Legal

Legal Terms & Policies

Effective Date: January 2026
Last Updated: July 2026
Governing Law: Republic of Kenya

1. Introduction & Legal Status

This Legal Terms document ("Legal Terms") forms an integral and binding part of Sibasi Ltd's contractual framework and applies to all customers, users, partners, and counterparties engaging with Sibasi Ltd ("Sibasi", "we", "us", or "our").

These Legal Terms supplement and form an extension of:

In the event of conflict, Kenyan law prevails, and the hierarchy of documents shall be:

  1. Signed contract (if any)
  2. These Legal Terms
  3. Terms of Use
  4. Privacy Policy

2. Corporate Structure & Affiliates

Sibasi Ltd is a company incorporated in the Republic of Kenya and may operate through:

  • Regional offices
  • Affiliated or subsidiary entities
  • Authorized partners and distributors

References to "Sibasi" include Sibasi Ltd and its affiliates acting within the scope of their authorization.

Nothing herein creates a partnership, agency, or joint venture unless expressly agreed in writing.

Part A — Data Processing Agreement (DPA)

3. Data Protection Roles

  • Client is the Data Controller
  • Sibasi acts as Data Processor when processing personal data on documented Client instructions

Sibasi does not determine the purpose or means of processing Client data except as required to deliver agreed services.

4. Client Instructions & Responsibility

Client warrants that:

  • It has lawful authority to process all data
  • Data subjects have been informed and consent obtained where required
  • Instructions provided to Sibasi are lawful

Sibasi is not responsible for unlawful instructions or Client misuse of systems.

5. Data Security Measures

Sibasi implements commercially reasonable administrative, technical, and organizational safeguards, including:

  • Encryption in transit and at rest (where feasible)
  • Role-based access control
  • Logical environment segregation
  • Monitoring and logging
  • Backup and disaster recovery

No system is perfectly secure; absolute security is not guaranteed.

6. Sub-Processors

Sibasi may engage sub-processors to deliver services.

All sub-processors are contractually bound to confidentiality and data protection obligations.

The current sub-processor list is set out in Part E, which also identifies third parties that act as independent controllers rather than sub-processors, and integrations connected only at the Client's election.

Part E, section 16.6 sets out how we notify Client of changes to the list and the Client's right to object.

7. Data Breach Notification

Sibasi will notify Client of a confirmed personal data breach without undue delay after becoming aware, where legally required.

Client remains responsible for regulatory notifications unless otherwise agreed.

8. Data Return & Deletion

Upon termination, Sibasi will delete or return Client data in accordance with contractual terms, subject to legal retention requirements.

Part B — Service Level Agreement (SLA)

9. Service Availability

Unless expressly agreed in writing:

  • Services are provided on an "as-available" basis
  • No guaranteed uptime is provided

10. Excluded Events

Sibasi is not liable for service interruptions caused by:

  • Cloud provider outages (Azure, AWS, Google Cloud)
  • Internet or telecommunications failures
  • Force majeure events
  • Client misconfiguration or misuse
  • Third-party services or integrations

11. Remedies

Where an SLA is expressly agreed:

  • Client's sole remedy is service credits
  • No refunds or damages apply

Part C — Acceptable Use Policy (AUP)

12. Prohibited Use

Clients and users must not:

  • Use services unlawfully
  • Upload malicious code
  • Attempt unauthorized access
  • Abuse system resources
  • Infringe IP or privacy rights

13. Reverse Engineering & IP Protection

Clients shall not, directly or indirectly:

  • Reverse engineer, decompile, or disassemble systems
  • Inspect source code, algorithms, or internal logic
  • Conduct benchmarking without written consent
  • Develop competing products using Sibasi systems

Violation constitutes material breach.

Part D — Security & Trust Statement

14. Security Posture

Sibasi adopts a defense-in-depth approach:

  • Secure development lifecycle practices
  • Access controls and audit logs
  • Cloud security best practices
  • Incident response readiness

Security measures vary by service model and contract scope.

