How we collect, use, and protect your personal data
This Privacy Policy describes how BioTrack Tech Limited ("BioTrack", "we", "us", or "our") collects, uses, stores, and protects personal information when you use BioTrack Payroll ("the Service"). We are committed to protecting your privacy and complying with the Kenya Data Protection Act, 2019 and its regulations.
BioTrack Tech Limited is a company registered in Kenya. We operate BioTrack Payroll, a web-based payroll management system for Kenyan businesses.
When you register an organisation on BioTrack Payroll, we collect:
To process payroll, we collect and store employee data that you input into the system:
We automatically collect certain technical data when you use the Service, including IP address, browser type, pages visited, and timestamps. This data is used for security monitoring and improving the Service.
We use the information we collect to:
We process personal data on the following legal bases under the Kenya Data Protection Act, 2019:
All data is stored on servers protected with 256-bit SSL encryption. We implement industry-standard technical and organisational measures to protect your data against unauthorised access, loss, or disclosure, including:
We do not sell your personal data to third parties. We may share data with:
We retain payroll records for a minimum of 7 years from the end of the tax year, in line with KRA requirements under the Income Tax Act. You may request deletion of non-statutory data at any time by contacting us.
Under the Kenya Data Protection Act, 2019, you have the right to:
To exercise these rights, contact us at payroll@biotrack.co.ke.
BioTrack Payroll uses session cookies necessary for authentication and security (CSRF protection). We do not use third-party advertising or tracking cookies. Google Fonts may set performance-related cookies. You can disable cookies in your browser settings, but this will affect your ability to log in.
BioTrack Payroll is a business service and is not intended for use by persons under 18 years of age. We do not knowingly collect personal data from children.
We may update this Privacy Policy to reflect changes in our practices or Kenyan law. We will notify registered account holders of material changes by email. The effective date at the top of this page will always reflect the most recent update.
For privacy-related inquiries, data access requests, or complaints: