Privacy notice
Effective date: 9 October 2026 · Questions: privacy@pryara.com
This notice explains what personal data Pryara collects, why, where it is kept, for how long, and your rights. If anything here is unclear, write to us.
1. Who we are
Pryara (pryara.com) is a trading name of Chess Digital Media Marketing, a sole proprietorship registered in Kenya, based in Nairobi. For the data in sections 2, 3 and 4 we are the data controller. Contact: privacy@pryara.com.
2. Website visitors
Our website sets no cookies and uses no analytics, tracking or advertising tools. It is hosted on GitHub Pages; GitHub may record technical data such as your IP address to deliver and secure the site (see GitHub’s privacy statement).
3. Firms we contact, and people who write to us
- What: firm name, public information about the firm’s work (its website, public contract awards and procurement notices), and the firm’s role addresses (for example info@ or bids@). We do not look up, collect or use named individuals’ details for marketing.
- If you reply: we use your message and work contact details only to answer you and, if you order, to serve you (steps you asked for before a contract). We never use them for further marketing without your consent.
- A person approves every message before it is sent. We never send automated bulk email. Each message tells you how to opt out. If you ask us to stop, we do, and we keep only your email address or company domain on a suppression list so we never contact you again.
4. Clients
- What: business contact details, invoicing and payment records, and the documents and answers you send for your order.
- Why and legal basis: to perform our contract with you, to invoice, and to meet legal obligations (for example tax records). Invoices are recorded with the Kenya Revenue Authority through eTIMS, as Kenyan tax law requires.
- Personal data inside your documents (for example your staff’s names and roles): you are the controller and we are your processor. We process it only on your instructions, under the data-processing terms in our client agreement.
5. How we use AI
We draft with AI tools (the OpenAI API). OpenAI does not train its models on API data by default, and we never use your material to train any model. A person, the founder, reviews every deliverable before it is sent. We make no decision about you by automated means alone.
6. Who helps us, and where
| Provider | What it does | Where |
|---|---|---|
| Contabo | Our private server, where work is stored and processed | France (EU) |
| OpenAI | AI drafting | United States |
| AgentMail | Our order mailbox (client emails and attachments) | United States |
| Google (Workspace, Drive) | Founder email; encrypted backups | Global |
| Paystack | Card and M-Pesa payments | Kenya; its cloud servers (for example Ireland) |
| GitHub | Website hosting | United States |
| Telegram | Short status alerts to the founder (never your documents or personal data) | Global |
| Brave Search | Public web searches for our own research (never your name, your documents or client detail) | United States |
Several providers are outside Kenya. We transfer personal data abroad only to the providers above, under their data-processing terms and appropriate safeguards, after a documented transfer assessment, and we keep a record of each transfer, as the Kenya Data Protection Act 2019 (sections 48–50) and the Data Commissioner’s cross-border transfer guidance require.
7. How long we keep data
- Client documents and deliverables: deleted 30 days after final delivery, or sooner if you ask; longer only if you ask us in writing to keep them for follow-on work.
- Encrypted backups: expire automatically; deleted data is gone from all backups within 7 months.
- OpenAI: may keep API inputs and outputs for up to 30 days to detect abuse, then deletes them, unless the law requires it to keep them longer.
- Invoices and payment records: 5 years, as Kenyan tax law requires.
- Firms we contacted: deleted after 12 months without contact, or at once if you ask (the suppression entry stays).
8. How we protect data
Our server is reachable only through a private encrypted network. Each client’s work runs in its own isolated workspace. Backups are encrypted before they leave the server. Our accounts use two-step verification.
9. Pryara Backup (our use of Google user data)
Pryara Backup is an internal tool. It connects only to
Pryara’s own Google Drive account and accesses only
files it created there (Google’s drive.file permission), to
store and restore Pryara’s own encrypted backups. We do not share, sell
or transfer this data, use it for advertising or use it to train AI
models. Backups follow the expiry in section 7; revoking the tool’s
access ends it at once. Pryara Backup’s use and transfer of information
received from Google APIs adheres to the Google
API Services User Data Policy, including the Limited Use
requirements.
10. Your rights
Under the Kenya Data Protection Act 2019 (and the UK GDPR where it applies) you may ask to be told what we hold about you, get a copy, correct or delete it, restrict or object to its use (including marketing, at any time), and move it. Write to privacy@pryara.com; we reply within the time the law requires. You may complain to the Office of the Data Protection Commissioner (odpc.go.ke) or, in the UK, the Information Commissioner’s Office (ico.org.uk).
11. Children and changes
Our services are for businesses; we do not knowingly collect children’s data. If we change this notice, we update this page and the effective date.