15. Staff & Governance

  • Confidentiality agreements for all staff
  • Security awareness training
  • Segregation of duties
  • Ethical and operational governance frameworks

Part E — Sub-Processor Disclosure List

16. Sub-Processors and Third-Party Recipients

16.1 How to read this list

Not every third party involved in delivering our services holds the same legal role. This list separates them, because the obligations differ:

  • Sub-processors (16.2) — engaged by Sibasi to process Client personal data on our documented instructions. Each is bound by a written data processing agreement imposing obligations no less protective than those in Part B.
  • Onward sub-processors (16.3) — parties engaged by our own sub-processors. We rely on the lists they publish rather than reproducing them here, so that the information you see is always current.
  • Independent controllers (16.4) — analytics, advertising and abuse-prevention providers that determine their own purposes and means. They are not sub-processors and act under their own privacy terms.
  • Client-enabled integrations (16.5) — connected only where the Client chooses to enable them. The Client authorises and controls each such transfer.

Which entries apply to a given Client depends on the modules that Client has subscribed to and the integrations it has enabled. Not every sub-processor processes every Client's data.

16.2 Sub-processors engaged by Sibasi

Sub-processorService providedData categories processedLocation & transfer safeguard
Infrastructure, hosting and storage
Microsoft Ireland Operations Limited / Microsoft Corporation (Microsoft Azure)Virtual machine hosting, Azure Blob StorageAll hosted application data; uploaded documents and files; encrypted database backups; system and audit logsIreland / EU contracting entity. Microsoft Products and Services Data Protection Addendum; Standard Contractual Clauses
Cloudflare, Inc.Authoritative DNS, CDN, web application firewall, TLS termination, bot managementIP address, request metadata and all traffic in transit to our origin serversUnited States. Cloudflare Data Processing Addendum; Standard Contractual Clauses
Internet Security Research Group (Let's Encrypt)TLS certificate issuance and renewalDomain names only. No personal dataUnited States
GitHub, Inc. (Microsoft)Source control and release artefact managementSibasi developer identities and release metadata. No Client production dataUnited States. Microsoft Data Protection Addendum
Email delivery
Amazon Web Services, Inc. (Amazon SES) — platform defaultTransactional email deliveryRecipient name and email address; message subject and body, which may contain invitations, one-time passcodes, approval requests and document notificationsUnited States / configured AWS region. AWS Data Processing Addendum; Standard Contractual Clauses
Resend, Inc.Transactional email delivery (alternative provider)As aboveUnited States. Standard Contractual Clauses
Intuit Inc. (Mailchimp Transactional)Transactional email delivery (alternative provider)As aboveUnited States. Standard Contractual Clauses
Microsoft Corporation (Exchange Online / Microsoft 365 SMTP)Transactional email delivery (alternative provider)As aboveMicrosoft Data Protection Addendum; EU Data Boundary where applicable
Twilio Inc. (SendGrid)Email delivery for enquiry forms on sibasi.comName, email address, telephone number and message content submitted through website formsUnited States. Standard Contractual Clauses
MailerLite LimitedNewsletter and marketing email deliverySubscriber name and email addressIreland / European Union
Messaging and notifications
UjumbeSMS — platform defaultSMS gatewayMobile telephone number and message body, including one-time passcodes and operational alertsKenya
AdvantaSMSSMS gateway (alternative)As aboveKenya
Africa's Talking LimitedSMS gateway (alternative)As aboveKenya
Google LLC (Firebase Cloud Messaging)Mobile and web push notification deliveryDevice push token and notification payloadUnited States. Google Cloud Data Processing Addendum; Standard Contractual Clauses
Meta Platforms, Inc. (WhatsApp Business Cloud API)WhatsApp notification delivery, where enabledMobile telephone number and message bodyUnited States / Ireland. Meta Data Processing Terms; Standard Contractual Clauses
Artificial intelligence and machine learning
Microsoft Corporation (Azure OpenAI Service)Large language model inferenceContent submitted to AI features, which may include document text, board papers, memoranda and meeting contentAzure region as configured. Microsoft Data Protection Addendum. Input is not used to train foundation models
Microsoft Corporation (Azure AI Speech)Speech-to-text transcription for meeting minutesMeeting audio recordings, transcripts and speaker attributionAzure region as configured. Microsoft Data Protection Addendum
OpenAI, L.L.C.Text embedding generation for semantic searchText submitted for indexingUnited States. OpenAI Data Processing Addendum. API data is not used to train models
Google LLC (Gemini API)Automated classification of published tender noticesPublicly published tender text, which may include named procurement contactsUnited States. Google Cloud Data Processing Addendum; Standard Contractual Clauses
Payments, abuse prevention and diagnostics
Stripe, Inc. / Stripe Payments Europe, LimitedCard payment processing and subscription billingCardholder name, email address, billing address and payment token. Sibasi does not store full card numbersUnited States / Ireland. PCI DSS Level 1; Standard Contractual Clauses
Cloudflare, Inc. (Turnstile)Automated abuse prevention on public formsIP address and browser characteristicsUnited States. Cloudflare Data Processing Addendum
Google LLC (Firebase Crashlytics)Crash and stability reporting in our mobile applicationsCrash stack traces, device model, operating system version and installation identifierUnited States. Google Cloud Data Processing Addendum; Standard Contractual Clauses

