Legal and data protection
Privacy and data protection policy
Effective date: 5 October 2026 · Version 1.3
This Privacy & Data Protection Policy explains how HeriBMS, operated by IHL Tech Africa, handles personal information when you visit our website, create an account, use a business workspace, contact our team, or otherwise interact with our services.
Important: HeriBMS does not process health or medical information as part of its intended use. Where a business uses HeriBMS to manage customer, order and inventory information, the business will generally determine the purposes and means of that processing and may act as the data controller. HeriBMS may process that information on the business's instructions as a data processor, subject to the applicable agreement and Kenyan law.
1. Who we are
HeriBMS is a business management platform operated by IHL Tech Africa. We provide technology that helps businesses organise operational workflows, staff access, customer records, inventory, orders, accounts and reporting.
For privacy questions, requests or concerns, contact us at invest@investit.click.
2. Scope
This policy applies to the HeriBMS website, trial workspaces, business workspaces, account-management features and related services that link to this policy.
It should be read together with our Terms of Service and, where applicable, a Data Processing Addendum or other agreement with a business.
3. Information we process
Website and enquiry information
We may process your name, email address, telephone number, business or organisation details, messages and information you provide when requesting a demo or contacting us.
Account and workspace information
We may process your name, email address, role, business membership, authentication information, account status, invitation records and workspace activity needed to operate the service.
Customer, order and inventory information
A business may enter information about its customers, orders, products, stock, invoices, payments, staff and other operational records into its HeriBMS workspace. This information is ordinary business and commercial data; it does not include health or medical information as part of the service's intended use. We process this information only as permitted by applicable law and, where HeriBMS acts as processor, according to the business's documented instructions.
Technical and security information
We may process IP addresses, device and browser information, authentication events, audit records, error information and other technical information necessary to secure and operate the service.
4. Why we process information
- to create and administer business workspaces and user accounts;
- to provide, maintain and improve HeriBMS;
- to authenticate users and enforce role-based access;
- to maintain audit and security records;
- to respond to support, demo and trial requests;
- to prevent fraud, misuse and unauthorised access;
- to meet legal, regulatory and contractual obligations; and
- to protect the rights, safety and security of our users, businesses and service.
5. Lawful bases
Depending on the context, we may rely on consent, performance of a contract, compliance with a legal obligation, legitimate interests, or another lawful basis recognised by applicable Kenyan data-protection law.
Where a business is the controller of customer information, the business is responsible for identifying and documenting the appropriate lawful basis for its processing. HeriBMS does not treat use of the platform as a blanket substitute for a business's own consent or legal requirements toward its customers.
6. Businesses and customer information
Businesses are responsible for determining why customer information is collected and how it is used, ensuring that collection and use are lawful, providing required notices, managing customer rights, and configuring user access appropriately.
HeriBMS is designed to support least-privilege access, individual staff accounts and accountable business workflows. Businesses should not share staff credentials and should promptly remove or change access when a staff member leaves or changes responsibilities.
7. Access, roles and confidentiality
Access to business information is intended to be limited according to assigned roles and permissions. We maintain technical and organisational measures intended to protect information against unauthorised access, disclosure, alteration, loss or destruction.
Users are responsible for protecting their credentials and for using information only for authorised business purposes.
9. International transfers
Some technology providers may process information outside Kenya. Where personal information is transferred outside Kenya, we will apply the safeguards required by applicable Kenyan data-protection law and the circumstances of the transfer.
We will not describe information as being stored exclusively in Kenya unless the underlying infrastructure and configuration actually support that statement.
10. Security
We use reasonable technical and organisational safeguards appropriate to the nature and risk of the information we process. These may include access controls, authentication controls, encryption where appropriate, audit logging, secure development practices, backups, monitoring and security reviews.
No internet-based system can be guaranteed to be completely secure. We continuously work to identify and reduce security risks and expect businesses and users to maintain appropriate access and credential practices.
11. Retention and deletion
We keep personal information only as long as we need it for the service, our legal obligations, resolving disputes and security. In particular:
- While a business uses HeriBMS, its records stay in its workspace. The business decides what to keep, and its administrators can export or erase a customer's details at any time.
- A trial that ends without a licence: the workspace, with its records and staff accounts, is deleted 90 days after the trial ends, or after the workspace was last used if that is later.
- A licensed business whose yearly fee is not paid: the workspace becomes read-only, and is deleted 12 months after the last paid year ends, or after it was last used if that is later.
- Our own billing records (licence and yearly-fee payments, and invoices from IHL Tech Africa to a business) are kept for 7 years: Kenyan tax law requires five, and contract claims can be brought for six. The business's name and code are kept with them.
- Platform administration audit records are kept for 7 years.
- Support messages are kept for 24 months after they are resolved.
- Marketplace alerts are kept for 12 months.
- A supplier account is kept while it is open. A supplier can ask us to close it and delete its details; orders businesses placed with it stay in those businesses' records.
- Sign-in sessions are deleted when they expire, and sign-in attempt counters after one day.
Kenyan tax law generally requires a business to keep its sales and payment records for at least five years. HeriBMS is not a substitute for that duty once a workspace has been deleted, so a business should export its records before its workspace is deleted. A locked or read-only workspace can still sign in to export.
Deleted data can remain in our database provider's backups until those backups expire, and is not restored from them except to recover from an incident.
12. Data-subject rights
Subject to applicable law and any lawful limitations, data subjects may have rights including the right to be informed, access personal information, request correction, object to processing, request erasure where applicable, restrict processing and request portability.
Where HeriBMS processes information for a business as a processor, requests relating to customer information may need to be directed to the relevant business as controller. We will reasonably assist the business with lawful requests where required by our agreement and applicable law.
13. Security incidents and breaches
We maintain processes for identifying, assessing and responding to security incidents. Where an incident involves personal information processed on behalf of a business, we will follow the incident-notification and cooperation requirements in the applicable agreement and law.
14. Children and minors
HeriBMS is a professional business-management service and is not directed at children as direct users. We do not knowingly collect personal information from children through the service.
16. Changes to this policy
We may update this policy when our services, legal obligations or data-processing practices change. We will publish the updated version with a new effective date. Material changes may be communicated through the service or another appropriate channel.
17. Contact and complaints
For privacy questions or requests, contact invest@investit.click.
If you believe your personal information has been handled in a way that infringes your rights, you may also seek appropriate remedies under Kenyan law, including through the Office of the Data Protection Commissioner (ODPC).