Privacy Policy - Bituls Company Ltd.
Last Updated: October 26, 2023
IMPORTANT NOTICE: This Privacy Policy explains how Bituls Company Ltd. (“Bituls,” “Bituls Ltd.,” “we,” “us,” or “our”), a company registered in Kenya, collects, uses, stores, shares, and protects your Personal Data in connection with your use of our websites, applications, and services (collectively, “Services”). We are committed to protecting your privacy in accordance with the Kenyan Data Protection Act, 2019, and other applicable laws.
1. Introduction
Bituls Company Ltd. provides technology services, including GPS tracking and fleet management solutions (Bituls GPS Tracking) and 24/7 roadside assistance and towing services (Duma Rescue). This Privacy Policy applies to all individuals who interact with our Services, including website visitors, potential clients, and active clients. By using our Services, you consent to the data practices described in this policy. Bituls is licenced by the Communications Authority of Kenya (CA) to provide GPS tracking services.
2. Information We Collect
We collect various types of information to provide and improve our Services, ensure security, and comply with legal obligations.
2.1 Personal Data You Provide Directly
When you interact with our Services, you may provide us with Personal Data, including but not limited to:
- Contact Information: Name, email address, phone number, physical address.
- Business Information: Company name, job title, industry, number of vehicles (for B2B clients).
- Vehicle Information: Vehicle make, model, registration number, VIN (for GPS tracking and Duma Rescue).
- Payment Information: Billing address. (Note: We do not store full payment card details; these are processed securely by third-party payment gateways).
- Account Credentials: Username and encrypted password (for accessing our software platforms).
- Communications: Information you provide when contacting our support team, sending emails, or providing feedback.
2.2 Usage Data Automatically Collected
When you access and use our Services, we may automatically collect certain information:
- Device Information: IP address, browser type and version, operating system, device identifiers, mobile network information.
- Website Usage Data: Pages visited, time spent on pages, referral sources, clicks, and other interactions with our website and content.
- Geographic Information: General location inferred from your IP address or specific location if you grant access via your mobile device for Duma Rescue.
- Google Click ID (GCLID): A unique identifier associated with a click on a Google Ads advertisement. We capture and store this ID to link ad clicks to specific leads and conversions in our internal CRM systems. This helps us optimize our advertising campaigns by understanding which ads generate valuable leads.
2.3 Tracking Data (Specific to Bituls GPS Tracking Service)
For clients utilizing Bituls GPS Tracking, we collect and process specific vehicle-related data through our installed Devices:
- Real-time Location Data: GPS coordinates of the vehicle(s).
- Movement Data: Speed, direction, mileage, trip history, idle times.
- Vehicle Status Data: Engine on/off status, battery voltage, and other diagnostic data depending on Device capabilities.
- Identifiers: Device ID, associated vehicle identifier (e.g., registration number).
IMPORTANT NOTE FOR GPS TRACKING CLIENTS: If you are a client of Bituls GPS Tracking and use our services to track vehicles operated by other individuals (e.g., your employees, drivers, or loan recipients), you are the Data Controller for the personal data collected from those individuals (e.g., their travel patterns, work hours). You are solely responsible for ensuring that you have obtained all necessary legal consents and made adequate disclosures to those individuals, in compliance with the Kenyan Data Protection Act, 2019, and any other applicable laws, before tracking them. Bituls acts as a Data Processor, processing this data on your behalf as per our service agreement.
3. How We Use Your Information
We use the collected information for various purposes, primarily to provide, maintain, and improve our Services:
- To Provide and Maintain Services:
- To set up and manage your Bituls GPS Tracking account and provide access to the platform.
- To install, maintain, and remove GPS tracking Devices.
- To dispatch Duma Rescue services to your location.
- To process your payments and manage your billing.
- To communicate with you about your account and Service updates.
- To Improve Our Services:
- To analyze website and service usage patterns using tools like Google Analytics 4 (GA4).
- To understand market trends and develop new features or services.
- To personalize your experience.
- For Communication and Marketing:
- To respond to your inquiries and support requests.
- To send you marketing communications about our Services, special offers, or news, where you have provided consent.
- To send service-related notifications (e.g., maintenance alerts).
- For Security and Fraud Prevention:
- To protect the security and integrity of our websites, systems, and client data.
- To detect and prevent fraudulent activities or unauthorized access to your account.
- For Legal and Compliance Purposes:
- To comply with legal obligations, Communication Authority, court orders, or government requests.
- To enforce our Terms of Service.
