Right to Access
Request a copy of the personal data we hold about you, including the purposes we process it for.
How Centipid Technologies collects, uses, protects, and shares information from venue operators, their customers, and visitors to our platform - in plain language, without the confusion.
This Privacy Policy explains how Centipid Technologies Limited ("Centipid", "we", "us", "our") handles personal data across two distinct contexts:
If your data is held in a customer account, you should contact that customer directly. Centipid processes that data on the customer's behalf. This policy explains how we do so and what protections are in place.
Centipid Technologies Limited is a technology company incorporated in Kenya. We build and operate a network monitoring and automation platform that allows customers to track infrastructure health, send alerts, automate backups, and manage operational workflows.
| DETAIL | INFORMATION |
|---|---|
| Company | Centipid Technologies Limited |
| Registration | Registered in Kenya under the Companies Act (Cap. 486) |
| Principal Office | I&M Bank Building, Upperhill, Nairobi, Kenya |
| Data Protection Officer | [email protected] |
| Privacy Enquiries | [email protected] |
| Applicable Laws | Kenya DPA 2019, NDPR 2023, Ghana DPA 2012, GDPR, CASL, CAN-SPAM |
Under applicable data protection laws, there is an important distinction between a data controller (who decides why and how data is processed) and a data processor (who processes data on behalf of a controller). Centipid acts in both capacities, depending on the context.
When Centipid is the Data Controller
For data relating to our platform users - including account registration data, billing information, support correspondence, and usage analytics of the Centipid platform itself - Centipid is the data controller. We decide the purposes and means of processing this data.
When Centipid is a Data Processor
For data collected through monitoring, alerting, and automation features operated by our customer accounts, Centipid acts as a data processor. The customer is the data controller. They determine what data to collect, what alerting rules to use, and what operational workflows to run. Centipid processes this data strictly on their documented instructions.
When a person uses a Centipid-powered service, the platform may collect the following, depending on the customer's configuration:
4a. Customer Data (Collected on Behalf of Customers)
| DATA TYPE | HOW COLLECTED | REQUIRED? |
|---|---|---|
| Device identifier | Device name, IP address, MAC address, or other technical identifiers | Technical - automatic |
| Telemetry data | Uptime, latency, error events, and other monitoring metrics | Technical - automatic |
| Configuration data | Alert rules, backup settings, dashboards, and automation workflows | Configured by customer |
| Account contacts | Names, email addresses, phone numbers, and roles for users and recipients | Configurable |
| Audit logs | Login time, actions taken, configuration changes, and API activity | Technical - automatic |
| Support details | Information you provide when contacting support | Optional |
4b. Platform Account Data (Centipid as Controller)
4c. Platform Usage Data & Analytics
When you use the Centipid dashboard, we automatically collect:
For Platform Users (Centipid as Controller)
For Customer-Managed Data (Centipid as Processor)
Centipid processes customer-managed data solely on the documented instructions of the customer (data controller). This includes:
We do not use customer-managed data for Centipid's own promotional purposes, we do not build profiles across multiple customers, and we do not share it with third parties except as necessary to deliver the service (sub-processors listed below).
Under the GDPR and comparable African data protection laws, processing must have a lawful basis. The following table sets out the bases we're reliant on:
| PROCESSING ACTIVITY | LEGAL BASIS |
|---|---|
| Providing our platform service to registered customers | Performance of contract |
| Processing payments and maintaining billing records | Performance of contract / Legal obligation |
| Sending essential service communications (security alerts, downtime notices) | Performance of contract / Legitimate interest |
| Sending product updates and account communications about Centipid Access | Legitimate interest (with opt-out) |
| Sending sales or outreach emails to prospective customers | Consent (where required) / Legitimate interest |
| Platform usage analytics and product improvement | Legitimate interest |
| Device and session management (IP address, session logs) | Legitimate interest of the customer |
| Monitoring data, alerts, and customer-configured automation | Performance of contract |
| Fraud detection and security monitoring | Legitimate interest / Legal obligation |
| Complying with legal requests from authorities | Legal obligation |
We do not sell personal data. We share data only in the following circumstances:
Sub-Processors
We use trusted third-party service providers ("sub-processors") to operate our platform. All sub-processors are bound by data processing agreements and may only process data for the purposes specified:
| SUB-PROCESSOR | PURPOSE | LOCATION |
|---|---|---|
| DigitalOcean | Cloud infrastructure, servers, and database hosting | USA (EU/Africa region available) |
| Stripe / Paystack / Flutterwave | Payment processing | USA / Nigeria / USA |
| Africa's Talking | SMS alert delivery | Kenya |
| WhatsApp Business API | WhatsApp alert delivery | USA (Meta) |
| Mailgun / SendGrid | Email alert delivery | USA |
| Sentry | Error monitoring and crash reporting | USA |
| Cloudflare | DDoS protection, CDN, WAF | USA / Global |
| Google Analytics | Website analytics (centipidaccess.com only) | USA |
Business Transfers
If Centipid is acquired, merges with another company, or transfers its assets, personal data may be transferred to the acquiring entity. We will notify affected users by email and provide an opportunity to delete accounts before any such transfer is completed.
