πŸ‡°πŸ‡ͺ

Refrigerated Delivery

A Nairobi supermarket received a cold-chain dairy consignment from Eldoret β€” temperature maintained throughout.

2 minutes ago
Legal

Data Protection Policy

How we collect, use, store, and protect your personal data β€” in compliance with Kenya's Data Protection Act 2019 and applicable East African data protection regulations.

Effective: 1 January 2025
Last updated: 1 January 2025
Regulation: Kenya DPA 2019

1 Overview

πŸ”’
Logistics & Beyond takes your privacy seriously. We collect only what we need, use it only for the purposes stated, and protect it with appropriate technical and organisational measures. We do not sell your personal data β€” ever.

This Data Protection Policy explains how Logistics & Beyond ("we", "our", "us") collects, processes, stores, and protects personal data in connection with the Logistics & Beyond platform, including our website at logisticsandbeyond.co.ke, our web application, and all associated services.

This Policy is governed by and compliant with Kenya's Data Protection Act 2019 (Act No. 24 of 2019) and the associated Data Protection (General) Regulations 2021. Where we operate in other East African jurisdictions, we also comply with applicable local data protection legislation including Tanzania's Electronic and Postal Communications Act, Uganda's Data Protection and Privacy Act 2019, and Rwanda's Law No. 058/2021 on Personal Data Protection.

2 Data Controller

The data controller responsible for your personal data is:

Logistics & Beyond
Nairobi, Kenya
πŸ“§ privacy@logisticsandbeyond.co.ke
🌐 logisticsandbeyond.co.ke

We are registered with the Office of the Data Protection Commissioner (ODPC) of Kenya as required under the Data Protection Act 2019.

3 Data We Collect

We collect different categories of personal data depending on your role on the platform and how you interact with us.

Data categoryExamplesSource
Identity dataFull name, company name, job title, profile photoProvided by you at registration
Contact dataEmail address, phone number, WhatsApp number, physical addressProvided by you at registration or in profile
Account dataUsername, password (hashed), account role, subscription tier, billing informationProvided by you; generated by the platform
Transaction dataOrders created, bids submitted and accepted, transport assignments, warehouse receipts, proof of delivery recordsGenerated through your use of the platform
Document dataWaybills, shipping instructions, delivery orders, packing lists, and other generated shipping documentsGenerated through your use of the platform
Vehicle & fleet dataVehicle registration numbers, fleet size, route information (for Transporters)Provided by you in your Transporter profile
Warehouse dataWarehouse location, capacity, storage types, inventory records (for Warehouse Managers)Provided by you in your Warehouse Manager profile
Communication dataMessages sent through the platform's messaging system, support tickets, demo booking requestsGenerated through your use of the platform
Technical dataIP address, browser type and version, device type, operating system, page visit data, time on platformCollected automatically via cookies and server logs
Marketing dataEmail open rates, click-through data, campaign attribution (for newsletter subscribers)Collected automatically via email marketing platform

We do not collect any special categories of personal data (also known as sensitive personal data) as defined under the Kenya Data Protection Act 2019.

5 How We Use Your Data

We use your personal data for the following purposes:

  • Creating and managing your account and platform subscription
  • Enabling the core platform workflows β€” order creation, bidding, transport assignment, tracking, and document generation
  • Processing payments for subscriptions and platform services
  • Sending transactional notifications β€” bid updates, order status, delivery confirmations, and payment receipts
  • Providing customer support and responding to enquiries
  • Sending marketing communications where you have consented or where we have a legitimate interest as an existing customer
  • Improving the platform through analysis of usage patterns and user feedback
  • Preventing fraud, abuse, and violations of our Terms of Service and Acceptable Use Policy
  • Complying with legal, regulatory, and tax obligations
  • Producing anonymised, aggregated industry insights β€” such as the East Africa Logistics Report β€” where no individual is identifiable
β›”
We will never: sell your personal data to third parties, use your data to make automated decisions with legal effect without human review, or share your data with advertisers for behavioural targeting.

6 Data Sharing

We share personal data with third parties only in the following circumstances:

  • Other platform users β€” shipment data, bid information, and relevant contact details are shared between parties to a transaction (e.g. a shipper and the freight forwarder they engage). Only data necessary to facilitate the transaction is shared.
  • Payment processors β€” payment card and M-Pesa transaction data is processed by our PCI-DSS compliant payment partners. We do not store full card numbers.
  • Cloud infrastructure providers β€” our platform is hosted on cloud infrastructure providers that process data on our behalf under data processing agreements.
  • Email service providers β€” transactional and marketing emails are sent via third-party email platforms under data processing agreements.
  • Analytics providers β€” anonymised usage data is processed by analytics platforms (such as Google Analytics 4) to help us understand platform performance.
  • Legal and regulatory authorities β€” we may disclose personal data when required by law, court order, or to protect the rights, property, or safety of Logistics & Beyond, our users, or the public.

