Back to home

Privacy Policy

Ivrify Data Limited

Last updated: August 2026

Effective date: August 2026

1. Introduction

Ivrify Data Limited (“Ivrify Data”, “we”, “us”, “our”) provides Origin Secure, a supply-chain traceability and verification platform for producers, exporters, and their partners.

This Privacy Policy explains how we handle personal data when you:

  • visit www.ivrifydata.io;
  • use the Origin Secure mobile application;
  • use the Origin Secure web dashboard;
  • scan a product or batch verification code; or
  • explore Origin Secure through our demo experience.

This Policy also applies to our website and business enquiries relating to other Ivrify Data products (such as Impact Secure) unless a separate notice applies.

If you do not agree with this Policy, please do not use our services.

Contact us
Email: partnerships@ivrifydata.io
Website: https://www.ivrifydata.io
Address: The Enclave Apartments, Lower Kabete Road, Nairobi, Kenya (00100)

2. Who is responsible for your data

Origin Secure is used in two main ways:

A. Our own services
For our website, demo experience, sales enquiries, and platform operations, Ivrify Data is the data controller.

B. Services we provide to client organisations
Many customers (such as exporters, cooperatives, brands, and their partners) use Origin Secure to manage their own supply-chain data. In those cases:

  • the client organisation is usually the data controller for operational data about its users, suppliers, and supply-chain activities; and
  • Ivrify Data acts as a data processor, handling that data only on the client's instructions and under our agreement with them.

If you are a field agent, administrator, or other user working for a client organisation, questions about how your organisation uses your data should be directed to that organisation in the first instance. We will support our clients in responding to valid requests where applicable.

We do not sell personal data.

3. Personal data we collect

3.1 Website and business enquiries

When you visit our website or contact us, we may collect:

  • name, email address, phone number, organisation, and job role;
  • the content of messages or forms you submit;
  • technical information such as IP address, browser type, device type, pages visited, and referral source; and
  • cookie and analytics data (see Section 12).

3.2 Origin Secure mobile application

If you use the mobile app as an authorised user of a client organisation, we may process:

  • Account information: name, email address, phone number, user identifiers, and role;
  • Operational data you enter or capture: supply-chain records, source and batch information, timestamps, and related business metadata;
  • Location information: GPS coordinates and related accuracy data when you use location-enabled features (with your permission). We do not track your location in the background;
  • Photos and documents: images and files you attach as supporting evidence;
  • Device and app information: device type, operating system, app version, and notification preferences;
  • Local app data: information stored on your device to support offline use and synchronisation when connectivity is available.

The app may request permission to use your camera (for setup and capture), location, photos/files, and notifications. You can manage these in your device settings.

3.3 Origin Secure web dashboard

If you use the web dashboard as an administrator or authorised user of a client organisation, we may process:

  • account and login information;
  • actions you take in the dashboard (such as reviews and approvals); and
  • technical session information (such as IP address, browser type, and access logs).

Dashboard data relates to the client organisation you work for and is handled on that organisation's behalf.

3.4 Product and batch verification

When a verification code is scanned or a verification page is opened, we may automatically collect:

  • the identifier of the item being verified;
  • date and time of access;
  • IP address and browser or device type; and
  • approximate location derived from IP address.

Account registration is not required to verify a product or batch.

3.5 Demo experience

We offer a demonstration version of Origin Secure so prospective users can explore the platform.

Exploring the demo
When you use demo mode, we may collect:

  • a session identifier;
  • demo entry and exit events;
  • session duration;
  • device operating system and app version; and
  • limited technical logs needed to operate and improve the demo.

Demo content is illustrative. Please do not enter real personal data about yourself or others into demo fields unless prompted by a contact form described below.

Requesting Origin Secure for your organisation
If you choose “Get Origin Secure for your organisation” (or similar) within the demo, we collect the contact details you submit, which may include:

  • email address;
  • phone number; and
  • name, if you provide it.

We use this information to respond to your enquiry, follow up about Origin Secure, and understand interest in our services. With your consent or where permitted by law, we may also send you relevant product or commercial information. You can opt out of marketing at any time by contacting partnerships@ivrifydata.io.

Demo operational data is reset periodically, including on a scheduled basis, and must not be treated as permanent or client production data.

3.6 Data processed through compliance and verification integrations

Origin Secure may connect to third-party services that support compliance, risk assessment, and regulatory workflows. Depending on the services enabled for a client organisation, this may involve sharing limited necessary data, such as geolocation boundaries, plot identifiers, batch references, and related supply-chain metadata, with providers such as:

  • Environmental and deforestation-risk assessment services (for example, forest-cover and land-use screening tools);
  • Verification and due-diligence partners;
  • Government, industry, or regulatory platforms (for example, EU traceability systems, national agriculture or export compliance systems, or similar authorities); and
  • Other specialist integrations introduced as the platform expands.

We only share data with these providers where required to deliver the relevant feature, under appropriate contractual safeguards, and in line with the client organisation's instructions where we act as processor.

We may update the categories of integrations over time. Material changes to how we use personal data will be reflected in updates to this Policy.

