General Privacy Policy

Introduction

Smart Applications International is committed to protecting the privacy and personal data of all individuals whose data we collect and process. This General Privacy Policy outlines how we collect, use, disclose, and safeguard personal data in accordance with the data protection laws in the countries we operate. This policy applies to our roles as both a Data Controller and a Data Processor.

Scope

This policy applies to all personal data collected by Smart Applications from the public, including but not limited to customers, website visitors, vendors, partners, employees, and job applicants. It covers all data collection points such as websites, mobile applications, physical offices, call centers, and third-party platforms.

What is Personal Data?

At Smart Applications International Limited, personal data refers to any information that relates to an identified or identifiable individual and is collected, processed, or stored in the course of our operations. This includes, but is not limited to:

  • Identity information such as full names, national ID or passport numbers;
  • Contact details including phone numbers, email addresses, and physical addresses;
  • Biometric identifiers such as fingerprints or facial recognition data used in healthcare or access control systems;
  • Health-related information collected through our healthcare technology platforms;
  • Employment and professional data such as CVs, job titles, and academic qualifications;
  • Digital identifiers like IP addresses, device IDs, and cookies collected through our websites and applications.

This data may be collected directly from individuals or indirectly through our systems, partners, or service providers, and is handled in accordance with the data protection laws in the countries we operate and international privacy standards.

How We Collect Personal Data

We collect personal data directly through forms, applications, interviews, and emails, and indirectly through cookies, CCTV, third-party referrals, and social media platforms.

Purpose of Collection

At Smart Applications, we collect personal data to support and enhance our operations across various domains. Specifically, we process personal information for the following purposes:

  • Service Delivery: To provide and manage access to our healthcare technology platforms, biometric authentication systems, and digital services for clients, partners, and end-users.
  • Employment and Human Resource Management: To facilitate recruitment, onboarding, payroll, benefits administration, performance evaluation, and compliance with employment laws.
  • Marketing and Communication: To inform our clients and stakeholders about our products, services, innovations, and events through targeted communications and campaigns.
  • Legal and Regulatory Compliance: To meet obligations under the data protection laws in the countries we operate, tax laws, labor laws, and other applicable regulations.
  • Security and Fraud Prevention: To protect our systems, premises, and data from unauthorized access, breaches, and fraudulent activities through monitoring tools such as CCTV, access logs, and cybersecurity protocols.

This data is collected and processed in accordance with applicable legal bases and is safeguarded through robust technical and organizational measures.

Lawful Basis for Processing

We ensure that all personal data is processed lawfully, fairly, and transparently. Our processing activities are grounded in one or more of the following legal bases, as defined under the data protection laws in the countries we operate:

  • Consent: We obtain clear and informed consent from individuals before collecting or processing their personal data, especially in cases involving marketing communications, biometric data, or other sensitive information.
  • Contractual Necessity: We process personal data when it is necessary to fulfill our contractual obligations, such as providing services to clients, managing employment relationships, or onboarding vendors and partners.
  • Legal Obligation: We process data to comply with statutory and regulatory requirements, including tax reporting, employment laws, and obligations under the local data protection laws.
  • Legitimate Interest: We may process data to support our operational efficiency, improve service delivery, enhance security, or prevent fraud, provided such interests do not override the rights and freedoms of the data subject.
  • Public Interest: In limited cases, we may process personal data to carry out tasks in the public interest or in the exercise of official authority, particularly in collaboration with government or regulatory bodies.

Each processing activity is assessed to ensure it aligns with the appropriate legal basis, and we maintain documentation to demonstrate compliance.

Data Subject Rights

As a data subject, you have specific rights under the data protection laws in the countries we operate and regulations such as the GDPR regarding how your personal data is collected, used, and protected by Smart Applications International Limited. These rights include the ability to:

  • Request access to the personal data we hold about you.
  • Receive a digital copy of the personal data you have provided to us, or request that we transfer it to a third party of your choice (data portability).
  • Request correction of any inaccurate or incomplete personal data.
  • Restrict processing of your personal data in certain circumstances.
  • Request deletion of your personal data where it is no longer necessary for the purposes for which it was collected.
  • Withdraw your consent at any time, where processing is based on consent (this does not affect the lawfulness of processing carried out before withdrawal).
  • Object to the processing of your personal data, including for direct marketing or where processing is based on legitimate interests.
  • Object to automated decision-making or profiling, where such processing has a legal or significant effect on you.
  • Lodge a complaint with us if you believe your data protection rights have been violated.

Please note that your ability to exercise these rights may depend on the nature of the data and the context of the processing. In some cases, we may not be able to fulfill your request if we have a compelling legal or operational reason to retain the data.

To exercise any of your rights or to raise a concern, please contact our Data Protection Officer at dpo@smartapplicationsgroup.com. If your personal data changes or you believe it is inaccurate, we encourage you to notify us promptly so we can update our records.

Data Sharing

At Smart Applications International Limited, we are committed to protecting your personal data and only share it under strict legal, contractual, and security safeguards. We may disclose personal data to internal departments, trusted third parties, and regulatory bodies for legitimate business, legal, and operational purposes. These disclosures are governed by data processing agreements, confidentiality obligations, and applicable data protection laws.

Internal Sharing: We share personal data internally with authorized departments and personnel who require access to perform their duties, including:

  • Human Resources — for recruitment, onboarding, performance management, and employee welfare.
  • Finance — for payroll processing, statutory deductions, and benefits administration.
  • ICT — for system access, cybersecurity, and data storage.
  • Legal and Compliance — for contract management, audits, and regulatory reporting.
  • Line Managers — for operational oversight and performance evaluations.

