Privacy Policy & Terms of Service

Last updated: 1 January 2026
Governed by Kenyan law
Reading time: ~20 minutes
Document One

Privacy Policy

What we collect, why we collect it, and what you can do about it.

Merut Tech Solutions we respect your privacy and are committed to protecting the personal information you share with us. This policy explains what we collect, why, how we handle it, and the choices you have.

It applies to our website meruttechsolutions.com, our business communications, and any services we provide that reference this policy. It does not apply to third-party sites or services we link to.

This policy is written to comply with the Kenya Data Protection Act, 2019 and, for visitors and clients in the European Economic Area and the United Kingdom, the General Data Protection Regulation (GDPR).

01 Who we are

Merut Tech Solutions is a software company registered and operating in Kenya, with our principal office at Thika Road, TRM Drive, Nairobi. We are the data controller for personal information collected through this website and our direct business communications.

For the purposes of the GDPR, we are the controller for any personal data processed in connection with providing our services. Where we process personal data on behalf of a client — for example, customer records stored inside a POS or ERP system we built — the client is the controller and we act as a data processor under a separate written agreement.

02 Information we collect

We collect information in three broad ways: information you provide to us directly, information collected automatically when you use our website, and information we receive from third parties in the course of doing business.

Information you provide directly

  • Contact details — name, email address, phone number, company name, and any other information you include when filling in a form, sending an email, or messaging us on WhatsApp.
  • Project information — details about your business, workflow, technical requirements, and any documents or data you share as part of scoping a project or during delivery.
  • Account information — where you hold a client account with us, your login credentials, profile information, and support history.
  • Billing information — invoicing details, tax identifiers, and payment transaction records. We do not store full card numbers on our systems; card payments are processed by PCI-compliant third-party providers.
  • Communications — records of calls, emails, WhatsApp messages, and other correspondence related to your enquiry or engagement.

Information collected automatically

  • Usage data — pages visited, time spent, referring URLs, and general interaction patterns on our website.
  • Device and network data — IP address, browser type and version, operating system, screen size, and language preference.
  • Cookies and similar technologies — described in more detail in Section 6.

Information from third parties

  • Where you engage with us through a partner organisation or referral, we may receive limited contact information from that partner.
  • Where you contact us via a third-party platform (LinkedIn, WhatsApp, etc.), the platform may share basic profile information with us.
  • Public information about your business, where relevant to assessing a potential engagement.
What we do not collect

We do not knowingly collect sensitive personal data (health information, religious beliefs, biometric data, etc.) through this website. If you are a client and your system legitimately processes such data, that is governed by your separate data processing agreement with us, not this policy. We also do not collect information from children under 16 — see Section 11.

03 How we use information

We use personal information for the following purposes, and only for the following purposes:

  • To respond to enquiries. When you contact us, we use your details to reply, ask clarifying questions, and determine whether we can help.
  • To deliver our services. Where you engage us to build, deploy, or support a system, we use your information to do that work and to manage the relationship that surrounds it.
  • To send service communications. Project updates, invoices, support notifications, and any other messages directly related to an active engagement.
  • To send occasional business communications. Where you have opted in, occasional updates about our services, projects, or articles. Every such message contains a working unsubscribe link.
  • To operate and improve our website. Understanding which pages are useful, which are not, and where the site can be made clearer.
  • To meet legal obligations. Tax, accounting, regulatory, and dispute-related requirements under Kenyan and, where applicable, international law.
  • To protect against fraud or abuse. Detecting and preventing misuse of our systems, spam, and unauthorised access attempts.

We do not sell your personal information. We do not rent, trade, or otherwise commercialise it. We do not use your data to train third-party AI models.

04 Legal bases for processing

Where the GDPR applies, we rely on the following legal bases to process your personal information:

  • Contract — processing necessary to enter into or perform a contract with you (e.g. delivering a project you have engaged us for).
  • Legitimate interests — processing necessary for our legitimate business interests, such as responding to enquiries, protecting our systems, and improving our services. We balance these interests against your rights and expectations.
  • Consent — where you have given us clear, specific consent, for example to receive marketing communications. You can withdraw this at any time.
  • Legal obligation — processing necessary to comply with a legal or regulatory requirement, such as tax record-keeping.

