Legal
Privacy Policy
We would rather you read this than agree to it. It is written to be understood, and it says what we actually do.
- Effective
- 6 September 2026
- Last updated
- 6 September 2026
- Applies to
- www.sayarisilicon.com
1. Who we are
Sayari Silicon Limited (“Sayari Silicon”, “we”, “us”, “our”) is a technology company incorporated in the Republic of Kenya. Our registered office is:
Elroy Hub Business Premises, Kugeria Road / Kiambu Road
P.O. Box 13305–00100
Nairobi, Kenya
For the processing described in this policy, Sayari Silicon Limited is the data controller — the party that decides why and how your personal information is used — within the meaning of the Kenya Data Protection Act, 2019 (the “DPA”), and, where applicable, the data controller under the EU and UK General Data Protection Regulation (the “GDPR”) and the equivalent term under United States state privacy laws.
That is not our only role. We act as a data processor where a business customer uses one of our products to process information for purposes that customer decides — section 2.2 explains that arrangement — and as an independent controller for the limited processing needed to secure our services, prevent abuse, keep the records the law requires us to keep, and establish or defend legal claims.
Our application for registration with the Office of the Data Protection Commissioner of Kenya (the “ODPC”) is pending. We will publish the approved registration particulars on this page once the ODPC issues them.
You can reach our data protection contact at privacy@sayarisilicon.com. Full contact details, and how to complain, are in section 16.
2. Scope of this policy
This policy applies to:
- this website, www.sayarisilicon.com, and any other page or subdomain that links to this policy;
- information you give us directly — by email, telephone, post, our contact form, or in the course of a business relationship, procurement process or recruitment;
- information we receive and handle at company level in our capacity as the parent company of our products, including information originating in those products, as described in section 5.
2.1 Our products are covered by their own notices
Sayari Silicon builds software-as-a-service and mobile applications. Each product publishes its own privacy notice and terms on its own website or in its app store listing, because what a product collects and why differs from product to product. This policy does not replace those notices. Where you use one of our products, that product's notice governs the processing carried out through it, and this policy governs the company-level processing described in section 5. If the two ever conflict on a point specific to a product, the product's notice prevails for that product.
2.2 Where a business customer uses our software
Some of our products are subscribed to by organisations and then used by their staff, customers or members. Where an organisation puts personal information about other people into one of our platforms, that organisation decides what goes in and why. In that arrangement the organisation is the data controller and we act as a data processor on its instructions, under a written processing agreement.
This policy does not describe that processing — the organisation's own privacy notice does. We handle such information only as our agreement with that organisation permits, we do not use it for our own purposes, and we do not use it to market to you. If you believe your information sits in a system one of our business customers uses and you are unsure who to approach, write to us and we will identify the controller for you and pass your request on.
2.3 Other sites
Where we link to a site or service we do not control, we are not responsible for its privacy practices, and this policy does not apply to it. We encourage you to read the notice on any site you visit.
3. Information we collect
3.1 Information you give us
- Identity and contact details — name, employer or organisation, job title, email address, telephone number, postal address.
- The content of your communications — what you write in an enquiry, email or letter, what is discussed on a call, and any documents you choose to send us.
- Business and commercial information — details of a project, requirement or procurement process; contract, billing and payment details; the record of your acceptance of our terms and agreements, including what was accepted and when and how it was accepted; and information needed to satisfy our legal and accounting obligations.
- Recruitment information — your CV, work history, qualifications, portfolio, references and right-to-work information, where you apply to us or we consider you for a role.
- Preferences — the marketing you have asked for or objected to, and the language or channel you prefer.
3.2 Information collected automatically when you use this website
Our web server and hosting provider record technical information as a normal part of delivering the site and keeping it secure. This includes your IP address, the date and time of your request, the pages requested, the referring page, and your browser and operating system as reported by your device. We use this for delivery, security, abuse prevention and diagnosis. We do not operate advertising or cross-site tracking technologies on this website — see section 14.
