English
Language
  • English
  • English
  • Soomaaliga

Legal

Privacy and Data Protection Notice

URL: /legal/privacy-data-protection-notice
Last updated: 5 August 2026

1. Scope and controller

This notice explains how BCE Systems Limited collects and uses personal data through www.bce.systems, its forms and portals, enquiries, sales activity, customer support, warranty processes, events, and related business interactions. It is issued under the Data Protection Act, Cap. 411C, and the Data Protection (General) Regulations, 2021.

BCE Systems Limited is the data controller for the processing described here when it determines why and how the data is used. We are incorporated in Kenya under company number PVT-7LU3DY6 and our registered office is The Address, 7th Floor, Muthangari Drive, Nairobi, Kenya.

Some regional transactions or services may be provided by BCE Systems (Somalia), a separate operating entity. The quotation, order, invoice, service notice, or collection point should identify the responsible entity. Where BCE Systems (Somalia) independently determines the purpose and means of processing, it acts as a separate controller. Where it processes data only on BCE Systems Limited’s documented instructions, it acts as a processor. We document the applicable role and safeguards for each data flow.

This notice does not cover recruitment, which is governed by the Recruitment Privacy Notice, or a third party’s independent website or service.

2. Contact for data protection

Send questions, consent withdrawals, objections, and rights requests to:

BCE Systems Limited
Attention: Data Protection
P.O. Box 11474-00100, Nairobi, Kenya
Email: bce@bce.systems
Telephone: +254 20 440 9223

3. Personal data we collect

Payment providers normally collect card, mobile-money, or banking credentials directly under their own privacy information. BCE ordinarily receives a payment confirmation, status, and transaction reference rather than complete payment credentials.

We may receive data directly from you, from your employer or organisation, from a person authorised to act for you, from manufacturers and distributors, from service and payment providers, from public professional or company sources, and automatically from your device after any required consent.

Please do not place sensitive operational-security information or unnecessary sensitive personal data in a general website form. Contact us to agree a suitable channel where a requirement involves protected locations, security operations, health information, biometrics, criminal-offence information, or another sensitive category.

4. Why we process data and our lawful bases

We identify and record a lawful basis for each processing purpose. The principal bases are:

If BCE relies on consent, giving it is voluntary. Refusal or withdrawal does not affect prior lawful processing, but it may prevent an optional feature or communication. BCE does not make access to a product or service conditional on consent to unrelated processing.

Where sensitive personal data is genuinely necessary, BCE applies the additional condition required by law, limits access, and provides a specific notice where appropriate. We do not infer consent from silence or a pre-selected option.

5. Direct marketing

BCE sends electronic direct marketing only where it holds valid express consent or another written-law basis that clearly applies. At collection, we identify BCE, the communication type, and the opportunity to refuse. Every marketing message provides a simple way to opt out.

You may withdraw consent or object to direct marketing at any time using the message link or the contact details in section 2. Direct-marketing objections are absolute. We stop the marketing and may keep a minimal suppression record so that we do not add the address back to a campaign unintentionally.

6. Cookies and similar technologies

Strictly necessary technologies support page delivery, security, consent storage, and a service expressly requested by the user. Optional analytics, marketing, live-chat tracking, and third-party embeds are used only after the relevant consent. The Cookie Policy and Preferences identifies the categories, providers, purposes, and durations and allows you to change your choice.

7. Recipients and processors

BCE limits disclosure to what the recipient needs. Recipients may include:

Zoho group companies and approved subprocessors supporting CRM, marketing automation, campaigns, live chat, analytics, page optimisation, helpdesk, recruitment, billing, and commerce;

payment service providers, banks, insurers, auditors, advocates, accountants, and other professional advisers;

manufacturers, distributors, software licensors, and programme operators where necessary to quote, register an opportunity, configure, license, fulfil, maintain, or support the requested product;

logistics, customs, warehousing, installation, hosting, security, and communication providers;

the organisation you represent and its authorised project, procurement, finance, compliance, or security personnel;

BCE Systems (Somalia), where a Somalia enquiry, project, subscriber matter, service, or support requirement needs to be routed or administered; and

courts, regulators, tax authorities, law-enforcement bodies, and other persons where disclosure is required or permitted by law.

Service providers acting for BCE are required by contract to process data only on documented instructions, apply appropriate security, assist with data-subject rights and incidents, and delete or return data at the end of the service, subject to lawful retention.

BCE does not sell personal data and does not allow a recipient to use it for the recipient’s independent direct marketing unless you have separately agreed to that use.

8. Transfers outside Kenya

Some recipients, hosting locations, support teams, and regional operations are outside Kenya. This may include BCE Systems (Somalia) and locations used by BCE’s configured technology and support providers.

Before a transfer, BCE records the recipient, country, date, categories of data, purpose, lawful transfer basis, and safeguards. Depending on the circumstances, BCE relies on an adequacy decision, appropriate contractual and organisational safeguards, a transfer necessary for a contract or legal claim, another statutory necessity ground, or the data subject’s specific consent after being informed of the possible risks. Sensitive personal data is transferred only where the additional requirements in section 49 of the Data Protection Act are met.

You may request information about the countries, recipients, and safeguards relevant to your data using the contact details in section 2. BCE may redact confidential security and commercial terms while still explaining the substance of the protection.

9. Retention

BCE keeps personal data only while the recorded purpose and a lawful basis continue, then securely deletes or anonymises it unless a legal hold applies.

We review retained data and may use a shorter period where the purpose can be met sooner. Backups are protected from ordinary use and expire through the managed backup cycle.

10. Your rights

Subject to the Act and lawful exceptions, you may:

be informed about the use of your data;

request access to your personal data;

request correction of inaccurate or incomplete data;

request restriction of processing;

object to processing, including an absolute objection to direct marketing;

request erasure where the legal conditions are met;

request data portability in a structured, commonly used, machine-readable form where applicable;

withdraw consent without affecting processing that was lawful before withdrawal; and

object to a decision based solely on automated processing that produces legal or similarly significant effects, and request human reconsideration where the law provides.

Send a request using section 2. We may ask for information reasonably necessary to verify identity and authority. We will respond within the statutory period. Under the General Regulations, this includes responding to an access request within 7 days, handling restriction and objection requests within 14 days, handling rectification and erasure processes within 14 days, and responding to a portability request within 30 days, subject to the precise legal rule and any permitted extension or exception.

Rights are generally provided without charge. A reasonable cost may apply to portability where the law permits, and BCE may refuse or limit a request only on a lawful, documented ground. We will explain a refusal and the available complaint route.

11. Automated decisions and profiling

BCE does not use the website to make a decision about a person based solely on automated processing where the decision has legal or similarly significant effects. Analytics, lead scoring, security alerts, or platform ranking may assist staff, but a person reviews any consequential action. If this changes, BCE will provide the additional notice and safeguards required by law.

12. Children

The website and BCE’s commercial services are intended for organisations and adults. BCE does not knowingly collect a child’s personal data through general website forms. If child data is needed for a specific lawful service, BCE will provide a tailored notice, use appropriate age-verification and parental or guardian consent controls, and treat the child’s best interests as paramount.

13. Security and personal-data breaches

BCE uses technical and organisational measures proportionate to the data and risk, including access controls, least-privilege permissions, confidentiality commitments, encryption in transit where supported, supplier controls, logging, backup, vulnerability management, and incident response. No internet transmission or storage system can be guaranteed completely secure.

If a personal-data breach creates a real risk of harm, BCE will notify the Office of the Data Protection Commissioner without delay and, where reasonably practicable, within 72 hours after becoming aware. Where the breach is likely to create a high risk, BCE will also notify affected people without undue delay unless the law permits an exception. Please report a suspected incident promptly to bce@bce.systems.

14. Complaints

Please contact BCE first so that we can investigate and respond. You may also complain to the Office of the Data Protection Commissioner using the current channels published at www.odpc.go.ke. You may seek another remedy available under Kenyan law.

15. Changes to this notice

We may update this notice to reflect changes in law, systems, vendors, or processing. We will publish the revised date and give appropriate notice of a material change. A current copy and relevant previous versions are retained for accountability.

Legal

Privacy & Data Protection Notice

​​1. Scope and controller

This notice explains how BCE Systems Limited collects and uses personal data through www.bce.systems, its forms and portals, enquiries, sales activity, customer support, warranty processes, events, and related business interactions. It is issued under the Data Protection Act, Cap. 411C, and the Data Protection (General) Regulations, 2021.

