Skip to main content

PRIVACY POLICY

Last Updated: 8/18/2026

Computer Revolution Africa Group (“CRAG”, “we”, “us”, or “our”) is committed to protecting the privacy and security of personal data belonging to visitors to our website cragroup.co.ke (the “Site”), our clients, prospective clients, and users of our products and services, including Secufortress, V-Book, Loan App, Telemetric, Fraud Detection, and Conveyancing, and our cloud, data, AI, infrastructure, network, cybersecurity, modern work, and IT consultation services (collectively, the “Services”).

This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights you have in relation to it, in accordance with the Kenya Data Protection Act, 2019 (the “DPA”) and other applicable law.

  1. Privacy Policy Introduction

This Policy applies to personal data we collect through the Site, through your use of our Services, through your interactions with our sales, support, or account teams, and through any other channel by which we collect personal data. We process personal data lawfully, fairly, and transparently, and only for the purposes described in this Policy.

2. Data Controller / Organisation Details

The data controller responsible for your personal data is Computer Revolution Africa Group, a company incorporated in Kenya, with its physical address in Nairobi, Kenya. For privacy-related queries, contact us at info@cragroup.co.ke.

3. Personal Data Collected

Depending on how you interact with us, we may collect the following categories of personal data:

Identity and contact data — such as full name, job title, company name, email address, and phone number;

Account data — such as usernames, passwords (stored in hashed/encrypted form), and account preferences for Services such as Secufortress, V-Book, Loan App, Telemetric, Fraud Detection, or Conveyancing;

Financial and transactional data — such as billing details and payment records, collected in connection with paid Services (see Clause 8);

Technical and usage data — such as IP address, browser type, device information, and pages visited on the Site, collected via cookies and similar technologies (see Clause 7);

Service-specific data — such as network, system, or security event data processed through cybersecurity and monitoring services (e.g. Secufortress), loan or applicant data processed through Loan App, or property and transaction-related data processed through Conveyancing, where CRAG acts as a processor on behalf of the relevant client; and

Communications data — such as records of correspondence, support tickets, and enquiries you send to us.

We only collect the categories of data set out above that are actually relevant to the specific Site interaction or Service you use; not every category applies to every visitor or user.

4. Sources of Personal Data

We collect personal data: (a) directly from you, for example when you fill in a contact form, request a demo, or register for a Service; (b) automatically, through your use of the Site and Services (see Clause 7); and (c) from third parties, such as our business partners, resellers, or publicly available sources, where relevant to a business relationship.

5. Purposes of Processing

We process personal data for the following purposes:

  • To provide, operate, and maintain the Site and our Services;
  • To create and manage user and client accounts;
  • To process payments and manage billing;
  • To respond to enquiries and provide customer and technical support;
  • To send administrative communications, service updates, and, where you have consented, marketing communications;
  • To maintain the security of our systems and the Services, including threat detection and incident response;
  • To carry out analytics and improve the Site and our Services; and
  • To comply with our legal, regulatory, and contractual obligations.

6. Lawful Basis for Processing

We rely on one or more of the following lawful bases under the DPA to process your personal data, depending on the context: (a) your consent; (b) the necessity of processing to perform a contract with you or take steps at your request before entering into a contract; (c) compliance with a legal obligation; or (d) our legitimate interests (such as maintaining the security of our Services and improving our offering), provided those interests are not overridden by your rights and freedoms.

7. Cookies & Tracking Technologies

The Site uses cookies and similar technologies (such as web analytics scripts) to operate the Site, remember your preferences, understand how the Site is used, and, where applicable, support marketing activities. Categories of cookies used may include strictly necessary, performance/analytics, and functionality cookies.

You can manage or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of the Site.

8. Data Sharing / Disclosure

We may share personal data with:

  • Our employees and personnel who need access to perform their roles;
  • Service providers and subcontractors who support our operations;
  • Government authorities or regulators, where required by law or to protect our legal rights;
  • Professional advisers, such as lawyers and auditors, where necessary; and
  • A buyer or successor entity, in the event of a merger, acquisition, or sale of assets.
  • We do not sell personal data to third parties.