3.3 Information from our products
Our products collect information as described in their own notices. That may include account and profile details, information you enter or upload, transaction and payment records, device and app diagnostics, usage and interaction data, and — where a product's function requires it and you have enabled it — location data. Some of this information is transmitted to us at company level; section 5 explains what we do with it.
3.4 Information from other sources
- Your colleagues and representatives — a customer, partner or supplier may give us your business contact details so that we can deal with you.
- Public and professional sources — company registries, professional networks, public websites and published directories, where we are researching a prospective customer, partner, supplier or candidate.
- Service providers acting for us — hosting, communications, payment, analytics, identity verification and security providers, in each case limited to what they are engaged to do.
- Referrals and introductions — where someone puts us in contact with you.
3.5 Sensitive information, and things we would rather you did not send
We do not seek sensitive personal data — such as information about health, genetic or biometric characteristics, race or ethnicity, religious or philosophical belief, sex life or sexual orientation, marital status, family details, political affiliation or trade union membership — through this website, and we ask that you do not include it in an enquiry. Please do not send us confidential information, trade secrets or sensitive personal data through the contact form or by unencrypted email. For the same reason, never send us a password, a payment PIN, a card security code or full card number, or personal information about a child, through this website or any of our products — we do not ask for any of them, we have no use for them, and they are not protected in transit by ordinary email. If you do so anyway, you accept that it was sent at your own initiative and risk; we will handle it in accordance with this policy and applicable law, but no confidentiality obligation arises merely because you sent it. Where we do process sensitive personal data — for example, an accessibility requirement you tell us about, or information required by employment law during recruitment — we do so only with your consent or where the DPA, the GDPR or other applicable law otherwise permits it.
Feedback and suggestions. If you send us an idea, suggestion or comment about our products or business, you agree that we may use it without restriction, attribution or payment, and that doing so creates no obligation to you and no confidential relationship between us. This does not affect your rights in your personal information under this policy.
3.6 If you do not provide information
Where information is needed to do something you have asked for — reply to an enquiry, enter a contract, consider a job application — not providing it simply means we cannot do that thing. Where information is required by law, we will tell you and we may be unable to continue a relationship without it.
4. How and why we use information
We use personal information for the purposes set out below. For each purpose we identify the lawful basis we rely on. Where more than one basis is available, the first listed is our primary basis.
| Purpose | Lawful basis |
|---|---|
| Responding to you. Answering enquiries, providing information you asked for, and managing our correspondence with you. | Consent; performance of a contract; our legitimate interests in running our business |
| Providing and administering our products. Setting up and managing accounts and subscriptions, operating and hosting the product, providing support, and handling billing, invoicing, renewals and collections. | Performance of a contract; legitimate interests; compliance with a legal obligation |
| Operating, securing and improving our systems. Delivering this website and our products, monitoring availability and performance, diagnosing faults, testing changes, detecting and preventing fraud, abuse and unauthorised access, and maintaining backups and business continuity. | Legitimate interests; compliance with a legal obligation |
| Understanding and developing our products. Analysing how our products and website are used, in aggregate wherever that is sufficient, to fix what does not work, decide what to build, and design new features and new products. | Legitimate interests; consent where required for a given technology or jurisdiction |
| Marketing and business development. Sending information about our products and services, publishing content, and contacting organisations that may have a professional interest in what we do. | Consent where required by law; otherwise our legitimate interests in growing our business |
| Recruitment. Assessing applications, communicating with candidates, verifying credentials and right to work, and keeping a record of applications. | Legitimate interests; compliance with a legal obligation; consent for a talent pool |
| Legal, regulatory and accounting compliance. Meeting obligations under Kenyan and other applicable law, including tax, accounting, employment, anti-money laundering, sanctions and data protection obligations, and responding to lawful requests from authorities. | Compliance with a legal obligation; legitimate interests; public interest |
| Protecting our rights. Establishing, exercising and defending legal claims, enforcing our terms, managing insurance and risk, obtaining professional advice, and conducting internal investigations and audits. | Legitimate interests; compliance with a legal obligation; legal claims |
| Corporate transactions. Evaluating, negotiating and completing a financing, acquisition, merger, reorganisation, sale of assets or similar transaction, and integrating a business afterwards. | Legitimate interests; compliance with a legal obligation |
4.1 About “legitimate interests”
Where we rely on legitimate interests, we have considered whether the processing is necessary for that interest, whether a less intrusive route would achieve it, and whether our interest is outweighed by your interests, rights and freedoms. We rely on this basis only where we conclude it is not. You can ask us for a summary of that assessment for any particular processing, and you can object to it — see sections 10 to 12.
