1. Who we are
RETACH Digital Ltd ("RETACH", "we", "us") is a private company limited by shares, incorporated in Kenya. For the personal data described in this notice, RETACH is the data controller: we decide why and how it is used.
| Registered address | Naivasha Road Villas, Naivasha Road, Nairobi West District, P.O. Box 26518-00100, Nairobi, Kenya |
| Privacy contact | privacy@retach.tech |
| Contact person | Paul N. Nduati, Director |
| Website | retach.tech |
2. What this notice covers
This notice covers personal data we collect when you:
- visit retach.tech and its pages, including our free tools (the S.I.N.S. Scanner, the CRQ Engine, the Identity & Access findings viewer and the Pentest Kit);
- use our online service catalogue and request a quote at erp.retach.tech;
- email us, message us on WhatsApp, or follow a link to us from retach.io or retach.ke.
It does not cover client engagement data. When we deliver a paid service (for example a vCISO engagement, an assessment or managed security), we usually process data on the client's behalf, as a data processor. That processing is governed by the engagement contract and its data processing agreement, not by this notice.
Our pages link to other sites (LinkedIn, X, Facebook, Instagram, YouTube, WhatsApp). Those sites have their own privacy notices; we don't control them.
3. What we collect
Most of our free tools run entirely in your browser. What you type into them is not sent to us.
| Where | What we collect | Sent to RETACH? |
|---|---|---|
| Any page of retach.tech | Technical data your browser sends with every request: IP address, browser and device type, pages requested, date and time. This is logged by our hosting providers, not by us. | Held by our hosting providers (section 5) |
| S.I.N.S. Scanner | Your answers to the questionnaire (no contact details are asked for) | No. Processed in your browser only; gone when you close the page |
| CRQ Engine: financial model | Revenue, sector and other figures you enter | No. Processed in your browser only |
| CRQ Engine: external exposure check | The internet domain you enter (e.g. company.co.ke), plus your IP address | Yes. Sent to our server so it can look up public DNS, certificate and exposure records for that domain |
| Identity & Access findings viewer | The findings file you open or paste | No. Read in your browser; never uploaded |
| Pentest Kit | Engagement details and findings you enter | No. Kept in your browser; the report is saved to your own device |
| Quote request form | Service or partner product of interest, your name, work email, organisation and organisation type; optionally phone/WhatsApp, staff, site and device counts, current security tools, licence term and any notes. You must tick a box agreeing we may contact you about the request. | Yes. Stored in our business system and emailed to us |
| Email or WhatsApp | Your name, contact details and whatever you write | Yes |
The domain check looks up public information. It queries public DNS records, public certificate logs and public internet-exposure data about the domain you enter. Please only check domains you own or are authorised to assess.
We don't ask for sensitive personal data (such as health data) through our website, and we ask you not to send it.
4. Why we use it, and our lawful basis
We only use personal data where the Data Protection Act, 2019 ("DPA") allows it (s.30), and only for the purpose we collected it for (s.25).
| Purpose | Data | Lawful basis |
|---|---|---|
| Running and securing the website: delivering pages, stopping abuse, fixing faults | Technical data, IP address | Legitimate interests: keeping a secure, working website |
| Running the domain check you asked for | Domain entered, IP address | Legitimate interests: carrying out the check you asked for |
| Replying to your quote request, email or message, and preparing a quotation | Contact details, request content | Steps you asked us to take before entering a contract; legitimate interests |
| Invoicing and records, if you become a client | Contact and billing details | Performance of a contract; compliance with legal obligations (tax, company law) |
| Following up on a quote you requested | Contact details | Legitimate interests. We stop if you ask us to. |
| Marketing emails or newsletters | Email address | Consent only. We don't send these today; if we start, we'll ask first. |
Is giving us your data required? No. You can browse the site and use the in-browser tools without giving us anything. Without contact details, though, we can't reply to a quote request.
We don't sell personal data. We don't make decisions about you based solely on automated processing that have legal or similarly significant effects. The scores our tools display are indicative guidance, not decisions about you.
5. Who we share it with
We share personal data only with service providers that help us run RETACH, and only as far as they need it. They act on our instructions (as processors) or under their own published terms.
| Provider | What they do for us | Data involved | Where |
|---|---|---|---|
| Oracle Cloud Infrastructure | Hosts our server: the domain-check service and our business system (quotes, records) | Domain checks, IP addresses, quote requests, client records | United Kingdom (London) |
| GitHub (Microsoft), with Fastly | Hosts and delivers retach.tech | Technical data, IP address | United States / global network |
| Cloudflare | Redirects retach.io and retach.ke to our site | Technical data, IP address | Global network |
| Google (Workspace) | Our email | Emails you send us | Outside Kenya (global) |
| Google (Fonts) | Supplies the typefaces our pages display | IP address, browser details | Global |
| SMTP2GO | Sends emails from our business system (quote confirmations, invoices) | Name, email address, message content | Outside Kenya |
| Public data sources: public DNS, certificate transparency logs (crt.sh), Shodan InternetDB | Answer the domain check | The domain name, or the IP address it points to (not your identity) | Various, mainly outside Kenya |
| Meta (WhatsApp) | Only if you choose to message us on WhatsApp | Your number and messages | Meta's terms apply |
We may also disclose personal data where the law requires it (for example to a regulator, a court or the Kenya Revenue Authority), or to our professional advisers under a duty of confidentiality.
