HeriBMSBack to home

Legal and data protection

Privacy and data protection policy

Effective date: 5 October 2026 · Version 1.3

This Privacy & Data Protection Policy explains how HeriBMS, operated by IHL Tech Africa, handles personal information when you visit our website, create an account, use a business workspace, contact our team, or otherwise interact with our services.

Important: HeriBMS does not process health or medical information as part of its intended use. Where a business uses HeriBMS to manage customer, order and inventory information, the business will generally determine the purposes and means of that processing and may act as the data controller. HeriBMS may process that information on the business's instructions as a data processor, subject to the applicable agreement and Kenyan law.

Contents

  1. 1.Who we are
  2. 2.Scope
  3. 3.Information we process
  4. 4.Why we process information
  5. 5.Lawful bases
  6. 6.Businesses and customer information
  7. 7.Access, roles and confidentiality
  8. 8.Sharing and service providers
  9. 9.International transfers
  10. 10.Security
  11. 11.Retention and deletion
  12. 12.Data-subject rights
  13. 13.Security incidents and breaches
  14. 14.Children and minors
  15. 15.Cookies and analytics
  16. 16.Changes to this policy
  17. 17.Contact and complaints

1. Who we are

HeriBMS is a business management platform operated by IHL Tech Africa. We provide technology that helps businesses organise operational workflows, staff access, customer records, inventory, orders, accounts and reporting.

For privacy questions, requests or concerns, contact us at invest@investit.click.

2. Scope

This policy applies to the HeriBMS website, trial workspaces, business workspaces, account-management features and related services that link to this policy.

It should be read together with our Terms of Service and, where applicable, a Data Processing Addendum or other agreement with a business.

3. Information we process

Website and enquiry information

We may process your name, email address, telephone number, business or organisation details, messages and information you provide when requesting a demo or contacting us.

Account and workspace information

We may process your name, email address, role, business membership, authentication information, account status, invitation records and workspace activity needed to operate the service.

Customer, order and inventory information

A business may enter information about its customers, orders, products, stock, invoices, payments, staff and other operational records into its HeriBMS workspace. This information is ordinary business and commercial data; it does not include health or medical information as part of the service's intended use. We process this information only as permitted by applicable law and, where HeriBMS acts as processor, according to the business's documented instructions.

Technical and security information

We may process IP addresses, device and browser information, authentication events, audit records, error information and other technical information necessary to secure and operate the service.

4. Why we process information

  • to create and administer business workspaces and user accounts;
  • to provide, maintain and improve HeriBMS;
  • to authenticate users and enforce role-based access;
  • to maintain audit and security records;
  • to respond to support, demo and trial requests;
  • to prevent fraud, misuse and unauthorised access;
  • to meet legal, regulatory and contractual obligations; and
  • to protect the rights, safety and security of our users, businesses and service.

5. Lawful bases

Depending on the context, we may rely on consent, performance of a contract, compliance with a legal obligation, legitimate interests, or another lawful basis recognised by applicable Kenyan data-protection law.

Where a business is the controller of customer information, the business is responsible for identifying and documenting the appropriate lawful basis for its processing. HeriBMS does not treat use of the platform as a blanket substitute for a business's own consent or legal requirements toward its customers.

6. Businesses and customer information

Businesses are responsible for determining why customer information is collected and how it is used, ensuring that collection and use are lawful, providing required notices, managing customer rights, and configuring user access appropriately.

HeriBMS is designed to support least-privilege access, individual staff accounts and accountable business workflows. Businesses should not share staff credentials and should promptly remove or change access when a staff member leaves or changes responsibilities.

7. Access, roles and confidentiality

Access to business information is intended to be limited according to assigned roles and permissions. We maintain technical and organisational measures intended to protect information against unauthorised access, disclosure, alteration, loss or destruction.

Users are responsible for protecting their credentials and for using information only for authorised business purposes.

8. Sharing and service providers

We do not sell personal information. We may disclose or permit access to information where necessary to provide the service, comply with law, protect the service, respond to a lawful request, or otherwise as permitted by the applicable agreement.

Where supplier or marketplace features are enabled, information necessary to place and fulfil an order (such as contact and order details) may be shared between the business and the relevant supplier account as part of that transaction.