4.2 Marketing, and how to stop it
We send marketing where you have asked us to, and — to business contacts, in jurisdictions where this is permitted — where we reasonably believe our products are professionally relevant to your role. Every marketing message we send includes a working means of unsubscribing. You can opt out of marketing at any time, at no cost, by using that link or by writing to privacy@sayarisilicon.com. We will act on your request promptly. We will still send you messages that are necessary to a service or contract you have with us, such as billing, security and service notices — those are not marketing and cannot be opted out of while the relationship continues. Agreeing to receive a transactional message is not agreement to receive marketing. Where we introduce direct marketing we will give the notice and obtain the consent the applicable law requires, identify ourselves as the sender, and provide a simple way to opt out; an opt-out never stops essential service or security messages. We do not use your information for automated decision-making that produces legal effects for you or otherwise significantly affects you.
4.3 New purposes
If we intend to use your personal information for a purpose that is not compatible with those described here, we will tell you before we do, identify the lawful basis, and — where the law requires it — obtain your consent.
5. Use across our products and group
This section describes something we think you should know plainly, rather than find buried in a longer clause.
Sayari Silicon operates its products as one company. Information collected through a product may be transmitted to us as parent company and combined with information from our other products, from this website, and from the other sources described in section 3. We do this for the following purposes, and no others:
- To run the product you are using — including shared infrastructure such as accounts, sign-in, payments, messaging, support and fraud prevention that serve more than one product.
- To improve and develop our products — understanding how our software is used so that we can fix problems, prioritise work and design new features and new products. Wherever aggregated or de-identified information is sufficient for this purpose, that is what we use.
- To keep our systems and users safe — detecting fraud, abuse, security threats and misuse across products, which is often only possible by looking across them.
- To measure and improve our business — internal reporting, analytics, planning and management of the company.
- To tell you about our other products and services — subject at all times to section 4.2 and to your right to opt out. Where the law in your jurisdiction requires your consent for cross-product marketing, we will obtain it before we do this.
- To comply with the law and protect our rights — as described in section 4.
Equally, we want to be clear about the limits we place on this:
- We do not sell your personal information, and we do not disclose it to third parties for their own independent marketing purposes.
- Where personal information reaches us because a business customer put it into one of our platforms about its own staff, customers or members, that information belongs to that relationship and we act as processor for it, as section 2.2 explains. We do not pool it into company-level use except as our agreement with that customer permits, and never for marketing to you.
- We do not combine information in a way that a product's own privacy notice tells you we will not.
- Where a product's notice states a narrower use than this section, the narrower statement applies to information collected through that product.
Our lawful basis for the processing in this section is our legitimate interest in operating, securing, understanding and developing our products and business as a whole; consent where the applicable law requires consent; and compliance with legal obligations where relevant. You may object to processing based on legitimate interests, and you may opt out of cross-product marketing at any time.
6. When we disclose information
We disclose personal information only in the circumstances below.
- Service providers acting on our instructions. Hosting and cloud infrastructure, email and communications, customer support tooling, payment processors, accounting and professional services, security and monitoring, and recruitment tools. They may use the information only to provide the service to us, are bound by written contract including confidentiality and security obligations, and may not use it for their own purposes.
- Our group. Any subsidiary, holding company or affiliate of Sayari Silicon, for the purposes described in sections 4 and 5, under equivalent protections.
- Our professional advisers. Lawyers, auditors, accountants, insurers and consultants, where they need it to advise us and subject to professional duties of confidence.
- Business customers and partners. Where you use one of our products through, or alongside, an organisation — and only to the extent that relationship requires.
