Pricing Blog
Legal

Privacy Policy

How IntelliFleet 360 collects, uses, stores and protects personal data — in alignment with Kenyan and international privacy law.

Last updated 7 May 2026 Version 1.0 Kenya DPA 2019 · GDPR aligned
Effective date: 7 May 2026  ·  Last updated: 7 May 2026  ·  Version: 1.0
Data controller: IntelliFleet 360 Limited (Company Registration: CR-734-773B-7D9C)
Registered office: Harrison House, 3rd Ngong Avenue, Upper Hill, Nairobi, Kenya
ODPC registration number: CR-734-773B-7D9C
Data Protection Officer: [email protected]
About this document. This Privacy Policy is the formal notice required under Section 29 of the Kenya Data Protection Act, 2019 ("DPA 2019"). It explains the personal data IntelliFleet 360 collects, why, on what lawful basis, with whom we share it, how long we keep it, and the rights you have under Kenyan law. If anything below is unclear, write to us at [email protected].

1. Scope and who this applies to

This Privacy Policy applies to all personal data processed by IntelliFleet 360 Limited ("IntelliFleet 360", "we", "us", or "our") in connection with:

  • Visitors to our public websites at www.intellifleet360.com and any related sub-domains.
  • Customers who subscribe to and use the IntelliFleet 360 fleet-management platform.
  • Drivers, operators and other end-users whose vehicles or devices are connected to the platform on behalf of our customers.
  • Suppliers, partners, prospective customers, employees and job applicants.

For data we process on behalf of our customers (for example, location data of their vehicles), our customer is the data controller and IntelliFleet 360 is the data processor. The terms of that relationship are set out in our Data Processing Addendum (DPA), which forms part of every customer contract. In all other cases, IntelliFleet 360 is the data controller.

2. Who we are

IntelliFleet 360 LLP is registered in the Republic of Kenya. Our registered office is at Harrison House, 3rd Ngong Avenue, Upper Hill, Nairobi. We are registered with the Office of the Data Protection Commissioner ("ODPC") under identification number 734-773B-7D9C as both a Data Controller (Certificate Serial No. 23166, valid 16 June 2026 – 16 June 2028) and a Data Processor (Certificate Serial No. 22977, valid 8 June 2026 – 8 June 2028). You can view the official certificates on our compliance documents page, or open them directly: Data Controller Certificate (PDF) · Data Processor Certificate (PDF).

We have appointed a Data Protection Officer ("DPO") in accordance with Sections 24 and 25 of the DPA 2019. You may contact our DPO directly:

  • Email: [email protected]
  • Postal: Data Protection Officer, IntelliFleet 360 Limited, Harrison House, 3rd Ngong Avenue, Upper Hill, P.O. Box 105028-00100, Nairobi, Kenya

3. Personal data we collect

Depending on how you interact with us, we may collect the categories of personal data set out below.

3.1 Personal data of website visitors and demo enquirers

  • Identification data: first and last name, work email, telephone number, employer name and job title.
  • Enquiry content: industry, fleet size, free-text message and any documents you attach.
  • Technical data: IP address, browser type and version, device and operating system, referring URL, pages viewed, time on site, and approximate geographic location derived from IP.
  • Cookie identifiers and similar tracking data, where you have given consent (see Cookie Policy).

3.2 Personal data of customer-account users

  • Account credentials: email address, hashed password, multi-factor-authentication tokens.
  • Profile data: name, role, language preference, time zone, notification preferences.
  • Usage data: log entries, configuration changes, queries run, dashboards opened, IP and device of access.
  • Support correspondence: tickets, chat transcripts, screen-share recordings (with notice).

3.3 Personal data of drivers and other end-users (processed on behalf of customers)

  • Identification: driver name, driver licence number, employee number, RFID / iButton identifier.
  • Vehicle assignment, scheduling and routing data.
  • Real-time and historical location of the vehicle assigned to the driver, including speed, heading, harsh-event flags, and engine telemetry.
  • Dash-cam media: forward-facing, in-cab, and side video clips captured around safety events; on-device AI inferences (e.g. distraction detection).
  • Driver-app interactions: trip log entries, vehicle inspections, document captures, score and coaching content.

3.4 Sensitive personal data

We do not knowingly process special-category personal data within the meaning of Section 44 DPA 2019 (such as data revealing race, health, biometric data, sex life, or political opinion) unless our customer has lawfully provided it as part of their fleet records (for example, a driver-medical clearance form attached to a vehicle inspection). When we do, we apply the additional safeguards required by the Act.

