Privacy Policy
Your privacy is protected under Article 31 of the Constitution of Kenya, 2010, and the Data Protection Act No. 24 of 2019. This Policy explains how Swavice collects, uses, stores, discloses, and protects personal data.
Request deletion without closing your account
You can ask Swavice to delete selected personal data, report data, photos, signatures, location data, or all eligible data while keeping your account active.
1. Introduction
Swavice ("we", "us", "our", or the "Company") is committed to protecting your privacy and the privacy of all individuals whose personal data we handle. This Privacy Policy ("Policy") describes how we collect, use, store, disclose, and protect personal data in connection with your use of the Swavice mobile application and related services (collectively, the "Platform").
We understand that privacy is a fundamental human right enshrined in Article 31 of the Constitution of Kenya, 2010, which guarantees every person the right not to have information relating to their family or private affairs unnecessarily required or revealed, and not to have the privacy of their communications infringed. We take this right seriously and build our Platform accordingly.
This Policy is designed to comply fully with the Data Protection Act No. 24 of 2019 (the "Act"), the Data Protection (General) Regulations, 2021, the Data Protection (Complaint Handling Procedures and Enforcement) Regulations, 2021, the Kenya Information and Communications Act (Cap 411A), the Computer Misuse and Cybercrimes Act No. 5 of 2018, and all guidelines issued by the Office of the Data Protection Commissioner of Kenya (the "ODPC").
By using the Platform, you acknowledge that you have read and understood this Policy and consent to the collection and processing of your personal data as described herein.
2. Data Controller Information
For the purposes of the Data Protection Act 2019, Swavice acts as the Data Controller in respect of personal data collected through the Platform.
Contact details for data protection queries:
Data Protection Officer
Swavice
Kingdom Business Centre
Nairobi, Kenya
Email: privacy@swavice.com
Support: support@swavice.com
We have appointed a Data Protection Officer (DPO) as required under Section 24 of the Data Protection Act 2019 for organisations that carry out large-scale processing of personal data. Our DPO is responsible for overseeing data protection strategy, ensuring compliance, and serving as the primary point of contact for all data protection matters.
3. Legal Framework
3.1 Constitutional Basis. The right to privacy is guaranteed under Article 31 of the Constitution of Kenya, 2010. This Policy gives effect to that constitutional right in the context of digital services.
3.2 Data Protection Act 2019. The Data Protection Act No. 24 of 2019 is the primary legislation governing the collection, use, storage, and disclosure of personal data in Kenya. Section 25 of the Act establishes the principles that govern our processing of personal data.
3.3 Data Protection Regulations. The Data Protection (General) Regulations, 2021, and the Data Protection (Complaint Handling Procedures and Enforcement) Regulations, 2021, provide detailed rules on how personal data must be handled and what rights individuals have.
3.4 Other Applicable Laws. Additional legal obligations arise from the Kenya Information and Communications Act (Cap 411A), which governs electronic communications; the Computer Misuse and Cybercrimes Act No. 5 of 2018, which addresses cybercrime and data security; and the Consumer Protection Act No. 46 of 2012, which protects consumer rights.
4. Personal Data We Collect
4.1 Account and Identity Data. When you register for an account, we collect your full name, email address, mobile phone number, job role or title, and the name of your employing organisation.
4.2 Authentication Data. We collect and store hashed authentication credentials (passwords are never stored in plain text), session tokens, device identifiers, and login timestamps.
4.3 Profile and Preference Data. We collect profile photographs or avatars that you choose to upload, digital signatures you create for inclusion in reports, and any theme or notification preferences you configure.
4.4 Professional Activity Data. We collect all data you enter in the course of using the Platform in your professional capacity, including: field service reports and their contents; site visit descriptions, findings, actions taken, and recommendations; photographs of work sites, equipment, and materials; machine nameplate data (manufacturer, model, serial number, power rating, voltage); materials used on site; job types, priorities, and statuses; GPS location data where you grant location permission.
4.5 Client Data. When you create reports for your clients, you may enter personal data relating to those clients, including: client or organisation name, site location and address, client contact person names and phone numbers, client representative signatures. You are solely responsible for ensuring you have appropriate authority and consent to enter and process this client data through the Platform.
4.6 Communications Data. We retain records of notifications sent to and received by your account, including job assignments, status updates, alerts, and broadcast messages.
4.7 Technical and Device Data. We automatically collect certain technical data when you use the Platform, including: device type, model, and operating system version; unique device identifiers; application version; network connection type; crash reports and error logs; app usage metrics and feature interaction data.
