Data Policy for Safiri by Citrus – School Account Users

1

Introduction & Scope

This Data Policy outlines how Safiri by Citrus ("the Platform") collects, processes, stores, and protects data provided by School account users. The purpose of this Policy is to ensure transparency in our data practices and compliance with Kenyan Data Protection laws (including the Data Protection Act 2025) and other applicable regulations. This Policy applies solely to users of the School account, which is designed to streamline school transport management by enabling administrators to manage student, parent, and driver profiles; configure routes and schedules; and monitor real-time transport activities, as well as facilitate fee management, communication, and safety tracking.

Transparency & compliance with Kenyan Data Protection laws
Applies to School Account users
Transport management functionalities
2

Definitions

For the purposes of this Policy, the following definitions apply:

Personal Data

Information relating to an identified or identifiable natural person, such as names, contact details, and identification numbers.

Processing

Any operation or set of operations performed on personal data, including collection, storage, retrieval, use, alteration, disclosure, or deletion.

Data Subject

Any individual whose personal data is processed by the Platform.

Data Controller

Citrus Labs Limited, which determines the purposes and means of processing personal data.

Data Processor

Any third party engaged by Citrus Labs Limited to process personal data on its behalf.

Sensitive Data

Personal data that requires special protection under Kenyan law, which may include biometric data or other classified sensitive information.

3

Types of Data Collected

Safiri by Citrus collects the following data from School account users:

Personal Information

School name, administrator name, contact details (email, phone number), and any additional identification or accreditation data provided during registration.

Usage Data

Information on how users interact with the Platform, including login timestamps, session durations, and activity logs.

Device Information

Data regarding the devices used to access the Platform, including IP addresses, device types, operating systems, and browser details.

Cookies and Tracking Data

Data collected through cookies and similar technologies to enhance user experience and optimize the Platform.

Sensitive Data

If applicable, any sensitive information will be collected and processed with heightened security measures, in compliance with Kenyan law.

5

Purpose of Data Collection and Processing

Data is collected and processed for the following purposes:

Service Delivery

To enable effective management of school transport operations, including the administration of student, parent, and driver profiles, route configuration, and real-time monitoring of transport activities.

Customer Support

To provide prompt and efficient support and troubleshooting services to School account users.

Marketing and Communication

To inform users about Platform updates, new features, and relevant promotional activities, provided that users have consented to receive such communications.

Security and Compliance

To safeguard the Platform, ensure data integrity, and meet regulatory obligations, including fraud detection and incident response.

System Improvement

To analyze usage data and feedback to continuously enhance the Platform's functionality and user experience.

6

Data Storage and Security Measures

Data Storage

Personal data is stored on secure, cloud-based servers operated by reputable third-party service providers that comply with industry-standard security practices. Data retention periods are determined based on legal requirements and operational needs.

Security Protocols

The Platform employs robust security measures, including:

Encryption

Data is encrypted both in transit and at rest.

Access Controls

Strict access controls and multi-factor authentication are implemented to protect user data.

Regular Audits

Ongoing security audits and vulnerability assessments are conducted to identify and mitigate risks.

Backup Procedures

Regular data backups and recovery procedures are in place to prevent data loss.

7

Data Sharing and Third-Party Disclosures

8

User Rights and Access

School account users have the following rights concerning their personal data:

Right of Access

The right to request a copy of the personal data held by Citrus Labs Limited.

Right to Rectification

The right to correct any inaccuracies in their personal data.

Right to Erasure

The right to request deletion of personal data, subject to applicable legal and contractual obligations.

Right to Restrict Processing

The right to limit the processing of their personal data in certain circumstances.

Right to Data Portability

The right to receive personal data in a structured, commonly used, and machine-readable format.

Right to Object

The right to object to processing based on legitimate interests or for direct marketing purposes.

Requests to exercise these rights should be submitted via the contact details provided in Section 13.

9

Data Retention and Deletion

Retention Period

Personal data is retained for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Specific retention periods are determined based on the nature of the data and regulatory requirements.

Deletion Process

Once data is no longer required, it will be securely deleted or anonymized in accordance with Citrus Labs Limited's data retention policies.

10

Data Breach Notification and Response

Detection and Reporting

The Platform employs monitoring systems to detect potential data breaches promptly. In the event of a breach, Citrus Labs Limited will investigate and take corrective actions immediately.

Notification Procedures

Affected users will be notified of any data breach affecting their personal data within a reasonable timeframe, and relevant regulatory authorities will be informed in accordance with Kenyan law.

Response Plan

A detailed data breach response plan is in place to mitigate potential risks and prevent future incidents.

11

Cookies and Tracking Technologies

Use of Cookies

The Platform may use cookies and similar technologies to enhance user experience, analyze usage patterns, and improve service functionality.

Management

Users can manage or disable cookies via their browser settings; however, disabling cookies may affect the Platform's functionality.

12

Policy Updates and Amendments

Updates

Citrus Labs Limited reserves the right to update this Data Policy as necessary. Material changes will be communicated to School account users via email or a prominent notice on the Platform.

User Acceptance

Continued use of the Platform after updates constitutes acceptance of the revised Data Policy.

13

Contact Information and Complaints

For any questions, clarifications, or complaints regarding this Data Policy, please contact:

Email

legal@citruslabs.co.ke

Mailing Address

P.O. Box 23983 - 00100

Phone

+254 112 400 000

If you believe that your data has been mishandled or wish to escalate a complaint, you may also contact the relevant data protection authority in Kenya.

By using the Safiri by Citrus School account, you acknowledge that you have read, understood, and consent to the collection, processing, storage, and sharing of your data as described in this Data Policy.

Ready to Experience Safiri by Citrus?

With Safiri by Citrus, every detail is engineered to deliver a smart, safe, and seamless school transport management experience.