Privacy notice
What we collect, why, who else sees it, how long we keep it, and what you can require us to do about it. Written for this site specifically, not adapted from a template.
Last reviewed
6 September 2026
Related
Who we are
MambaTech Services is the data controller for personal data collected through this website. We are an independent IT consulting and systems engineering practice based in Nairobi, Kenya.
- Registered name
- To be completed before launch.
- Company number
- To be completed before launch.
- Registered office
- To be completed before launch.
- Data protection contact
- mambatech@zohomail.com
- ODPC registration
- To be completed before launch.
What we collect
There is exactly one place on this site where personal data is collected: the diagnostic request form on the contact page. Nothing else on www.mamba-tech.co.ke asks you for anything or records anything about you. Two other things happen and neither is personal data, but you should be able to check that for yourself rather than take our word for it: we count page views without any identifier, and one page stores a single character in your browser, described under cookies and storage.
What you type into the form
- Your name
- Your organisation
- Your work email address
- Your telephone or WhatsApp number
- The focus area you select
- Anything you choose to write in the optional context field
- The fact that you ticked the consent box, and when
Every field except the context box is required, because we cannot respond to an enquiry without a way to reach you and something to reach you about. If you would rather not complete the form, email or telephone us instead. The addresses are at the foot of every page and no form is involved.
What the server records
- The date and time the enquiry was received.
- A truncated one-way hash of your IP address. We use this to stop the same connection submitting the form repeatedly. It is not reversible into an IP address and we do not store the address itself.
Separately, our hosting provider keeps standard web server access logs, which ordinarily include IP addresses, in order to run and secure the server. Those logs are the hosting provider's, kept under their retention policy, and we do not use them for anything.
Page views
We count page views, so that we know which pages are worth keeping. When you open a page it sends five things to our own server, and this is the complete list:
- the date and the hour;
- the path of the page, for example
/services; - the hostname of the site that linked you here, if there was one, for
example
google.com. Never the full address of that page; - and whether your screen was narrow, medium or wide.
There is no identifier of any kind in that record. No cookie, no visitor or session id, no IP address and no hash of one, no browser or device string, no screen dimensions, no language, no timezone. Nothing that could be combined into a fingerprint, and nothing that could be used to recognise you on a second page or a second day.
The consequence is deliberate. Because the rows share no identifier, they cannot be joined to one another. We can see that a page was opened forty times. We cannot see whether that was forty people or one person forty times, and we cannot follow anybody from one page to the next. Most analytics products answer those questions precisely because they do collect an identifier. We would rather not know.
If your browser sends Do Not Track or Global Privacy Control, nothing is sent at all. The page checks before making the request, and the server drops it again on arrival.
Counts are kept for 13 months, so that one year can be compared with the one before it, then whole months are deleted together. There is nothing in them to delete on request, because there is nothing in them that is yours.
What we deliberately do not collect
- No third-party analytics product, no tag manager
- No heatmaps and no session recording
- No advertising or conversion pixels
- No fingerprinting
- No newsletter list, and no marketing automation
- No data brokered or bought from anyone else
Why we process it
To read your enquiry and reply to it. That is the whole purpose. We do not add enquirers to a mailing list, we do not send follow-up sequences, and we do not use enquiry details to train any model.
Page views are counted for a different reason and on a different basis: our legitimate interest in knowing which pages are worth keeping. That basis is only available because the counting carries no identifier, so it cannot affect anybody's rights or freedoms. Were it to identify people, consent would be required, and there would be a banner asking for it.
Our lawful basis for the enquiry itself is your consent, given by ticking the box on the form. You may withdraw it at any time by emailing mambatech@zohomail.com, and withdrawal will not affect processing that already took place. For the rate-limiting hash our basis is our legitimate interest in keeping the form usable and free of automated abuse.
Cookies and storage
This site sets no cookies. Not one, on any page. It runs no analytics, no tag manager and no advertising pixel, it does not use local storage or IndexedDB, and it does not fingerprint your browser or device.
There is one exception, and it is the whole of it. On the clients page, a short notice explains how client names are handled. When that notice is shown, the page stores a single value in your browser's session storage so that you are not shown it again while you look around the site. The value is the character 1. It is not an identifier, it cannot be used to recognise you or anyone else, it is never transmitted to us or to anyone, and your browser discards it when you close it.
That is why you are not being shown a cookie consent banner. Consent obligations attach to storage that identifies or tracks a person, and there is none here. If we ever add analytics, an embedded map or video, or a chat widget, this section changes first and a consent mechanism goes in before any of it loads, not after.
