us at privacy@intellinksea.com. We will respond within the timeframes required under the DPA (generally without undue delay).
9. Data Security
We implement technical and organizational measures appropriate to the risk, in line with section 41 of the DPA, including access controls, encryption in transit (HTTPS/TLS), network security controls, and staff awareness training — consistent with the security practices we deliver for our own clients. No system is completely secure; if you have reason to believe your interaction with the Site is no longer secure, please contact us immediately at security@intellinksea.com or via our Responsible Disclosure Policy.
10. Cookies
Our use of cookies and similar tracking technologies is described in full in our separate Cookie Policy, which is incorporated into this Privacy Policy by reference. You can accept or reject non-essential cookies at any time using the “Cookie Settings” link in the site footer.
11. Children\u2019s Privacy
The Site is intended for business use by adults (18+) representing organizations. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
12. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The “Last updated” date at the top of this page indicates when it was last revised. Material changes will be highlighted on the Site.
13. Contact Us
Intellinks East Africa Limited
Company Registration No. CPR/2009/7331 · ODPC Registration No. 323-888B-1461
Vision Plaza, 5th Floor, Suite 18, Mombasa Road, Nairobi, Kenya
P.O Box 24235 - 00100 Nairobi, Kenya
Email: privacy@intellinksea.com · General: info@intellinksea.com
Tel: +254 (0) 242-7834 | Mob: +254701125923
Supervisory authority: Office of the Data Protection Commissioner, Kenya (ODPC) — www.odpc.go.ke