Skip to content
Start a Project

Privacy Policy

This Policy explains how Avidni handles personal data about website visitors, prospects, clients, portal users, suppliers, applicants, and other business contacts.

Effective 11 July 2026

On this page

1. Who controls your personal data

1.1 Avidni Firm is the data controller for personal data it determines how and why to use, including data collected through avidnifirm.com, project inquiries, business communications, billing, its portals, and its own operations. Avidni operates from Nairobi, Kenya.

1.2 Contact us at services@avidnifirm.com or through https://avidnifirm.com/start-project for privacy questions or requests. If a project-specific agreement identifies another controller or a different contact, that document applies to the relevant processing.

1.3 When Avidni handles personal data solely on a client's documented instructions while building or operating that client's system, the client is normally the controller and Avidni is its processor. The client's privacy notice and the applicable data-processing agreement govern that processing.

2. People and services covered

2.1 This Policy covers visitors, people who submit inquiries or estimates, current and former clients, authorised portal users, client contacts, suppliers, professional advisers, event or newsletter contacts, job applicants where relevant, and people whose data is included in material sent to us.

2.2 It covers the public website, forms, client and staff portals, proposals, contracts, estimates, invoices, payments, project delivery, files, communications, support, analytics, APIs, MCP tools, automation, and related Avidni business systems.

2.3 It does not govern an external site or service merely because we link to it. It also does not replace a client's own notice where Avidni processes data for that client.

3. Personal data we collect

3.1 Identity and contact data may include your name, organisation, role, email address, telephone number, postal or business address, account identifier, signature, and authorised-contact status.

3.2 Inquiry and project data may include your service interest, brief, budget range, timeline, business requirements, feedback, approvals, support requests, meeting notes, correspondence, and information contained in uploaded files.

3.3 Account and security data may include login email, authentication records, role, permissions, multi-factor status, session and device information, IP address, user agent, security events, access logs, and evidence of account or legal acceptance.

3.4 Commercial and transaction data may include proposals, estimates, contracts, purchase details, invoice and receipt records, currency, tax information, payment status, provider references, refunds, disputes, and limited payment-method information returned by a payment provider. Avidni does not intentionally store full card numbers or security codes.

3.5 Technical and usage data may include requested URL, date and time, referral source, consent status, browser and device information, coarse network information, session identifier, page views, and selected calls to action. Optional first-party analytics is collected only after the consent recorded by the public site.

3.6 We may receive data from you, your organisation, another authorised user, service providers, payment and authentication providers, public professional sources, referrals, or systems you ask us to integrate.

4. Sensitive data and data minimisation

4.1 Please do not submit passwords, secret keys, payment-card security codes, government identifiers, health records, biometric data, children's data, or other sensitive personal data through a general inquiry form or ordinary email.

4.2 Where sensitive data is genuinely necessary for an approved service, we will define an appropriate transfer method, access boundary, lawful basis, retention approach, and any required impact assessment or agreement before routine processing.

4.3 We aim to collect data that is adequate, relevant, and limited to the stated purpose. We may delete, redact, quarantine, or ask you to resubmit information sent through an unsuitable channel.

5. Purposes and lawful bases

5.1 We process data to take steps at your request before a contract, enter and perform contracts, administer accounts, deliver projects, issue and manage commercial records, collect payment, provide support, and carry out agreed handover or transition work.

5.2 We process data where necessary for legitimate interests such as responding to business inquiries, managing client relationships, improving services, maintaining accurate records, preventing fraud and abuse, securing systems, establishing or defending legal claims, and communicating relevant business information. We balance those interests against your rights and expectations.

5.3 We process data to comply with legal obligations, court orders, tax and accounting requirements, data-protection duties, sanctions and fraud checks, lawful authority requests, and other binding requirements.

5.4 We rely on consent where law requires it, including optional analytics or marketing communications in relevant circumstances. Consent can be withdrawn without affecting processing that was lawful before withdrawal.

5.5 Where another lawful basis is more appropriate under the Kenya Data Protection Act, 2019 or other applicable law, we will document and apply it to the relevant processing.

6. Inquiries, estimates, and project intake

6.1 When you contact us, we use the submitted information to understand the request, assess fit and risk, communicate with you, prepare a scope or estimate, prevent spam, and maintain a record of the discussion.

6.2 Public form submissions may be validated, rate-limited, screened for abuse, routed internally, and converted into a lead, client, project, support, or commercial record where appropriate. We do not use the free-text contents of sensitive fields as analytics properties.

6.3 If an inquiry does not proceed, we retain a proportionate record for follow-up, suppression, dispute prevention, and business administration, then delete or anonymise it when no longer reasonably needed.

