LegalPrivacy Policy

Privacy Policy

ActivHR Privacy Policy
12/08/2026
This Privacy Policy explains how Priority Activator consulting ("ActivHR", "we", "us") collects, uses, and protects personal data through ActivHR (the "Service"), in accordance with the Kenya Data Protection Act, 2019 ("the Act").
This Policy applies to two groups of people, and the sections below indicate which apply to which: Client organisations that subscribe to ActivHR; Employees and other individuals ("Users") whose attendance data is processed through ActivHR on behalf of a Client organisation. If you are an employee using ActivHR through your employer, please also read the ActivHR Employee Notice at actichr.africa/employee-notice, which explains your rights in plain language.

1. Who we are and our role
For Client organisations, ActivHR acts as a Data Processor, processing User personal data only on the Client's instructions. The Client organisation is the Data Controller responsible for its employees' data. [[PLACEHOLDER pending L1 legal opinion: confirm this characterisation applies across all deployment models before publishing]]
For data we collect directly from Client organisations themselves, such as billing contacts and account administrator details, ActivHR acts as a Data Controller.
Our data protection contact: [[PLACEHOLDER: data protection contact email]]

2. What data we collect
Data category | Collected from | Examples
Account and billing data | Client organisation | Company name, billing contact, payment details
User identity data | Client organisation | Employee name, employee ID, role
Attendance data | User, via the app | Clock-in and clock-out timestamps
Location data | User, via the app | [[PLACEHOLDER: if applicable, confirm whether location is collected]]
Biometric data | User, via the app | Fingerprint template, collected only if the Client enables biometric roll-call and the User consents
Technical data | Automatically | Device type, app version, IP address, log data
Cookies | Web dashboard visitors | See our Cookie Policy at actichr.africa/cookie-policy
We do not collect biometric data unless biometric roll-call is enabled by the Client and the individual User has given explicit, opt-in consent. See Section 5.

3. Why we process this data
To provide the attendance tracking and reporting features of the Service
To verify User identity at clock-in, including via biometric matching where enabled
To maintain account security and prevent misuse
To communicate service updates, maintenance notices, and support responses
To meet legal and regulatory obligations, including retention and reporting requirements

4. Lawful basis for processing
[[PLACEHOLDER pending L1 legal opinion: insert confirmed lawful basis per data category, likely a mix of: performance of the Client's contract with its employees, the Client's legitimate interest in workforce management, explicit consent for biometric data, and compliance with legal obligations. Do not finalise before counsel review.]]

5. Biometric data specifically
Biometric data is sensitive personal data under the Act and receives additional protection:
Collected only when the Client organisation enables biometric roll-call
Requires explicit opt-in consent from the individual User, captured with a timestamp and policy version
Users who decline can still clock in using an alternative method (see the Employee Notice)
Stored as a mathematical template, not a reconstructable image, and encrypted at rest [[PLACEHOLDER: confirm actual technical implementation before publishing]]
Retained only for [[PLACEHOLDER pending L4: retention window, e.g. duration of employment plus X days]] and deleted thereafter

6. Who we share data with
We do not sell personal data. We share data only with:
Sub-processors, who process data on our behalf to operate the Service:
[[PLACEHOLDER: List of Sub-processors, Purpose, Location]]
Other Client-authorised recipients, such as the Client's own HR or payroll systems, where the Client configures an integration or export.
Legal and regulatory bodies, where required by law, including the Office of the Data Protection Commissioner (ODPC).
Cross-border transfers: [[PLACEHOLDER: Cross-border transfer details]]

7. How long we keep data
We retain personal data only as long as necessary for the purposes described in this Policy. Data is deleted automatically at the end of each retention window through scheduled deletion processes.

8. Your rights
Under the Act, individuals have the right to: Be informed of the use to which their personal data is to be put; Access their personal data; Request correction of inaccurate or outdated data; Request deletion of false or unlawfully collected data; Object to the processing of some or all of their data; Withdraw consent, where processing is based on consent (such as biometric enrolment); Lodge a complaint with the Office of the Data Protection Commissioner (ODPC).
Employees: To exercise these rights, contact your employer's HR team or [[PLACEHOLDER: ActivHR data protection contact]].
Client organisations: Contact [[PLACEHOLDER: contact]] for data access, export, or deletion requests relating to your account.

9. Data security
We implement technical and organisational measures appropriate to the sensitivity of the data processed, including encryption in transit, access controls, and [[PLACEHOLDER: additional measures]].

10. Data breach notification
In the event of a personal data breach affecting User data, we will notify the affected Client organisation without undue delay, and in any event within [[PLACEHOLDER: e.g. 72 hours]] of becoming aware, so the Client can meet its own notification obligations.

11. Children's data
The Service is not directed at, and we do not knowingly collect data from, individuals under the age of 18. ActivHR is intended for use by employed adults within a Client organisation's workforce.

12. Changes to this policy
We may update this Privacy Policy from time to time.

13. Contact us
For questions about this Policy or to exercise your data protection rights, contact:[[PLACEHOLDER: data protection contact name/role and email]]
You may also lodge a complaint directly with the Office of the Data Protection Commissioner (ODPC), Kenya.