Legal
Processors and sub-processors
Our privacy policy tells you the categories of company we share information with. This page names them, one by one.
- Effective
- 6 September 2026
- Last updated
- 6 September 2026
- Applies to
- www.sayarisilicon.com
1. What this page is
Section 6 of our Privacy Policy sets out the categories of recipient we disclose personal information to. This page is the specific version of that disclosure: it names the individual third parties that process personal information on our instructions in connection with www.sayarisilicon.com, and it states the safeguards that apply to each.
We publish it because section 29(f) of the Kenya Data Protection Act, 2019 asks that you be told the third parties your personal data is transferred to, including details of the safeguards adopted — and because a named list is simply more useful than a category. Nothing on this page narrows the Privacy Policy; where the two differ, the Privacy Policy governs.
1.1 A note on the two words in the title
The distinction matters and we use both words deliberately.
- For this website, Sayari Silicon Limited is the data controller. The companies listed in section 2 are our processors — they act only on our instructions. Their own vendors are our sub-processors, and they are named alongside the processor that engages them.
- Where a business customer uses one of our products to process information for purposes that customer decides, the roles reverse: the customer is the controller and we are its processor, as section 2.2 of the Privacy Policy explains. In that relationship our vendors are the customer's sub-processors, and they are governed by the data processing agreement with that customer rather than by this page.
2. Processors for this website
Each entry below is engaged under written terms covering confidentiality, security, purpose limitation, deletion and assistance to us, as required by section 42 of the DPA and article 28 of the GDPR. None of them may use your information for their own purposes.
They are listed in the order your information would meet them, rather than by importance: the company that serves you the page, then the one that carries an enquiry you send, then the one that holds it once it arrives. All three are in the United States, so the same transfer safeguards apply to each. Section 7 of the Privacy Policy explains what that means, and Questions about a processor below tells you how to ask us for a copy of them.
2.1 Namecheap — Server hosting, DNS and domain registration
| Entity | Namecheap, Inc. |
|---|---|
| Why we use it | Operating the virtual private server this website is served from, answering the DNS queries that point your browser at it, and registering the domain name itself. Namecheap provides the machine and the network; the software on it, and the decisions it makes, are ours. |
| What it receives | The technical information described in section 3.2 of our Privacy Policy — your IP address, the time of your request, the pages requested, the referring page, and your browser and operating system. Its nameservers additionally see the DNS lookups your resolver makes for our domain. It does not receive the contents of your enquiry: the contact form hands that straight to our email providers. |
| Location | United States — the server is in Namecheap’s Phoenix, Arizona facility. |
| Its retention | This is a virtual private server rather than a managed service, so the web server logs live on our own disk and it is we, not Namecheap, who set how long they are kept. Namecheap keeps its own account, billing and abuse records about us as a customer, under its privacy policy. |
| Transfer safeguard | A written data processing agreement incorporating the European Commission’s Standard Contractual Clauses, relied on together with the appropriate-safeguards route in sections 48 and 49 of the Kenya DPA, and the UK International Data Transfer Addendum where the UK GDPR applies. |
| Its terms | Namecheap privacy policy · Namecheap data processing agreement |
2.2 Resend — Transactional email delivery
| Entity | Resend, Inc. |
|---|---|
| Why we use it | Carrying the enquiries submitted through our contact form from our server to our own mailboxes. Resend transmits the message on our instructions; it does not use it for any purpose of its own, and we do not use it to send marketing. |
| What it receives | Your name, email address, and the company name, phone number, subject and message content you choose to enter in the contact form. Your IP address is not sent to Resend — the abuse controls that use it run on our own server, and the address goes no further. |
| Location | United States |
| Sub-processors | Resend engages its own vendors, which are our sub-processors. All of them are in the United States. The ones in the path of an enquiry are Amazon Web Services (hosting and sending), Vercel (server hosting), PlanetScale and Supabase (database hosting), Cloudflare (web application firewall) and Datadog (monitoring). Its published list names further providers that support its own operations, including providers engaged for artificial-intelligence features. Resend maintains the complete and current list at the link below and may change it. |
| Its retention | Resend retains email logs, message content and delivery metadata for 30 days, on every plan, and then deletes its copy. That period governs Resend’s copy only — it is how long the message sits with the courier, not how long we keep it. |
| Transfer safeguard | A written data processing agreement incorporating the European Commission’s Standard Contractual Clauses, relied on together with the appropriate-safeguards route in sections 48 and 49 of the Kenya DPA, and the UK International Data Transfer Addendum where the UK GDPR applies. |
| Its terms | Resend privacy policy · Resend data processing agreement · Resend sub-processors |
2.3 Zoho — Business email and mailbox hosting
| Entity | Zoho Corporation |
|---|---|
| Why we use it | Hosting the mailboxes published on this site, including the data protection address. This is where an enquiry actually arrives and where our correspondence with you is kept and read, so it is the provider that holds our email for longest. |
