Effective date: 30 August 2026
This Privacy Policy explains how Solviq Technologies, of P.O. Box 5365, 80401 Diani, Kenya ("ArkCAE", "we", "us" or "our"), collects and uses personal data in connection with ArkCAE. It is intended to meet the transparency requirements of Kenya's Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021.
1. Our role
We are a data controller for account, subscription, billing, website, security, support and business-relationship data that we determine how to use. When a business customer enters customer, supplier, employee, payroll, accounting or similar data into ArkCAE ("Customer Data"), that customer is normally the controller and ArkCAE is its data processor, acting on documented instructions. Questions about Customer Data should ordinarily be directed first to the relevant customer, though we will assist it as required by law and contract.
2. Personal data we collect
- Account and identity: name, email, telephone number, organisation, role and authentication records.
- Subscription and transaction: plan, invoices, payment status and Paystack references; payment-card details are handled by Paystack and are not intended to be stored by us.
- Customer Data: contacts, invoices, suppliers, transactions, tax records, payroll records, national identifiers, bank or mobile-money details and other information a customer submits.
- Technical and usage: IP address, device/browser information, timestamps, diagnostic, audit, security and feature-usage logs.
- Communications: support requests, feedback, survey responses and other correspondence.
- Integration data: identifiers, tokens, settings and records exchanged with integrations you enable.
If required data is not provided, we may be unable to create an account, process payment, secure the Service or provide requested features.
3. Why and on what basis we process data
- To create accounts, provide features, support users and collect fees, as necessary to perform our contract.
- To secure, troubleshoot, audit and improve the Service and prevent fraud, based on our legitimate interests, balanced against individual rights.
- To keep tax, accounting, corporate and compliance records and respond to lawful requests, to comply with legal obligations.
- To send essential service communications and, where permitted, relevant product updates. Marketing consent may be withdrawn at any time; we will honour objections to direct marketing.
- For any other specific purpose disclosed at collection and supported by consent or another lawful basis.
We process Customer Data to perform our contract with the customer and on its instructions. The customer is responsible for identifying its lawful basis, including for employee and sensitive personal data.
4. Sensitive personal data and payroll
Payroll may include national identity numbers, financial details, family information and other sensitive personal data. We process it only where necessary for the enabled payroll service, on the customer's instructions, with safeguards appropriate to the risk, and where a lawful condition permits. Customers must limit access, provide required employee notices and avoid entering unnecessary sensitive data. ArkCAE is not designed for children and must not be used to create accounts for persons under 18.
5. Sources of data
We collect data directly from users, from the customer organisation that authorises them, automatically from use of the Service, and from integrations the customer enables. Customer Data about employees, customers or suppliers is supplied by the relevant customer, which must ensure that indirect collection is lawful and transparent.
6. Disclosures and subprocessors
We do not sell personal data. We disclose only what is reasonably necessary to:
- hosting, infrastructure, communications, analytics and support providers bound by data-protection terms;
- Paystack for subscription payment;
- Google services, KRA eTIMS, and banking or mobile-money providers when a customer enables the relevant integration;
- professional advisers, auditors, insurers and a successor in a genuine corporate transaction under confidentiality; and
- courts, regulators, law-enforcement or public authorities where lawfully required, or to establish, exercise or defend legal claims.
| Recipient | Purpose and data | When used |
|---|---|---|
| Paystack | Subscription payment, transaction identifiers and payment status | When you subscribe or pay |
| Account and spreadsheet data needed for the selected Google integration | Only when you enable it | |
| KRA eTIMS | Invoice and tax information required for eTIMS functionality | Only when configured or submitted |
| Connected bank or mobile-money provider | Account identifiers and transaction data needed for the connection | Only when you enable it |
| Infrastructure and communications providers used by ArkCAE | Hosted Customer Data, logs and message-delivery information strictly necessary to operate and support the Service | As necessary to provide the Service |
We assess providers before appointment, require appropriate privacy and security terms, and remain responsible for subprocessors as required by law and contract. We will maintain this section as our provider list changes and, where practicable, notify account administrators of a new subprocessor before it begins processing Customer Data.
7. Transfers outside Kenya
Some providers or integrations may process data outside Kenya. Before a transfer, we will establish a lawful transfer basis under Kenyan law, such as appropriate safeguards, an applicable adequacy decision, necessity recognised by law, or valid consent; assess the recipient and destination; contractually restrict use; and apply appropriate technical and organisational measures. We will obtain consent where Kenyan law requires it, including for sensitive personal data transferred out of Kenya where applicable. Contact us for information about a specific transfer and its safeguards.
