Privacy Policy
Last updated: 28 September 2026
This policy explains how Azly Software ("Azly") handles personal data as a data controller and data processor, in compliance with the Kenya Data Protection Act 2019 (DPA) and, where our customers or their data subjects are in the European Economic Area or the United Kingdom, the General Data Protection Regulation (GDPR).
1. Who we are
Azly is a software company headquartered at Captain Mungai, Nairobi, Kenya. For data collected through this website (such as the contact form), Azly is the data controller. For personal data processed through our modules on our customers' platforms, and for Services performed for customers, Azly acts as a data processor acting on the customer's instructions; the customer is the controller. Azly is registered with the Office of the Data Protection Commissioner (ODPC) in Kenya as required by the DPA.
2. Data we process
2.1 Website and contact form
- Name, email address, company name, and message content you submit through the contact form.
- Basic request metadata (IP address) used solely for rate limiting and abuse prevention, retained for a maximum of ten minutes.
2.2 Module data, by platform
- GoHighLevel modules: sub-account contact data, invoice and payment records, messaging metadata, and calendar entries that our modules read or write on the customer's instructions.
- HubSpot modules: portal contact properties, deal and ticket records, SMS and WhatsApp conversation metadata, and quote documents processed by the module.
- monday.com modules: board item data, form submissions and uploaded files, and notification recipients.
- Pipedrive modules: person and organization records, deal data, message logs, and enrichment results.
- Shopify modules: merchant store data, order and customer records, inventory data, and message opt-in records.
- Across messaging modules: WhatsApp Business API metadata (phone numbers, message identifiers, delivery status, template names) processed to deliver the module's function.
- Across payment modules: transaction references and statuses. Card details and mobile-money credentials are never processed by Azly; they are handled by the payment gateways themselves.
2.3 Services (custom development)
Client project materials shared under a statement of work, including credentials to client systems (stored in a password manager, scoped to the minimum access needed), requirement documents, and correspondence.
3. Purposes and lawful bases
- Contract: delivering modules and Services you or your customers have subscribed to.
- Legitimate interests: securing our website (rate limiting, honeypot) and improving our products.
- Consent: where a platform's end users have opted in to messaging features, and for any optional communications from us.
- Legal obligation: keeping records required by Kenyan tax and company law, and responding to lawful requests.
4. Sharing and sub-processors
We do not sell personal data. We share it only with providers necessary to operate the business, under written data protection terms: the platforms and marketplaces on which modules run (their own policies govern the platform relationship), payment gateways (Paystack, Flutterwave, and M-Pesa providers, as processors for our customers), messaging providers (WhatsApp Business API, operated by Meta), our email delivery provider (Resend, for contact form messages), and our hosting provider. An up-to-date list of sub-processors is available on request.
5. International transfers
Azly operates from Kenya, and some providers above process data outside Kenya and outside the EEA. Transfers from Kenya are made in line with the DPA's transfer conditions; transfers subject to the GDPR are protected by the provider's Standard Contractual Clauses or an adequacy decision where available.
6. Retention
- Contact form messages: up to 24 months after the conversation ends.
- Module data: retained only while the module subscription is active, plus a 30-day wind-down window, unless a platform requires longer.
- Services records: seven years for invoicing and contract records, per Kenyan law.
- Rate-limiting metadata: ten minutes, then deleted.
7. Your rights
Under the DPA and the GDPR you have rights to access, correct, delete, restrict, or object to processing, to data portability, and to withdraw consent at any time. To exercise any right, email hello@azly.io. If you are in Kenya you may also complain to the ODPC; if you are in the EEA or UK, to your local supervisory authority. We respond within the statutory periods.
8. Security
We apply encryption in transit, strict access controls, least-privilege credentials, and dependency auditing. Module scopes are limited to the minimum platform permissions needed for the module's function. We notify the ODPC and affected customers of qualifying personal data breaches within 72 hours of becoming aware of them, and GDPR controllers without undue delay so they can meet their own obligations.
9. Children
Our products are business tools and are not directed at children under 18, and we do not knowingly collect their data.
10. Changes and contact
We post any change to this policy at this address with a new last-updated date. Questions: hello@azly.io.