Privacy Policy
1. Who We Are
ICT Africa Consulting Services Limited (“ICT Africa”, “we”, “us”, “our”) is a member of the Ramco Group, incorporated in Kenya. We develop and operate Mgeni VMS, a cloud-based Visitor and Vehicle Management System used by organisations across Kenya to manage and record access to their premises.
Mgeni VMS serves businesses, estates, manufacturing facilities, warehouses, logistics operators, and other organisations (“Clients”) that need to log and track the movement of visitors, employees, contractors, delivery personnel, and vehicles at their entry points.
You may contact us at any time at info@ict-a.com or at www.ict-a.com.
2. Scope of This Policy
This Privacy Policy applies to:
- Account users — security guards, gate operators, administrators, and managers who hold accounts on Mgeni VMS.
- Visitor and personnel data — personal information captured about visitors, contractors, employees, delivery personnel, and vehicle occupants during check-in and check-out at premises operating Mgeni VMS.
- Technical and usage data — information collected automatically when the application is in use.
This policy covers the Mgeni VMS Android application, the Mgeni VMS web dashboard, and associated notification and communication services.
3. Data Controller and Data Processor
Under the Kenya Data Protection Act, 2019, the following roles apply to the Mgeni VMS service:
The subscribing organisation (our Client) is the Data Controller for visitor and personnel data captured through their Mgeni VMS account. They determine what data is collected, for what purpose, and for how long it is retained at a premises level.
If you are a visitor, employee, or contractor whose data was captured at a premises operating Mgeni VMS and you wish to exercise your data rights, you should first contact the organisation that operates that premises. You may also contact us directly and we will assist in directing your request to the relevant Data Controller.
4. Personal Data We Collect
4.1 — Visitor and Personnel Data (captured at check-in)
The following data is captured by security personnel when an individual enters or exits a premises operating Mgeni VMS.
| Data Field | Purpose of Collection | When Collected |
|---|---|---|
| Full name | Identifying the individual entering or exiting the premises | All check-ins |
| Phone number | Contact verification and SMS host notifications | All check-ins |
| National ID / Passport number | Identity verification at the gate | All check-ins |
| Vehicle registration number | Vehicle tracking and drive-in / drive-out records | Vehicle check-ins |
| Vehicle type and description | Vehicle management and entry/exit condition checklists | Vehicle check-ins |
| Organisation or company name | Recording who the visitor or contractor represents | All check-ins |
| Host / person being visited | Routing arrival notifications to the correct employee | All check-ins |
| Purpose of visit | Security screening and premises access records | All check-ins |
| Visitor category | Classification: visitor, contractor, employee, delivery, hailing cab, etc. | All check-ins |
| Check-in and check-out timestamps | Digital audit trail of all premises movement | Automatically recorded |
| Watchlist / blacklist status | System flag to alert security when a restricted individual attempts entry | System-generated on match |
4.2 — Account User Data (guards, administrators, managers)
| Data Field | Purpose of Collection |
|---|---|
| Full name | Account identification and user management |
| Email address | Account registration, login, and system notifications |
| Phone number | Account management and SMS communications |
| Job title / role | Access control and permission management within Mgeni VMS |
| Organisation affiliation | Multi-site and multi-tenant account management |
| User ID (system-generated) | Unique account identification across the platform |
4.3 — Host Data (employees receiving visitor notifications)
| Data Field | Purpose of Collection |
|---|---|
| Full name | Identifying the employee to be notified of their visitor’s arrival |
| Email address | Sending visitor arrival notifications (all subscription plans) |
| Phone number | Sending SMS visitor arrival notifications (Pro plan and above) |
4.4 — Technical and Usage Data (collected automatically)
| Data Field | Purpose of Collection |
|---|---|
| Device type and model | Application compatibility and technical support |
| Mobile operating system version | Ensuring the application functions correctly on the user’s device |
| Device ID (Android ID) | Session management and application security |
| IP address | Security monitoring and fraud prevention |
| App interaction logs | Application improvement and feature usage analysis |
| Crash logs and diagnostics | Identifying and resolving application errors |
| Session timestamps and duration | Usage analytics and service improvement |
5. How We Use Personal Data
Core Service Delivery
- Logging and tracking visitor, contractor, employee, and vehicle movements through client premises in real time
- Enabling security guards to perform fast, accurate check-ins and check-outs at the gate
- Sending host email and SMS notifications when visitors arrive or depart
- Matching arriving individuals against watchlists and blacklists and triggering security alerts where a match is found
- Providing a real-time on-site dashboard showing all individuals and vehicles currently on the premises
- Generating emergency evacuation roll calls and live accountability reports
- Supporting pre-registration of expected visitors and quick re-check-in of returning visitors
- Managing records of inbound and outbound dispatch movements
Reporting and Compliance
- Generating automated daily, weekly, and monthly access reports in PDF and Excel format
- Maintaining complete digital audit trails available for reporting, investigations, audits, and regulatory compliance
- Assisting organisations in meeting their obligations under the Kenya Data Protection Act, 2019, and applicable health, safety, and security regulations
Account and Service Management
- Creating and managing user accounts for guards, administrators, and managers
- Providing customer support and responding to enquiries from account holders
- Sending service notifications, security advisories, and product updates to registered account users
- Authenticating users and preventing unauthorised access to the platform
Application Improvement
- Analysing usage patterns to improve application features and performance
- Diagnosing and resolving technical errors and application crashes
- Conducting internal analytics, in aggregate and anonymised form, to understand how Mgeni VMS is used across different industries and premises types
6. Legal Basis for Processing
Under the Kenya Data Protection Act, 2019, we process personal data on the following legal bases:
- Contractual necessity — processing required to deliver the Mgeni VMS service to subscribing organisations and their account users.