6. Transfers outside Kenya
Our main server is in the United Kingdom. Quote requests, client records and domain checks are stored and processed on Oracle Cloud Infrastructure in London. Our website host, email provider and other providers in section 5 may also process data outside Kenya.
Under ss.48–50 of the DPA we transfer personal data out of Kenya only when appropriate safeguards are in place. For each transfer we rely on one or more of these:
- Contractual safeguards. Our providers' data processing terms bind them to protect personal data, keep it confidential and use it only on our instructions.
- Security of the destination. Data is encrypted in transit (HTTPS/TLS), and access to our server is restricted (section 8).
- Necessity. Some transfers are needed to do what you asked, such as answering your quote request or running the domain check.
You can ask us for more detail on the safeguards for any transfer (section 10).
7. How long we keep it
We keep personal data only as long as we need it for the purpose we collected it for, or as the law requires (s.39). Then we delete or anonymise it.
| Data | How long |
|---|---|
| Quote requests and enquiries that don't lead to an engagement | 24 months from our last contact |
| Records of clients (contracts, quotations, invoices, payments) | At least 5 years, or longer where the law requires |
| Server logs | Web server access logs (IP address, date, page requested, browser): 30 days. The domain-check service itself logs no domains or IPs. |
| Emails and WhatsApp messages | 24 months, or longer if they form part of a client record |
| Anything processed only in your browser (scanner, CRQ model, viewer, Pentest Kit) | Not held by us |
| Hosting providers' technical logs | Under each provider's own retention policy |
We may keep data longer if we need it to deal with a complaint, a legal claim or a regulator's request.
8. How we protect it
We apply the same controls we recommend to our clients (DPA s.41, data protection by design and by default):
- Data minimisation by design. Our free tools run in your browser wherever possible, so we never receive most of what you enter.
- Encryption in transit. All our sites and services use HTTPS/TLS.
- Restricted access. Only authorised RETACH personnel can reach our server and business system, using key-based access.
- Hardened hosting. The server sits behind a firewall with only the services we need exposed.
- Vetted providers. We use established providers with published security certifications.
- Breach response. If a personal data breach is likely to put your rights at real risk, we'll notify the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware of it. Where the law requires, we'll tell you too (s.43).
No system is completely secure, but we work to keep the risk low and proportionate.
9. Cookies and analytics
retach.tech sets no cookies today, and uses no analytics or tracking. Our tool pages don't store data in your browser's local storage.
Our quote and catalogue site (erp.retach.tech) uses strictly necessary cookies to keep your session working and your form secure. They expire when your session ends or soon after.
If we ever add analytics, we'll update this notice first and ask for your consent before any analytics cookies are set.
10. Your rights
Under s.26 of the DPA, and the related sections cited below, you have the right to:
- be informed how your personal data is used (this notice);
- access the personal data we hold about you;
- object to our processing of all or part of it, including follow-up contact;
- correct data that is false, inaccurate or misleading;
- delete data that is false or misleading, or that we no longer have a lawful reason to keep;
- withdraw consent at any time, where we rely on consent (s.32); this doesn't affect processing already done;
- data portability: receive data you gave us in a common machine-readable format (s.38).
How to use them: email privacy@retach.tech, or write to the postal address in section 1. Tell us what you're asking for and how we can reach you. We may need to verify your identity before acting. It's free. We'll respond promptly, and within the period set by the Data Protection (General) Regulations, 2021. If we can't meet a request, we'll explain why.
11. Children
Our website and services are for organisations and professionals. They are not aimed at anyone under 18, and we don't knowingly collect children's personal data (s.33). If you think a child has sent us personal data, contact privacy@retach.tech and we'll delete it.
12. Complaints
If you're unhappy with how we've handled your personal data, please contact us first at privacy@retach.tech so we can try to put it right. You also have the right to complain to the Office of the Data Protection Commissioner at www.odpc.go.ke.
13. Changes to this notice
We'll update this notice when our services or the law change. The effective date at the top shows when it last changed. For significant changes, we'll post a notice on retach.tech.