×

Privacy & Data Protection Policy

Expertech Electrical Contractors Ltd

Effective Date: 30 May 2021

Last Updated: 15 September 2025


Introduction

At Expertech Electrical Contractors Ltd (“Expertech”, “we”, “us”, or “our”), we are committed to protecting your privacy. This Privacy and Data Protection Policy explains the types of personal data we collect, the reasons for collecting it, how we process it, and how you can exercise your rights regarding your personal information.

This policy applies to all individuals including customers, suppliers, contractors, and visitors interacting with Expertech offices, systems, or websites.


Definitions

Customer

Individuals requesting electrical installation, maintenance, consultancy or related services.

Supplier / Contractor / Agent

Individuals or companies engaged to provide goods or services to Expertech.

Visitor

Any person accessing Expertech premises including subcontractors and third parties.

Personal Data

Information identifying a natural person such as names, identification numbers, and contact details.

Sensitive Personal Data

Data requiring additional protection including health records, biometric information, financial data, or property details.

Data Controller

Expertech Electrical Contractors Ltd which determines the purposes and means of processing personal data.


Collection of Information

We collect personal data when you:

  • Request electrical services such as installation, inspection, or maintenance
  • Contact us via phone, email, or website forms
  • Visit our offices or project sites
  • Engage with us as a contractor, supplier, or consultant
  • Participate in surveys, events, or promotions

We may also collect information from public records, government agencies, or utility partners where required.


Information We Collect

Identity Information

Name, national ID number, KRA PIN, email address, phone number, and physical address.

Service Details

Project location, property information, land ownership documents, and installation data.

Financial Information

Bank account details, invoices, payment records, and billing data.

Usage Data

Browser information, IP address, device details, and website interactions.

CCTV & Visitor Logs

Security camera recordings and visitor register records when accessing company premises.

Technical Installation Data

Operational data from installed systems where monitoring or maintenance services apply.


Use of Information

Your personal information may be used to:

  • Provide electrical installation, maintenance, and consultancy services
  • Process payments and issue invoices
  • Communicate service updates or technical notices
  • Meet regulatory requirements from EPRA, KPLC, REREC, or other authorities
  • Maintain site and workplace security
  • Conduct internal audits, surveys, and service improvements
  • Prevent fraud and protect company operations

Lawful Basis for Processing

Contractual Necessity

Processing required to provide requested services.

Legal Obligation

Compliance with statutory and regulatory requirements.

Consent

Where individuals opt-in to marketing or communications.

Legitimate Interests

Ensuring security, service quality, and business continuity.

Vital Interests

Protecting life or safety in emergency situations.


Retention of Data

Personal data is retained only for the period necessary to fulfill service delivery, legal compliance, and dispute resolution requirements.

Where possible, anonymized information may be retained indefinitely for statistical or research purposes.


Data Sharing Guidelines

Developers & Technical Partners

Limited access may be granted to internal or contracted software developers strictly for system development, troubleshooting, maintenance, or security testing. All such access is monitored and subject to confidentiality obligations.

Data may be shared based on:

  • Customer consent
  • Contractual necessity with subcontractors
  • Legal obligations to regulators such as EPRA, KPLC, REREC, or tax authorities
  • Legitimate interests such as fraud prevention or audits

All sharing follows strict safeguards including:

  • Formal data sharing agreements
  • Encrypted transfer methods
  • Secure file systems or VPN connections
  • Use of anonymized or aggregated data where possible

Data Security

Encryption

Sensitive data is protected through encryption technologies.

Secure Storage

Data is stored using secure infrastructure and backup systems.

Monitoring

Systems are monitored and audited to detect unauthorized access.

Staff Training

Employees receive training on confidentiality and data protection.


Data Breach Handling

  • Incidents are immediately reported to the Data Protection Officer.
  • Breaches are investigated and documented.
  • The Office of the Data Protection Commissioner (ODPC) is notified within 72 hours.
  • Affected individuals are informed promptly.
  • Preventive corrective actions are implemented.

Your Rights Under the Data Protection Act, 2019

Right to Be Informed

Understand how personal data is collected and used.

Right to Access

Request access to your personal information.

Right to Correction

Request correction or deletion of inaccurate data.

Right to Restrict Processing

Object to certain forms of data processing.

Right to Withdraw Consent

Withdraw previously given consent where applicable.

Right to Data Portability

Request transfer of your data in electronic format.

To exercise these rights contact: customercare@expertech.co.ke


Children’s Privacy

Expertech services are not directed to individuals under the age of 18. If such data is identified it will be deleted promptly.


International Data Transfers

Where data is transferred outside Kenya (for example through cloud hosting providers), appropriate safeguards will be implemented to comply with the Data Protection Act, 2019.


Training & Awareness

  • Regular staff training on data protection practices
  • Internal awareness campaigns on data protection compliance
  • Mandatory reporting of suspected data breaches

Right to Lodge Complaint

Individuals may file complaints with the Office of the Data Protection Commissioner (ODPC) if they believe their rights have been violated.


Non-Compliance

Expertech reserves the right to terminate agreements with employees, contractors, or suppliers who violate this policy.


Updates to This Policy

This policy may be revised periodically. The latest version will always be available on our website.


Contact Us

Expertech Electrical Contractors Ltd

Email: customercare@expertech.co.ke

Website: www.expertech.co.ke

   We are Online