External Bodies: We may share personal data with the following external service providers and partners:

RecipientPurpose of Sharing
United States of AmericaRecruitment system hosting and applicant tracking
South AfricaHR and payroll system hosting and employee data management
Background checks organisationsBackground checks and employee verification
Banks, insurance companies and pension administratorsBenefits administration, statutory compliance, and financial services
Revenue authoritiesTax compliance and statutory reporting
Legal advisors and auditorsLegal compliance, dispute resolution, and financial audits
Statutory bodiesStatutory certification and compliance
Third-party vendorCourier and logistics services involving personal data delivery or collection

All third-party processors are subject to due diligence and are required to implement appropriate technical and organizational measures to protect personal data.

International Transfers

We may store or process your personal data in countries other than where it was initially collected. This includes jurisdictions where our company, affiliated data centers, or trusted third-party service providers operate, such as the United States and South Africa.

These countries may have data protection laws that differ from those in your country of residence. However, we are committed to ensuring that your personal data remains protected regardless of where it is transferred or stored.

For all transfers, we implement appropriate safeguards to ensure compliance with the data protection laws in the countries we operate, including:

  • Adequacy Decisions: Where the destination country is recognized as providing an adequate level of data protection under Kenyan law or comparable frameworks such as the EU GDPR.
  • Standard Contractual Clauses (SCCs): For countries not deemed adequate, we use legally binding agreements approved by the Local Data Protection Authority (ODPC) or other recognized authorities to ensure your data is handled securely and lawfully.

You may request more information about these safeguards or obtain a copy of the relevant contractual clauses by contacting our Data Protection Officer at dpo@smartapplicationsgroup.com.

Data Retention

At Smart Applications, we retain your personal data only for as long as necessary to fulfill the specific purposes for which it was collected, such as delivering services, managing employment, complying with legal obligations, or supporting operational needs. Once these purposes have been met, we take appropriate steps to securely delete or anonymize the data.

In some cases, we may be required or permitted by law to retain personal data for longer periods, for example to comply with legal, tax, accounting, anti-money laundering, counter-terrorism, regulatory, or reporting obligations.

After our relationship with you ends, such as when your account is closed, your application is declined, or you choose not to proceed, we will retain only the data that is necessary and appropriate for:

  • Maintaining business records for audits and internal analysis
  • Complying with applicable laws and regulatory requirements
  • Responding to legal claims, investigations, or proceedings
  • Cooperating with law enforcement, courts, or government authorities
  • Honoring opt-out requests for marketing communications
  • Addressing future service-related complaints or inquiries
  • Preventing fraud and financial crime
  • Evaluating the effectiveness of our marketing efforts

Our retention practices are guided by internal policies and aligned with the data protection laws in the countries we operate. We regularly review the data we hold to ensure it is not kept longer than necessary and is handled securely throughout its lifecycle.

Security Measures

SMART has implemented an ISO/IEC 27001:2022-certified Information Security Management System (ISMS) to ensure robust protection of personal data. The company is also registered with the local data protection regulators/authorities and maintains a valid, up-to-date data protection certificate.

To safeguard data, SMART applies:

  • Technical controls: encryption, antivirus, firewalls, and secure access systems
  • Organizational controls: staff training, internal audits, and policy enforcement
  • Physical controls: CCTV surveillance and restricted access to sensitive areas
  • Third-party oversight: due diligence and binding data protection agreements

These measures ensure data is protected throughout its lifecycle.

Cookies and Tracking

Smart Applications International Limited uses cookies and similar technologies, including pixel tags, web beacons, and server-side tags, across our websites, mobile applications, and digital communications (such as emails and push notifications). These technologies help us enhance user experience, improve service delivery, and support secure and efficient platform functionality.

Cookies are small text files stored on your device when you visit our platforms. When you return, these cookies allow our systems, or those of our trusted partners, to recognize your device and remember your preferences, enabling smoother navigation and personalized content.

We use these technologies for several purposes:

  • Essential functionality: To enable secure login, session management, and navigation across our platforms.
  • Performance and analytics: To understand how users interact with our websites and apps, helping us improve usability and content (e.g., through tools like Google Analytics).
  • Marketing and personalization: To deliver relevant content and advertisements, including on social media platforms like Facebook, where permitted. This may involve sharing limited data with social media providers to tailor ads based on your interactions with our platforms.
  • Email and notification tracking: To assess engagement with our communications and improve future outreach.

You can manage or opt out of non-essential cookies at any time via our cookie banner or your browser settings. For more details, please contact our Data Protection Officer at dpo@smartapplicationsgroup.com.

Breach Notification

In the event of a data breach, we will notify the affected individuals and the Local Data Protection Authority in accordance with the local data protection laws.

Contact Information

For any questions or to exercise your data protection rights, please contact our Data Protection Officer at: dpo@smartapplicationsgroup.com

Policy Updates

SMART shall review and update this policy annually or when there are significant legal, regulatory, or operational changes. Updates will be:

  • Reviewed and approved by the Information Security Management Committee
  • Communicated to all relevant stakeholders
  • Documented with version control and change logs

This process ensures ongoing compliance with the Kenya Data Protection Act, ISO/IEC 27001:2022, and ISO/IEC 27701:2019.