4.8 Location Data. With your explicit permission, we collect GPS coordinates at the time a report is created. Location data is embedded in the report and associated with the specific site visit. You may decline location access at any time through your device settings.
5. How We Collect Personal Data
5.1 Directly from You. The majority of personal data we collect is provided directly by you when you register an account, complete your profile, create reports, upload photographs, capture signatures, or communicate through the Platform.
5.2 Automatically. Technical and device data is collected automatically when you use the Platform through software running on your device and our servers.
5.3 From Your Organisation. If your account was created or provisioned by your employer or Organisation's Administrator, we may receive your name, email address, and role from that Organisation.
5.4 From Third Parties. We may receive account-related information from identity verification providers, or technical security information from fraud detection services, where applicable.
6. Lawful Basis for Processing
Under Section 30 of the Data Protection Act 2019, we must have a lawful basis for every processing activity. The lawful bases we rely upon are:
6.1 Performance of a Contract. The majority of our processing is necessary to perform the contract we have with you — namely, providing you with access to and functionality of the Platform.
6.2 Consent. For processing that goes beyond what is strictly necessary to deliver the service — such as location data collection — we rely on your freely given, specific, informed, and unambiguous consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
6.3 Compliance with Legal Obligations. We process personal data where necessary to comply with legal obligations applicable to us under Kenyan law, including tax obligations, court orders, and regulatory requirements.
6.4 Legitimate Interests. We process certain technical and usage data on the basis of our legitimate interests in maintaining the security, performance, and improvement of the Platform, provided these interests are not overridden by your rights and interests.
7. Purposes of Processing
7.1 Providing and Maintaining the Platform. We use your personal data to create and manage your account, authenticate your identity, deliver the features and functionality of the Platform, and provide technical support.
7.2 Report Generation and Management. We process the data you enter to generate, store, and export field service reports and PDF documents in accordance with your instructions.
7.3 Team and Job Management. For Organisations, we process personal data of Technicians and Supervisors to facilitate job assignments, team visibility, performance tracking, and notification delivery.
7.4 Synchronisation and Backup. We process your data to synchronise information between your device and our cloud infrastructure, ensuring data consistency and preventing loss.
7.5 Security and Fraud Prevention. We analyse technical and usage data to detect, investigate, and prevent security incidents, unauthorised access, fraud, and abuse of the Platform.
7.6 Legal Compliance. We process data as necessary to comply with applicable laws, respond to lawful requests from competent authorities, and enforce our Terms and Conditions.
7.7 Service Improvement. We use aggregated, anonymised usage data to understand how the Platform is used, identify areas for improvement, and develop new features. This processing does not involve individually identifiable personal data.
7.8 Communications. We use your contact details to send you transactional notifications (job assignments, report updates, system alerts), security alerts, and where you have consented, product and service updates.
8. Data Storage and Security
8.1 Local Device Storage. The Platform stores data locally on your device using SQLite, a secure embedded database, to enable offline functionality. This local data is protected by your device's operating system sandboxing, hardware-level encryption (where your device supports it), and application-level access controls.
8.2 Cloud Storage. When your device is online, data is synchronised to our cloud infrastructure hosted on Supabase, a PostgreSQL-based platform, located in the European Union (eu-west-1 region). Supabase complies with internationally recognised security standards.
8.3 Encryption in Transit. All data transmitted between your device and our servers is encrypted using Transport Layer Security (TLS 1.2 or higher). We do not transmit personal data over unencrypted connections.
8.4 Encryption at Rest. Personal data stored on our cloud infrastructure is encrypted at rest using AES-256 encryption.
8.5 Access Controls. Access to personal data within our systems is restricted to authorised personnel on a need-to-know basis. We implement role-based access controls, multi-factor authentication for system administrators, and regular access reviews.
8.6 Row Level Security. Our database is configured with Row Level Security (RLS) policies that enforce strict data isolation between different Organisations. No Organisation can access another Organisation's data at the database level.
8.7 Security Testing. We conduct periodic security assessments, vulnerability scanning, and where appropriate, penetration testing to identify and remediate security risks.
8.8 Incident Response. We maintain a documented security incident response plan. In the event of a data breach, we will follow the notification procedures set out in Section 14 of this Policy and the requirements of the Data Protection Act 2019.
9. Data Retention
9.1 Active Accounts. We retain your personal data for as long as your account is active and for such period thereafter as may be necessary to fulfil the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements.
9.2 Account Deletion. When you delete your account or your Organisation's subscription is terminated, we will delete or anonymise your personal data within ninety (90) calendar days, except where we are required by law to retain it for a longer period.