Where a Client supplies its own credentials for email, SMS or electronic signature delivery, messages are sent through that Client's chosen provider instead of ours. That provider is engaged by the Client, not by Sibasi, and does not appear on this list.

16.3 Onward sub-processors

Several of the sub-processors above engage their own sub-processors. Each publishes and maintains a current list, and each remains contractually responsible to us for its sub-processors' compliance. We link to those lists rather than copying them, so that what you read here does not fall out of date:

16.4 Independent controllers

The following providers determine their own purposes and means of processing. They are not sub-processors, and they process under their own privacy terms rather than on our instructions. Consent requirements for these technologies, and the controls available to you, are described in section 9 of our Privacy Policy.

ProviderTechnologyPurpose and notes
Microsoft CorporationMicrosoft ClarityProduct analytics and session replay. Microsoft acts as an independent data controller. Data is stored in Microsoft Azure and retained for up to 30 days. Microsoft states that Clarity does not sell this data. Explicit consent is required before Clarity cookies are set for visitors in the European Economic Area, the United Kingdom and Switzerland
Google LLCGoogle Analytics 4, Google Tag ManagerAggregate usage measurement and tag deployment. Collects IP address, device and browser characteristics, and pages visited
Google LLCGoogle Ads conversion tracking and remarketingAdvertising measurement and audience building
Google LLCreCAPTCHAAutomated abuse prevention on public forms. Collects IP address and interaction signals
Google LLCYouTube embedded videoVideo playback on our websites and in-product news items
Adobe Inc.Adobe Document Cloud View SDKIn-browser PDF rendering. Receives a viewer profile when a document is opened
Content delivery networksGoogle Fonts, Fontshare, CDN Fonts, cdnjs (Cloudflare), unpkg, jsDelivr, Microsoft Office and authentication script hostsDelivery of fonts, stylesheets and scripts. Each necessarily receives the visitor's IP address and user agent when an asset is requested
OpenStreetMap FoundationMap tile deliveryRendering of map views in data collection features

16.5 Client-enabled integrations

These are connected only where a Client chooses to enable them, using that Client's own account with the provider. The Client authorises the transfer and remains responsible for its relationship with the provider.