That is a deliberate constraint, not an oversight. Fonts are served from this domain rather than a font network, icons are drawn inline rather than fetched, and there is no analytics product, no tag manager, no embedded video, no map and no chat widget. The page-view count described above goes to our own server and no further. The links to our profiles in the footer are ordinary links: nothing from those platforms is embedded, so they learn nothing about you unless you choose to follow one. The site makes no request to any third party while you read it, so no third party learns you were here.
The site's Content Security Policy is set to permit same-origin resources only, so this remains true even if something were added by mistake: a third-party script would be blocked rather than silently loaded.
One page is excluded, and it is not one you can reach. /admin is the tool our own staff use to write the articles on
this site. It necessarily talks to GitHub, where the articles are kept, and
it loads two typefaces for its own interface from a font service. It is not
linked from anywhere, it is excluded from search engines, and nothing on any
page you can navigate to loads any part of it. We mention it because saying
"no third-party requests" without this footnote would not be quite true.
Who else sees it
We do not sell personal data, and we do not share it for anyone else's marketing. Enquiry details reach only:
- Netlify, which hosts this site and receives form submissions on our behalf. Your enquiry is stored in our account there until we delete it.
- Our email provider, which delivers the notification to our practice inbox and holds it there.
- Our own staff, specifically the engineer who will answer you.
We will also disclose personal data where we are required to by law, by a court, or by a regulator acting within its powers.
Transfers outside Kenya
Our hosting and email providers may store or process data on servers outside Kenya. Where that happens, sections 48 and 49 of the Data Protection Act, 2019 apply, and we rely on the provider's contractual data protection terms together with your consent to the transfer for the purpose of answering your enquiry.
If you would prefer your details not to leave Kenya, telephone us instead of using the form and say so, and we will handle the enquiry accordingly.
How long we keep it
- Enquiries that do not become engagements
- Deleted within 12 months of our last correspondence with you.
- Enquiries that become engagements
- Kept for the duration of the engagement and for seven years afterwards, because engagement records support tax and statutory record-keeping obligations.
- Rate-limiting hashes
- Expire one hour after the submission that created them, and the record is removed once it is empty.
- Page view counts
- 13 months, so one year can be compared with the one before it, then whole months are deleted together. They contain no identifier, so there is nothing in them belonging to any particular person.
- Hosting provider access logs
- Kept under the provider's own retention policy, not ours.
You can ask us to delete your details sooner. See your rights, below.
How it is protected
- The site is served over HTTPS, and plain HTTP requests are redirected.
- Enquiries are written to a file held outside the public web root, so it cannot be requested over the web.
- Form input is validated and sanitised on the server, not only in the browser, and mail headers are stripped of injection attempts.
- Submissions from one connection are rate limited, and an automated submission is rejected.
- Access to the practice inbox is restricted to staff who need it and is protected by multi-factor authentication.
No system is perfect. If we become aware of a breach affecting your personal data, we will notify the Office of the Data Protection Commissioner and, where the breach is likely to result in real risk to you, notify you as well, in line with section 43 of the Act.
Your rights
Under section 26 of the Data Protection Act, 2019 you have the right:
- to be informed of the use to which your personal data is put;
- to access the personal data we hold about you;
- to object to the processing of all or part of it;
- to correction of false or misleading data; and
- to deletion of false or misleading data about you.
In practice we will also delete accurate data on request, unless we are required to keep it. To exercise any of these, write to mambatech@zohomail.com. We will respond within seven days and complete the request within 30 days. There is no charge. We may ask you to confirm your identity first, so that we do not disclose your details to someone else.
Client data we process on your behalf
This notice covers personal data we control, which is essentially enquiries and correspondence. It is separate from the personal data we handle inside a client's systems during an engagement.
In that work we usually act as a data processor and the client remains the controller. Those arrangements are governed by a written data processing agreement issued alongside the engagement letter, which sets out the scope of processing, our security obligations, sub-processors, breach notification, and what happens to the data when the engagement ends. We do not use client data for any purpose of our own, and we do not use it to train models.
Complaints
If you think we have handled your personal data improperly, tell us first at mambatech@zohomail.com and we will try to put it right.
You also have the right to lodge a complaint with the Office of the Data Protection Commissioner, which regulates data protection in Kenya, at odpc.go.ke. You do not have to come to us first.
Changes to this notice
We will update this page when our processing changes, and the review date in the margin will change with it. We will not reduce your rights under this notice without telling you.