Mgeni VMS - ICT Africa Consulting Services Limited Legal Documents

Privacy Policy

ICT Africa Consulting Services Limited, a member of the Ramco Group, operates Mgeni VMS and is registered as a Data Processor with the Office of the Data Protection Commissioner (ODPC) of Kenya. This policy describes how we collect, use, store, and protect personal data in connection with the Mgeni VMS service.

1. Who We Are

ICT Africa Consulting Services Limited (“ICT Africa”, “we”, “us”, “our”) is a member of the Ramco Group, incorporated in Kenya. We develop and operate Mgeni VMS, a cloud-based Visitor and Vehicle Management System used by organisations across Kenya to manage and record access to their premises.

Mgeni VMS serves businesses, estates, manufacturing facilities, warehouses, logistics operators, and other organisations (“Clients”) that need to log and track the movement of visitors, employees, contractors, delivery personnel, and vehicles at their entry points.

You may contact us at any time at info@ict-a.com or at www.ict-a.com.

2. Scope of This Policy

This Privacy Policy applies to:

This policy covers the Mgeni VMS Android application, the Mgeni VMS web dashboard, and associated notification and communication services.

3. Data Controller and Data Processor

Under the Kenya Data Protection Act, 2019, the following roles apply to the Mgeni VMS service:

ICT Africa Consulting Services Limited is a Data Processor for visitor and personnel data collected at client premises. We process that data solely on the instructions of our subscribing Client organisations and do not use it for our own independent purposes.

The subscribing organisation (our Client) is the Data Controller for visitor and personnel data captured through their Mgeni VMS account. They determine what data is collected, for what purpose, and for how long it is retained at a premises level.

If you are a visitor, employee, or contractor whose data was captured at a premises operating Mgeni VMS and you wish to exercise your data rights, you should first contact the organisation that operates that premises. You may also contact us directly and we will assist in directing your request to the relevant Data Controller.

4. Personal Data We Collect

4.1 — Visitor and Personnel Data (captured at check-in)

The following data is captured by security personnel when an individual enters or exits a premises operating Mgeni VMS.

Data Field Purpose of Collection When Collected
Full name Identifying the individual entering or exiting the premises All check-ins
Phone number Contact verification and SMS host notifications All check-ins
National ID / Passport number Identity verification at the gate All check-ins
Vehicle registration number Vehicle tracking and drive-in / drive-out records Vehicle check-ins
Vehicle type and description Vehicle management and entry/exit condition checklists Vehicle check-ins
Organisation or company name Recording who the visitor or contractor represents All check-ins
Host / person being visited Routing arrival notifications to the correct employee All check-ins
Purpose of visit Security screening and premises access records All check-ins
Visitor category Classification: visitor, contractor, employee, delivery, hailing cab, etc. All check-ins
Check-in and check-out timestamps Digital audit trail of all premises movement Automatically recorded
Watchlist / blacklist status System flag to alert security when a restricted individual attempts entry System-generated on match

4.2 — Account User Data (guards, administrators, managers)

Data Field Purpose of Collection
Full name Account identification and user management
Email address Account registration, login, and system notifications
Phone number Account management and SMS communications
Job title / role Access control and permission management within Mgeni VMS
Organisation affiliation Multi-site and multi-tenant account management
User ID (system-generated) Unique account identification across the platform

4.3 — Host Data (employees receiving visitor notifications)

Data Field Purpose of Collection
Full name Identifying the employee to be notified of their visitor’s arrival
Email address Sending visitor arrival notifications (all subscription plans)
Phone number Sending SMS visitor arrival notifications (Pro plan and above)

4.4 — Technical and Usage Data (collected automatically)

Data Field Purpose of Collection
Device type and model Application compatibility and technical support
Mobile operating system version Ensuring the application functions correctly on the user’s device
Device ID (Android ID) Session management and application security
IP address Security monitoring and fraud prevention
App interaction logs Application improvement and feature usage analysis
Crash logs and diagnostics Identifying and resolving application errors
Session timestamps and duration Usage analytics and service improvement

5. How We Use Personal Data

Core Service Delivery

Reporting and Compliance

Account and Service Management

Application Improvement

6. Legal Basis for Processing

Under the Kenya Data Protection Act, 2019, we process personal data on the following legal bases:

For visitor and personnel data captured at client premises, the legal basis is determined by the subscribing organisation as the Data Controller — typically on the grounds of legitimate security interests or the contractual relationship between the organisation and those accessing their premises.