Where the Kenya Data Protection Act, 2019 applies, we process personal data on the basis of one or more of the grounds set out in Section 30 of the Act, which are substantially similar.

05 Sharing and disclosure

We share personal information only in the limited circumstances described below, and always with appropriate safeguards in place.

Service providers (sub-processors)

We use a small number of trusted third-party services to operate our business. These may include:

  • Hosting and infrastructure providers — to run our website and the systems we deliver.
  • Email and communication platforms — to send and receive correspondence.
  • Payment processors — to handle invoicing and payment collection (e.g. Stripe, Flutterwave, M-Pesa Daraja).
  • Analytics services — to understand how our website is used.
  • Accounting and legal advisors — where necessary for compliance and dispute resolution.

All such providers are contractually bound to process personal data only on our instructions and to maintain appropriate security. Where any provider is located outside Kenya or the EEA, additional safeguards apply — see Section 9.

Business transfers

In the event of a merger, acquisition, restructuring, or sale of assets, personal information may be transferred as part of that transaction. We will notify affected individuals and provide a link to any updated privacy policy before data becomes subject to a different controller.

Legal requirements

We may disclose personal information where required to do so by law, court order, or a lawful request from a competent authority, or where disclosure is necessary to protect the rights, property, or safety of Merut Tech Solutions, our clients, or the public.

What we never do

We never sell your data. We never share it with advertising networks for behavioural targeting. We never transfer it to third parties for their own independent marketing purposes.

06 Cookies and similar technologies

Our website uses cookies and similar technologies (local storage, session identifiers) to function properly and to understand how visitors use it.

Categories of cookies we use

  • Strictly necessary — required for the website to work, including security, session management, and load balancing. These cannot be disabled.
  • Functional — remember your preferences, such as language or form state, so you don't have to re-enter them.
  • Analytics — help us understand which pages are visited, how long visitors stay, and where they come from. We use aggregated data and, where possible, IP anonymisation.

You can control cookies through your browser settings. Blocking strictly necessary cookies may affect how the site functions. Where required by law, we will ask for your consent before setting any non-essential cookies.

07 How long we keep information

We retain personal information only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.

  • Enquiry data (contact forms, emails from non-clients): retained for up to 24 months from last contact, then deleted.
  • Client project data: retained for the duration of the engagement, plus 7 years after final invoicing to satisfy tax and legal record-keeping requirements.
  • Support communications: retained for the duration of the support relationship, plus 3 years.
  • Marketing subscriptions: retained until you unsubscribe, plus a suppression record to ensure we don't contact you again by mistake.
  • Website analytics: aggregated data retained for up to 26 months. Identifiable data is minimised.

08 How we protect information

We take the security of personal information seriously, and we apply the same engineering discipline to it that we apply to our clients' systems.

  • Encryption in transit — all traffic to and from our website uses HTTPS with modern TLS.
  • Encryption at rest — databases and backups containing personal information are encrypted.
  • Access controls — internal access to personal data is limited to the staff who need it for their role, with individual accounts, role-based permissions, and audit logging.
  • Authentication — multi-factor authentication is required for all internal systems handling personal data.
  • Vendor review — we assess the security posture of third-party services before adopting them and periodically thereafter.
  • Incident response — we maintain a documented incident response procedure, and we will notify affected individuals and the relevant authorities as required by law if a breach occurs.

No system is completely secure. If you become aware of a security issue affecting our website or services, please contact us at inquiries@meruttechsolutions.com.

09 International data transfers

We are headquartered in Kenya, but some of the services we rely on (hosting, email, analytics, payment processing) may process personal information in other countries, including the European Economic Area, the United Kingdom, and the United States.

