01Who we are
Florid Innovations LTD, trading as florid.io ("florid.io", "we", "us"), is responsible for the personal data described in this Notice where we determine why and how that data is processed (acting as a data controller under Kenya's Data Protection Act, 2019).
For some customer services and hosted applications (such as tenant management, enterprise ERP or custom deployed AI workflows), florid.io acts as a data processor on behalf of the customer rather than as the controller. Where that applies, the customer determines the purposes of processing, and individual inquiries regarding that data should be directed to that customer.
02Scope
This Notice applies to personal data processed through:
- the florid.io website (
florid.io); - contact and project-enquiry forms;
- business-development and discovery communications;
- client and supplier commercial relationships;
- support and technical interactions;
- events, newsletters or updates where offered;
- accounts for florid.io-operated services where this Notice is incorporated; and
- AI-enabled features where florid.io acts as controller.
A separate product privacy notice or customer agreement may apply where a specific product has materially distinct processing activities.
03Personal data we collect
Depending on how you interact with florid.io, we may process:
Contact data
Full name, work email address, telephone number, organisation name, job title, and communication preferences.
Enquiry & relationship data
Project requirements, timeline estimates, technical notes, correspondence history, meeting records, and proposals.
Account data
Account identifiers, organisation tenant, credentials in cryptographically protected form (e.g. Argon2/passkeys), assigned roles, and configuration preferences.
Transaction & billing data
Billing contact information, tax identification, invoicing records, and payment status references. We do not store raw credit card details on our servers; card payments are processed directly by certified third-party payment providers.
Technical & usage data
IP address, browser type and version, operating system, referrer URL, timestamps, diagnostic logs, and interaction telemetry.
Support data
Support tickets, system error logs, troubleshooting attachments, and resolution communications.
AI interaction data
Prompts or requests, context documents intentionally supplied, system outputs, feedback signals, tool execution logs, and operational audit trails.
04How we collect data
We collect personal data directly from you when you submit forms, correspond with our team, or use our digital services. We may also receive data from your organisation when they authorize your account, from integrated services you connect, and automatically via technical logs and permitted cookies or local storage.
05Why we use personal data
We process personal data only when we have a clear purpose and an established legal basis under Section 30 of the Kenyan Data Protection Act, 2019:
Table 5.1 — Purposes of processing and legal grounds
| Purpose | Typical data categories | Legal basis / Justification |
|---|---|---|
| Respond to enquiries | Contact and enquiry data | Steps requested prior to entering a contract; legitimate business interest |
| Provide contracted services | Account, customer, billing, support data | Performance of contract; customer instructions where we act as processor |
| Operate and secure the Site | Technical, log and security data | Legitimate interests in securing infrastructure; legal obligations where applicable |
| Manage client relationships | Contact, correspondence, billing | Performance of contract; legitimate business interests |
| Improve products and usability | Usage, feedback, diagnostic telemetry | Legitimate interests or consent where required by law |
| Send opted-in updates & insights | Contact details, subscription preferences | Explicit consent and compliance with direct marketing regulations |
| Meet legal obligations | Statutory, accounting & tax records | Compliance with legal obligations under Kenyan law |
| Establish or defend legal claims | Relevant account and dispute records | Legitimate interests in legal defense and claims management |
| Prevent abuse and fraud | Usage, security and identity logs | Legitimate interests in fraud prevention; statutory compliance |
| Operate AI features | Prompts, contextual inputs, outputs, logs | Contract, explicit consent, or customer instructions as processor |
Scroll horizontally to view full table →
06AI, automated processing & human review
florid.io develops and deploys intelligent systems, including machine learning models, retrieval-augmented generation systems, and automated agents.
Under Section 35 of the Data Protection Act, 2019, individuals have the right not to be subjected to decisions based solely on automated processing which produce legal effects or similarly significant effects, without appropriate safeguards.
florid.io builds systems with human-in-the-loop oversight. Our general-purpose AI tooling is not configured to make autonomous, unreviewed decisions that deny legal rights, employment, housing, credit, or healthcare.
