Data Policy

Smart. Safe. Seamless.

1

Introduction & Scope

This Data Policy outlines how Safiri by Citrus ("the Platform") collects, uses, stores, and protects the personal and other data of Parent/Student account users. The purpose of this Policy is to ensure transparency and compliance with Kenyan Data Protection laws, including the Data Protection Act (2025), and any other applicable regulations. This Policy applies solely to users of the Parent/Student account who utilize the Platform to gain real-time visibility and control over school transport services.

Transparency and Compliance

We are committed to transparency in our data practices and to complying with all relevant data protection laws in Kenya, ensuring that your data is handled responsibly and lawfully.

Real-time Visibility and Control

Our platform provides parents and students with real-time visibility and control over school transport, including bus tracking, schedules, and communication with administrators and drivers.

2

Definitions

For clarity and consistency throughout this Policy, the following terms are defined:

Personal Data

Any information relating to an identified or identifiable natural person, including names, contact details, and other identifiers.

Processing

Any operation or set of operations performed on personal data, whether automated or manual, such as collection, recording, storage, alteration, retrieval, consultation, use, disclosure, or deletion.

Data Subject

Any Parent/Student account user whose personal data is processed by the Platform.

Data Controller

Citrus Labs Limited, which determines the purposes and means of processing personal data.

Data Processor

Any third party engaged by Citrus Labs Limited to process personal data on its behalf.

Sensitive Data

Personal data that requires special protection under Kenyan law, such as biometric data or other information classified as sensitive.

3

Types of Data Collected

The Platform collects the following data from Parent/Student account users:

Personal Information

Name, contact details (email, phone number), and any other identifiers provided during registration.

Usage Data

Information on how users interact with the Platform, including login timestamps, session durations, and feature usage.

Device Information

Data related to the device used to access the Platform (e.g., IP address, device type, operating system, and browser).

Cookies and Tracking Data

Data collected through cookies and similar technologies to enhance user experience and improve service functionality.

Sensitive Data

If applicable, any sensitive information (e.g., biometric data for secure access) is handled with additional security measures as required by law.

5

Purpose of Data Collection and Processing

Data collected from Parent/Student account users is processed for the following purposes:

Service Delivery

To provide real-time bus tracking, transport schedule notifications, and secure communication with school administrators and drivers.

Customer Support

To respond to inquiries, resolve issues, and provide technical assistance.

Marketing

To send information about updates, new features, and promotional content, provided users have consented to such communications.

Security

To safeguard the Platform and its users through monitoring, fraud prevention, and incident response.

System Improvement

To analyze usage data and feedback for continuous enhancement of the Platform's functionalities and user experience.

6

Data Storage and Security Measures

Data Storage

Personal data is stored on secure, cloud-based servers operated by reputable third-party providers compliant with industry standards. Data retention periods are defined based on legal requirements and the operational needs of the Platform.

Security Protocols

The Platform employs robust security measures, including:

End-to-end Encryption

Data is encrypted in transit and at rest using industry-standard encryption protocols to ensure confidentiality.

Access Controls & MFA

Strict access controls and multi-factor authentication to restrict data access to authorized personnel only.

Security Audits

Regular security audits, vulnerability assessments, and monitoring to detect and mitigate potential threats.

Data Backup & Recovery

Robust data backup and recovery procedures to prevent data loss and ensure business continuity.

7

Data Sharing and Third-Party Disclosures

8

User Rights and Access

Parent/Student account users have the following rights:

Right of Access

The right to request and obtain a copy of personal data held by Citrus Labs Limited.

Right to Rectification

The right to request corrections to any inaccurate or incomplete data.

Right to Erasure

The right to request deletion of personal data, subject to legal and contractual obligations.

Right to Restrict Processing

The right to request that processing of personal data be limited under certain circumstances.

Right to Data Portability

The right to receive personal data in a structured, commonly used, and machine-readable format.

Right to Object

The right to object to processing based on legitimate interests or direct marketing.

Users can exercise these rights by contacting us using the contact information provided in Section 13.

9

Data Retention and Deletion

Retention Period

Personal data is retained for the duration necessary to fulfill the purposes for which it was collected, or as required by law. Specific retention periods will be defined based on data type and regulatory requirements.

Deletion Process

When personal data is no longer needed, it will be securely deleted or anonymized in accordance with Citrus Labs Limited's data retention and deletion policies.

1

Identification of data that has reached the end of its retention period

2

Review of legal and operational requirements for retention

3

Secure deletion or anonymization using industry-standard methods

4

Verification of complete data removal from all systems

10

Data Breach Notification and Response

Detection and Reporting

In the event of a data breach, Citrus Labs Limited will promptly investigate the incident and take appropriate remedial action.

Notification Procedures

Users will be notified of a data breach involving their personal data within a reasonable timeframe, in compliance with Kenyan law, and relevant regulatory authorities will be informed as required.

Response Plan

A comprehensive data breach response plan is in place to mitigate potential harm, including immediate remediation measures and continuous monitoring.

11

Cookies and Tracking Technologies

Usage of Cookies

The Platform may use cookies and similar tracking technologies to improve user experience, analyze usage patterns, and enhance service functionality. These small text files are stored on your device and help us make your experience better, faster, and more secure.

User Options

Users can manage or opt out of cookies through their browser settings, although doing so may affect the functionality of the Platform. You can:

  • Delete all cookies from your browser
  • Configure your browser to block cookies
  • Configure your browser to alert you when cookies are being set
  • Use private browsing mode to automatically delete cookies at the end of your session
12

Policy Updates and Amendments

Updates

Citrus Labs Limited reserves the right to update this Data Policy periodically. Any material changes will be communicated to users via email or through a notice on the Platform.

User Notification

Continued use of the Platform after such updates constitutes acceptance of the amended Policy. We encourage users to review this Data Policy regularly to stay informed about how we protect their information.

13

Contact Information and Complaints

For any questions, clarifications, or complaints regarding this Data Policy, please contact us using the following details:

Email

legal@citruslabs.co.ke

Mailing Address

P.O. Box 23983 - 00100

Phone

+254 112 400 000

Escalation Process

If you are not satisfied with our response, you may escalate your complaint to the relevant data protection authority in Kenya.

Parent/Student Data Journey

Data Collection During Registration

Personal and account information is collected when you register for the platform

Data Processing For Services

Your data is processed to provide you with real-time tracking and notifications

Data Storage on Secure Cloud Servers

All your data is securely stored with encryption and access controls

Data Sharing With Service Providers

When necessary, data is shared with trusted third parties to provide services

Data Deletion When No Longer Needed

Your data is securely deleted when it's no longer required for service delivery

By using the Safiri by Citrus Parent/Student account, you acknowledge that you have read, understood, and consent to the collection, processing, and use of your personal data as described in this Data Policy.

Ready to Experience Safiri by Citrus?

With Safiri by Citrus, every detail is engineered to deliver a smart, safe, and seamless school transport experience. Join us today and stay connected with your child's journey every step of the way.