8. Retention and account closure
We keep personal data only for as long as necessary for the stated purpose, taking account of legal duties, disputes, security and the customer's documented instructions. During an active account, Customer Data is retained to provide the Service.
You should export Customer Data before closing the account. After account closure, we delete or irreversibly anonymise Customer Data from active systems within six months and from backups within a further three months, unless law, a preservation duty, a dispute or the controller's lawful instruction requires longer retention. A cancelled paid account may remain available on a read-only basis where the Service supports it. We may delete an unpaid account after 120 consecutive days of inactivity, but will first provide notice and a reasonable opportunity to export data.
ArkCAE's own contract, invoice, tax and corporate accounting records may be retained for up to seven years after the relevant transaction or longer where a legal proceeding, audit or written legal requirement applies. Kenyan tax rules may require relevant tax documents for at least five years, while company accounting records may require seven years. Customers remain responsible for exporting and retaining their own statutory records; account closure does not transfer that duty to ArkCAE.
Security and audit logs are ordinarily retained for up to two years. Support records and failed-trial or prospect records are retained only while needed to resolve the request, administer the relationship, prevent abuse or meet legal obligations, and are then deleted or anonymised. Suppression records may be kept to honour marketing opt-outs.
9. Your rights
Subject to the Data Protection Act, 2019 and lawful exceptions, you may ask to be informed about use of your personal data; access it; object to all or part of its processing; correct false, inaccurate, outdated, incomplete or misleading data; and erase data where the legal conditions are met. You may also request restriction, withdraw consent without affecting earlier lawful processing, object to direct marketing, and seek review of a solely automated decision that significantly affects you where applicable.
Send a request to dennismacharia@zohomail.com, describing the right and data concerned. We may reasonably verify identity and authority. Access requests will be handled within the period required by law (currently seven days under the General Regulations), and rectification requests within the applicable period (currently fourteen days). Other requests will be handled without undue delay and within applicable statutory periods. Requests are ordinarily free, but lawful exceptions may apply.
Where ArkCAE processes Customer Data for a customer, we may refer the request to that controller. A right to erasure is not absolute; we may retain data required by law or needed for legal claims, while restricting it from other use where appropriate.
10. Complaints
Please contact us first so we can investigate. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya through its official channels at odpc.go.ke. This does not affect any other legal remedy.
11. Security and personal-data breaches
We use risk-appropriate administrative, technical and physical measures designed to protect confidentiality, integrity and availability, including access controls, authentication safeguards, encryption where appropriate, tenant separation, logging, backups, staff confidentiality and vendor oversight. No system is completely secure, and these statements must be verified against implemented controls before publication.
We assess suspected breaches and comply with Kenyan notification duties. Where we act as processor, we notify the customer without delay and, where reasonably practicable, within 48 hours after awareness. Where we act as controller and unauthorised access or acquisition creates a real risk of harm, we notify the Data Commissioner without delay and within 72 hours after awareness, and communicate with affected individuals as required.
12. Cookies and similar technologies
We use session and persistent cookies or similar local-storage technologies. Strictly necessary technologies support sign-in, authentication, security, load balancing, session continuity and saved consent choices and cannot be disabled through our preference controls without affecting the Service.
Where deployed, functional cookies remember settings such as language, region and display preferences. Analytics cookies help us understand aggregate use, performance and feature adoption. Embedded third-party content or an integration may set its own technologies when you use it. We do not permit advertising trackers merely to build third-party advertising profiles.
Non-essential functional, analytics or third-party cookies will be off until you consent where consent is required. You may change your choice through the cookie-preference control, where available, or your browser settings. Cookie duration is limited to the period needed for its stated purpose: session cookies expire when the session ends, preference and consent cookies ordinarily within one year, and analytics identifiers ordinarily within two years. Disabling some cookies may reduce functionality.
13. Changes to this Policy
We may update this Policy to reflect changes in law, technology or our practices. We will post the revised version with a new effective date and give reasonable notice of material changes. Where required, we will obtain consent before applying a new use to data already collected.
14. Contact and data-protection details
Privacy requests and questions: dennismacharia@zohomail.com. Postal address: P.O. Box 5365, 80401 Diani, Kenya. Privacy contact: dennismacharia@zohomail.com. Registration with the Office of the Data Protection Commissioner as a data controller and/or processor is ongoing; applicable registration number(s) will be published once issued.