9.3 Report and Professional Data. Field service reports and associated data created through the Platform are retained for a minimum of seven (7) years from the date of creation to satisfy potential regulatory, legal, and professional record-keeping obligations that may apply to your industry.
9.4 Backup Data. Deleted data may persist in encrypted backup copies for up to thirty (30) days after deletion from the live system, after which it is permanently and irreversibly destroyed.
9.5 Anonymised Data. We may retain anonymised, aggregated data derived from your personal data indefinitely for analytical purposes, as such data no longer constitutes personal data under the Data Protection Act 2019.
9.6 Legal Hold. Notwithstanding the above, if personal data is subject to a legal hold, court order, or regulatory investigation, we will retain it for the duration required by such legal process, regardless of the retention periods above.
10. Disclosure and Sharing of Personal Data
We do not sell, rent, or trade your personal data to third parties. We disclose personal data only in the following circumstances:
10.1 Within Your Organisation. Personal data relating to Technicians and their reports is accessible to Administrators and Supervisors within the same Organisation account, in accordance with the role-based permissions configured for that account.
10.2 Service Providers. We share personal data with carefully selected third-party service providers who assist us in operating the Platform, including: cloud infrastructure and database hosting providers; email and notification delivery services; payment processing providers; analytics and error monitoring services. Each service provider is bound by contractual data processing agreements that restrict their use of personal data to the specific services they provide to us.
10.3 Legal and Regulatory Requirements. We may disclose personal data where required to do so by applicable law, court order, regulatory authority, or governmental request. We will, where legally permissible, provide you with prior notice before making such a disclosure.
10.4 Protection of Rights. We may disclose personal data where we believe it is necessary to protect the rights, property, or safety of the Company, our Users, or the public, and where such disclosure is permitted under applicable law.
10.5 Business Transfers. In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency, personal data held by the Company may be transferred to a successor entity, subject to equivalent privacy protections. We will notify you of any such transfer and any material changes to how your data will be processed.
10.6 With Your Consent. We may share your personal data with other parties with your explicit, informed consent.
11. International Data Transfers
11.1 Transfer Outside Kenya. Your personal data is stored on cloud infrastructure located in the European Union. This constitutes a transfer of personal data outside Kenya as contemplated by Section 48 of the Data Protection Act 2019.
11.2 Adequate Safeguards. We ensure that any transfer of personal data outside Kenya is made only to countries or organisations that provide an adequate level of data protection as determined by the Cabinet Secretary responsible for data protection, or subject to appropriate safeguards including: standard contractual clauses approved by the ODPC; binding corporate rules; certification schemes; or explicit consent where required.
11.3 EU Adequacy. The European Union has a comprehensive data protection framework under the General Data Protection Regulation (GDPR) that provides protections comparable to the Data Protection Act 2019. Our cloud infrastructure is located in an EU jurisdiction subject to these protections.
12. Your Rights as a Data Subject
Under the Data Protection Act 2019 and the Data Protection (General) Regulations, 2021, you have the following rights in respect of your personal data:
12.1 Right to be Informed. You have the right to be informed about the collection and use of your personal data, as set out in this Privacy Policy.
12.2 Right of Access. You have the right to request confirmation of whether we process your personal data, and to obtain a copy of the personal data we hold about you. We will respond to access requests within thirty (30) days of receipt.
12.3 Right to Rectification. You have the right to request the correction of inaccurate, incomplete, or misleading personal data. You may update much of your personal data directly through the Profile section of the Platform.
12.4 Right to Erasure. You have the right to request the deletion of your personal data, subject to our legal retention obligations under Section 9 of this Policy. We will action erasure requests within thirty (30) days.
12.5 Right to Object. You have the right to object to the processing of your personal data where we rely on legitimate interests as our lawful basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
12.6 Right to Withdraw Consent. Where processing is based on your consent, you may withdraw that consent at any time through your device settings or by contacting us. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
12.7 Right to Data Portability. You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another service, where processing is based on consent or a contract and is carried out by automated means.
12.8 Right against Automated Decision-Making. You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects concerning you.
12.9 How to Exercise Your Rights. To exercise any of these rights, you may use our Data Deletion Request form or contact our Data Protection Officer at privacy@swavice.com. We may need to verify your identity before processing your request. We will not charge a fee for access requests unless the request is manifestly unfounded or excessive.
13. Location Data
13.1 Permission-Based. The Platform requests access to your device's GPS location only when you are creating a field service report, to embed the site coordinates in that report. We do not track your location continuously or in the background.