4. How we obtain personal data

We collect personal data:

  • Directly from you — when you fill in a form, request a demo, sign a contract, log into the platform, communicate with our team, or attend an event.
  • From your employer — when our customer enrols you as a user or driver on their account.
  • From IntelliFleet hardware — GPS units, AI dash cams, OBD-II adapters and other devices installed in the vehicle automatically generate telemetry and media that we receive over the air.
  • From third parties — limited to information lawfully shared by integration partners (e.g. NTSA verification responses, M-Pesa transaction confirmations) for the purposes of running the service contracted by our customer.
  • From cookies and analytics — see our Cookie Policy for full detail.

5. Why we use it and our lawful basis

Section 30 DPA 2019 requires us to identify a lawful basis for each processing activity. We rely on the following:

  • Performance of a contract (Sec. 30(1)(b)) — providing the platform to our customers; provisioning hardware; supporting users; processing payments.
  • Compliance with a legal obligation (Sec. 30(1)(c)) — tax records, NTSA reporting where applicable, retaining transaction logs for the period required by Kenyan law, responding to lawful requests from authorities.
  • Legitimate interests (Sec. 30(1)(f)) — improving the service, fraud and security monitoring, network and information security, internal analytics, defending claims. We document a balancing test for each legitimate-interest assessment and we will share it with you on request.
  • Consent (Sec. 30(1)(a)) — for non-essential cookies, marketing emails, and any other processing for which we explicitly ask. You can withdraw consent at any time.
  • Vital interests (Sec. 30(1)(d)) — in rare driver-welfare situations (e.g. an SOS press from the driver app on a remote route).
  • Public task / official authority (Sec. 30(1)(e)) — limited to public-sector customer engagements where the customer's mandate is a relevant lawful basis we rely on as processor.

6. Who we share personal data with

We share personal data only where it is necessary, lawful and proportionate. Recipients fall into the categories below.

  • Our customers and their authorised users — for driver and vehicle data, the data is being held on behalf of the employer; only that customer's authorised users can see it.
  • Sub-processors — third parties we engage to run the platform (cloud hosting, email delivery, mapping, payment processing, customer-support tooling). The current list is published at trust.html and we update it monthly. Sub-processors are bound by written contracts that pass through the protections in this policy and the DPA 2019 (Sec. 42).
  • Integration partners — only where you or your employer has explicitly enabled an integration (e.g. SAP, QuickBooks, M-Pesa, Microsoft 365). Data flows are under your control via the integrations dashboard.
  • Professional advisors — auditors, lawyers, accountants and insurers, bound by professional confidentiality.
  • Authorities — where we are required by Kenyan law (for example, a valid court order under the Criminal Procedure Code, or a request lawfully issued under the Computer Misuse and Cybercrimes Act, 2018, or NTSA inspection powers under the NTSA Act, 2012). We assess every request and challenge any that exceed legal authority.
  • In a corporate transaction — if IntelliFleet 360 is involved in a merger, acquisition, asset sale or insolvency, your personal data may be transferred to the successor, subject to the same protections set out in this policy.

We do not sell personal data and we never share it with advertising networks for monetisation.

7. International transfers

Our primary production data centre is in Nairobi, Kenya. We operate an active failover region in Cape Town, South Africa, and store encrypted backups in Frankfurt, Germany. Some of our sub-processors operate in other jurisdictions (Ireland, the United States, the United Kingdom).

Where personal data is transferred outside Kenya, we comply with Sections 48 to 50 of the DPA 2019. The transfer mechanism is one of the following, as applicable:

  • The destination country has been determined by the ODPC to provide an adequate level of data protection.
  • The transfer is governed by binding, written contractual clauses (including the ODPC's recommended standard contractual clauses or equivalent recognised under the GDPR) imposing the protections required by Kenyan law.
  • Your explicit consent has been obtained, where appropriate.
  • The transfer is necessary for the performance of our contract with you or your employer.

Premium-plan customers may elect single-region pinning so that all production data remains within Kenya. Contact your account manager to enable this.

8. Security measures

Section 41 DPA 2019 requires us to take technical and organisational measures appropriate to the risk. We implement, among others:

  • Encryption at rest (AES-256) and in transit (TLS 1.3).
  • Multi-factor authentication for all administrative access.
  • Role-based access control with least-privilege defaults.
  • Annual independent penetration testing; ongoing vulnerability scanning.
  • ISO/IEC 27001-aligned information-security management system.
  • Documented incident-response plan with a one-hour acknowledgement target.
  • Mandatory privacy and security training for all staff.
  • Background checks for personnel with access to production data.
  • Geo-redundant active-active infrastructure with RPO < 30 seconds and RTO < 4 minutes.

Despite these measures, no system is perfectly secure. If we ever experience a personal-data breach affecting your data, we will notify the ODPC within 72 hours of becoming aware (Sec. 43 DPA 2019) and we will notify affected data subjects without undue delay where required.

