Smart Applications International is committed to protecting the privacy and personal data of all individuals whose data we collect and process. This General Privacy Policy outlines how we collect, use, disclose, and safeguard personal data in accordance with the data protection laws in the countries we operate. This policy applies to our roles as both a Data Controller and a Data Processor.
This policy applies to all personal data collected by Smart Applications from the public, including but not limited to customers, website visitors, vendors, partners, employees, and job applicants. It covers all data collection points such as websites, mobile applications, physical offices, call centers, and third-party platforms.
At Smart Applications International Limited, personal data refers to any information that relates to an identified or identifiable individual and is collected, processed, or stored in the course of our operations. This includes, but is not limited to:
This data may be collected directly from individuals or indirectly through our systems, partners, or service providers, and is handled in accordance with the data protection laws in the countries we operate and international privacy standards.
We collect personal data directly through forms, applications, interviews, and emails, and indirectly through cookies, CCTV, third-party referrals, and social media platforms.
At Smart Applications, we collect personal data to support and enhance our operations across various domains. Specifically, we process personal information for the following purposes:
This data is collected and processed in accordance with applicable legal bases and is safeguarded through robust technical and organizational measures.
We ensure that all personal data is processed lawfully, fairly, and transparently. Our processing activities are grounded in one or more of the following legal bases, as defined under the data protection laws in the countries we operate:
Each processing activity is assessed to ensure it aligns with the appropriate legal basis, and we maintain documentation to demonstrate compliance.
As a data subject, you have specific rights under the data protection laws in the countries we operate and regulations such as the GDPR regarding how your personal data is collected, used, and protected by Smart Applications International Limited. These rights include the ability to:
Please note that your ability to exercise these rights may depend on the nature of the data and the context of the processing. In some cases, we may not be able to fulfill your request if we have a compelling legal or operational reason to retain the data.
To exercise any of your rights or to raise a concern, please contact our Data Protection Officer at dpo@smartapplicationsgroup.com. If your personal data changes or you believe it is inaccurate, we encourage you to notify us promptly so we can update our records.
At Smart Applications International Limited, we are committed to protecting your personal data and only share it under strict legal, contractual, and security safeguards. We may disclose personal data to internal departments, trusted third parties, and regulatory bodies for legitimate business, legal, and operational purposes. These disclosures are governed by data processing agreements, confidentiality obligations, and applicable data protection laws.
Internal Sharing: We share personal data internally with authorized departments and personnel who require access to perform their duties, including:
External Bodies: We may share personal data with the following external service providers and partners:
| Recipient | Purpose of Sharing |
|---|---|
| United States of America | Recruitment system hosting and applicant tracking |
| South Africa | HR and payroll system hosting and employee data management |
| Background checks organisations | Background checks and employee verification |
| Banks, insurance companies and pension administrators | Benefits administration, statutory compliance, and financial services |
| Revenue authorities | Tax compliance and statutory reporting |
| Legal advisors and auditors | Legal compliance, dispute resolution, and financial audits |
| Statutory bodies | Statutory certification and compliance |
| Third-party vendor | Courier and logistics services involving personal data delivery or collection |
All third-party processors are subject to due diligence and are required to implement appropriate technical and organizational measures to protect personal data.
We may store or process your personal data in countries other than where it was initially collected. This includes jurisdictions where our company, affiliated data centers, or trusted third-party service providers operate, such as the United States and South Africa.
These countries may have data protection laws that differ from those in your country of residence. However, we are committed to ensuring that your personal data remains protected regardless of where it is transferred or stored.
For all transfers, we implement appropriate safeguards to ensure compliance with the data protection laws in the countries we operate, including:
You may request more information about these safeguards or obtain a copy of the relevant contractual clauses by contacting our Data Protection Officer at dpo@smartapplicationsgroup.com.
At Smart Applications, we retain your personal data only for as long as necessary to fulfill the specific purposes for which it was collected, such as delivering services, managing employment, complying with legal obligations, or supporting operational needs. Once these purposes have been met, we take appropriate steps to securely delete or anonymize the data.
In some cases, we may be required or permitted by law to retain personal data for longer periods, for example to comply with legal, tax, accounting, anti-money laundering, counter-terrorism, regulatory, or reporting obligations.
After our relationship with you ends, such as when your account is closed, your application is declined, or you choose not to proceed, we will retain only the data that is necessary and appropriate for:
Our retention practices are guided by internal policies and aligned with the data protection laws in the countries we operate. We regularly review the data we hold to ensure it is not kept longer than necessary and is handled securely throughout its lifecycle.
SMART has implemented an ISO/IEC 27001:2022-certified Information Security Management System (ISMS) to ensure robust protection of personal data. The company is also registered with the local data protection regulators/authorities and maintains a valid, up-to-date data protection certificate.
To safeguard data, SMART applies:
These measures ensure data is protected throughout its lifecycle.
Smart Applications International Limited uses cookies and similar technologies, including pixel tags, web beacons, and server-side tags, across our websites, mobile applications, and digital communications (such as emails and push notifications). These technologies help us enhance user experience, improve service delivery, and support secure and efficient platform functionality.
Cookies are small text files stored on your device when you visit our platforms. When you return, these cookies allow our systems, or those of our trusted partners, to recognize your device and remember your preferences, enabling smoother navigation and personalized content.
We use these technologies for several purposes:
You can manage or opt out of non-essential cookies at any time via our cookie banner or your browser settings. For more details, please contact our Data Protection Officer at dpo@smartapplicationsgroup.com.
In the event of a data breach, we will notify the affected individuals and the Local Data Protection Authority in accordance with the local data protection laws.
For any questions or to exercise your data protection rights, please contact our Data Protection Officer at: dpo@smartapplicationsgroup.com
SMART shall review and update this policy annually or when there are significant legal, regulatory, or operational changes. Updates will be:
This process ensures ongoing compliance with the Kenya Data Protection Act, ISO/IEC 27001:2022, and ISO/IEC 27701:2019.