- Authorities and legal process. Courts, regulators, law enforcement, tax and other public authorities where we are required to disclose by law or by a valid legal request, or where disclosure is necessary to establish, exercise or defend legal claims, to enforce our terms, or to protect the rights, property or safety of Sayari Silicon, our users or the public. Where we are lawfully able to notify you of such a request, and it is reasonable to do so, we will.
- In a corporate transaction. To an actual or prospective investor, acquirer, merger party or purchaser of assets, and to their advisers, in connection with a transaction of the kind described in section 4 — subject to confidentiality undertakings during diligence. If such a transaction completes, the recipient will be bound to handle your personal information in a manner consistent with this policy, and we will notify you of any material change through the means described in section 15.
- With your consent or at your direction, in any other case.
Where a recipient acts as our processor, it is bound by written terms covering confidentiality, security, purpose limitation, deletion and assistance to us. Some recipients are not our processors at all: a regulated payment provider, bank or mobile-network operator involved in a transaction you choose to make processes your information as an independent controller, under its own privacy notice and its own legal duties, and we do not control that processing.
Those are the categories, and they are what this policy commits to. We also publish the individual companies behind them: our processor and sub-processor list names each third party that processes personal information for this website, what it receives, where it is, how long it keeps its own copy and the transfer safeguard that applies to it. We maintain it as a separate page so that replacing a supplier does not require us to rewrite this policy, and it is updated when our processors change.
We may also disclose aggregated or de-identified information that cannot reasonably be used to identify you — for example, industry statistics, benchmarks, research or marketing material. See section 8.2.
7. International transfers
We are based in Kenya and we serve users and customers internationally. Personal information we hold may therefore be transferred to, stored in, or accessed from countries other than the one you are in — including by the service providers described in section 6, whose infrastructure may be located outside Kenya. Data protection law in those countries may differ from the law where you live.
Wherever we transfer personal information across a border, we do so only where a lawful transfer mechanism applies, and we take steps intended to ensure the information continues to be protected to the standard described in this policy. Depending on the transfer, we rely on one or more of:
- Sections 48 and 49 of the DPA — including transfers made on the basis of appropriate safeguards and proof that the recipient country or organisation affords adequate protection, transfers necessary for the performance of a contract, and transfers made with your consent, together with the requirements of the Data Protection (General) Regulations, 2021. Where the DPA or its regulations require particular categories of data to be processed or stored within Kenya, we comply with that requirement.
- For transfers out of the EEA, the United Kingdom or Switzerland — an adequacy decision where one covers the transfer, or the Standard Contractual Clauses approved by the European Commission (with the UK International Data Transfer Addendum or the IDTA where the UK GDPR applies), supported by a transfer risk assessment and any additional technical and organisational measures that assessment identifies as necessary.
- Any other mechanism permitted by the applicable law, including your explicit consent to a specific transfer where no other mechanism is available and the law allows consent to be relied on.
You can ask us which mechanism applies to a particular transfer, and request a copy of the relevant safeguards, by writing to privacy@sayarisilicon.com. We may redact commercial terms and other information we are not permitted to disclose. For the transfers this website makes, you do not have to ask: our processor and sub-processor list states the mechanism relied on for each recipient, and identifies which of them are outside Kenya.
8. How long we keep information
8.1 Retention criteria
We keep personal information only for as long as we need it for the purposes described in this policy, and then delete it or de-identify it. Because the right period depends on the information and the relationship, we set retention by reference to the following criteria rather than a single fixed term:
- how long we need it to provide what you or our customer asked for;
- how long we are required to keep it by law — for example, tax, accounting, corporate and employment record-keeping obligations under Kenyan law, which commonly require records to be kept for a number of years after a transaction or the end of a relationship;
- whether it may be needed to establish, exercise or defend a legal claim, having regard to applicable limitation periods;
- whether you have asked us to keep it, or asked us to stop using it;
- the sensitivity of the information and the risk of harm from retaining it against the reason for retaining it.