9. How long we keep personal data

We retain personal data only for as long as it is needed for the purposes described in this policy, after which it is deleted or anonymised.

  • Active-customer data: for the term of the contract plus any contractually-agreed retention period.
  • Driver and vehicle telemetry: by default 90 days for live playback; longer where the customer's contract specifies (e.g. 12 months for compliance reporting).
  • Demo and marketing-form submissions: 24 months from last activity, unless you opt in to ongoing communications.
  • Financial and tax records: at least 7 years, as required by the Income Tax Act and the Tax Procedures Act, 2015.
  • Security logs: 12 months.
  • Job-applicant data (unsuccessful applicants): 6 months unless you consent to a longer talent-pool retention.

10. Children's data

Under Section 33 DPA 2019, the age of consent for processing personal data of a child is 18 years. The IntelliFleet 360 platform is a business-to-business service. We do not knowingly direct services at children, and we do not knowingly process the personal data of a person under 18 except where the child is incidentally captured (for example, a passenger inside a vehicle whose silhouette appears in dash-cam footage). We apply additional safeguards to such data and we will delete it on request.

11. Your rights as a data subject

Under Sections 26 and 34-40 of the DPA 2019, you have the following rights in relation to your personal data:

  • Right to be informed — to receive clear information about how your data is processed (this policy is part of how we discharge that duty).
  • Right of access — to obtain confirmation of processing and a copy of the data we hold about you.
  • Right to rectification — to have inaccurate data corrected.
  • Right to erasure — to have your data deleted in the circumstances set out in the Act.
  • Right to restrict processing — for example while a complaint is being investigated.
  • Right to data portability — to receive a copy in a structured, commonly used, machine-readable format.
  • Right to object — including to direct marketing and to processing based on legitimate interests, where applicable.
  • Right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on you.
  • Right to withdraw consent at any time, where consent is the lawful basis we rely on. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

12. How to exercise your rights

Submit a request to [email protected] from the email address associated with your account, or by post to the address in section 2 of this policy. We may need to verify your identity before acting; we do this in the least-intrusive way possible. We will respond within 30 days, or explain any extension as permitted by the Act.

For data we process on behalf of an employer (driver telemetry, vehicle data), the employer is the controller and we will direct your request to them.

There is no fee for exercising your rights, except where the request is manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable administrative fee or refuse to act, as permitted by the Act.

13. Cookies and similar technologies

We use cookies and similar technologies on our public website. We do not use them in the customer platform beyond what is strictly necessary for the platform to work. Full detail is in our Cookie Policy. You can withdraw or change your cookie consent at any time using the "Cookie preferences" link at the bottom of every page.

14. Marketing communications

If you opt in, we may send you newsletters, product updates, event invitations and case studies by email. You can unsubscribe at any time using the link in any email or by writing to [email protected]. Unsubscribing from marketing does not stop transactional or service communications (such as security alerts, invoices, or product change notifications) sent to active customers.

15. Automated decision-making and profiling

Our AI safety and predictive-maintenance models surface insights that managers act on. These do not produce legal or similarly significant decisions about a data subject without human review. A safety alert flagged by a model is reviewed by a fleet manager before any disciplinary or coaching outcome is decided. If you believe a decision affecting you was made solely by automated means, contact our DPO and we will review.

16. Complaints to the ODPC

If you are not satisfied with how we have handled your personal data or your data-subject request, you may lodge a complaint with the Office of the Data Protection Commissioner:

We would always prefer the chance to address your concern first; please write to [email protected] before approaching the regulator.

17. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our services, the law, or industry practice. Material changes will be notified to active customers by email and prominently on this page at least 30 days before they take effect. The "Last updated" date at the top of this page always reflects the current version, and superseded versions are archived and available on request.

18. Contact us

For any question about this policy or how we handle your personal data:

  • Data Protection Officer: [email protected]
  • General privacy enquiries: [email protected]
  • Postal: IntelliFleet 360 Limited, Attn: Data Protection Officer, Harrison House, 3rd Ngong Avenue, Upper Hill, P.O. Box 105028-00100, Nairobi, Kenya
  • Phone: +254 790 509 427
Disclaimer. This Privacy Policy was prepared as a template aligned with the Kenya Data Protection Act, 2019, the Constitution of Kenya 2010 (Article 31), the GDPR (Regulation EU 2016/679), and prevailing best practice as at 7 May 2026. It is not a substitute for legal advice. IntelliFleet 360 Limited engages qualified Kenyan counsel to review and finalise this document before formal adoption. Customers and data subjects should rely on the executed version published with the issued ODPC registration number, not this template.

Questions about this policy? Write to [email protected] — or see our Terms and Cookie Policy.