ProviderIntegrationData shared when enabled
Microsoft CorporationMicrosoft Entra ID single sign-on; Microsoft Graph for Teams, Outlook, SharePoint and OneDrive; Power BI; Power Automate; Dynamics 365 Business CentralUser identity and directory attributes; calendar and meeting data; documents synchronised to or from the Client's tenant; payroll and general ledger records where the finance connector is enabled
Google LLCGoogle sign-in; Google Calendar and Google MeetUser identity; calendar events and meeting links
Apple Inc.Sign in with AppleUser identity, which may be a relay email address
Zoom Communications, Inc.Meeting scheduling and cloud recordingParticipant identity, meeting recordings and transcripts
Docusign, Inc.Electronic signatureSignatory name and email address, the document to be signed, and the signature audit trail
Adobe Inc.Adobe Acrobat Sign electronic signatureAs above
Factorial HR, S.L.Human resources data synchronisationEmployee records, which may include compensation data
Safaricom PLCM-Pesa collections and disbursementsPayer or payee mobile number, name and transaction amount

Where a Client uses our tax compliance features, invoice data is transmitted to the Kenya Revenue Authority through the eTIMS system. That is a statutory transmission to a public authority, not a sub-processing arrangement.

16.6 Changes to this list

Sibasi maintains this list as the current record of its sub-processors. Where we intend to add or replace a sub-processor, we will update this page before the change takes effect and, where the Client has subscribed to notifications at [email protected], give the Client reasonable prior notice. The Client may object on reasonable data protection grounds, in which case the parties will discuss the objection in good faith; if it cannot be resolved, the Client may terminate the affected service without penalty.

We may engage a replacement sub-processor without prior notice where it is necessary to maintain the security or continuity of the service, and will record the change here promptly afterwards.

Part F — Incident Response & Breach Policy

17. Incident Response

Sibasi maintains internal procedures to:

  • Detect and contain incidents
  • Assess impact
  • Mitigate harm
  • Prevent recurrence

18. Client Cooperation

Client agrees to cooperate during investigations and mitigation efforts.

Part G — Intellectual Property & Ownership

19. Sibasi Ownership

All platforms, software, methodologies, frameworks, tools, configurations, documentation, and derivatives remain exclusive intellectual property of Sibasi, unless expressly agreed otherwise.

Clients receive a limited, non-exclusive, non-transferable license for internal use only.

19A. Trademarks

"Sibasi", the Sibasi logo, eBoard™, Monival™, EBM Suite™, and Smart Memo are trademarks or trade names of Sibasi Ltd. Nothing in these terms grants any right to use Sibasi's marks, and they may not be used — including in domain names, product names, or advertising — without Sibasi's prior written consent. Microsoft, Dynamics 365, SharePoint, Azure, and related marks are trademarks of Microsoft Corporation; other marks belong to their respective owners.

20. Client Data Ownership

Clients retain ownership of their data and grant Sibasi a limited license to process such data solely to provide services.

Part H — Third-Party & Partner Services

21. Partner Ecosystem

Sibasi solutions may integrate with or rely on third-party platforms and partners, including cloud providers, distributors, and software partners.

Such partners operate under their own agreements.

Sibasi:

  • Does not control third-party platforms
  • Is not liable for their actions, outages, or compliance
  • Disclaims warranties relating to partner services

Part I — Limitation of Liability & Risk Allocation

22. Limitation of Liability

To the maximum extent permitted by law:

  • No liability for indirect or consequential damages
  • No liability for data loss (unless expressly agreed)
  • Aggregate liability capped at fees paid in preceding 6 (six) months

23. Indemnity

Client indemnifies Sibasi against claims arising from:

  • Client data
  • Client misuse
  • Third-party integrations enabled by Client
  • Breach of these Legal Terms

Part J — Governing Law & Final Provisions

24. Governing Law

These Legal Terms are governed exclusively by the laws of the Republic of Kenya.

25. Severability

Invalid provisions do not affect enforceability of remaining terms.

26. Contact

Legal Inquiries:
[email protected]

Postal Address:
Sibasi Ltd
P.O. Box 37602-00100
Nairobi, Kenya