1. Introduction
Croma Interactive Limited ("CromaHR", "we", "us", or "our") is registered with the Office of the Data Protection Commissioner (ODPC) under the Kenya Data Protection Act, 2019. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use CromaHR, our human resources and payroll software platform (the "Service").
This policy applies to two categories of personal data we process:
- Customer Data: Personal data of your employees that you submit to the Service for HR and payroll processing. In this relationship, you are the data controller and we are the data processor.
- User Data: Personal data of the individuals who register for and use the Service on behalf of our customers, such as account administrators and HR managers.
2. Data We Collect
2.1 Customer Data (Employee Records)
To provide the Service, you submit personal data about your employees, which may include:
- Identification details: name, national ID number, KRA PIN, NSSF number, NHIF/SHIF number;
- Contact information: address, phone number, email address;
- Employment information: job title, department, hire date, salary, bank account details, contract type;
- Attendance and leave records: time worked, leave taken, leave balances;
- Payroll information: gross pay, statutory deductions, net pay, allowances, benefits;
- Documents: employment contracts, payslips, tax certificates, identification document copies.
2.2 User Data (Account Users)
When you register for the Service, we collect:
- Your name, work email address, and phone number;
- Your company name, industry, and number of employees;
- Account credentials and login activity;
- Communications you send to us, such as support requests and feedback.
2.3 Technical Data
We automatically collect certain technical information when you access the Service:
- IP address, browser type, and device information;
- Pages visited within the Service and timestamps;
- Usage analytics to help us improve the Service.
3. How We Use Your Data
We process personal data for the following purposes:
- Providing the Service: calculating payroll, generating payslips, filing statutory returns, managing employee records, and producing reports;
- Account management: creating and managing your account, authenticating users, and providing support;
- Compliance: meeting our obligations under Kenyan tax, employment, and data protection law, including filing returns with KRA, NSSF, SHIF/NHIF, and HELB where applicable;
- Service improvement: analysing usage patterns to fix bugs, improve features, and develop new functionality;
- Communication: sending you service notifications, billing updates, and important product information;
- Security: detecting and preventing fraud, unauthorised access, and other security threats.
4. Legal Basis for Processing
Under the Kenya Data Protection Act, 2019, we process personal data on the following legal bases:
- Consent: where you have given us explicit consent to process personal data for a specific purpose;
- Contract: where processing is necessary to provide the Service under our subscription agreement with you;
- Legal obligation: where processing is required to comply with Kenyan tax, employment, or data protection law;
- Legitimate interest: where processing is necessary for our legitimate business operations, such as security and service improvement, and does not override your rights.
5. Data Sharing and Disclosure
We do not sell your personal data. We may share it in the following circumstances:
5.1 Statutory Bodies
As part of payroll processing, we may be required to file returns and submit data to Kenyan government bodies on your behalf, including:
- Kenya Revenue Authority (KRA), PAYE, payroll taxes;
- National Social Security Fund (NSSF);
- State Department for Social Health Insurance (SHIF, formerly NHIF);
- Higher Education Loans Board (HELB);
- Other statutory bodies as required by law.
5.2 Service Providers
We use third-party providers to deliver certain aspects of the Service, such as cloud hosting, email delivery, and payment processing. These providers have access to personal data only as necessary to perform their services and are bound by confidentiality and data protection obligations.
5.3 Legal Requirements
We may disclose personal data where required by law, court order, or government authority, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
6. Data Retention
We retain personal data only for as long as necessary to provide the Service and to meet our legal obligations:
- Active subscriptions: Customer Data is retained for the duration of your subscription. Upon termination, we make your data available for export for thirty (30) days;
- After termination: we delete Customer Data within ninety (90) days of the end of the export period, unless we are legally required to retain it for longer;
- Tax records: payroll-related data may be retained for up to seven (7) years as required under Kenyan tax law;
- Free trial data: data submitted during a free trial may be deleted within sixty (60) days after the trial ends, unless you convert to a paid subscription.
7. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS and at rest using industry-standard encryption;
- Role-based access controls, only authorised personnel can access personal data, and only to the extent necessary for their role;
- Regular security assessments and penetration testing;
- Audit logs of data access and system activity;
- Staff training on data protection and security practices.
Despite these measures, no system can be guaranteed to be completely secure. If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ODPC and affected individuals within seventy-two (72) hours, as required by the Data Protection Act, 2019.
8. Your Rights Under the Data Protection Act
Under the Kenya Data Protection Act, 2019, data subjects have the following rights:
- Right to be informed: the right to know what personal data is being collected and how it is being used;
- Right of access: the right to request a copy of the personal data we hold about you;
- Right to rectification: the right to request correction of inaccurate or incomplete personal data;
- Right to erasure: the right to request deletion of your personal data, subject to legal retention obligations;
- Right to data portability: the right to receive your personal data in a structured, machine-readable format;
- Right to object: the right to object to processing based on legitimate interests or for direct marketing;
- Right to restrict processing: the right to request that we limit how we use your data while a request is being reviewed.
To exercise any of these rights, contact us using the details in Section 11. We will respond within thirty (30) days of receiving a valid request.
For Customer Data (employee records), these rights are generally exercised through the employer, as the employer is the data controller. We will assist employers in fulfilling data subject requests where requested.
9. Cross-Border Data Transfers
The Service is hosted on cloud infrastructure that may store data outside Kenya. Where personal data is transferred outside Kenya, we ensure that:
- The receiving country provides an adequate level of data protection, or;
- Appropriate safeguards are in place, such as standard contractual clauses, and;
- The transfer is necessary for the performance of the contract or compliance with a legal obligation.
We comply with the ODPC's guidance on cross-border data transfers under the Data Protection Act, 2019.
10. Cookies and Tracking
The Service uses essential cookies to maintain user sessions and enable core functionality. We also use analytics tools to understand how the Service is used and to improve it. We do not use cookies for advertising or third-party tracking.
You can control cookies through your browser settings. Disabling essential cookies will prevent you from logging into the Service.
11. Contacting Us and the ODPC
If you have any questions about this Privacy Policy or how we handle your personal data, please contact our Data Protection Officer:
You also have the right to lodge a complaint with the Office of the Data Protection Commissioner if you believe we have not handled your personal data in accordance with the law:
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. We will notify you of material changes by email or through the Service at least thirty (30) days before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Related Documents
This Privacy Policy should be read alongside our Terms of Service, which governs your use of the Service. Together, these documents set out the complete framework for your relationship with CromaHR.