BCE Systems Limited is the data controller for the processing described here when it determines why and how the data is used. We are incorporated in Kenya under company number PVT-7LU3DY6 and our registered office is The Address, 7th Floor, Muthangari Drive, Nairobi, Kenya.

Some regional transactions or services may be provided by BCE Systems (Somalia), a separate operating entity. The quotation, order, invoice, service notice, or collection point should identify the responsible entity. Where BCE Systems (Somalia) independently determines the purpose and means of processing, it acts as a separate controller. Where it processes data only on BCE Systems Limited’s documented instructions, it acts as a processor. We document the applicable role and safeguards for each data flow.

This notice does not cover recruitment, which is governed by the Recruitment Privacy Notice, or a third party’s independent website or service.

​​2. Contact for data protection

Send questions, consent withdrawals, objections, and rights requests to:

BCE Systems Limited Attention: Data Protection P.O. Box 11474-00100, Nairobi, Kenya Email: bce@ke.bce.systems Telephone: +254 20 440 9223

​​3. Personal data we collect

Payment providers normally collect card, mobile-money, or banking credentials directly under their own privacy information. BCE ordinarily receives a payment confirmation, status, and transaction reference rather than complete payment credentials.

We may receive data directly from you, from your employer or organisation, from a person authorised to act for you, from manufacturers and distributors, from service and payment providers, from public professional or company sources, and automatically from your device after any required consent.

Please do not place sensitive operational-security information or unnecessary sensitive personal data in a general website form. Contact us to agree a suitable channel where a requirement involves protected locations, security operations, health information, biometrics, criminal-offence information, or another sensitive category.

​​4. Why we process data and our lawful bases

We identify and record a lawful basis for each processing purpose. The principal bases are:

If BCE relies on consent, giving it is voluntary. Refusal or withdrawal does not affect prior lawful processing, but it may prevent an optional feature or communication. BCE does not make access to a product or service conditional on consent to unrelated processing.

Where sensitive personal data is genuinely necessary, BCE applies the additional condition required by law, limits access, and provides a specific notice where appropriate. We do not infer consent from silence or a pre-selected option.

​​5. Direct marketing

BCE sends electronic direct marketing only where it holds valid express consent or another written-law basis that clearly applies. At collection, we identify BCE, the communication type, and the opportunity to refuse. Every marketing message provides a simple way to opt out.

You may withdraw consent or object to direct marketing at any time using the message link or the contact details in section 2. Direct-marketing objections are absolute. We stop the marketing and may keep a minimal suppression record so that we do not add the address back to a campaign unintentionally.

​​6. Cookies and similar technologies

Strictly necessary technologies support page delivery, security, consent storage, and a service expressly requested by the user. Optional analytics, marketing, live-chat tracking, and third-party embeds are used only after the relevant consent. The Cookie Policy and Preferences identifies the categories, providers, purposes, and durations and allows you to change your choice.

​​7. Recipients and processors

BCE limits disclosure to what the recipient needs. Recipients may include:

Zoho group companies and approved subprocessors supporting CRM, marketing automation, campaigns, live chat, analytics, page optimisation, helpdesk, recruitment, billing, and commerce;

payment service providers, banks, insurers, auditors, advocates, accountants, and other professional advisers;

manufacturers, distributors, software licensors, and programme operators where necessary to quote, register an opportunity, configure, license, fulfil, maintain, or support the requested product;

logistics, customs, warehousing, installation, hosting, security, and communication providers;

the organisation you represent and its authorised project, procurement, finance, compliance, or security personnel;

BCE Systems (Somalia), where a Somalia enquiry, project, subscriber matter, service, or support requirement needs to be routed or administered; and

courts, regulators, tax authorities, law-enforcement bodies, and other persons where disclosure is required or permitted by law.

Service providers acting for BCE are required by contract to process data only on documented instructions, apply appropriate security, assist with data-subject rights and incidents, and delete or return data at the end of the service, subject to lawful retention.

BCE does not sell personal data and does not allow a recipient to use it for the recipient’s independent direct marketing unless you have separately agreed to that use.