All third-party processors are bound by data processing agreements that require them to protect your data in accordance with applicable law and to use it only for the purposes we specify.

7 Data Retention

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, and in accordance with our legal obligations.

Data typeRetention periodReason
Active account dataDuration of account + 30 days after closureService delivery; allow account reactivation
Transaction & shipment records7 years from transaction dateKenya tax and commercial law requirements
Shipping documents (Waybills, PODs)7 years from document dateKenya Customs and customs audit requirements
Payment records7 years from transaction dateFinancial records and tax compliance
Support communications3 years from last interactionQuality assurance and dispute resolution
Marketing consent records3 years from consent or last engagementODPC consent compliance evidence
Technical / server log data12 monthsSecurity monitoring and fraud prevention

When data is no longer required, it is securely deleted or anonymised in accordance with our data deletion procedures.

8 Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, alteration, or disclosure. These measures include:

  • Encryption in transit β€” all data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS). HSTS is enforced.
  • Encryption at rest β€” sensitive personal data is encrypted at rest in our database infrastructure.
  • Password security β€” passwords are hashed using bcrypt. We never store plaintext passwords.
  • Access controls β€” access to personal data is restricted to authorised personnel on a need-to-know basis. All administrative access is logged.
  • Two-factor authentication β€” 2FA is available and recommended for all platform accounts.
  • Regular security reviews β€” our codebase and infrastructure undergo regular security assessments.
  • Data breach response β€” we maintain a data breach response plan. In the event of a breach affecting your personal data, we will notify the ODPC within 72 hours and affected users without undue delay, as required by the Data Protection Act 2019.

No data transmission over the internet is 100% secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security.

9 Your Rights

Under the Kenya Data Protection Act 2019, you have the following rights in relation to your personal data:

πŸ‘οΈ
Right to access
Request a copy of the personal data we hold about you.
✏️
Right to rectification
Request correction of inaccurate or incomplete data.
πŸ—‘οΈ
Right to erasure
Request deletion of your data where there is no lawful basis to retain it.
⏸️
Right to restriction
Request that we restrict processing of your data in certain circumstances.
πŸ“¦
Right to portability
Receive your data in a structured, machine-readable format.
🚫
Right to object
Object to processing based on legitimate interests or for direct marketing.

To exercise any of these rights, please contact us at privacy@logisticsandbeyond.co.ke. We will respond within 21 days as required by the Data Protection Act 2019. We may ask you to verify your identity before processing a request.

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at odpc.go.ke.

10 International Data Transfers

Our primary servers are located within Africa. Where personal data is transferred outside Kenya β€” for example, to cloud infrastructure or software services headquartered internationally β€” we ensure appropriate safeguards are in place, including:

  • Data processing agreements incorporating standard contractual clauses approved by the ODPC
  • Transfers only to countries or organisations with adequate data protection standards as recognised under the Data Protection Act 2019
  • Technical measures to protect data in transit, including TLS encryption for all cross-border data flows

11 Cookies & Tracking

We use cookies and similar tracking technologies on our website and platform. You can manage your cookie preferences at any time.

Cookie typePurposeCan be disabled?
Strictly necessarySession management, authentication, security (CSRF protection, login state)No β€” required for the platform to function
FunctionalRemembering your language, dashboard preferences, and notification settingsYes β€” with reduced functionality
AnalyticsUnderstanding how users navigate the platform to improve the experience (Google Analytics 4, anonymised)Yes
MarketingTracking which marketing campaigns led you to the platform (LinkedIn Insight Tag, Google Ads conversion tracking)Yes

A cookie consent banner is displayed on your first visit. You can update your preferences at any time via the cookie settings link in the footer.

12 Children's Data

The Logistics & Beyond platform is a professional business tool and is not intended for use by persons under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@logisticsandbeyond.co.ke and we will delete such data without delay.

13 Contact Us

For any questions, concerns, or requests relating to this Data Protection Policy or the processing of your personal data, please contact our Data Protection Officer:

Data Protection Officer β€” Logistics & Beyond

We aim to acknowledge all data protection enquiries within 3 business days and respond fully within 21 days as required by law.

πŸ“§ privacy@logisticsandbeyond.co.ke
πŸ“§ hello@logisticsandbeyond.co.ke
🌐 logisticsandbeyond.co.ke
πŸ›οΈ Office of the Data Protection Commissioner: odpc.go.ke
πŸ“ Nairobi, Kenya  |  Mon–Fri, 8am–6pm EAT

L&B Assistant