As a general guide: enquiry correspondence is kept for up to two years from our last exchange unless it becomes part of a customer relationship; customer and supplier records are kept for the duration of the relationship and then for the period required by law and by applicable limitation periods; transaction, invoice and accounting records, and the evidence of an agreement and its acceptance, may be kept for up to seven years where that is reasonably required for contractual, accounting, regulatory or dispute purposes; unsuccessful job applications are kept for up to twelve months unless you ask us to keep them longer; and records we must keep for legal or accounting reasons are kept for the period the relevant law prescribes. Marketing preferences and suppression records are kept indefinitely, because that is what allows us to honour your opt-out.
Those periods are how long we keep information. A service provider acting on our instructions may hold a copy for a shorter period of its own while it does the work we engaged it for — our email delivery provider, for example, retains message content, delivery metadata and logs for 30 days and then deletes its copy, while the mailbox provider that holds the message after it arrives keeps it for as long as we do, because the deletion is ours to make. Our processor and sub-processor list gives each provider's retention period alongside the rest of its entry. Where you ask us to erase information and the request is one we must act on, we pass the request on to the processors holding a copy, as section 10 explains.
8.2 Aggregated and de-identified information
We may aggregate, anonymise or otherwise de-identify personal information so that it can no longer reasonably be associated with you, and we may retain and use that information indefinitely — including for research, analytics, benchmarking, product development, training and improving our systems, and for publication in a non-identifying form. Once information has been de-identified it is no longer personal information, this policy no longer applies to it, and we will not attempt to re-identify it except to test the effectiveness of our own de-identification or where the law requires us to.
9. Security
We take the security of personal information seriously and we implement technical and organisational measures appropriate to the risk. Depending on the system, those measures include encryption of data in transit and at rest, access control on a least-privilege basis, separation of environments, logging and monitoring, secure development and code review practices, vendor security assessment, backup and recovery procedures, and confidentiality obligations and training for our people.
No method of transmitting or storing information is completely secure, and we cannot and do not guarantee that personal information will never be subject to unauthorised access, loss, alteration or disclosure. What we undertake is to maintain safeguards appropriate to the risk, to keep them under review, and to act promptly if something goes wrong. Nothing in this section limits any liability that cannot be limited under applicable law.
You also have a part in this. Keep any credentials you use with us confidential, use a strong and unique password, and tell us immediately at security@sayarisilicon.com if you believe an account or communication channel has been compromised. Security researchers should use the same address to report a suspected vulnerability.
Where a personal data breach occurs that presents a real risk of harm, we will notify the Office of the Data Protection Commissioner, any controller on whose behalf we were processing, and affected individuals, as and when the DPA, the GDPR or other applicable law requires and within the time limits those laws set. Every incident is recorded, investigated and remediated whether or not it is notifiable.
10. Your rights (Kenya)
Under the DPA, you have the right:
- to be informed of the use to which your personal data is to be put — which this policy is intended to satisfy;
- to access the personal data we hold about you, and to be told how it is being used;
- to object to the processing of all or part of your personal data;
- to correction of false or misleading personal data about you;
- to deletion of false or misleading personal data about you;
- to data portability — to receive your personal data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible; and
- to safeguards against solely automated decisions that produce legal effects concerning you or similarly significantly affect you. We do not make decisions of that kind about you by automated means.
10.1 How to exercise a right
Write to privacy@sayarisilicon.com and tell us which right you wish to exercise and what information your request concerns. There is no fee.
We will ask you to verify your identity before we act. This protects you: acting on an unverified request is itself a way for personal information to end up with the wrong person. Verification is usually straightforward — replying from the address we already hold for you, or confirming details we already have. Where a request is made on your behalf, we will ask for evidence of authority to act.
We will respond as soon as we can and in any event within the time the DPA allows. If your request is complex, or you have made several requests, we may need more time — we will tell you if so, and why.
10.2 Limits on these rights
These rights are important but they are not absolute, and applicable law provides exceptions. We may decline all or part of a request where the law permits or requires us to — for example where complying would mean deleting records we are legally obliged to keep, would prejudice the prevention or detection of a crime, would reveal another person's personal information, would breach legal professional privilege or a duty of confidence we owe someone else, or where a request is manifestly unfounded or excessive, including because it is repetitive. Where we decline, we will tell you why, unless the law prevents us from doing so, and we will tell you how to complain.