9. Third-Party Processors

We engage third-party service providers to support delivery of our Services, which may include cloud hosting and infrastructure providers (such as Microsoft Azure and Amazon Web Services), email and collaboration platforms (such as Microsoft 365, Google Workspace, or Zoho Mail), analytics providers, customer relationship management (CRM) tools, and SSL/certificate providers. These providers process personal data on our behalf and are contractually bound to protect it and use it only for the purposes we specify.

10. International Data Transfers

Some of our third-party processors (including certain cloud and hosting providers referenced in Clause 10) may store or process personal data outside Kenya. Where this occurs, we take steps to ensure such transfers comply with the DPA, including verifying that the recipient country, or the recipient itself, provides an adequate level of data protection, or by putting in place appropriate contractual safeguards.

11. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including satisfying any legal, accounting, or reporting requirements. Retention periods vary by data category — for example, account data is generally retained for the duration of the relevant account plus 6 years, and billing records are retained for 7 years to meet tax and accounting obligations. Where data is no longer needed, we securely delete or anonymise it.

12. Data Security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, consistent with our broader cybersecurity practices (including identity and access management, encryption, and network security controls). While we take data security seriously, no system can be guaranteed to be completely secure.

13. Data Breach / Incident Response

In the event of a personal data breach, CRAG will assess the risk to affected individuals and, where required by the DPA, notify the Office of the Data Protection Commissioner without undue delay and, in any event, within the timeframe required by law. Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly where required to do so.

14. Data Subject Rights

Subject to applicable law, you have the right to: (a) access the personal data we hold about you; (b) request correction of inaccurate or incomplete data; (c) request deletion of your data; (d) object to or restrict certain processing; (e) request data portability; (f) withdraw consent at any time, where processing is based on consent; and (g) lodge a complaint with the Office of the Data Protection Commissioner.

15. How to Exercise Privacy Rights

To exercise any of the rights listed in Clause 15, please contact us at info@cragroup.co.ke . We may need to verify your identity before making your request. We will respond to valid requests within the timeframe required by the DPA (generally within seven days).

16. Children’s Privacy

Our Site and Services are intended for businesses and individuals acting in a professional capacity and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so that we can take appropriate action.

17. Automated Decision-Making / Profiling

Certain Services, such as our AI and machine learning solutions or Fraud Detection product, may involve automated analysis of data to generate insights, flag anomalies, or support decision-making. Where CRAG provides such Services to a client, the client, as the relevant data controller for its own end users, is responsible for ensuring appropriate safeguards and transparency around any automated decision-making applied to individuals. Where CRAG itself makes any automated decision with legal or similarly significant effect on an individual, we will provide information about the logic involved and your right to request human review, as required by the DPA.

18. Marketing Communications

Where you have consented to receive marketing communications from us, you may opt out at any time by using the unsubscribe link in our emails or by contacting us at info@cragroup.co.ke. Opting out of marketing communications will not affect service-related communications necessary for us to deliver a Service you have engaged us for.

19. Third-Party Links

The Site may contain links to third-party websites. This Policy does not apply to those websites, and we encourage you to review the privacy policies of any third-party site you visit.

20. Policy Changes

We may update this Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be communicated by posting a notice on the Site or updating the “Last Updated” date above. Your continued use of the Site or Services after changes take effect constitutes acceptance of the revised Policy.

21. Privacy Complaints

If you have concerns about how we handle your personal data, please contact us first at info@cragroup.co.ke so that we can resolve the matter directly. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner, Kenya.

22. Data Protection Officer / Privacy Contact

Our designated privacy contact can be reached at:

Email: info@cragroup.co.ke

Telephone: +254 20-2675208 / +254 20-2513222 / +254 20-2518713

Address: Nairobi, Kenya.