13.2 Granularity. Location data is collected at the moment of report creation and is a single GPS coordinate pair (latitude and longitude) embedded in the report record. We do not build location history profiles.
13.3 Withdrawing Permission. You may revoke location permission at any time through your device's application settings. Revoking location permission will prevent GPS coordinates from being embedded in future reports but will not affect previously created reports.
14. Data Breach Notification
14.1 Internal Response. In the event of a personal data breach, we will immediately activate our incident response procedures, contain the breach, assess the risk to data subjects, and take all steps necessary to prevent recurrence.
14.2 Notification to the ODPC. In accordance with Section 43 of the Data Protection Act 2019, we will notify the Office of the Data Protection Commissioner of any personal data breach that is likely to result in a risk to the rights and freedoms of data subjects within seventy-two (72) hours of becoming aware of the breach, unless the breach is unlikely to result in such a risk.
14.3 Notification to Data Subjects. Where a personal data breach is likely to result in a high risk to the rights and freedoms of affected individuals, we will notify those individuals without undue delay. The notification will include: a description of the nature of the breach; the categories and approximate number of individuals affected; the likely consequences of the breach; the measures taken or proposed to address the breach; and the contact details of our Data Protection Officer.
14.4 Documentation. We will document all personal data breaches, including those that are not required to be notified to the ODPC, in accordance with Section 43(3) of the Data Protection Act 2019.
15. Photographs and Biometric Data
15.1 Report Photographs. Photographs taken during site visits and attached to reports are stored as part of those reports. They are accessible only to the Technician who created the report and the Administrators and Supervisors of their Organisation.
15.2 Profile Photographs. Profile photographs you voluntarily upload are stored and displayed within your Organisation's account context. You may delete your profile photograph at any time through the Profile settings.
15.3 Digital Signatures. The Platform enables clients to draw a digital signature on your device screen to sign off completed work. This signature is captured as an image file, embedded in the PDF report, and stored associated with that specific report. We treat handwritten signature images as sensitive personal data and apply additional access restrictions accordingly.
16. Children's Privacy
The Platform is intended for use by professional adults engaged in field service and engineering work. We do not knowingly collect personal data from children under the age of eighteen (18). If you believe we have inadvertently collected personal data from a child, please contact us immediately at privacy@swavice.com and we will promptly delete such data.
17. Third-Party Services and Links
The Platform integrates with third-party services to deliver its functionality, including cloud infrastructure, push notification, and file sharing services. These third parties operate under their own privacy policies, which we encourage you to review.
The Platform may allow you to share reports via third-party applications such as email clients, WhatsApp, or cloud storage services. Once a report is shared via a third-party application, that application's own privacy terms apply to the shared data. We do not control how third-party applications handle the data you choose to share with them.
18. Cookies and Local Storage
As a mobile application, Swavice does not use browser cookies. However, we use local device storage technologies including AsyncStorage for session persistence and SQLite for offline data storage. These technologies are essential to the operation of the Platform and cannot be disabled without rendering the Platform non-functional.
Session tokens stored in AsyncStorage are used to keep you securely logged in between app sessions. They are encrypted and are never transmitted to any party other than the Supabase authentication service.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or the features of the Platform. When we make material changes, we will notify you through an in-app notification and, where required, by email to your registered address, at least thirty (30) days before the changes take effect.
We will maintain a record of previous versions of this Policy and make them available upon request. The date at the top of this Policy indicates when it was last updated.
Your continued use of the Platform after the effective date of a revised Policy constitutes your acceptance of the changes. If you do not agree with the revised Policy, you must stop using the Platform and may request deletion of your account.
20. Complaints to the ODPC
If you are not satisfied with how we have handled your personal data or responded to a request to exercise your rights, you have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya (ODPC), which is the supervisory authority for data protection in Kenya established under the Data Protection Act 2019.
Office of the Data Protection Commissioner
Britam Tower, Upper Hill
P.O. Box 30084 — 00100
Nairobi, Kenya
Email: info@odpc.go.ke
Website: www.odpc.go.ke
We encourage you to contact us first at privacy@swavice.com before filing a complaint with the ODPC, as we are committed to resolving all data protection concerns promptly and fairly.
21. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact our Data Protection Officer:
Data Protection Officer
Swavice
Kingdom Business Centre, Nairobi, Kenya
Email: privacy@swavice.com
General Support: support@swavice.com
We aim to acknowledge all privacy-related enquiries within two (2) business days and to provide a substantive response within thirty (30) days.
This Privacy Policy was last updated on 3 June 2026 and is effective as of that date.