- Legitimate interests — processing necessary for premises security, fraud prevention, and the physical safety of individuals accessing client facilities.
- Legal obligation — processing required to comply with the Kenya Data Protection Act, 2019, the Data Protection (General) Regulations, 2021, and other applicable Kenyan legal requirements.
- Consent — where we rely on consent for specific optional communications, consent may be withdrawn at any time by contacting us at info@ict-a.com.
For visitor and personnel data captured at client premises, the legal basis is determined by the subscribing organisation as the Data Controller — typically on the grounds of legitimate security interests or the contractual relationship between the organisation and those accessing their premises.
7. Data Sharing and Disclosure
We do not sell personal data to third parties. We share personal data only in the following circumstances:
With the Subscribing Organisation
Visitor, personnel, and vehicle data is accessible to the subscribing organisation’s authorised administrators and security personnel. This is the primary purpose of the service.
With Service Providers
We engage trusted third-party providers to operate Mgeni VMS, including cloud hosting providers, and email delivery services. These providers are contractually bound to process data only on our instructions and in accordance with this Privacy Policy.
For Legal Compliance and Safety
We may disclose personal data to law enforcement authorities, courts, or regulatory bodies where required by Kenyan law, a valid court order, or where necessary to protect the rights, property, or safety of individuals.
8. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes described in this policy and to comply with applicable legal obligations.
| Data Category | Retention Period |
|---|---|
| Visitor and personnel check-in records | Duration of the Client’s active subscription plus 12 months after account closure, unless a shorter period is configured by the Client or deletion is requested earlier. |
| Vehicle access and dispatch records | Duration of the Client’s active subscription plus 12 months after account closure. |
| Watchlist and blacklist entries | Until removed by the Client organisation or until account closure, whichever is earlier. |
| Account user data (guards, admins, managers) | Duration of the user’s account plus 24 months after account closure to resolve any disputes or post-termination queries. |
| Host notification records | 12 months from the date of the notification event. |
| Crash logs and technical diagnostics | Up to 12 months from the date of collection. |
| Usage and analytics data | Up to 24 months, retained in aggregated or anonymised form only. |
| Customer support correspondence | Up to 24 months from the date the matter was resolved. |
Upon expiry of retention periods, personal data is securely deleted or irreversibly anonymised. Residual copies in encrypted backup systems are retained only in line with our standard backup schedule and are not used for any active processing purpose.
9. Security of Personal Data
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- Encryption of all data in transit using HTTPS / TLS protocols
- Access controls restricting data access to authorised personnel only
- Role-based permissions within the Mgeni VMS application limiting what each user can access
- Regular security monitoring and vulnerability assessments
- Secure cloud infrastructure managed in accordance with industry standards
No method of internet transmission or electronic storage is completely secure. In the event of a personal data breach, we will notify the Office of the Data Protection Commissioner (ODPC) and affected parties in accordance with the requirements of the Kenya Data Protection Act, 2019.
10. Your Data Rights
Under the Kenya Data Protection Act, 2019, you have the following rights in relation to your personal data:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may request correction of inaccurate or incomplete personal data.
- Right to erasure — you may request deletion of your personal data where there is no lawful basis to retain it.
- Right to restrict processing — you may request that we limit how we use your data in certain circumstances.
- Right to object — you may object to processing based on legitimate interests or for direct marketing purposes.
- Right to data portability — you may request your personal data in a structured, machine-readable format.
To exercise any of these rights, please contact us at info@ict-a.com. We will respond within 21 days as required under the Kenya Data Protection Act, 2019.
If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at www.odpc.go.ke.
11. Children’s Privacy
Mgeni VMS is a professional security management tool intended for use by adults in a business context. The application is not directed at individuals under the age of 18 and we do not knowingly collect personal data from anyone under that age.
If we become aware that personal data from a person under 18 has been collected, we will take prompt steps to delete it. If you are a parent or guardian and believe your child’s data has been collected, please contact us at info@ict-a.com.
14. Contact and Data Protection Enquiries
For any questions regarding this Privacy Policy, to exercise your data rights, or to report a data protection concern, please contact us using the details below.
| Company | ICT Africa Consulting Services Limited |
| Group | Ramco Group, Kenya |
| info@ict-a.com | |
| Website | www.ict-a.com |
| Country of Operation | Kenya |
| ODPC Registration | Registered Data Processor — Office of the Data Protection Commissioner, Kenya |
| Applicable Law | Kenya Data Protection Act, 2019 — Data Protection (General) Regulations, 2021 |