11. Additional rights (EEA and United Kingdom)
If you are in the European Economic Area, the United Kingdom or Switzerland, the GDPR or the UK GDPR may apply to our processing of your personal information. In that case, in addition to the rights in section 10, you have the right:
- to restrict processing — to ask us to pause our use of your personal data in certain circumstances, such as while we check its accuracy or consider your objection;
- to erasure (“the right to be forgotten”) where one of the grounds in Article 17 applies;
- to object to processing based on legitimate interests, in which case we will stop unless we can demonstrate compelling legitimate grounds that override your interests, or we need to continue for legal claims;
- to object to direct marketing at any time and absolutely — if you object, we will stop, with no balancing exercise;
- to withdraw consent at any time, where we rely on consent. Withdrawal does not affect the lawfulness of processing carried out before you withdrew;
- not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. We do not carry out such processing;
- to lodge a complaint with a supervisory authority in your country of residence, place of work, or the place of the alleged infringement.
We will respond to a request under this section within one month, extendable by two further months for complex or numerous requests, as Article 12 permits. We do not currently maintain an establishment in the EEA or the UK, and are not required to designate a representative under Article 27 in respect of the processing described in this policy; if that changes we will publish the representative's details here.
12. Additional rights (United States)
If you are a resident of California or of another US state with a comprehensive consumer privacy law — including Colorado, Connecticut, Texas, Virginia and a growing number of others — you may have the rights described below in respect of personal information we hold about you as a business or controller. Terms used in this section have the meanings given to them in the applicable state law.
12.1 Your rights
- To know and to access — the categories of personal information we have collected about you, the categories of source, the business or commercial purpose for collecting it, the categories of third party to whom we disclose it, and the specific pieces of personal information we hold.
- To delete personal information we have collected from you.
- To correct inaccurate personal information.
- To opt out of sale, and of sharing for cross-context behavioural advertising, and to limit the use and disclosure of sensitive personal information to what is necessary to provide the service.
- To opt out of profiling in furtherance of decisions that produce legal or similarly significant effects, where your state law provides that right. We do not carry out such profiling.
- To non-discrimination — we will not deny you goods or services, charge you a different price, or provide a different level of quality because you exercised a privacy right.
- To appeal — where your state law provides an appeal right, you may appeal a refusal by replying to our response, and we will inform you in writing of the outcome and reasons. If we deny your appeal you may contact your state Attorney General.
12.2 Sale, sharing and sensitive information
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising. We have not done so in the twelve months preceding the date of this policy. We do not use or disclose sensitive personal information for purposes beyond those permitted without an opt-out right under the California Consumer Privacy Act as amended. We do not knowingly sell or share the personal information of consumers under 16. If any of this changes, we will update this policy before the change takes effect and provide the opt-out mechanism the law requires.
12.3 Categories of information and the purposes we use them for
The categories of personal information we collect, described using the categories set out in the California Consumer Privacy Act, are: identifiers; personal information listed in the California Customer Records statute; commercial information; internet or other electronic network activity information; geolocation data (through our products only, where enabled); professional or employment-related information; and inferences drawn from the above. Section 3 describes what each category actually contains, section 4 the purposes, section 6 the recipients, and section 8 how long we keep it.
12.4 Making a request
Submit a request by writing to privacy@sayarisilicon.com. We will acknowledge within 10 business days and respond within 45 days, extendable by a further 45 days where reasonably necessary, and we will tell you if we need the extension. We must verify your identity before disclosing or deleting personal information, and we may decline a request we cannot verify. An authorised agent may make a request on your behalf with written permission signed by you, or a valid power of attorney; we may still contact you to confirm the agent's authority and your identity.
13. Children’s information
This website is intended for a business and adult audience. It is not directed at children, and we do not knowingly collect personal information from children through it.