Where personal information is transferred out of Kenya or the EEA, we ensure that appropriate safeguards are in place. Depending on the destination and the provider, this may include:

  • Standard Contractual Clauses approved by the European Commission.
  • Adequacy decisions by the relevant authority.
  • Contractual commitments from providers to apply equivalent protections.

You can request more information about the specific safeguards applicable to your data by contacting us using the details in Section 13.

10 Your rights

Depending on where you are located, you have certain rights over the personal information we hold about you. Under the Kenya Data Protection Act, 2019 and the GDPR, these typically include:

  • Right of access — to receive a copy of the personal information we hold about you.
  • Right to rectification — to have inaccurate or incomplete information corrected.
  • Right to erasure — to have your information deleted in certain circumstances.
  • Right to restrict processing — to limit how we use your information while a concern is being resolved.
  • Right to object — to object to processing based on legitimate interests or for direct marketing.
  • Right to data portability — to receive your information in a structured, machine-readable format.
  • Right to withdraw consent — where processing is based on consent, to withdraw it at any time.
  • Right to lodge a complaint — with the Office of the Data Protection Commissioner (Kenya) or, if you are in the EEA/UK, your local supervisory authority.

To exercise any of these rights, email inquiries@meruttechsolutions.com with the subject line "Data Subject Request." We will acknowledge receipt within 5 business days and respond substantively within 30 days, unless a longer period is permitted by law. We may ask you to verify your identity before actioning a request.

There is no charge for exercising these rights, though we may charge a reasonable fee for manifestly unfounded or excessive requests.

11 Children's privacy

Our website and services are intended for businesses and professional users. They are not directed at children under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

12 Changes to this policy

We may update this policy from time to time to reflect changes in our practices, technology, or legal requirements. When we do, we will revise the "Last updated" date at the top of this page.

For material changes — those affecting how we use personal information — we will provide clearer notice, such as an email to registered clients or a prominent banner on the site, before the change takes effect. Continued use of our website or services after an update constitutes acceptance of the revised policy.

13 Contact

If you have any questions about this policy, want to exercise your rights, or have a concern about how we handle your information, please contact us using the details below. We take every privacy concern seriously and will respond as quickly as we can.

End of Document One · Start of Document Two
Document Two

Terms of Service

The baseline terms that apply to our website and any engagement with us.

These Terms of Service ("Terms") govern your access to and use of the Merut Tech Solutions website, and set out the baseline terms applicable to any services we provide, unless we have signed a separate written agreement with you that says otherwise.

Please read them carefully. By using our website or engaging our services, you confirm that you have read, understood, and agree to be bound by these Terms.

Where we have a signed Master Services Agreement, Statement of Work, or Proposal with you, that document takes precedence over these Terms to the extent of any conflict.

01 Agreement to terms

This website is operated by Merut Tech Solutions, a company registered in Kenya with its principal office at Thika Road, TRM Drive, Nairobi.

By accessing our website, submitting an enquiry, or engaging us to provide services, you agree to these Terms. If you do not agree, you should not use our website or services.

If you are entering into this agreement on behalf of a company or other legal entity, you represent that you have the authority to bind that entity to these Terms.

02 Definitions

Throughout these Terms, the following capitalised words have the meanings set out below.

  • "We," "us," "our," "Merut" Merut Tech Solutions, its employees, contractors, and authorised representatives.
  • "You," "Client," "your" The individual, company, or entity accessing our website or engaging our services.
  • "Services" Any software development, deployment, configuration, support, consulting, hardware supply, or rental services provided by us, whether delivered under a signed agreement or an accepted proposal.
  • "Deliverables" The software, systems, documentation, configuration, data structures, designs, and other materials we produce specifically for you as part of the Services.
  • "Proposal" or "Statement of Work" A written document setting out the specific scope, timeline, and fees for an engagement, signed or otherwise formally accepted by both parties.
  • "Confidential Information" Non-public information disclosed by one party to the other in connection with the Services, whether marked confidential or which a reasonable person would understand to be confidential.

