DODI TELECOM

Privacy Policy

Last updated: to be set at publication

This document is a baseline and is under review by our legal team.

What this page is

The Privacy Policy says what we do with personal data. This page says how we look after it, and what we ask of the partners who process it with us. It describes our practice; it does not claim any approval, and it is not a contract.

Who can see what

Access to enquiry data is limited to the people who need it to answer. Each person has their own account, with a role that decides what that account can reach, and every administrative action is written to an activity log.

How accounts are protected

A password alone never opens a session: a six-digit code is sent by email and must be entered. Codes are stored as fingerprints, never in readable form, and expire. Passwords are stored hashed.

Data in transit and at rest

[To complete: TLS certificate provider and the date the production certificate is issued.] Outgoing email credentials are stored encrypted and are never displayed back in the administration.

Sub-processors

[To complete: the list of providers who process data on our behalf — hosting, email delivery — with the country each operates from.]

Keeping and deleting

An enquiry is kept while the conversation it started is live. When you ask us to delete it, we delete it, and we say when it is done. The retention period we will publish depends on the law that applies: [To complete: applicable jurisdiction].

If something goes wrong

If we find that personal data has been exposed, we will say so to the people concerned and to whichever authority the applicable law designates — [To complete: applicable jurisdiction] — within the time that law requires. [To complete with counsel: the notification deadline once the jurisdiction is settled.]

Asking us something

Write to muthoni.n@doditelecom.co.ke. A question about data is answered by a person, not by a form.