ROMER SERVICES DATA PRIVACY POLICY
Last updated: June 24, 2025
About Us
Romer Services Limited is a leading data governance consultancy firm based in Kenya. We specialize in offering tailored data protection services to organizations, helping them navigate compliance, implement best practices, and manage personal data responsibly. Our marketing efforts are designed to keep our clients and prospects informed about our products, services, thought leadership content, and industry developments.
We value your privacy and are dedicated to protecting your personal information in accordance with the Kenya Data Protection Act (2019) and other applicable laws.
This Privacy Policy describes our policies and procedures on the collection, use and disclosure of your information when you interact with our Services and tells you about your privacy rights and how the law protects you.
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
- Affiliate means an entity that controls, is controlled by or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
- Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to Romer Services Limited.
- Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
- Country refers to: Kenya
- Device means any device that can access the website such as a computer, a cellphone or a digital tablet.
- Personal Data is any information that relates to an identified or identifiable individual.
- Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Services, to provide the Services on behalf of the Company.
- Usage Data refers to data collected automatically, either generated by the use of the website or from the website infrastructure itself (for example, the duration of a page visit).
- Website refers to Romer website, accessible from:
https://www.romer.co.ke/
- You means the individual accessing or using our Services, or the company, or other legal entity on behalf of which such individual is accessing or using our Services, as applicable.
Collecting and Using Your Personal Data
Types of Data Collected
Personal Data
Personal Information will differ based on our relationship (e.g. Members, Employees, Business Partner, Prospective Members) including the type of communications between us and the services we provide. Most of the personal information we process is provided to us directly by you through sources such as:
- Application forms or other documents you complete
- Our website (http://www.romer.co.ke/).
- Telephone conversations, emails, or meetings with us.
Personally identifiable information may include, but is not limited to:
- Email address
- First and last name
- Phone number
- Email Address
- Employment history
- Educational background
- Profession
- Usage Data
Usage Data
Usage Data is collected automatically when using the website.
Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the time and date You visit our website, the time spent on the page, unique device identifiers and other diagnostic data.
When You access the website by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit our website or when You access the website by or through a mobile device.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
- For the performance of a contract such as delivering products or services you have purchased
- To contact You via email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
- To provide You with news, special offers and general information about similar goods, services and events upon obtaining your consent
- To manage Your requests and respond to inquiries or complaints.
- To improve our services and train staff through data analysis and usage trends
We may share Your personal information in the following situations:
- With Service Providers: We may share Your personal information with Service Providers to monitor, analyze the use of our Services, to enhance our services or to contact You.
- With Government Authorities: When required by law, such as the office of the Data Protection Commissioner (ODPC)
- With Business Partners: Such as reinsurers or legal advisors, to fulfil contractual or legal obligations
- With Your consent: We may disclose Your personal information for any additional purpose you explicitly agree to.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service.
Typically, for consumer financial products, the retention period is seven 7 years.
Your Rights Under The Kenya Data Protection Act (2019)
You have the following rights regarding your personal data:
- Right to Access: You may request copies of your personal information.
- Right to Rectification: You may ask Us to correct inaccurate or incomplete data
- Right to Erasure: You may request deletion of your data in certain circumstances.
- Right to Restriction of Processing: You may limit how We process Your data in specific cases
- Right to object to Processing: You may object to certain uses of your data
- Right to Data Portability: You may request Your data to be transferred to another entity or to You
These rights are subject to applicable laws. Requests are free, and we will respond within one month. Contact us at privacy@romer.co.ke to exercise these rights.
Transfer of Your Personal Data
Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to and maintained on computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction.
Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer.
The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.
International Data Transfers:
Prior to transferring personal data outside Kenya, we shall ascertain that the transfer is based on the provided legal and regulatory standards. Circumstances in which we may transfer your personal data outside Kenya are highlighted in the table below;
- When following your express consent, we transfer your personal data to another jurisdiction.
- There being appropriate data protection safeguards with respect to the security and protection of personal data in respect to the jurisdiction to which the data is being transferred to.
- Storage of your personal data in a cloud whose data server is located in one of the European countries that is implemented the General Data Protection Regulation (GDPR).
- When we reinsure your risk as part of our legitimate interest and the re-insurance company requests for your personal data in respect to the insurance policy.
Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You. You may also contact Us to request access to, correct, or delete any personal information that You have provided to Us.
Please note, however, that We may need to retain certain information when we have a legal obligation or lawful basis to do so.
Disclosure of Your Personal Data
Law enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Other legal requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Protect the personal safety of Users or the public
- Protect against legal liability
Security of Your Personal Data
Your information is securely stored Zoho Severs.
Information security is extremely important to us. We put in place technical and physical security measures to keep Personal Information safe and secure. If, despite our efforts, you believe that Personal Information is no longer secure, please tell us so that we can resolve any security issue.
Romer Services Limited uses appropriate technical, physical, legal and organisational measures, which comply with data protection laws to keep Personal Information secure. As most of the Personal Information we hold is stored electronically we have implemented appropriate IT security measures to ensure this Personal Information is kept secure.
For example, we may use anti-virus protection systems, firewalls, and data encryption technologies. We have procedures in place at our premises to keep any hard copy records physically secure. We also train our staff regularly on data protection and information security.
The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.
How to Complain
If You have concerns about Our use of Your personal information, please contact Us at:
- Email: privacy@romer.co.ke
- Phone: +254 739 770031
You may also lodge a complaint with the Office of the Data Protection Commissioner:
- Address: Britam Tower, Hospital Road, Upperhill, Nairobi, P.O. Box 30920-00100, G.P.O Nairobi
- Email:info@odpc.co.ke
- Phone: 0796954269 / 0778048164
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and update the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, You can contact us:
- By email: privacy@romer.co.ke
- By visiting this page on our website: https://www.romer.co.ke/
- By phone number: +254 739 770031