​​8. Transfers outside Kenya

Some recipients, hosting locations, support teams, and regional operations are outside Kenya. This may include BCE Systems (Somalia) and locations used by BCE’s configured technology and support providers.

Before a transfer, BCE records the recipient, country, date, categories of data, purpose, lawful transfer basis, and safeguards. Depending on the circumstances, BCE relies on an adequacy decision, appropriate contractual and organisational safeguards, a transfer necessary for a contract or legal claim, another statutory necessity ground, or the data subject’s specific consent after being informed of the possible risks. Sensitive personal data is transferred only where the additional requirements in section 49 of the Data Protection Act are met.

You may request information about the countries, recipients, and safeguards relevant to your data using the contact details in section 2. BCE may redact confidential security and commercial terms while still explaining the substance of the protection.

​​9. Retention

BCE keeps personal data only while the recorded purpose and a lawful basis continue, then securely deletes or anonymises it unless a legal hold applies.

We review retained data and may use a shorter period where the purpose can be met sooner. Backups are protected from ordinary use and expire through the managed backup cycle.

​​10. Your rights

Subject to the Act and lawful exceptions, you may:

be informed about the use of your data;

request access to your personal data;

request correction of inaccurate or incomplete data;

request restriction of processing;

object to processing, including an absolute objection to direct marketing;

request erasure where the legal conditions are met;

request data portability in a structured, commonly used, machine-readable form where applicable;

withdraw consent without affecting processing that was lawful before withdrawal; and

object to a decision based solely on automated processing that produces legal or similarly significant effects, and request human reconsideration where the law provides.

Send a request using section 2. We may ask for information reasonably necessary to verify identity and authority. We will respond within the statutory period. Under the General Regulations, this includes responding to an access request within 7 days, handling restriction and objection requests within 14 days, handling rectification and erasure processes within 14 days, and responding to a portability request within 30 days, subject to the precise legal rule and any permitted extension or exception.

Rights are generally provided without charge. A reasonable cost may apply to portability where the law permits, and BCE may refuse or limit a request only on a lawful, documented ground. We will explain a refusal and the available complaint route.

​​11. Automated decisions and profiling

BCE does not use the website to make a decision about a person based solely on automated processing where the decision has legal or similarly significant effects. Analytics, lead scoring, security alerts, or platform ranking may assist staff, but a person reviews any consequential action. If this changes, BCE will provide the additional notice and safeguards required by law.

​​12. Children

The website and BCE’s commercial services are intended for organisations and adults. BCE does not knowingly collect a child’s personal data through general website forms. If child data is needed for a specific lawful service, BCE will provide a tailored notice, use appropriate age-verification and parental or guardian consent controls, and treat the child’s best interests as paramount.

​​13. Security and personal-data breaches

BCE uses technical and organisational measures proportionate to the data and risk, including access controls, least-privilege permissions, confidentiality commitments, encryption in transit where supported, supplier controls, logging, backup, vulnerability management, and incident response. No internet transmission or storage system can be guaranteed completely secure.

If a personal-data breach creates a real risk of harm, BCE will notify the Office of the Data Protection Commissioner without delay and, where reasonably practicable, within 72 hours after becoming aware. Where the breach is likely to create a high risk, BCE will also notify affected people without undue delay unless the law permits an exception. Please report a suspected incident promptly to bce@ke.bce.systems.

​​14. Complaints

Please contact BCE first so that we can investigate and respond. You may also complain to the Office of the Data Protection Commissioner using the current channels published at www.odpc.go.ke. You may seek another remedy available under Kenyan law.

​​15. Changes to this notice

We may update this notice to reflect changes in law, systems, vendors, or processing. We will publish the revised date and give appropriate notice of a material change. A current copy and relevant previous versions are retained for accountability.

Discuss your requirement

Tell us about your operational objective and we will advise on the right system, not the largest one.


Heading Goes Here

You can edit text on your website by double clicking on a text box on your website. Alternatively, when you select a text box a settings menu will appear. your website by double clicking on a text box on your website. Alternatively, when you select a text box.

Heading Goes Here

You can edit text on your website by double clicking on a text box on your website. Alternatively, when you select a text box a settings menu will appear. your website by double clicking on a text box on your website. Alternatively, when you select a text box.