7. Accounts, portals, and authentication

7.1 We use account data to authenticate users, assign roles, enforce permissions, maintain sessions, support password or multi-factor recovery, show the correct organisation records, and record security-relevant actions.

7.2 Supabase provides authentication and application data services for the platform. Authentication may use necessary browser cookies or storage controlled by the authentication library. These technologies are required for a signed-in service and are not used for advertising.

7.3 We may record acceptance of a legal document with the version, timestamp, account, IP context, and user agent where reacceptance or evidence is required. We may require recent authentication before sensitive changes.

8. Projects, files, and client instructions

8.1 Project records may contain contact details, approvals, tasks, messages, content, access information, technical logs, and files provided by a client. We use them to deliver, test, secure, document, and support the engagement.

8.2 Cloudflare R2 is used for file and media storage where configured. Uploads may be scanned, quarantined, versioned, access-controlled, or removed if unsafe. Public website media and private client files use separate access arrangements.

8.3 Clients must avoid placing unrelated or excessive personal data in project files and must ensure they have a lawful basis to share data with Avidni. A client remains responsible for instructions it gives as controller unless the parties agree otherwise in writing.

9. Payments and financial records

9.1 We use billing identity, invoice, receipt, payment, currency, tax, and refund data to administer contracts, collect and reconcile funds, issue records, manage disputes, prevent fraud, and meet accounting or tax duties.

9.2 Paystack processes supported online payments. Payment details entered in Paystack's checkout are handled under Paystack's terms and privacy notice. Avidni receives transaction status, reference, amount, channel, and limited payer or method information needed for reconciliation and support, not full card credentials.

9.3 Financial and tax records may be retained for the statutory period and longer where reasonably required for an active dispute, audit, investigation, or legal claim.

10. Email, notifications, and support

10.1 We use contact and account data to send inquiry responses, project messages, account and security alerts, estimates, invoices, receipts, support messages, legal notices, and other service communications.

10.2 Resend provides transactional email delivery where configured. Delivery logs may include recipient, sender, subject or template identifiers, status, timestamps, and technical diagnostics. Email providers and receiving networks may process message metadata outside Kenya.

10.3 Mandatory security, billing, legal, and service messages are not marketing and may continue while an account or obligation remains active. You may opt out of optional marketing using the provided control or by contacting us.

11. Analytics, cookies, and similar technologies

11.1 The public website records a consent choice in local storage. If you accept optional analytics, a first-party analytics component creates a random session identifier in session storage and sends limited page-view and selected internal call-to-action events to Avidni's analytics endpoint.

11.2 The current analytics payload includes the path, referral source, event time, consent version, random session identifier, and limited event properties. It is designed not to include inquiry field contents. We use it to understand site use, diagnose issues, and improve content and journeys.

11.3 Signed-in services use necessary authentication and security technologies. The Cookie Policy gives the current inventory, categories, duration, providers, and controls.

12. Automation, APIs, MCP, and AI

12.1 We may process data through configured workflows, APIs, webhooks, MCP tools, or AI services to perform a task requested by a client or user, such as routing an inquiry, generating an internal draft, classifying a request, or completing an approved integration action.

12.2 We define the purpose, data boundary, access, failure handling, and human review according to the workflow. We do not intentionally use client confidential data to train a general model unless the client expressly approves that use and receives the necessary information.

12.3 A third-party AI or automation provider may process inputs and outputs under its own service terms or as our processor. The relevant provider and safeguards should be documented in the project scope where personal or confidential data is involved.

12.4 We may keep audit information about an automated action, including the requester, tool, parameters, approval decision, status, and outcome. We do not make solely automated decisions producing legal or similarly significant effects unless a lawful and expressly approved arrangement supports them.

13. When we share personal data

13.1 We share data only as reasonably necessary with authorised Avidni personnel, contractors under appropriate duties, service providers, professional advisers, a client's authorised users, payment and financial institutions, and authorities or counterparties where law or a legal claim requires it.

13.2 We do not sell personal data. We do not share inquiry or client data with third parties for their independent advertising unless we first provide the information and obtain any consent required by law.

13.3 If Avidni is involved in a merger, acquisition, financing, reorganisation, or transfer of assets, relevant data may be disclosed under confidentiality protections and transferred subject to applicable law and continued protection.

14. Material service providers

14.1 Supabase provides database, authentication, and related application services. Cloudflare provides edge, security, worker, and R2 storage services. Vercel may provide website and application deployment. Resend provides transactional email. Paystack provides online payment processing.

14.2 A provider receives only the categories needed for its role. Its processing, locations, subprocessors, retention, and security are also governed by its contract and privacy documentation. Provider use can change as the platform evolves, and this Policy will be updated when a material change affects the notice.