07AI model training & customer content
Our Core Commitment:
We do not use private customer content or confidential business data to train general-purpose florid.io foundation models unless the customer has provided express, informed written consent.
When utilizing vetted third-party model providers (such as enterprise API endpoints), we configure zero-retention or zero-training flags wherever supported, ensuring customer data is not retained to train public third-party models.
09Direct marketing
We do not send unsolicited marketing communications. Where we provide insights or project updates, we obtain prior affirmative opt-in consent. Every marketing email includes an immediate, one-click unsubscribe mechanism.
10Who we share personal data with
We do not sell personal data. We may share data with vetted service providers:
- Cloud infrastructure & hosting providers;
- Secure transactional email & communication services;
- Error monitoring and infrastructure telemetry systems;
- Enterprise AI model and compute providers under strict data privacy agreements;
- Professional legal, accounting and audit advisers; and
- Regulatory bodies or law enforcement authorities where strictly mandated by Kenyan law.
11International transfers
Some of our cloud infrastructure and enterprise software vendors operate across multiple jurisdictions. Where personal data originating in Kenya is transferred across borders, florid.io adheres to Section 48 and 49 of the Data Protection Act, 2019.
We ensure appropriate safeguards are in place, including contractual protections, security assessments, and transfer impact evaluations.
12Data retention schedule
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or to comply with statutory legal, accounting and audit obligations:
Table 12.1 — Standard retention periods
| Data category | Retention rule |
|---|---|
| General enquiries | 24 months after last meaningful communication, unless converted into a client relationship |
| Client contracts & invoices | 7 years or duration required by Kenyan tax, accounting and statutory limitation requirements |
| Marketing contacts | Until opt-out/withdrawal plus minimal suppression record to honor preferences |
| Security & access logs | 30–365 days depending on system and threat-intelligence requirements |
| Support tickets | Duration of contract term plus 2 years support-record history |
| Account data | Duration of active account plus 90 days post-closure archival period |
| Customer processor data | Governed strictly by customer instructions and Data Processing Agreement |
| AI interaction logs | Shortest practical period consistent with service reliability, security and contract |
Scroll horizontally to view full table →
13Technical & organisational security controls
florid.io applies modern technical and organizational safeguards to protect personal data against accidental loss, unauthorized access, destruction or alteration. Controls include TLS 1.3 encryption in transit, AES-256 encryption at rest, role-based access control, least-privilege permissions, automated secret management, and continuous vulnerability monitoring.
14Personal-data breaches
In the event of a confirmed personal data breach that creates a real risk of harm to individuals, florid.io maintains an incident response procedure. Where required by Section 43 of the Data Protection Act, 2019, we will notify the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware of the breach, and inform affected data subjects without undue delay.
15Your privacy rights
Under the Data Protection Act, 2019, you have specific rights regarding your personal data:
- Right to be informed: To know what personal data is collected and why;
- Right of access: To request a copy of the personal data we hold about you;
- Right to rectification: To correct inaccurate or incomplete data;
- Right to erasure: To request deletion of data no longer required;
- Right to restrict processing: To pause processing under specific conditions;
- Right to data portability: To receive your data in a structured, commonly used format;
- Right to object: To object to processing based on legitimate interests; and
- Right to human review: Regarding automated decisions.
16Complaints & regulator oversight
If you have concerns about how we handle your personal data, please contact our privacy officer at [email protected].
You also have the right to lodge a formal complaint with Kenya's regulatory authority, the Office of the Data Protection Commissioner (ODPC).
17Children's data
The public florid.io website and enterprise services are intended for professional and business audiences. We do not knowingly solicit or collect personal data from children under the age of 18 through general website forms.
18Changes to this Notice
We may update this Privacy Notice from time to time to reflect changes in our technologies, legal requirements, or operational practices. The updated notice will be posted here with a revised "Last updated" date.
19Contact
For privacy inquiries or to reach our data protection contact:
Official Contact & Entity
Legal Entity
Florid Innovations LTD
Trading as florid.io
Registered Address
Nairobi, Kenya
Email Inquiries
Telephone
+254 (0) 700 000 000