Suppliers can add product photos to their listings. HeriBMS resizes each photo and removes the details cameras store in it, such as location and device, before keeping it in a private storage bucket run by Cloudflare, our storage provider. Photos are shown to businesses using the marketplace, and are deleted when the supplier replaces or removes them or HeriBMS takes them down.

We may use carefully selected technology and service providers to support hosting, infrastructure, security, communications, monitoring, support and other service functions. Where they process personal information on our behalf, we seek to require appropriate confidentiality and data-protection obligations.

9. International transfers

Some technology providers may process information outside Kenya. Where personal information is transferred outside Kenya, we will apply the safeguards required by applicable Kenyan data-protection law and the circumstances of the transfer.

We will not describe information as being stored exclusively in Kenya unless the underlying infrastructure and configuration actually support that statement.

10. Security

We use reasonable technical and organisational safeguards appropriate to the nature and risk of the information we process. These may include access controls, authentication controls, encryption where appropriate, audit logging, secure development practices, backups, monitoring and security reviews.

No internet-based system can be guaranteed to be completely secure. We continuously work to identify and reduce security risks and expect businesses and users to maintain appropriate access and credential practices.

11. Retention and deletion

We keep personal information only as long as we need it for the service, our legal obligations, resolving disputes and security. In particular:

  • While a business uses HeriBMS, its records stay in its workspace. The business decides what to keep, and its administrators can export or erase a customer's details at any time.
  • A trial that ends without a licence: the workspace, with its records and staff accounts, is deleted 90 days after the trial ends, or after the workspace was last used if that is later.
  • A licensed business whose yearly fee is not paid: the workspace becomes read-only, and is deleted 12 months after the last paid year ends, or after it was last used if that is later.
  • Our own billing records (licence and yearly-fee payments, and invoices from IHL Tech Africa to a business) are kept for 7 years: Kenyan tax law requires five, and contract claims can be brought for six. The business's name and code are kept with them.
  • Platform administration audit records are kept for 7 years.
  • Support messages are kept for 24 months after they are resolved.
  • Marketplace alerts are kept for 12 months.
  • A supplier account is kept while it is open. A supplier can ask us to close it and delete its details; orders businesses placed with it stay in those businesses' records.
  • Sign-in sessions are deleted when they expire, and sign-in attempt counters after one day.

Kenyan tax law generally requires a business to keep its sales and payment records for at least five years. HeriBMS is not a substitute for that duty once a workspace has been deleted, so a business should export its records before its workspace is deleted. A locked or read-only workspace can still sign in to export.

Deleted data can remain in our database provider's backups until those backups expire, and is not restored from them except to recover from an incident.

12. Data-subject rights

Subject to applicable law and any lawful limitations, data subjects may have rights including the right to be informed, access personal information, request correction, object to processing, request erasure where applicable, restrict processing and request portability.

Where HeriBMS processes information for a business as a processor, requests relating to customer information may need to be directed to the relevant business as controller. We will reasonably assist the business with lawful requests where required by our agreement and applicable law.

13. Security incidents and breaches

We maintain processes for identifying, assessing and responding to security incidents. Where an incident involves personal information processed on behalf of a business, we will follow the incident-notification and cooperation requirements in the applicable agreement and law.

14. Children and minors

HeriBMS is a professional business-management service and is not directed at children as direct users. We do not knowingly collect personal information from children through the service.

15. Cookies and analytics

We may use essential cookies and similar technologies required for authentication, security and service functionality. If we introduce non-essential analytics, advertising or similar technologies, we will provide appropriate information and choices where required.

16. Changes to this policy

We may update this policy when our services, legal obligations or data-processing practices change. We will publish the updated version with a new effective date. Material changes may be communicated through the service or another appropriate channel.

17. Contact and complaints

For privacy questions or requests, contact invest@investit.click.

If you believe your personal information has been handled in a way that infringes your rights, you may also seek appropriate remedies under Kenyan law, including through the Office of the Data Protection Commissioner (ODPC).

Questions?

Email invest@investit.click or call 0181 660 123. We are happy to explain anything on this page.