A division of Jiranisoko Market Ltd
Jiranisoko Tech

Legal

Privacy notice

This notice explains what personal data we collect when you use this website or deal with us, why we hold it, how long we keep it and what you can require of us. It covers data for which we are the controller. Where we process personal data on a client's instructions we are a processor, and the data processing addendum governs that instead.

Controller
Jiranisoko Market Ltd (PVT-YQ195JQY), a company incorporated in the Republic of Kenya, acting through its Jiranisoko Tech Solutions division. Correspondence to P.O. Box 91-30105, Soy, Eldoret, Kenya.
Data protection contact
Our Data Protection Officer, at privacy@jiranisokotech.co.ke. This is a monitored role address, not an individual, so a leave or a departure never orphans a request.
Version
1.0, effective 9 September 2026.

What we collect, and why

Everything below is something this site or this business actually does. We have not listed categories we do not collect in order to look thorough.

What Why we hold it Lawful basis How long
Request for proposal
Organisation, your name and role, business email, telephone, country, indicative budget band, timeline, a description of the scope, the disciplines you are interested in, and whether you want an NDA first.
To answer your enquiry, prepare a proposal and run the engagement that may follow. Steps taken at your request before entering a contract; and our legitimate interest in responding to business enquiries. Twenty-four months from the last contact, unless it becomes an engagement, in which case it is kept for the life of the engagement and seven years after it, for tax and limitation purposes.
Submission metadata
The IP address the submission came from and the page you came from.
To detect and investigate abuse of the form, and to evidence when and from where a submission arrived if it is ever disputed. Our legitimate interest in the security and integrity of our systems. Deleted with the submission it belongs to.
Correspondence
Whatever you put in an email to one of our role addresses, and our reply.
To deal with what you wrote to us about and keep a record of what was agreed. Performance of a contract, or our legitimate interest in handling correspondence. Twenty-four months from the end of the exchange, or seven years where it records something contractual.
Job applications
Your CV and anything you send with it, sent to careers@jiranisokotech.co.ke.
To assess you for the role you applied for. Steps taken at your request before entering a contract of employment. Six months after the role is filled or withdrawn. Longer only if you ask us to keep you on file, which we will confirm in writing.
Session cookies
A session cookie and a cross-site request forgery token.
To make the forms on this site work and to protect them from being submitted from another site in your name. Strictly necessary. No consent banner is shown because there is nothing to consent to. The browser session, or two hours of inactivity, whichever ends first.
Server logs
Requests to the site, with IP address, time, page and browser.
To keep the service running and to investigate faults and attacks. Our legitimate interest in operating and securing the service. As configured by our hosting provider. We do not mine these logs for any purpose beyond operations and security.

What this site does not do

These are worth stating because they are unusual, and because they are the reason this page is short.

  • No analytics. We do not run Google Analytics or any equivalent, and we do not know how many people read any given page.
  • No advertising, no remarketing, no tracking pixels, no social media embeds.
  • No third-party fonts or content delivery network. Every font, image and script is served from this domain, so your IP address is not disclosed to a third party by loading a page here.
  • No profiling and no automated decision-making that produces legal or similarly significant effects.
  • We do not sell personal data, and we do not share it for anyone else's marketing.

Who else sees it

Personal data you give us is seen by the people in this firm who need it for the purpose it was collected for, and by the service providers that run our infrastructure. Those providers are named in the sub-processor register, which states each one's role, where it processes data and the safeguard relied upon.

We will also disclose personal data where we are legally required to — to a court, a regulator, or the Office of the Data Protection Commissioner. Where we are permitted to tell you that we have done so, we will.

Where it is processed

Our infrastructure is provided by a Kenyan company and we do not transfer personal data out of Kenya for our own purposes. Where any processing does take place outside Kenya, the sub-processor register states it and the safeguard relied upon, which will be an adequacy finding, appropriate safeguards recognised by the Kenya Data Protection Act 2019, or standard contractual clauses where the GDPR also applies.

Your rights

Under the Kenya Data Protection Act 2019, and under the GDPR where it applies to you, you may:

Be informed
Know how your personal data is being used. That is what this notice is for.
Access
Obtain a copy of the personal data we hold about you.
Correct
Have inaccurate or incomplete data corrected or completed.
Delete
Have data erased where we no longer have a good reason to hold it.
Object and restrict
Object to processing we carry out on the basis of legitimate interests, and ask us to restrict processing while an objection or a correction is being resolved.
Portability
Receive data you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where that is technically feasible.
Withdraw consent
Where we rely on consent, withdraw it at any time. That does not affect processing already carried out.

To exercise any of these, write to privacy@jiranisokotech.co.ke. We will acknowledge within one business day and respond substantively within thirty days. If a request is complex we may extend that, and we will tell you why before the thirty days are up rather than after. We do not charge for this. We may ask you to verify your identity, and we will ask for no more than is necessary to do so.

If you are not satisfied with how we have handled your data or your request, you may complain to the Office of the Data Protection Commissioner in Kenya, or to the supervisory authority where you live if the GDPR applies to you. We would rather you raised it with us first, but you are not obliged to.

How it is protected

Connections to this site are encrypted in transit. Access to submitted data is limited to the people who need it, granted by named post rather than shared account, and withdrawn when someone's role changes. Passwords to our systems are stored only as one-way hashes. The specific technical and organisational measures we operate are listed in Annex 2 of the data processing addendum, including the measures we do not yet operate, because a controller assessing us is better served by an accurate list than a flattering one.

If a breach affects your personal data and is likely to result in a risk to your rights and freedoms, we will notify the Data Commissioner within seventy-two hours of becoming aware of it, and tell you without undue delay where the risk to you is high.

Changes to this notice

This notice carries a version number and an effective date, both shown at the top. When we change it materially we will say what changed and when it takes effect, and where the change affects data we already hold on the basis of your consent, we will ask again rather than assume.