Legal
Privacy Policy
What personal data we hold, why we hold it, and what you can ask us to do with it.
Last updated 14 September 2026
This policy covers personal data we handle in connection with the Noria CRM service and this website. “We” is Noria Technologies LTD, a company incorporated in Kenya and operating from Nairobi, and the law behind this policy is the Data Protection Act, 2019. It is written for two different readers, and the first thing to sort out is which one you are.
Two different roles
Data we decide about. When you visit this site, open a workspace, sign in, get invoiced, or write to us for support, we decide why and how that data is used. For that data we are the data controller, and this policy tells you what we do.
Data our customers decide about. The CRM records inside a workspace, the accounts, contacts, deals, activities and messages, belong to the customer who put them there. They decide what goes in and what it is for. We only hold and process it to run the service for them. For that data they are the controller and we are the processor, and our obligations are set out in the Data Processing Addendum.
If you are a customer’s contact and want your details corrected or removed from their CRM, ask that organisation rather than us. If you write to us instead, we will pass your request to them and tell you that we have.
The rest of this policy is about the first kind of data.
What we hold
Account data. Your name, work email address, phone number where you give one, the workspace you belong to, your role in it, and your language and timezone. This comes from you or from the colleague who invited you.
Sign-in data. The fact and time of each sign in, and where you sign in through Google, the profile details Google returns. We do not receive your Google password.
Billing data. The organisation’s name and billing address, plan and seat count, invoices and payment status.
Support data. What you write to us and what we write back.
Technical data. IP address, browser and device type, pages requested, and timestamps, in our server logs. We keep these to run the service, find faults and investigate abuse.
Site data. This marketing website sets no cookies and runs no analytics. Requests to it appear in the same server logs as everything else. See the Cookie Policy.
We do not collect special category data about you, and you should not send it to us in a support message.
Why we hold it, and on what basis
| What for | Basis |
|---|---|
| Giving you access to the service you or your employer signed up for | Performance of a contract |
| Invoicing, collecting payment, and keeping accounting records | Contract, and a legal obligation |
| Support, and telling you about changes that affect your use | Contract, and our legitimate interest in running the service |
| Keeping the service secure, investigating abuse and fixing faults | Our legitimate interest in a service that works and is not abused |
| Telling you about other things we offer | Consent, which you can withdraw at any time |
Where we rely on a legitimate interest, we have weighed it against your interests and you can ask us to explain the result.
Who else sees it
We use other companies to provide parts of the service. Each one is listed, with what it does and where it does it, on the sub-processors page. They act on our instructions and may not use your data for their own purposes.
Beyond those, we share personal data only where the law requires it, where it is needed to establish or defend a legal claim, or with a buyer if our business is sold, in which case we will tell you.
We do not sell personal data, and we do not share it for anybody else’s advertising.
Where it goes
Some of the providers we use operate outside Kenya. Where personal data is transferred out, we rely on the safeguards required by that law, which for our current providers means the transfer terms in their data processing agreements.
The sub-processors page names where each provider holds data.
How long we keep it
Account data lasts as long as your account, and then 30 days. Billing and accounting records are kept for seven years: the Tax Procedures Act requires five, and we keep them longer so an audit or a company law request later in that window can still be answered. Support messages are kept for 24 months. Server logs are kept for 90 days and then deleted.
Backups are kept on a rolling basis and age out. Data deleted from the live service remains in a backup until that backup expires.
Security
We protect personal data with measures appropriate to the risk, covering access control, encryption in transit and at rest, separation between customers, logging, and review of who can reach what. We describe the commitments rather than the mechanisms, because a published description of exactly how a system is defended helps the wrong reader most.
No service is perfectly secure. If a breach affects your personal data and is likely to result in a risk to you, we will tell you and the regulator within the period the law requires.
Your rights
Subject to the conditions in the applicable law, you can ask us to:
- tell you what we hold about you and give you a copy
- correct something that is wrong or incomplete
- delete data we no longer have a reason to hold
- restrict what we do with it while a dispute is resolved
- give you, or another provider, a portable copy of data you gave us
- stop processing that relies on a legitimate interest, where your situation gives you grounds
- stop sending you marketing, which you can also do from any message we send
We answer within the period the law requires and will not charge unless a request is repetitive or excessive. We may need to confirm who you are first.
There is no automated decision-making with a legal or similarly significant effect on you. AI features in the product make suggestions to a person, who decides.
Complaints
Tell us first, at [email protected], and we will try to put it right.
You can also complain to the Office of the Data Protection Commissioner, which supervises this under the Data Protection Act, 2019. Complaints go through their portal at cie.odpc.go.ke(opens in a new tab), by email to [email protected], or by post to P.O. Box 30920-00100 G.P.O. Nairobi. Their offices are on the 12th floor of Britam Towers, Hospital Road, Upperhill, Nairobi.
Changes
We will update this page when what we do changes, and the date at the top will change with it. Where a change matters to you, we will tell you rather than rely on you noticing.
Contact
Write to [email protected], or to Noria Technologies LTD, Nairobi, Kenya. That address reaches the people who handle data protection here, and what arrives at it is logged and answered rather than left sitting in an inbox.