Where a product of ours is directed at, or may be used by, children, its own privacy notice will say so and will describe the additional protections and consent arrangements that apply — including parental or guardian consent where the DPA, the GDPR, the United States Children's Online Privacy Protection Act or other applicable law requires it.
If you believe a child has provided us with personal information, please contact privacy@sayarisilicon.com and we will take reasonable steps to delete it. A parent or guardian may exercise the rights in sections 10 to 12 on behalf of a child.
14. Cookies and similar technologies
A cookie is a small file a website can store on your device. Similar technologies include local storage, pixels and software development kits.
This website does not use analytics, advertising or tracking cookies, and it does not set any non-essential cookie. We do not run third-party advertising or social media tracking on it, and there is therefore nothing for you to consent to or opt out of, which is why you have not been shown a cookie banner. Your browser and our hosting provider will still exchange the technical information described in section 3.2, because that is how the web works and the site cannot be delivered without it.
If we later introduce analytics or any other non-essential technology, we will update this section before doing so and — where the law requires consent, as it does in the EEA and the United Kingdom for non-essential cookies — we will ask for your consent first and give you a means to change your mind.
Our products are separate. Each product's own privacy notice describes the cookies and similar technologies it uses and how to control them.
You can in any case block or delete cookies through your browser settings, and set your browser to send a “Do Not Track” or Global Privacy Control signal. Because this site sets no non-essential cookies, there is nothing for such a signal to disable here; where a Global Privacy Control signal is legally recognised as an opt-out request, we will honour it in our products.
15. Changes to this policy
Our business will change, and this policy will change with it. We may update it to reflect new products, new processing, changes in the law, or changes in how we operate.
When we do, we will revise the “Last updated” date at the top of this page. Where a change materially affects your rights or how we use your personal information, we will give you reasonable prior notice — by a prominent notice on this website and, where we hold your contact details and it is appropriate, by email — before the change takes effect. Where the applicable law requires your consent to a change, we will obtain it rather than rely on notice.
Please review this page from time to time. Continuing to use this website after a change takes effect means the updated policy applies to your continued use; it does not, by itself, constitute consent to processing for which the law requires consent.
16. Contacting us and complaints
For anything in this policy — a question, a request to exercise your rights, or a concern about how we have handled your information:
Sayari Silicon Limited
Attention: Data Protection
Elroy Hub Business Premises, Kugeria Road / Kiambu Road
P.O. Box 13305–00100
Nairobi, Kenya
Email: privacy@sayarisilicon.com
Telephone: +254 734 880 880
16.1 Complaining to us first
If you are unhappy with how we have handled your personal information, please tell us. We would rather hear it directly and put it right. Write to the address above and we will investigate and respond.
16.2 Complaining to a regulator
You do not have to come to us first, and nothing in this policy prevents you from complaining to a regulator at any time.
- Kenya. You may lodge a complaint with the Office of the Data Protection Commissioner under section 56 of the DPA. Complaints are filed through the ODPC's own portal at cie.odpc.go.ke. The ODPC can otherwise be reached at odpc.go.ke, info@odpc.go.ke, or P.O. Box 30920–00100 G.P.O., Nairobi, Kenya.
- EEA and United Kingdom. You may complain to the supervisory authority in your country of residence, your place of work, or the place where you believe an infringement occurred. In the United Kingdom this is the Information Commissioner's Office.
- United States. You may contact the Attorney General of your state, or the California Privacy Protection Agency if you are a California resident.
17. Governing law
This policy and any dispute arising out of it or the processing it describes are governed by the laws of the Republic of Kenya, and the courts of Kenya have jurisdiction — except that nothing in this section deprives you of the protection of, or of any right to bring proceedings under, the mandatory law of the country in which you habitually reside, where that law applies to you and cannot be excluded by agreement. Where the GDPR, the UK GDPR or a United States state privacy law applies to particular processing, the rights that law gives you apply to that processing regardless of this section.
If any provision of this policy is found to be unenforceable, the remainder continues to apply.
Sayari Silicon Limited · Privacy Policy · Effective 6 September 2026