Legal Obligations
We may disclose personal data when required to do so by law, court order, or regulatory authority, or when we believe disclosure is necessary to protect the rights, property, or safety of Centipid, our customers, or the public. We will notify affected individuals unless legally prohibited from doing so.
Under Section 48 of Kenya's Data Protection Act, 2019, Centipid may only transfer personal data outside Kenya where one of the following applies:
Where sensitive personal data is transferred outside Kenya, we rely on the data subject's explicit consent in addition to the above.
Centipid's infrastructure relies on a small number of sub-processors located outside Kenya (see "Sharing & Disclosure" above). Where personal data is transferred to these sub-processors, we:
We are monitoring the ODPC's ongoing guidance on cross-border data transfers, including any requirements for local data residency, and will update our infrastructure and this policy as needed. Customers who require data residency within Kenya should contact us; we can accommodate this for Enterprise plan customers on request.
| DATA CATEGORY | RETENTION PERIOD | BASIS |
|---|---|---|
| Platform account data | Duration of account + 90 days after deletion request | Service delivery |
| Monitoring data (Free / Starter) | 7 days from capture | Plan limit |
| Monitoring data (Growth) | 30 days from capture | Plan limit |
| Monitoring data (Pro) | 90 days from capture | Plan limit |
| Monitoring data (Scale / Enterprise) | 180 days from capture or custom | Plan limit |
| Billing and invoice records | 7 years from invoice date | Kenya tax / accounting law |
| Alert and notification logs | 12 months from send date | Deliverability and compliance |
| Support conversation records | 3 years from last interaction | Legitimate interest |
| Session / audit logs | 90 days rolling | Security and fraud prevention |
| Backup copies | Purged within 30 days of primary deletion | Technical |
When an account is closed, we export a final data snapshot for the account holder upon request, then permanently delete all personal data from production systems within 30 days and from backup systems within 90 days.
We implement technical and organisational measures appropriate to the risk of processing personal data. These include:
Depending on your location, you have the following rights in relation to your personal data. To exercise any of these rights, contact us at [email protected]. We respond within 30 days (or such shorter period as required by law).
Request a copy of the personal data we hold about you, including the purposes we process it for.
Ask us to correct inaccurate or incomplete data we hold about you.
Request deletion of your personal data where we no longer have a lawful basis to process it.
Ask us to restrict processing while a dispute is resolved, rather than deleting your data.
Receive your data in a structured, machine-readable format (CSV or JSON) to transfer to another provider.
Object to processing based on legitimate interests, including profiling and product communications.
Right not to be subject to decisions made solely by automated processing that significantly affect you.
Where processing is based on consent, withdraw it at any time. Withdrawal doesn't affect prior lawful processing.
Customer Contacts
If your details are held in a customer account and you want to exercise your rights, you should contact that customer (the data controller) directly. You may also email us at [email protected] and we will direct your request to the appropriate customer within 5 business days.
You can opt out of non-essential product communications at any time using the unsubscribe link in any email. Operational alerts and service notices may still be sent where needed to deliver the service.
Supervisory Authority
If you believe your rights have not been respected, you have the right to lodge a complaint with the relevant supervisory authority in your country - including the Office of the Data Protection Commissioner (Kenya), the Nigeria Data Protection Commission (NDPC), or the Data Protection Commission (Ghana).
Centipid's platform is not directed at children under the age of 13 (or 16 where required by applicable law). We do not knowingly collect personal data from children. If you are a customer and believe children may use your services, you are responsible as data controller for implementing age-appropriate safeguards where required.
If we become aware that we have collected personal data from a child without appropriate parental consent, we will delete that data promptly. Contact [email protected] if you have concerns.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
For significant changes that affect the legal basis or purposes of processing, we will seek fresh consent where required. Your continued use of the platform after the effective date constitutes acceptance of the updated policy.
For any questions, concerns, or requests relating to this Privacy Policy or to your personal data, please contact us:
We take data protection seriously. Our Data Protection Officer responds to all enquiries within 5 business days. For urgent matters - including suspected breaches - please mark your subject line URGENT.
General privacy enquiries
Email privacyData Protection Officer
Email DPOSecurity vulnerabilities
Report securityI&M Bank Building, Upperhill, Nairobi
Open contact page