Legal
Privacy Policy
Last updated: November 1, 2026
Clarivexa Technologies Ltd. (“Clarivexa”, “we”, “us”) provides an agentic Governance, Risk & Compliance (GRC) and AI governance platform. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit our website, book a demo, or use the Clarivexa platform.
1. Data we collect
- Account data: name, work email, organization, role.
- Workspace data: frameworks, controls, evidence, policies, risks, incidents, and audit records that you or your team upload or generate through the platform.
- Usage data: device, browser, IP address, pages viewed, and product events used to secure and improve the service.
- Communications: emails and support messages you send to us.
2. How we use data
- Deliver, secure, and improve the Clarivexa platform.
- Run AI agents that operate on your workspace data strictly on your instructions.
- Respond to your requests, provide support, and send service notifications.
- Meet legal, regulatory, and contractual obligations.
We do not use customer content to train Clarivexa or third-party AI models.
3. Legal bases (GDPR / Kenya DPA 2019)
We process personal data under one or more of: performance of a contract, legitimate interests (product security and improvement), consent (marketing communications), and legal obligation.
4. Sharing and subprocessors
We share data with vetted subprocessors that host our infrastructure, send email, provide analytics, or supply AI model inference. A current list is available on our Trust Center.
5. International transfers
Where personal data leaves your jurisdiction, we rely on Standard Contractual Clauses, adequacy decisions, or equivalent safeguards recognized under GDPR and the Kenya Data Protection Act, 2019.
6. Data retention
We retain workspace data for as long as your organization maintains an active subscription, plus a limited grace period. Audit logs are retained for at least seven years to preserve inspection integrity. You may request earlier deletion at any time.
7. Security
AES-256 encryption at rest, TLS 1.3 in transit, isolated tenant environments, SSO/SCIM, least-privilege access, continuous monitoring, and independent penetration testing.
8. Your rights
Subject to applicable law, you may access, correct, delete, port, or object to the processing of your personal data, and lodge a complaint with a supervisory authority (including the Office of the Data Protection Commissioner in Kenya). Submit requests to privacy@clarivexa.io.
9. Cookies
We use strictly necessary cookies for authentication and session integrity, and optional analytics cookies to understand product usage. You can manage preferences in your browser.
10. Contact
Clarivexa Technologies Ltd. · Nairobi, Kenya · privacy@clarivexa.io