03 Use of our website

You may use our website for lawful purposes only. You agree not to:

  • Use the website in any way that breaches applicable law or regulation.
  • Attempt to gain unauthorised access to any part of the website, its servers, or any connected system.
  • Introduce malware, viruses, or any other harmful code.
  • Scrape, harvest, or systematically extract content or data from the website for commercial purposes without our written permission.
  • Use the website to transmit unsolicited commercial communications (spam).
  • Reproduce, duplicate, or resell any part of the website in breach of these Terms.

We reserve the right to restrict or terminate access to our website at our discretion, including where we reasonably believe these Terms have been breached.

04 Services and proposals

Information on our website about our services is provided for general information. It does not constitute a binding offer, and it may change without notice.

How an engagement begins

An engagement between us and a client typically proceeds in the following stages:

  • Discovery. An initial conversation to understand the client's requirements, business context, and constraints.
  • Proposal. Where we believe we can help, we issue a written proposal setting out scope, deliverables, timeline, assumptions, exclusions, and fees.
  • Acceptance. The proposal becomes a binding contract when the client accepts it in writing (including by email) and, where applicable, pays any agreed mobilisation or deposit fee.
  • Delivery. Work proceeds under the accepted proposal, and any changes are handled according to the change process described below.

Scope changes

Any change to the scope, timeline, or fees set out in an accepted proposal must be agreed in writing by both parties before the change takes effect. We will always quote a change before doing the work, so there are no surprise invoices. Verbal requests for changes are not binding until confirmed in writing.

Exclusions

Unless expressly stated in a proposal, our Services do not include: third-party licence fees, hardware (except where separately agreed under Section 11), content creation, ongoing hosting after the first 30 days, or any work not explicitly listed in the scope.

05 Client obligations

Successful delivery depends on both parties. As a client, you agree to:

  • Provide accurate, complete, and timely information required for us to perform the Services.
  • Nominate a single point of contact with authority to make decisions on the project.
  • Respond to questions, review submissions, and provide sign-offs within reasonable timeframes (typically 5 business days unless otherwise agreed).
  • Ensure that any data, content, or materials you provide to us do not infringe the rights of any third party and are provided lawfully.
  • Maintain any credentials, licences, or third-party accounts necessary for us to perform the Services (for example, M-Pesa Paybill access, domain names, hosting accounts).
  • Comply with all applicable laws in your jurisdiction relating to your use of the Deliverables.

Delays caused by a failure to meet these obligations may result in adjustments to timelines or additional charges, which we will always raise with you first.

06 Fees and payment

Fees for our Services are set out in each accepted proposal. Unless stated otherwise:

  • Currency. Fees are quoted in KES, USD, GBP, or EUR as agreed in the proposal.
  • Deposits. Projects typically require a mobilisation deposit — commonly 40% of the total fee — before work begins.
  • Milestone payments. Remaining fees are invoiced at agreed milestones during delivery. Final payment is due before the production launch of any system.
  • Retainers. Ongoing support, maintenance, and hosting are invoiced monthly in advance, and are payable within 7 days of invoice date.
  • Taxes. Fees are exclusive of VAT and any other applicable taxes, which will be added where required by law.
  • Payment methods. We accept bank transfer, M-Pesa, card, and other methods as stated on each invoice.

Late payment

Invoices unpaid 14 days after the due date may attract a late payment charge of 1.5% per month on the outstanding balance, or the maximum permitted by law, whichever is lower. Where invoices remain unpaid 30 days after the due date, we reserve the right to suspend Services, hosting, or support until payment is received. Suspension does not relieve the client of the obligation to pay outstanding amounts.

Refunds

Deposits and milestone payments are non-refundable once the corresponding work has begun, except where we materially fail to deliver the agreed scope and do not remedy that failure within a reasonable period after written notice.

07 Intellectual property

This section sets out who owns what. It is one of the most important sections in these Terms, so we have tried to make it as clear as possible.