7. Data Sharing and Disclosure

We do not sell personal data to third parties. We share personal data only in the following circumstances:

With the Subscribing Organisation

Visitor, personnel, and vehicle data is accessible to the subscribing organisation’s authorised administrators and security personnel. This is the primary purpose of the service.

With Service Providers

We engage trusted third-party providers to operate Mgeni VMS, including cloud hosting providers, and email delivery services. These providers are contractually bound to process data only on our instructions and in accordance with this Privacy Policy.

For Legal Compliance and Safety

We may disclose personal data to law enforcement authorities, courts, or regulatory bodies where required by Kenyan law, a valid court order, or where necessary to protect the rights, property, or safety of individuals.

8. Data Retention

We retain personal data only for as long as is necessary to fulfil the purposes described in this policy and to comply with applicable legal obligations.

Data Category Retention Period
Visitor and personnel check-in records Duration of the Client’s active subscription plus 12 months after account closure, unless a shorter period is configured by the Client or deletion is requested earlier.
Vehicle access and dispatch records Duration of the Client’s active subscription plus 12 months after account closure.
Watchlist and blacklist entries Until removed by the Client organisation or until account closure, whichever is earlier.
Account user data (guards, admins, managers) Duration of the user’s account plus 24 months after account closure to resolve any disputes or post-termination queries.
Host notification records 12 months from the date of the notification event.
Crash logs and technical diagnostics Up to 12 months from the date of collection.
Usage and analytics data Up to 24 months, retained in aggregated or anonymised form only.
Customer support correspondence Up to 24 months from the date the matter was resolved.

Upon expiry of retention periods, personal data is securely deleted or irreversibly anonymised. Residual copies in encrypted backup systems are retained only in line with our standard backup schedule and are not used for any active processing purpose.

9. Security of Personal Data

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

No method of internet transmission or electronic storage is completely secure. In the event of a personal data breach, we will notify the Office of the Data Protection Commissioner (ODPC) and affected parties in accordance with the requirements of the Kenya Data Protection Act, 2019.

10. Your Data Rights

Under the Kenya Data Protection Act, 2019, you have the following rights in relation to your personal data:

To exercise any of these rights, please contact us at info@ict-a.com. We will respond within 21 days as required under the Kenya Data Protection Act, 2019.

Account deletion: Account users (guards, administrators, managers) may request deletion of their account at any time by contacting info@ict-a.com. Account data will be removed in accordance with the retention periods set out in Section 8. Visit and access log records associated with client premises may be retained where a continuing legal obligation or legitimate security interest applies.

If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at www.odpc.go.ke.

11. Children’s Privacy

Mgeni VMS is a professional security management tool intended for use by adults in a business context. The application is not directed at individuals under the age of 18 and we do not knowingly collect personal data from anyone under that age.

If we become aware that personal data from a person under 18 has been collected, we will take prompt steps to delete it. If you are a parent or guardian and believe your child’s data has been collected, please contact us at info@ict-a.com.

14. Contact and Data Protection Enquiries

For any questions regarding this Privacy Policy, to exercise your data rights, or to report a data protection concern, please contact us using the details below.

Company ICT Africa Consulting Services Limited
Group Ramco Group, Kenya
Email info@ict-a.com
Website www.ict-a.com
Country of Operation Kenya
ODPC Registration Registered Data Processor — Office of the Data Protection Commissioner, Kenya
Applicable Law Kenya Data Protection Act, 2019 — Data Protection (General) Regulations, 2021