Skip to content
Domexa Technologies

Privacy policy

Last updated August 2026

Two different relationships are covered here, and the difference matters. For this website we decide what is collected, so we are the data controller. For the records an agency keeps inside the product, the agency decides and we act on their instructions, so we are their processor. Written to comply with Kenya's Data Protection Act, 2019.

1. Who we are

Domexa Technologies Ltd (“Domexa Technologies”, “we”), registered in Nairobi, Kiambu County. This policy covers this website (domexatechnologiesltd.com) and, at the level described in section 3, the Domexa Technologies products.

Questions, requests and complaints go to hello@domexatechnologiesltd.com, which reaches the person responsible for data protection here.

2. What this website collects

Only what a form asks for directly:

  • Contact form: your name, email, phone (optional) and your message.
  • Demo request: your name, email, business name and approximate unit count, so the demo is about your situation rather than a generic one.
  • Cookie-less analytics: aggregate page views and interactions that do not identify you. See the cookie policy.
  • Spam protection: a challenge from our anti-spam provider may process technical signals from your browser when you submit a form.

We do not ask for a password, ID number or payment details on this website, and there is no account to create here.

3. Data inside the product

When an agency, landlord or builder uses Domexa Technologies, they put personal data into it: tenant names and contacts, ID numbers, lease terms, payment histories, staff accounts, site attendance. For all of that:

  • They are the controller. They decide what to collect, why, and how long to keep it. We process it on their documented instructions and for no other purpose.
  • We do not sell it, rent it, or use it to train anything. It is not repackaged as market insight and it is not shared with other customers.
  • We access it only to run the service: to fix a fault, restore a backup, or when the customer asks us to help with something specific. That access leaves a trail like any other action.

If you are a tenant and want to know what is held about you, or want it corrected, ask your agency first: it is their record. Domexa Technologies Tenant also shows you your own bills, payments and deposit directly.

4. Why we are allowed to process it

  • Consent: for the website forms, given when you submit one. You can withdraw it at any time.
  • Contract: to provide the service to a customer who has subscribed, and to bill for it.
  • Legitimate interest: responding to enquiries, keeping the service secure, and understanding in aggregate which pages are useful.
  • Legal obligation: tax, accounting and record-keeping duties that apply to any company.

5. Who we share data with

Only the categories of processor below, each under a contract that limits them to our instructions. We do not sell personal data to anyone, in any circumstances.

  • Our hosting provider, to run the site and the product.
  • Our email delivery provider, to route form submissions and product notifications.
  • Our SMS provider, for product notifications (not this website).
  • Our cookie-less analytics provider.
  • Our anti-spam provider, for form submissions.
  • A licensed payment aggregator for product payments. Domexa Technologies itself never holds client funds.

We may also disclose data where we are legally required to. If that ever happens and we are permitted to tell the affected customer, we will.

6. Where it is stored

Some of the providers above operate infrastructure outside Kenya. Where personal data is transferred outside the country, we rely on the safeguards required by the Data Protection Act, 2019 and contract terms that hold the provider to standards equivalent to our own. We will name the current providers to any customer who asks.

7. How long we keep it

  • Contact and demo enquiries: as long as reasonably needed to respond and, if you become a customer, as part of that relationship. Otherwise up to 24 months from your last contact.
  • Customer account records: for the life of the subscription, then for the period we are required to keep financial records.
  • Data inside a customer's account: for as long as the customer keeps it. After an account closes we delete it, other than what we must legally retain.
  • Backups: cycle out on a rolling schedule, so deleted data may persist briefly in a backup before being overwritten.

8. How it is protected

  • Encrypted in transit and at rest.
  • Access inside an account is by role, so people see only what their job needs.
  • Records are append-only where they matter: a correction is a new entry and the original stays visible, including to us.
  • Backed up, with restores tested rather than assumed.
  • Staff access to production is limited, logged, and removed when someone leaves.

No system is perfectly secure, and we would rather say so than imply otherwise. If a breach affects your data we will notify you and the Data Commissioner as the Act requires, and tell you what we know rather than waiting until we know everything.

9. Your rights

Under the Data Protection Act, 2019 you can ask us to:

  • Confirm whether we hold data about you, and give you a copy.
  • Correct it where it is wrong or incomplete.
  • Delete it where we have no lawful reason to keep it.
  • Restrict or object to how we use it.
  • Provide it in a portable format.
  • Withdraw consent, where consent is what we relied on.

Write to hello@domexatechnologiesltd.com. We will respond within the period the Act allows, and we will not charge you for a reasonable request. Where the data sits inside a customer's account, we will pass your request to them as the controller and tell you we have done so.

If you are not satisfied with how we handle a request, you may complain to the Office of the Data Protection Commissioner. We would appreciate the chance to put it right first.

10. Children

Our products are for businesses and the adults who deal with them. We do not knowingly collect data from children, and we do not market to them. If you believe a child's data has reached us, tell us and we will remove it.

11. Changes to this policy

We will update this policy as the product and our providers change. The “last updated” date above always reflects the current version, and for material changes affecting customers we will give notice by email or in the product rather than quietly editing the page.