Skip to content

Privacy policy

Last updated 6 October 2026

This policy explains what personal data BimaStack collects when you use bimastack.com and the BimaStack platform, why, who we share it with, and the rights you have. Questions: info@bimastack.com.

Who we are

BimaStack provides a software platform that insurance agencies, independent agents, brokerages and insurers use to run their business. For the data in this policy (accounts, organisations’ registrations, website visits, blog comments and demo requests) BimaStack is the data controller.

Organisations on the platform hold their own clients’ data (policies, quotes, claims). For that data the organisation is the controller, and BimaStack processes it on their behalf as a data processor under our agreement with them. Ask the agency, brokerage or insurer you deal with about their privacy policy.

What we collect

  • Your account: name, email address, a hashed password (never the password itself), and the sign-in providers you link (Google, Microsoft, GitHub).
  • Your organisation: its name, registered legal name, licence number, country and web address, and the people who belong to it with their roles.
  • Security records: sign-ins, failed sign-ins, and changes to access, kept in an audit log to protect your account and your organisation.
  • Blog comments: what you write, with your account’s name, shown publicly beside the post.
  • Demo requests: your name, work email, organisation, phone (optional) and message, emailed to our team and not stored on the platform.
  • Website use: with your consent only, analytics and marketing cookies (see our cookie policy).

Why we use it, and our lawful basis

Purpose Lawful basis
Creating and running your account and organisation Performance of our contract with you
Reviewing organisations before they go live Legitimate interest in keeping the platform for genuine, licensed businesses
Security, fraud prevention and audit logs Legitimate interest, and our legal obligations
Emails about your account and your organisation’s application Performance of contract
Replying to demo requests Your consent, given when you send the request
Analytics and advertising measurement Your consent, through the cookie banner, which you can withdraw at any time

Who we share it with

We never sell personal data.

  • Hosting and email providers that run the platform for us, under contracts that require them to protect it.
  • Google, Meta and LinkedIn, only if you accept analytics or marketing cookies.
  • Organisations you join, which see your name, email and role in them.
  • Authorities, when the law requires it.

Transfers outside Kenya

Some providers, including Google, Meta and LinkedIn, process data outside Kenya. Where they do, we rely on appropriate safeguards as sections 48 to 50 of the Data Protection Act require, such as contractual protections, or on your consent.

How long we keep it

  • Account and organisation data: while the account or organisation is open, then as long as the law requires for business and tax records.
  • Security audit records: as long as needed to investigate incidents and meet legal obligations.
  • Blog comments: until you delete them, or your account is closed.
  • Cookie choices: 12 months, then we ask again.

Your rights

Under the Data Protection Act you may ask to be informed of how your data is used, to access it, to have it corrected or deleted, to object to its use, and to have it moved to another service. Write to info@bimastack.com and we will reply within the time the law allows. You may also complain to the Office of the Data Protection Commissioner (odpc.go.ke).

Security

Each organisation’s data is kept apart from every other’s by the database itself. Clients’ identifiers are encrypted, passwords are stored only as hashes, sessions expire, and security-relevant changes are recorded in an audit log.

Changes

If we change this policy we update the date above, and tell account holders about significant changes by email.