Legal

Privacy Policy

Last updated: November 1, 2026

Clarivexa Technologies Ltd. (“Clarivexa”, “we”, “us”) provides an agentic Governance, Risk & Compliance (GRC) and AI governance platform. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit our website, book a demo, or use the Clarivexa platform.

1. Data we collect

  • Account data: name, work email, organization, role.
  • Workspace data: frameworks, controls, evidence, policies, risks, incidents, and audit records that you or your team upload or generate through the platform.
  • Usage data: device, browser, IP address, pages viewed, and product events used to secure and improve the service.
  • Communications: emails and support messages you send to us.

2. How we use data

  • Deliver, secure, and improve the Clarivexa platform.
  • Run AI agents that operate on your workspace data strictly on your instructions.
  • Respond to your requests, provide support, and send service notifications.
  • Meet legal, regulatory, and contractual obligations.

We do not use customer content to train Clarivexa or third-party AI models.

3. Legal bases (GDPR / Kenya DPA 2019)

We process personal data under one or more of: performance of a contract, legitimate interests (product security and improvement), consent (marketing communications), and legal obligation.

4. Sharing and subprocessors

We share data with vetted subprocessors that host our infrastructure, send email, provide analytics, or supply AI model inference. A current list is available on our Trust Center.

5. International transfers

Where personal data leaves your jurisdiction, we rely on Standard Contractual Clauses, adequacy decisions, or equivalent safeguards recognized under GDPR and the Kenya Data Protection Act, 2019.

6. Data retention

We retain workspace data for as long as your organization maintains an active subscription, plus a limited grace period. Audit logs are retained for at least seven years to preserve inspection integrity. You may request earlier deletion at any time.

7. Security

AES-256 encryption at rest, TLS 1.3 in transit, isolated tenant environments, SSO/SCIM, least-privilege access, continuous monitoring, and independent penetration testing.

8. Your rights

Subject to applicable law, you may access, correct, delete, port, or object to the processing of your personal data, and lodge a complaint with a supervisory authority (including the Office of the Data Protection Commissioner in Kenya). Submit requests to privacy@clarivexa.io.

9. Cookies

We use strictly necessary cookies for authentication and session integrity, and optional analytics cookies to understand product usage. You can manage preferences in your browser.

10. Contact

Clarivexa Technologies Ltd. · Nairobi, Kenya · privacy@clarivexa.io