| What it receives | The full content of email correspondence with us — enquiries delivered from the contact form, anything you email us directly, sender and recipient addresses, message headers, attachments, and the record of our replies. |
| Location | United States. Zoho operates regional data centres and ours is the US one, which you can verify independently: the MX records for our domain point at mx.zoho.com rather than a regional hostname such as mx.zoho.eu. |
| Sub-processors | Zoho publishes a sub-processor directory that can be filtered by product and by data centre, and which separates its sub-processors from third-party service providers and from providers engaged for artificial-intelligence features. The entries for Zoho Mail in the United States data centre are the ones that apply to us. |
| Its retention | This is our own mailbox, so retention here is ours to set rather than Zoho’s: a message stays until we delete it, on the criteria in section 8.1 of our Privacy Policy — as a general guide, up to two years from our last exchange. Zoho removes data from its systems after our account ends, within the period its terms specify. |
| Transfer safeguard | A written data processing agreement incorporating the European Commission’s Standard Contractual Clauses, relied on together with the appropriate-safeguards route in sections 48 and 49 of the Kenya DPA, and the UK International Data Transfer Addendum where the UK GDPR applies. |
| Its terms | Zoho privacy policy · Zoho sub-processors · Zoho GDPR compliance |
The contact form is the only part of this website that sends anything anywhere. It is also the channel through which you can make a data protection request, and a request sent that way is routed straight to privacy@sayarisilicon.com. Writing to that address yourself instead keeps the message out of the delivery provider in section 2.2 entirely — though it still arrives in the mailbox described in section 2.3, as any email to us must. If you would rather not put something in an email at all, the postal address in section 1 of the Privacy Policy reaches us without any of these companies being involved.
3. How this fits together
Two things can happen on this website, and it is worth setting out plainly which companies are involved in each — the entries above describe the parties, this describes the path.
3.1 Reading a page
Your browser asks Namecheap's nameservers where www.sayarisilicon.com is, then requests the page from our server in their Phoenix facility. The server writes the technical details of that request to a log on its own disk. Nothing else happens: the site is built as static files, there is no database behind it and no account to create, so nothing is stored about you between visits beyond that log. No other company on this page is involved, and no company that is not on this page is involved either.
3.2 Sending us an enquiry
Your submission reaches the same server, which runs the abuse checks described in section 9 of the Privacy Policy — your IP address is used there and goes no further. The message is then handed to Resend, which delivers it to a mailbox we host with Zoho. Resend holds its copy for 30 days and deletes it; the copy in our Zoho mailbox is the one that persists, and it is governed by our own retention criteria rather than by either provider's.
That is the whole path, and it is worth noticing what is absent from it: your enquiry is not written to a database, not passed to a customer relationship management system, not enriched against a third-party data source, and not used to build a marketing profile.
4. What we do not use
A list of processors is only as informative as what it leaves out, so it is worth being explicit about the vendors this website does not send anything to.
- No analytics provider. We do not run Google Analytics or any other analytics or product-telemetry service on this website.
- No advertising or tracking networks. There are no advertising pixels, no conversion tags, no social media tracking scripts and no data brokers. We do not sell or share personal information for cross-context behavioural advertising, as section 12 of the Privacy Policy confirms.
- No third-party fonts or script CDNs. Everything the page needs is served from our own domain, so loading a page does not disclose your IP address to anyone else.
- No hosted CAPTCHA. The contact form is protected by a proof-of-work check that runs entirely on our own server and in your browser. There is no third-party CAPTCHA service, no account behind it, and it sets no cookie.
- No non-essential cookies, which is why you have not been asked to consent to any — see section 14 of the Privacy Policy.
5. Our products
This page covers www.sayarisilicon.com only. Each of our products publishes its own privacy notice on its own site, with its own processor list, because a product handles categories of information this website never touches.
Business customers who need a data processing agreement, a current sub-processor list with a contractual right to object to a new sub-processor, or answers to a security questionnaire should write to privacy@sayarisilicon.com. Those come from the agreement between us, not from this page.
6. Changes to this list
We update this page when we engage a new processor, when one we use changes materially, or when we stop using one. The date at the top of the page is the date of the last such change, and it moves independently of the Privacy Policy's own effective date — replacing a vendor is a change of fact rather than a change of policy.
Where a change to our processors also changes what the Privacy Policy says we do, we update the Privacy Policy and give notice of it in the way section 15 of that policy describes.
7. Questions about a processor
You can ask us which transfer mechanism applies to a particular processor and request a copy of the relevant safeguards, as section 7 of the Privacy Policy provides. Write to privacy@sayarisilicon.com, or use the contact form and choose Data protection request. We may redact commercial terms and other information we are not permitted to disclose.
If you are not satisfied with our answer you may complain to the Office of the Data Protection Commissioner in Kenya, or to your local supervisory authority — section 16 of the Privacy Policy explains how.