Your privacy is as vast and important as the savannah. We are committed to protecting the personal data of every operator and traveller on our platform with institutional-grade integrity and full compliance with the Data Protection Act, 2019 (Kenya).
This Privacy Policy ("Policy") is issued by Roam Operating Systems Kenya ("Company", "we", "us", or "our") and governs the collection, processing, storage, and disclosure of personal data and business information obtained through your use of the RoamOs platform ("Service").
This Policy applies to all registered Operators, their authorised users, and any guests whose data is processed through the platform on behalf of operators. We are committed to protecting your privacy in accordance with the Data Protection Act, 2019 (Kenya) and any regulations or guidelines issued by the Office of the Data Protection Commissioner (ODPC) of Kenya.
By using the Service, you acknowledge that you have read and understood this Policy and consent to the collection and processing of data as described herein.
We collect the following categories of data in order to provide and continuously improve the Service:
Operator Account Data: Business name, business registration number, physical address, billing address, contact email, phone number, and the identity of authorised users associated with your account.
Guest & Customer Data (processed on your behalf): Names, nationality, passport numbers, date of birth, dietary requirements, travel preferences, emergency contacts, and any other information you upload or input on behalf of your clients. This data is processed by us as a data processor acting under your instructions as the data controller.
Financial & Transactional Data: Subscription payment records, invoice histories, rate configurations, and supplier cost data entered into the platform.
Technical & Usage Data: IP addresses, browser type, device identifiers, session logs, pages visited, features used, and timestamps. This data is collected automatically to ensure platform security and improve user experience.
We process personal data on the following legal bases as recognised under the Data Protection Act, 2019 (Kenya):
Contractual Necessity: Processing is necessary to perform our contractual obligations to you as a subscriber, including account management, service delivery, and billing.
Legal Obligation: Where processing is required to comply with Kenyan law, tax obligations, or lawful requests from competent regulatory authorities including the Kenya Revenue Authority, the Tourism Regulatory Authority, or law enforcement agencies.
Legitimate Interests: For platform security, fraud prevention, service improvement, and aggregated analytical reporting, where such interests are not overridden by your fundamental rights and freedoms.
Consent: Where we seek to use your data for marketing or communications beyond the scope of service delivery, we will obtain your explicit consent, which you may withdraw at any time.
We use data collected through the Service exclusively for the following purposes: (a) creating and managing your Operator account; (b) delivering the features and functionality of the RoamOs platform; (c) processing subscription payments and issuing invoices; (d) providing technical support and responding to queries; (e) ensuring the security and integrity of the platform; (f) complying with applicable Kenyan laws and regulatory requirements; and (g) sending essential operational communications, including system alerts, security notices, and billing reminders.
We do not sell, rent, or trade your personal data or your clients' data to third parties for commercial or marketing purposes.
We may share data with trusted third-party service providers ("sub-processors") solely to enable delivery of the Service. These include cloud infrastructure providers, payment processors, and email delivery services. All sub-processors are contractually required to handle data in a manner consistent with this Policy and applicable law.
We may disclose personal data to government authorities, courts, or law enforcement bodies if required to do so by applicable Kenyan law, including but not limited to the National Intelligence Service Act or a valid court order. In such cases, we will notify you to the extent permitted by law.
All data processed on the platform is stored on secure servers. Where data is transferred outside Kenya, we ensure adequate safeguards are in place as required by the Data Protection Act, 2019.
We retain Operator account data and associated business records for the duration of your active subscription and for a further period of seven (7) years following termination, in compliance with the Kenya Tax Procedures Act and applicable financial regulations.
Guest data uploaded to the platform is retained for as long as your account is active and for a period of up to three (3) years after account closure, unless you request earlier deletion or a longer retention period is required by law.
Technical and usage logs are retained for a rolling period of twelve (12) months.
You may request deletion of your data at any time subject to our legal retention obligations. Deletion requests should be sent to privacy@roamos.com.
We implement industry-standard technical and organisational security measures to protect your data against unauthorised access, loss, alteration, or disclosure. These measures include encryption of data in transit (TLS) and at rest, access controls limited to authorised personnel, multi-factor authentication for platform access, and regular security audits.
While we take all reasonable steps to protect your data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security and encourage Operators to adopt strong internal security practices, including strong passwords and restricted access for their own users.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the ODPC and affected parties in accordance with the Data Protection Act, 2019, within seventy-two (72) hours of becoming aware of the breach where feasible.
Under the Data Protection Act, 2019 (Kenya), you and your clients (as data subjects) have the following rights with respect to personal data we hold:
Right of Access: You may request a copy of the personal data we hold about you. Right to Rectification: You may request correction of inaccurate or incomplete personal data. Right to Erasure: You may request deletion of your personal data, subject to legal retention requirements. Right to Restriction: You may request that we restrict processing of your data in certain circumstances. Right to Data Portability: You may request that we provide your data in a structured, machine-readable format. Right to Object: You may object to processing based on legitimate interests or for direct marketing purposes.
To exercise any of these rights, contact our Data Protection Officer at privacy@roamos.com. We will respond within thirty (30) days. If you are unsatisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya.
The RoamOs platform uses essential session cookies to maintain your authenticated session and to ensure the platform functions correctly. We do not use third-party advertising cookies or cross-site tracking technologies.
Analytical data is collected in aggregate and anonymised form to help us understand platform usage patterns and improve the Service. You may configure your browser to refuse cookies; however, doing so may impair certain platform functionality.
As an Operator, you act as the data controller with respect to the personal data of your guests and clients that you upload or process through the platform. You are independently responsible for ensuring that you have a lawful basis for collecting and sharing such data with us, and that your clients are informed of how their data will be used.
You warrant that all guest data uploaded to the platform has been collected in compliance with applicable law, including the Data Protection Act, 2019, and any relevant sector-specific regulations under the Tourism Act (Cap. 383) of Kenya.
Our role as data processor in relation to guest data is governed by our Data Processing Agreement, which forms part of your subscription agreement with us.
We reserve the right to update this Privacy Policy at any time. Where changes are material, we will notify registered Operators via email and in-platform notification at least fourteen (14) days before the changes take effect.
The date of the most recent revision is indicated at the top of this Policy. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Policy.
Roam Operating Systems Kenya has designated a Data Protection Officer (DPO) as required under the Data Protection Act, 2019. You may contact our DPO for any privacy-related enquiries, data subject rights requests, or complaints:
Data Protection Officer — Roam Operating Systems Kenya, Nairobi, Kenya. Email: privacy@roamos.com.
For general enquiries: support@roamos.com.
© 2026 Roam Operating Systems Kenya. All rights reserved.