- To establish, exercise, or defend our legal rights.
- For Advertising Optimization:
- We use the GCLID to measure the effectiveness of our Google Ads campaigns, understand which keywords and ads drive successful leads, and optimize our advertising spend. This allows Google’s algorithms to learn and deliver more relevant ads to potential customers.
4. How We Share Your Information
We do not sell your Personal Data to third parties. We may share your information only in the following circumstances:
- With Service Providers: We engage trusted third-party service providers to perform functions on our behalf, such as:
- Hosting providers: For website and application hosting.
- Payment processors: To handle payment transactions securely.
- Analytics providers: Like Google Analytics (GA4), to help us understand service usage.
- CRM/ERP systems: Like our CRM/ERP systems, to manage leads, clients, and internal operations.
- Towing Partners/Drivers (for Duma Rescue): If applicable, to dispatch and coordinate roadside assistance.
- These providers are contractually obligated to protect your data and only use it for the purposes for which it was disclosed.
- With Bituls GPS Tracking Clients (for B2B services): For services provided to auto-lending institutions or other businesses, the tracking data collected from vehicles will be shared with the respective client who is the Data Controller, as per your service agreement with them.
- For Legal Reasons: If required by law, court order, or governmental regulation, or if we believe such action is necessary to comply with legal processes, protect our rights or property, or ensure the safety of our users or the public.
- Business Transfers: In the event of a merger, acquisition, asset sale, or other business transaction, your Personal Data may be transferred as part of the assets involved. We will notify you of any such change of ownership or control of your Personal Data.
- With Your Consent: We may share your information for any other purpose with your explicit consent.
5. Data Retention
We retain your Personal Data for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- Client Data: We retain client information for the duration of your service agreement and for a period thereafter as required by law (e.g., tax records) or for legitimate business interests (e.g., dispute resolution).
- Tracking Data: GPS tracking data is typically retained for a specific period as agreed in your service contract or for our standard operational periods, after which it is anonymized or securely deleted.
- Website Usage Data: Analytics data is retained according to Google Analytics’ retention policies.
- GCLID: GCLID data linked to leads in our CRM/ERP is retained as long as the associated Lead record exists, enabling long-term ROI analysis.
6. Data Security
We implement appropriate technical and organizational measures to protect your Personal Data from unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit (e.g., SSL/TLS for website traffic).
- Access controls and authentication mechanisms for our systems.
- Regular security audits and updates.
- Employee training on data protection. However, no method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
7. Your Data Protection Rights (Under Kenyan Data Protection Act, 2019)
As a data subject in Kenya, you have the following rights concerning your Personal Data:
- The Right to Be Informed: To be informed of the use to which your Personal Data is to be put. This Policy serves to inform you.
- The Right to Access: To request access to the Personal Data we hold about you.
- The Right to Rectification: To request that any inaccurate or incomplete Personal Data we hold about you be corrected or updated.
- The Right to Erasure (Right to Be Forgotten): To request the deletion of your Personal Data, subject to certain legal exceptions (e.g., if we are legally required to retain it).
- The Right to Object: To object to the processing of your Personal Data, including for direct marketing purposes.
- The Right to Restriction of Processing: To request the restriction of processing of your Personal Data under certain circumstances.
- The Right to Data Portability: To receive your Personal Data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
- The Right Not to Be Subject to Automated Decision Making: To object to decisions based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
- The Right to Withdraw Consent: Where we rely on your consent to process your Personal Data, you have the right to withdraw that consent at any time.
To exercise any of these rights, please contact us using the contact details provided in Section 11 of this Policy. We will respond to your request within the timeframe required by law.
8. Third-Party Links
Our website may contain links to other websites that are not operated by us. This Privacy Policy does not apply to those third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.
9. Cookies Policy
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and support our marketing efforts. This includes technologies used by Google Analytics 4 and Google Ads for conversion tracking and audience segmentation. You can control cookie preferences through your browser settings.
10. Children’s Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect Personal Data from children. If you are a parent or guardian and believe your child has provided us with Personal Data, please contact us.
11. Changes to This Privacy Policy
We may update our Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Last Updated” date. We encourage you to review this Privacy Policy periodically.
12. Contact Information
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:
Bituls Company Ltd.
Email: privacy@bituls.com
Phone: +254 722 969 847
Address: Rhodes Court, 3rd Floor, Upper Hill Road, Upper Hill, Nairobi, Kenya, or by visiting this page on our website: https://www.bituls.com/contact