1. Who We Are
DRONGO Technology Limited ("DRONGO", "we", "us") is an enterprise technology and logistics company headquartered in Westlands, Nairobi, Kenya, with regional offices in Mogadishu and Addis Ababa. We are the data controller for the personal data described in this policy.
This policy applies to drongotech.co.ke, our business messaging channels built on the Meta platforms (including the WhatsApp Business Platform), our newsletters and reports, and any other service that links to this policy.
2. Personal Data We Collect
2.1 Data you give us
- Contact details — name, email address, phone number, company and job title when you fill in a contact form, request a report, or subscribe to our newsletter.
- Enquiry content — the messages, requirements, attachments and other information you send us.
2.2 Data from WhatsApp and other Meta messaging channels
When you message us on WhatsApp, or we message you after you have opted in, we receive and process the following through the WhatsApp Business Platform (Cloud API) provided by Meta:
- Your WhatsApp phone number and WhatsApp profile name.
- Message content — text, images, documents, voice notes, locations, contacts and other media you choose to send, and our replies.
- Message metadata — timestamps, message IDs, and delivery and read status.
- Opt-in and opt-out records — when and how you agreed to receive messages from us, and any request to stop.
If you contact us through Facebook Messenger or Instagram Direct, we receive the equivalent information those services make available to businesses (for example your page-scoped user ID, public profile name and the messages you send).
We do not receive or have access to your contacts list, your other WhatsApp chats, your WhatsApp status, or your payment credentials.
2.3 Data collected automatically
- Technical data — IP address, browser type, device type, pages visited and referring URL, collected through server logs and essential cookies.
- Preference data — for example your light/dark theme choice, stored locally in your browser.
3. How We Use Your Data and Our Legal Basis
| Purpose | Legal basis |
|---|---|
| Responding to enquiries and support requests, including over WhatsApp | Taking steps at your request before entering into a contract; legitimate interests |
| Delivering services you have contracted (order updates, deployment scheduling, support tickets, service notifications) | Performance of a contract |
| Sending WhatsApp messages you have opted in to, including updates and, where you agreed, marketing | Consent |
| Sending newsletters and regional reports | Consent |
| Securing our systems, preventing fraud and abuse, and keeping records | Legitimate interests; legal obligation |
| Complying with law, regulators and lawful requests | Legal obligation |
We do not sell your personal data, and we do not use data received through WhatsApp or other Meta platforms for any purpose other than communicating with you and providing our services. We do not use that data to build advertising profiles or share it with data brokers.
4. WhatsApp Messaging
- Opt-in. We only start a WhatsApp conversation with you if you have messaged us first or have given us clear permission to contact you on WhatsApp (for example through a form, in person, or by replying to us).
- Opt-out. You can stop messages at any time by replying
STOP, by blocking our number in WhatsApp, or by emailing info@drongotech.com. We will record the request and stop sending non-essential messages. - Meta's role. WhatsApp messages are carried by WhatsApp LLC / Meta Platforms, Inc. and Meta Platforms Ireland Limited. Meta processes message data on our behalf to deliver the Cloud API service, and also processes some data as an independent controller under its own terms. Please read the WhatsApp Privacy Policy and the WhatsApp Business Terms of Service.
- Encryption. Messages are end-to-end encrypted between your device and the WhatsApp Cloud API. They are decrypted on Meta's infrastructure so they can be delivered to our systems, where they are stored under the safeguards in section 8.
- Automated replies. Some messages may be answered by automated systems (for example to route your enquiry or acknowledge receipt). You can always ask to speak with a person.
5. Who We Share Data With
We share personal data only as needed, and only with:
- Meta Platforms — to send and receive messages on WhatsApp, Messenger and Instagram.
- Service providers acting on our instructions — cloud hosting, email delivery, customer-support and CRM tools, and IT security providers — bound by confidentiality and data protection terms.
- Partners involved in your order — for example, manufacturers, logistics carriers or financial institutions, only where needed to deliver a service you requested.
- Authorities — where required by law, court order, or to protect our rights, users or the public.
- A successor business — in a merger, acquisition or sale of assets, subject to this policy.
6. International Transfers
We operate in Kenya, Somalia and Ethiopia, and our service providers (including Meta) may process data in other countries, including the United States and the European Union. Where data leaves the country in which it was collected, we rely on appropriate safeguards such as contractual data protection clauses, the recipient's adequacy status, or your consent, as required by the Kenya Data Protection Act, 2019 and other applicable laws.
7. How Long We Keep Data
- WhatsApp and other chat messages — up to 24 months after our last interaction, unless the conversation forms part of a contract, dispute or legal record that we must keep longer.
- Opt-out records — kept for as long as needed to make sure we honour your request.
- Customer and contract records — for the life of the contract plus 7 years to meet tax and accounting obligations.
- Newsletter subscriptions — until you unsubscribe.
- Server logs — up to 90 days.
When data is no longer needed, we delete or anonymise it.
8. Security
We protect personal data with administrative, technical and physical safeguards appropriate to the risk, including encryption in transit (TLS), access controls based on role and least privilege, logged administrative access, and regular security review. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you and the regulator where the law requires.
9. Your Rights
Depending on where you live, including under the Kenya Data Protection Act, 2019 and, where applicable, the EU/UK GDPR, you have the right to:
- be informed about how your data is used;
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- have your data deleted (see our Data Deletion Instructions);
- object to or restrict processing, including direct marketing;
- withdraw consent at any time, without affecting processing already carried out;
- data portability, where technically feasible.
To exercise these rights, email info@drongotech.com. We will respond within 30 days. If you are unhappy with our response, you may complain to the Office of the Data Protection Commissioner (Kenya) or your local data protection authority.
10. Cookies
Our website uses only essential cookies needed for security (for example, form protection) and session management, plus local browser storage for display preferences. We do not use third-party advertising cookies.
11. Children
Our services are aimed at businesses and are not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has sent us personal data, contact us and we will delete it.
12. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top shows when it last changed. If we make material changes, we will take reasonable steps to tell you, for example by a notice on this website.
Contact Us
DRONGO Technology Limited
Westlands, Nairobi, Kenya
Email: info@drongotech.com
Phone / WhatsApp: +254 724 441 724