Novascape Technologies

Privacy Policy

How Novascape Technologies handles personal data across our website, products, subscriptions and project work.

Last updated 7 August 2026

This document is a working draft prepared in-house. It has not yet been reviewed by a qualified Kenyan advocate or a data protection specialist. The health-data and processor clauses in particular need review before this is relied on — and if you process health data at scale, check whether you are required to register with the Office of the Data Protection Commissioner and appoint a Data Protection Officer.

1. Who we are and what this covers

Novascape Technologies (Nairobi, Kenya) provides software and automation services to businesses in Kenya. This policy explains how we handle personal data across everything we offer: our website, our subscription products (PharmaSync, ZyncAPI), our automation subscriptions (AI Employee, WhatsApp Automation, Executive Dashboard, AI Internal Automation), and our project services (eTIMS Integration, Payment Integration, API Integration, Custom Software, Automations, Web Design).

It is written against the Kenyan Data Protection Act 2019. You can reach us about anything in this policy at hello@novascape.co.ke.

2. Our two different roles

We handle personal data in two distinct capacities, and your rights differ depending on which applies.

As controller

For our own website visitors, enquiries, lead-magnet downloads, newsletter subscribers, account holders and client billing records. We decide why and how this data is processed, and you can exercise your rights directly against us.

As processor

For the data inside a customer's product account — their customers, invoices, prescriptions, transactions. Our customer is the controller; we act on their documented instructions. If you are that customer's customer, raise your request with them and we will support them in answering it.

3. What we collect directly from you

When you interact with us as a business or a prospect:

  • Enquiry and lead-magnet forms: your name, email address, phone number, company name and industry, plus any message you write and which resource you requested.
  • Accounts: your name, email address, phone number, a hashed password (never the password itself) and your role.
  • Client records: company name, contact details, KRA PIN, billing address, invoices, payments and support tickets.
  • Technical data: IP address and request metadata, used to secure the service and rate-limit abusive form submissions.
  • Attribution: the page you arrived on and any campaign parameters in the link you followed.

We do not use advertising cookies and we do not build behavioural profiles of visitors.

4. What our products process on your behalf

When you use one of our products, you decide what goes into it. We process that data only to run the service for you, to support you when you ask, and to meet our legal obligations.

PharmaSync

Customer and prescription records, insurance and NHIF/SHA claim details, stock and sales transactions, and eTIMS invoice data. This can include health information about your customers.

ZyncAPI

The request and response payloads you send through the API — which may include taxpayer identifiers, transaction amounts, phone numbers and NHIF/SHA membership details, depending on the endpoint you call.

For automation subscriptions and project services, the data involved depends entirely on the systems we connect. We agree that in writing at scoping, and we access only what the work requires.

5. Health and other sensitive data

Some of our work touches data the Data Protection Act 2019 treats as sensitive — in particular health information in pharmacy prescription records and NHIF/SHA claims.

  • Where we process this data, we do so as a processor acting on the pharmacy's or provider's instructions, not for our own purposes.
  • We never use health data for marketing, analytics, product development or model training.
  • Access is restricted to the specific staff supporting that customer, and access is logged.
  • If you are a pharmacy or health provider, you remain the controller of your patients' data and are responsible for the lawful basis on which you collected it.

6. Why we process it, and on what basis

We rely on the following grounds under the Data Protection Act 2019:

Performance of a contract

Providing the product or service you bought, supporting it, and invoicing you for it.

Consent

Sending you a resource you requested, and marketing emails. You can withdraw consent at any time without affecting service messages.

Legitimate interests

Responding to a business enquiry you sent us, securing our systems against abuse, and understanding in aggregate which parts of the site are useful.

Legal obligation

Keeping tax and accounting records for the period Kenyan law requires.

7. Marketing

If you give us your details we may contact you about services relevant to your enquiry. Every marketing email carries an unsubscribe link, and unsubscribing never affects service messages such as invoices, security notices or password resets.

Where we contact you on WhatsApp, we do so on the number you gave us, and you can ask us to stop at any time by replying.

8. Who else sees your data

We do not sell personal data. We share it only with providers who help us run the service, under contract and on our instructions:

Cloud hosting

Running the application and its database. Hosted in a region we can confirm on request.

Amazon Web Services (SES)

Sending transactional and notification email — password resets, invoices, enquiry confirmations.

Cloudflare R2

Storing files such as downloadable resources and documents you upload.

Payment and compliance rails

Where the service requires it, data passes to KRA (eTIMS), Safaricom (M-PESA) and NHIF/SHA. These parties are independent controllers of what they receive.

Some of these providers store data outside Kenya. Where that happens, we rely on contractual safeguards with the provider. We share data with anyone else only where the law requires it, and we will tell you unless we are legally barred from doing so.

9. Demonstration environments

We publish demo environments — including GlowSuite — that use shared logins so anyone can try the product.

Anything entered into a demo may be visible to other people evaluating it, and may be reset or deleted without notice. Please do not enter real customer, patient or payment data into a demo.

10. How long we keep it

  • Enquiries and lead records: while there is an active business relationship, and for up to 24 months after the last contact.
  • Newsletter subscriptions: until you unsubscribe.
  • Customer product data: for the life of your subscription, then available for export for at least 30 days before deletion.
  • Invoices, payments and tax records: for the statutory retention period, regardless of whether you remain a customer.
  • Security and access logs: typically 90 days.

11. Your rights

Under the Data Protection Act 2019 you can ask us to give you a copy of the data we hold about you, correct it, delete it, restrict how we use it, or object to a particular use. You can also ask for it in a portable format, and withdraw consent where consent is the basis we relied on.

Write to hello@novascape.co.ke and we will respond within the statutory period. We may need to verify your identity first. If you are unhappy with our response, you can complain to the Office of the Data Protection Commissioner.

Where we hold your data as a processor for one of our customers, we will direct your request to them, since it is their decision to make.

12. How we protect it

  • Data is transmitted over encrypted connections and stored on access-controlled infrastructure.
  • Passwords are stored hashed with a modern algorithm. We can never read your password.
  • Access to systems holding personal data is limited to staff who need it for their role.
  • Password reset links are single-use and expire within an hour.
  • No system is perfectly secure. If a breach affects your data we will notify you and the Data Protection Commissioner as the law requires.

13. Cookies

We use only cookies that are necessary for the site to work — keeping you signed in, protecting forms against cross-site request forgery, and remembering your light or dark theme preference. We do not use advertising or cross-site tracking cookies, so there is no consent banner to dismiss.

14. Children

Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18 through this website. Where a customer's own records include data about minors — for example a pharmacy dispensing to a child — we process it only as their processor, on their instructions.

15. Changes and contact

We may update this policy. The current version is always posted here with its revision date, and we will tell customers directly about material changes.

Questions, requests or complaints: hello@novascape.co.ke, or write to us at Nairobi, Kenya.