4. How we use personal data

We use personal data to:

  • provide, maintain, and secure Origin Secure and our website;
  • authenticate authorised users and manage access;
  • synchronise data entered in the field or dashboard;
  • send operational notifications where enabled;
  • support traceability, verification, audit, and compliance workflows;
  • run deforestation-risk and related compliance checks where enabled;
  • operate the demo experience and respond to demo enquiries;
  • respond to sales and support requests;
  • analyse website and product usage in aggregated or pseudonymous form where appropriate;
  • comply with law and protect against misuse; and
  • improve our services.

Legal bases (Kenya Data Protection Act, 2019): consent; performance of a contract; legitimate interests (such as security and service improvement); and legal obligation. Where we process data on behalf of a client organisation, that organisation determines the primary legal basis for operational processing.

5. How we share personal data

We share personal data only where necessary:

Recipient typeWhy
Client organisationsOperational data is handled for the organisation that authorised your use of Origin Secure
Infrastructure and hosting providersSecure hosting, storage, backups, and operations
Authentication and security providersUser login, access control, and fraud prevention
Notification servicesMobile alerts where you have opted in
Mapping and location-display servicesShowing maps and location context in the app
Compliance and verification partnersRisk assessment, due diligence, and regulatory submissions where enabled (see Section 3.6)
Website and business toolsAnalytics, scheduling, and communications for our website and sales process
Professional advisersLegal, audit, and compliance support
Regulators and authoritiesWhere required by law or valid legal process

Service providers may only use personal data to perform services for us or our clients and must protect it appropriately.

We do not sell personal data.

6. International transfers

Personal data may be processed or stored outside Kenya, including in countries where our service providers operate. Where required, we use appropriate safeguards under applicable law, including contractual protections with processors.

7. Data retention

We keep personal data only as long as needed for the purposes described:

Data categoryRetention approach
Website and sales enquiriesTypically up to 24 months after last contact, unless a longer period is needed for legal or business purposes
Demo session analyticsTypically up to 12 months
Demo contact requests (“Get Origin Secure…”)Typically up to 24 months, or until the enquiry is resolved and any applicable follow-up period ends
Demo operational contentReset periodically; not retained as production data
Client operational dataRetained according to the client organisation's instructions, contract, and applicable law
Security and access logsTypically up to 12 months
Verification access logsTypically up to 24 months

When data is no longer needed, we delete or anonymise it in accordance with our retention procedures and contractual obligations.

8. Security

We apply appropriate technical and organisational measures, including access controls, encryption in transit, secure storage practices, and monitoring. No method of transmission or storage is completely secure; please protect your account credentials and device.

9. Your rights

Under the Kenya Data Protection Act, 2019, you may have the right to:

  • access your personal data;
  • request correction of inaccurate data;
  • request deletion in certain circumstances;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with the Office of the Data Protection Commissioner (ODPC), Kenya.

How to exercise your rights

  • Website, demo contact, privacy questions, or marketing opt-out: partnerships@ivrifydata.io
  • Data held for a client organisation: contact that organisation first; we will assist them where we act as processor
  • Account deactivation: contact your organisation's administrator, or email partnerships@ivrifydata.io with your name, organisation, and registered contact details

We may need to verify your identity. Some rights may be limited by law or by our role as processor on a client's instructions.

If you are in the European Economic Area and personal data is processed in connection with EU-related compliance workflows (such as product verification or due-diligence features), you may also have rights under applicable data protection law. Contact partnerships@ivrifydata.io.

10. Children

Origin Secure is a business platform for authorised users. It is not directed at children under 18, and we do not knowingly collect personal data from children. If you believe a child has provided personal data, please contact partnerships@ivrifydata.io.

11. Third-party links and services

Our website and apps may link to third-party websites or services. Their privacy practices are governed by their own policies. Compliance and verification integrations are operated by third parties under their own terms and privacy notices, in addition to the protections described in this Policy.

12. Cookies and website analytics

This section applies to www.ivrifydata.io only.

We use cookies and similar technologies to operate the website, remember preferences, and understand how visitors use our site.

Essential cookies
Required for the website to function (for example, session and security cookies).

Analytics cookies
Help us understand website traffic and usage, including through services such as Google Analytics and Apollo.io.

Functional cookies
Support features such as scheduling (for example, Calendly) and preference storage.

Marketing and conversion cookies
Where enabled, may include Google Ads conversion tracking to measure the effectiveness of our marketing campaigns.

Third-party cookies
Some cookies are set by third-party services on our pages. Their use is governed by those providers' policies.

When you first visit our website, you can accept or reject non-essential cookies through our cookie banner. You can also manage cookies in your browser settings; disabling some cookies may affect website functionality.

Third parties we use on the website:

We do not use the Origin Secure mobile app for cross-app advertising tracking.

13. Mobile app store disclosures

Origin Secure is distributed through the Apple App Store and Google Play. Store operators may collect data under their own policies. Our in-store privacy disclosures reflect the categories of data described in this Policy. You can manage app permissions in your device settings.

Privacy Policy URL: https://www.ivrifydata.io/privacy

14. Changes to this Policy

We may update this Policy to reflect legal, technical, or business changes, including new integrations or features. Updates will be posted at https://www.ivrifydata.io/privacy with a revised “Last updated” date. Where required, we will provide additional notice.

15. Contact and complaints

Privacy enquiries, demo contact, and rights requests
Email: partnerships@ivrifydata.io
Address: The Enclave Apartments, Lower Kabete Road, Nairobi, Kenya (00100)

ODPC (Kenya)
https://www.odpc.go.ke