Legal

Legal Terms & Policies

Effective Date: January 2026
Last Updated: July 2026
Governing Law: Republic of Kenya

1. Introduction & Legal Status

This Legal Terms document ("Legal Terms") forms an integral and binding part of Sibasi Ltd's contractual framework and applies to all customers, users, partners, and counterparties engaging with Sibasi Ltd ("Sibasi", "we", "us", or "our").

These Legal Terms supplement and form an extension of:

In the event of conflict, Kenyan law prevails, and the hierarchy of documents shall be:

  1. Signed contract (if any)
  2. These Legal Terms
  3. Terms of Use
  4. Privacy Policy

2. Corporate Structure & Affiliates

Sibasi Ltd is a company incorporated in the Republic of Kenya and may operate through:

  • Regional offices
  • Affiliated or subsidiary entities
  • Authorized partners and distributors

References to "Sibasi" include Sibasi Ltd and its affiliates acting within the scope of their authorization.

Nothing herein creates a partnership, agency, or joint venture unless expressly agreed in writing.

Part A — Data Processing Agreement (DPA)

3. Data Protection Roles

  • Client is the Data Controller
  • Sibasi acts as Data Processor when processing personal data on documented Client instructions

Sibasi does not determine the purpose or means of processing Client data except as required to deliver agreed services.

4. Client Instructions & Responsibility

Client warrants that:

  • It has lawful authority to process all data
  • Data subjects have been informed and consent obtained where required
  • Instructions provided to Sibasi are lawful

Sibasi is not responsible for unlawful instructions or Client misuse of systems.

5. Data Security Measures

Sibasi implements commercially reasonable administrative, technical, and organizational safeguards, including:

  • Encryption in transit and at rest (where feasible)
  • Role-based access control
  • Logical environment segregation
  • Monitoring and logging
  • Backup and disaster recovery

No system is perfectly secure; absolute security is not guaranteed.

6. Sub-Processors

Sibasi may engage sub-processors to deliver services.

All sub-processors are contractually bound to confidentiality and data protection obligations.

A current sub-processor list is provided in Part E.

7. Data Breach Notification

Sibasi will notify Client of a confirmed personal data breach without undue delay after becoming aware, where legally required.

Client remains responsible for regulatory notifications unless otherwise agreed.

8. Data Return & Deletion

Upon termination, Sibasi will delete or return Client data in accordance with contractual terms, subject to legal retention requirements.

Part B — Service Level Agreement (SLA)

9. Service Availability

Unless expressly agreed in writing:

  • Services are provided on an "as-available" basis
  • No guaranteed uptime is provided

10. Excluded Events

Sibasi is not liable for service interruptions caused by:

  • Cloud provider outages (Azure, AWS, Google Cloud)
  • Internet or telecommunications failures
  • Force majeure events
  • Client misconfiguration or misuse
  • Third-party services or integrations

11. Remedies

Where an SLA is expressly agreed:

  • Client's sole remedy is service credits
  • No refunds or damages apply

Part C — Acceptable Use Policy (AUP)

12. Prohibited Use

Clients and users must not:

  • Use services unlawfully
  • Upload malicious code
  • Attempt unauthorized access
  • Abuse system resources
  • Infringe IP or privacy rights

13. Reverse Engineering & IP Protection

Clients shall not, directly or indirectly:

  • Reverse engineer, decompile, or disassemble systems
  • Inspect source code, algorithms, or internal logic
  • Conduct benchmarking without written consent
  • Develop competing products using Sibasi systems

Violation constitutes material breach.

Part D — Security & Trust Statement

14. Security Posture

Sibasi adopts a defense-in-depth approach:

  • Secure development lifecycle practices
  • Access controls and audit logs
  • Cloud security best practices
  • Incident response readiness

Security measures vary by service model and contract scope.

15. Staff & Governance

  • Confidentiality agreements for all staff
  • Security awareness training
  • Segregation of duties
  • Ethical and operational governance frameworks

Part E — Sub-Processor Disclosure List

16. Core Sub-Processors

Category Purpose
Cloud InfrastructureHosting & storage — Microsoft Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP)
Identity & AccessAuthentication — Microsoft Entra ID
Monitoring & AnalyticsPerformance & security; consent-based website analytics — Google Analytics, Microsoft Clarity
Support & CommunicationsService delivery; newsletter delivery — MailerLite

Sibasi may update this list as its services evolve and will provide notice of sub-processor changes where required by law or by contract; enterprise clients may request the current list at any time via [email protected].

Part F — Incident Response & Breach Policy

17. Incident Response

Sibasi maintains internal procedures to:

  • Detect and contain incidents
  • Assess impact
  • Mitigate harm
  • Prevent recurrence

18. Client Cooperation

Client agrees to cooperate during investigations and mitigation efforts.

Part G — Intellectual Property & Ownership

19. Sibasi Ownership

All platforms, software, methodologies, frameworks, tools, configurations, documentation, and derivatives remain exclusive intellectual property of Sibasi, unless expressly agreed otherwise.

Clients receive a limited, non-exclusive, non-transferable license for internal use only.

19A. Trademarks

"Sibasi", the Sibasi logo, eBoard™, Monival™, EBM Suite™, and Smart Memo are trademarks or trade names of Sibasi Ltd. Nothing in these terms grants any right to use Sibasi's marks, and they may not be used — including in domain names, product names, or advertising — without Sibasi's prior written consent. Microsoft, Dynamics 365, SharePoint, Azure, and related marks are trademarks of Microsoft Corporation; other marks belong to their respective owners.

20. Client Data Ownership

Clients retain ownership of their data and grant Sibasi a limited license to process such data solely to provide services.

Part H — Third-Party & Partner Services

21. Partner Ecosystem

Sibasi solutions may integrate with or rely on third-party platforms and partners, including cloud providers, distributors, and software partners.

Such partners operate under their own agreements.

Sibasi:

  • Does not control third-party platforms
  • Is not liable for their actions, outages, or compliance
  • Disclaims warranties relating to partner services

Part I — Limitation of Liability & Risk Allocation

22. Limitation of Liability

To the maximum extent permitted by law:

  • No liability for indirect or consequential damages
  • No liability for data loss (unless expressly agreed)
  • Aggregate liability capped at fees paid in preceding 6 (six) months

23. Indemnity

Client indemnifies Sibasi against claims arising from:

  • Client data
  • Client misuse
  • Third-party integrations enabled by Client
  • Breach of these Legal Terms

Part J — Governing Law & Final Provisions

24. Governing Law

These Legal Terms are governed exclusively by the laws of the Republic of Kenya.

25. Severability

Invalid provisions do not affect enforceability of remaining terms.

26. Contact

Legal Inquiries:
[email protected]

Postal Address:
Sibasi Ltd
P.O. Box 37602-00100
Nairobi, Kenya