Our pre-existing IP

We retain ownership of all tools, libraries, frameworks, code, designs, and know-how that we developed or acquired before an engagement, or that we develop independently of it (including improvements and generalisations developed during the engagement but not specific to your Deliverables). Where any such material is incorporated into your Deliverables, we grant you a perpetual, non-exclusive, royalty-free licence to use it as part of those Deliverables.

Client materials

You retain ownership of all data, content, trademarks, business information, and materials you provide to us. You grant us a limited licence to use those materials solely for the purpose of delivering the Services.

Custom Deliverables

On full payment of all fees due for a project, we assign to you all intellectual property rights in the custom Deliverables we developed specifically for that project. This includes source code, database schemas, documentation, and project-specific designs. Assignment is conditional on full payment — until all fees are settled, ownership remains with us.

Third-party components

Deliverables may include open-source or commercially licensed third-party components. Those components remain subject to their own licences, which we will identify in project documentation. You are responsible for complying with those licences.

Portfolio use

We may reference a project in our portfolio, case studies, or marketing materials, using only information that you have approved for public reference. We will not disclose confidential business details without your written consent.

08 Confidentiality

Each party agrees to keep the other's Confidential Information confidential, to use it only for the purpose of the engagement, and to disclose it only to those employees, contractors, or advisors who need to know it and are bound by equivalent confidentiality obligations.

These obligations do not apply to information that: (a) is or becomes publicly available through no fault of the receiving party; (b) was already known to the receiving party without a duty of confidence; (c) is independently developed without reference to the disclosing party's information; or (d) is required to be disclosed by law or court order, provided the receiving party gives prompt notice where legally permitted.

Confidentiality obligations survive termination of the engagement for a period of 5 years, or indefinitely for trade secrets.

09 Warranties and disclaimers

What we warrant

  • We will perform the Services with reasonable skill, care, and diligence, in line with industry standards.
  • Deliverables will materially conform to the specifications agreed in the accepted proposal.
  • We have the right to enter into the engagement and to grant the licences and assignments described in these Terms.
  • To the best of our knowledge, custom Deliverables do not infringe the intellectual property rights of any third party.

What we do not warrant

  • That Deliverables will be error-free. Software of any complexity contains bugs, and we address them through our support and warranty process rather than by claiming perfection.
  • That the Deliverables will meet requirements that were not documented and agreed in the proposal.
  • That third-party services (payment gateways, hosting providers, communication platforms) will be uninterrupted, secure, or error-free. Our warranties do not extend to systems we do not control.
  • Any specific commercial outcome — for example, a particular level of revenue increase, cost reduction, or business growth. The systems we build are tools, and their impact depends on how they are used.

Warranty period

We will correct defects in Deliverables that materially deviate from the agreed specifications, free of charge, for 30 days from the date of production launch. This warranty does not cover issues caused by client modifications, misuse, third-party systems, or changes in the client's environment.

10 Third-party services and integrations

Deliverables often integrate with third-party services — for example, M-Pesa, card payment gateways, SMS providers, email delivery platforms, cloud hosting, and analytics tools. Your use of those services is governed by the terms of the relevant providers.

We are not responsible for:

  • Changes to third-party APIs, terms, pricing, or availability that affect an existing integration.
  • Outages, errors, or security incidents originating with third-party providers.
  • Any third-party fees, licences, or subscription costs.

Where a third-party change requires us to modify an integration, that work may be chargeable at our standard rates. We will notify clients promptly when we become aware of a material change.

11 Hardware sales and rentals

Where we supply hardware — POS terminals, printers, scanners, tablets, networking equipment, and similar — the following additional terms apply.

Purchased hardware

  • Ownership passes to the client on full payment.
  • Manufacturer warranties apply and are passed through to the client where possible.
  • We will facilitate warranty claims during the manufacturer warranty period, but we are not the warrantor.

Rented hardware

  • Ownership remains with Merut Tech Solutions at all times. Rented equipment is not the client's property and may not be sold, pledged, or transferred.
  • The client is responsible for the equipment while in their possession and must take reasonable care of it. Loss or damage through negligence, misuse, or theft may result in a replacement charge.
  • Rental fees are payable monthly in advance. The minimum rental term is 6 months unless otherwise agreed.
  • Where a rented unit fails through no fault of the client, we will replace it. Response times are set out in the rental agreement.
  • On termination of the rental, equipment must be returned in reasonable working condition, or made available for collection at an agreed time.
  • Rented equipment remains subject to the confidentiality and data protection obligations described in Section 8. On return, we will securely erase any residual client data.

12 Limitation of liability

Nothing in these Terms excludes or limits either party's liability for: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; or any other liability that cannot be excluded or limited under applicable law.

Subject to the paragraph above, and to the maximum extent permitted by law:

  • Neither party is liable to the other for indirect, consequential, incidental, or punitive damages, or for loss of profit, loss of revenue, loss of anticipated savings, loss of business, loss of data, or loss of goodwill, whether arising in contract, tort, or otherwise.
  • Our total aggregate liability arising out of or in connection with an engagement is limited to the total fees paid by the client to us under the applicable proposal in the 12 months preceding the event giving rise to the claim.
  • Where the Services involve a free or trial element, our liability in respect of that element is excluded to the fullest extent permitted by law.

These limitations reflect the commercial reality of the pricing structure of our Services, and both parties acknowledge them as a reasonable allocation of risk.

13 Indemnity

You agree to indemnify, defend, and hold harmless Merut Tech Solutions and its officers, employees, and contractors from any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or connected with:

  • Your breach of these Terms or any accepted proposal.
  • Your use of the Deliverables in a manner that is unlawful or that infringes the rights of a third party.
  • Content, data, or materials you provided to us that infringe third-party rights or violate applicable law.
  • Your failure to comply with the terms of any third-party service used in connection with the Deliverables.

14 Term and termination

These Terms apply for as long as you use our website or engage our Services.

Termination for convenience

Either party may terminate an engagement on 30 days' written notice. On termination, the client is liable for all work performed and costs incurred up to the termination date, and any outstanding invoices become immediately due.

Termination for cause

Either party may terminate immediately on written notice if the other: (a) commits a material breach of these Terms and fails to remedy it within 14 days of written notice; (b) becomes insolvent or enters administration or liquidation; or (c) engages in conduct that makes continuation of the engagement untenable, including fraud, wilful misconduct, or a serious breach of confidentiality.

Effect of termination

  • On termination, we will provide the client with a final handover of work completed to date, subject to settlement of outstanding fees.
  • Ownership of custom Deliverables transfers to the client on full payment, as described in Section 7.
  • Provisions that by their nature should survive — including confidentiality, intellectual property, limitation of liability, indemnity, and governing law — survive termination.

15 Governing law and dispute resolution

These Terms and any engagement entered into under them are governed by the laws of the Republic of Kenya, without regard to conflict of laws principles.

The parties agree to attempt to resolve any dispute arising out of or in connection with these Terms through good-faith negotiation first. If a dispute cannot be resolved within 30 days of written notice, either party may refer it to mediation in Nairobi, and failing that, to the exclusive jurisdiction of the courts of Kenya.

Where a client is located outside Kenya, the parties may agree in a signed proposal to a different governing law or dispute resolution forum, in which case that agreement will prevail over this section.

16 Changes to these Terms

We may update these Terms from time to time to reflect changes in our services, legal requirements, or industry practice. When we do, we will update the "Last updated" date at the top of this page.

For material changes, we will provide reasonable notice — by email to active clients, or by a prominent banner on the site — before the changes take effect. Changes do not apply retroactively to an engagement already underway under a signed proposal, unless required by law or agreed in writing between the parties.

17 Contact

If you have questions about these Terms, or want to raise a concern about how an engagement is being handled, please contact us using the details below. We would much rather hear about a problem early than have it escalate.

Contact us about anything on this page

Whether your question is about privacy, a data subject request, a commercial engagement, or a dispute — this is the address to use. Emails are monitored during business hours and routed to the right person.

Registered address Thika Road, TRM Drive
Nairobi, Kenya
Shopping Basket