14.3 Client-directed services, such as a registrar, hosting account, analytics property, commerce platform, messaging provider, or AI model selected for a project, may process data under the client's contract and instructions. The engagement documents should identify responsibility for those services.

15. International data transfers

15.1 Avidni is based in Kenya, while cloud, email, payment, and technical providers may process or store data in other countries. International transfers may therefore occur when we use those services, support an international client, or communicate across borders.

15.2 We use transfer mechanisms required by applicable law, which may include an adequacy basis, contractual safeguards, binding provider commitments, necessity for a contract, legal necessity, or informed consent in limited circumstances. We also consider data minimisation, encryption, access control, and provider due diligence.

15.3 Contact us if you need further information about safeguards relevant to a specific transfer. We may redact confidential or security-sensitive terms from a copy we provide.

16. How long we retain data

16.1 We retain data only for as long as reasonably necessary for the purpose collected, an active account or engagement, client instructions, security, audit, warranty or support needs, legal claims, and accounting, tax, or other legal obligations.

16.2 Inquiry records that do not become an engagement are periodically reviewed and deleted or anonymised when follow-up, suppression, security, and dispute needs no longer justify identification. Account data is retained while the account is active and then for a proportionate closure and claims period. Project records and final deliverables may be retained for support, evidence, and continuity according to the agreement. Financial records are retained for the applicable statutory period.

16.3 Security logs, audit events, backups, and provider records may follow different rolling schedules. Backup copies may persist until overwritten under the backup cycle. When deletion is required, data may first be restricted from ordinary use and then removed or irreversibly anonymised from active systems and later from backups.

16.4 A legal hold, dispute, fraud concern, regulatory request, or client instruction may require longer retention. We will not keep data indefinitely merely because storage is available.

17. Security safeguards

17.1 We use safeguards proportionate to the data and service, which may include access controls, role-based permissions, multi-factor authentication, encryption in transit, protected secrets, signed links, file quarantine, audit logs, rate limits, backups, monitoring, and separation of public and private files.

17.2 Security is a shared responsibility. Users must protect credentials and devices, use approved sharing methods, keep access lists current, and promptly report suspected compromise. Clients must not send sensitive data through an unapproved channel.

17.3 No safeguard eliminates all risk. If we confirm a personal-data breach, we will investigate, contain it where practicable, document it, and notify affected parties and the Office of the Data Protection Commissioner where applicable law requires.

18. Your data-protection rights

18.1 Depending on applicable law and the circumstances, you may have the right to be informed, access personal data, request correction, object to processing, request restriction, request deletion, receive portable data, withdraw consent, and not be subject to certain solely automated decisions.

18.2 Rights are not absolute. We may retain or continue processing data where a contract, legal duty, public interest, freedom of expression, legal claim, security need, or another lawful exception applies. If we cannot fulfil a request in full, we will explain the reason where permitted.

18.3 To exercise a right, email services@avidnifirm.com with enough detail to locate the data and identify the relevant relationship. We may verify identity and authority, especially where a request concerns an organisation account or another person. We will respond within the period required by applicable law.

18.4 If Avidni processes data only for a client, we may direct the request to that client or assist it under the data-processing agreement.

19. Children

19.1 Avidni's website and business services are not directed to children, and we do not knowingly invite a child to create a business account or submit a project inquiry.

19.2 A client service involving children's data requires an expressly approved scope, a lawful basis, appropriate parent or guardian involvement where required, age-appropriate information, risk assessment, and safeguards before processing begins.

19.3 If you believe a child has submitted personal data to Avidni without appropriate authority, contact us so we can investigate and take suitable action.

20. Questions and complaints

20.1 Please contact services@avidnifirm.com first so we can understand and address a privacy concern. Include the relevant service, approximate date, and the result you seek, but do not email identity documents unless we request them through a suitable channel.

20.2 You may lodge a complaint with the Office of the Data Protection Commissioner in Kenya. Its current information and complaint channels are available at https://www.odpc.go.ke. You may also have the right to contact another competent authority where local law applies.

20.3 Raising a concern does not affect any other lawful remedy, and we will not penalise a person for making a good-faith privacy request or complaint.

21. Changes and contact

21.1 We may update this Policy when our services, providers, processing, or legal duties change. The effective date and version identify the current notice. Material changes may be announced on the website, by email, through a portal notice, or through a new consent or acceptance request where required.

21.2 Earlier published versions are retained in the CMS for audit. A change does not make earlier lawful processing unlawful, but a new purpose or basis will be assessed before it begins.

21.3 Contact: Avidni Firm, Nairobi, Kenya. Email services@avidnifirm.com. Online contact https://avidnifirm.com/start-project. Please use the subject Privacy Request for a data-subject request.