1. Who we are
Griot Data Technologies (“Griot”, “we”) operates the Griot platform: Griot Cloud, Ask Griot, and the Griot Marketplace — a storefront for contract-governed, certified datasets on African markets. This policy explains how we handle personal data when you browse our sites, create an account, or use the platform.
For your account and billing data, Griot is the data controller.
Questions or requests: brackly@griotdata.com
2. The short version
We collect only what running your account requires. We do not sell personal data. We do not use your browsing for advertising. Personal data inside producer datasets is masked before it ever leaves the producer's environment. The rest of this page is the detail behind those sentences.
3. Data we collect, and why
Browsing. We collect no personal data from anonymous visitors to our marketing and marketplace pages. They are pre-rendered; we set no tracking identifiers.
Account. When you sign in we collect your name, email address, and organisation. Lawful basis: performance of our contract with you.
Billing. When you subscribe we collect billing details and transaction records. Card details are handled by our payment processor, Paystack, and never touch our servers. Lawful basis: contract, and our legal obligations on tax and financial records.
Platform audit records. Authenticated use generates audit records — who accessed which dataset, under which contract, and when. These records are a governance feature of the platform, not advertising telemetry. Lawful basis: our legitimate interests in security, governance, and being able to prove how data was handled — the thing the platform exists to do.
Support. If you write to us, we keep the correspondence. Lawful basis: legitimate interest in answering you.
4. What we do NOT do
We do not sell personal data. We do not use browsing data for advertising. We do not train models on your personal data. Personal data contained in producer datasets never appears on the marketplace: public samples are frozen at publish time with personally identifiable fields masked before they leave the producer's environment.
5. Sharing
We share personal data only with the service providers that run the platform (hosting, email delivery, payments), each bound by contract to equivalent protections; and with authorities where the law requires it. No one else.
6. Cross-border transfers
Where personal data is transferred outside Kenya, we do so only as the Kenya Data Protection Act permits: to destinations with appropriate safeguards, under contractual clauses providing equivalent protection, or with your consent. Dataset storage locations on the platform are declared in each dataset's contract.
7. Retention
Account data is kept for the life of the account plus any period the law requires (tax and financial records typically longer). Audit records are retained per the platform's governance policy — they exist to answer “how was this data handled”, so they outlive the access they record. When nothing requires retention, we delete.
8. Security
Data is encrypted in transit and at rest. Access is role-gated and logged. The same contract-enforcement machinery the platform sells is what guards the data inside it: purpose checks on every query, masking in the query path, and signed records of every access.
9. If something goes wrong
If a breach of personal data occurs, we will notify the Office of the Data Protection Commissioner without undue delay and within 72 hours of becoming aware of it, and notify you directly where the breach is likely to put your rights at real risk — with what happened, what data was involved, and what we are doing about it.
10. Your rights
Under the Kenya Data Protection Act, 2019 (and comparable laws where they apply to you), you have the right to: be told what data of yours we hold and why; access it; correct it; delete it; object to or restrict processing; and receive a portable copy. You will never be subject to a solely automated decision with legal effect on you, and we do not send direct marketing without consent.
Write to brackly@griotdata.com. We respond within the timelines the Act prescribes — access requests within seven days, corrections within fourteen. If you are not satisfied with our answer, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (odpc.go.ke).
11. Cookies
Our public sites set no advertising or analytics cookies. Signing in sets the strictly necessary cookies that keep your session working, and nothing else.
12. Changes
We will post changes to this policy on this page with a new effective date. Material changes are notified to account holders by email before they take effect.