Effective date: 18 July 2026. Raygun Security & Investigations Limited ("Raygun", "we", "us", or "our") is committed to protecting your privacy. This policy explains how we handle personal data in accordance with the Data Protection Act, 2019 (Kenya), the Data Protection (General) Regulations, 2021, and other applicable Kenyan law. It applies to this website, to the services we provide to our clients, and to the field and monitoring operations we carry out under client instruction.
1. Data controller and contact
Raygun Security & Investigations Limited is the data controller responsible for the personal data described in this policy. Our registered office is 4th Floor, Highway Mall, Nairobi, Kenya. You can reach our data protection contact at management@raygun.co.ke or +254 730 599 999.
In some engagements we act as a data processor on behalf of a client — for example when we monitor a financier’s asset portfolio or investigate a matter on their instruction. In those cases the client is the data controller and their own privacy notice governs the purposes of processing; we process the data only on their documented instructions.
2. Personal data we collect
- Contact & enquiry data you submit through our forms — name, email address, phone number, company or organisation, industry, and the content of your message.
- Identification data used to verify individuals in the course of an engagement — such as name, national ID or passport number, date of birth, and photograph.
- Client & engagement data provided to us to deliver services, which may include information about assets, accounts, agreements, incidents, and — where lawfully instructed — data relevant to investigations.
- Location & telematics data generated by GPS devices fitted to tracked assets, including position, movement, trip history, and tamper or geofence alerts.
- Operational & surveillance data captured during field work — incident photographs and video, body-worn or vehicle camera footage, CCTV at our premises, field notes, and recovery or handover records.
- Technical data collected automatically, such as IP address, device and browser type, and pages visited, together with limited cookie data (see section 10).
Where we handle sensitive personal data in the course of an engagement, we do so only where permitted by law and under a lawful instruction from the relevant client.
3. How we collect data
- Directly from you — when you complete a form on this website, email or call us, or interact with our staff.
- Automatically — through our website and through GPS and monitoring equipment operating under a client engagement.
- From our clients — financiers, fleet operators, and corporate clients who instruct us and supply the data needed to carry out that instruction.
- From third parties and public sources — including public registries, lawfully accessible records, auctioneers, and law-enforcement or regulatory bodies, where this is necessary and permitted by law.
4. Why we use your data and our lawful basis
- To respond to your enquiries and provide requested information — on the basis of your consent or steps taken at your request.
- To deliver, manage, and document our services — on the basis of performance of a contract and our legitimate business interests.
- To monitor, trace, recover, and protect assets under lawful client instruction — on the basis of contract, legitimate interests, and, where applicable, the client’s own lawful basis.
- To prevent, detect, and investigate fraud and other unlawful acts, and to support disciplinary, civil, or criminal proceedings.
- To meet legal, regulatory, and reporting obligations, including cooperation with lawful authorities and our PSRA and Communications Authority obligations.
- To secure, maintain, and improve our website — on the basis of our legitimate interests.
We do not sell your personal data, and we do not use it for automated advertising profiling.
5. Our data-protection principles
In line with section 25 of the Data Protection Act, 2019, we commit to processing personal data:
- lawfully, fairly, and in a transparent manner in relation to the data subject;
- for explicit, specified, and legitimate purposes, and not in a way incompatible with those purposes;
- adequately, relevantly, and limited to what is necessary — we collect no more than the engagement requires;
- accurately and, where necessary, kept up to date;
- kept no longer than is necessary for the purposes for which it was collected;
- with appropriate security, integrity, and confidentiality safeguards; and
- accountably — we maintain records of our processing and can demonstrate our compliance.
6. How we share data
We share personal data only where there is a lawful reason to do so, and only to the extent necessary:
- Our clients — where you have engaged with us on their behalf, or where we act on their instruction.
- Service providers who process data on our documented instructions, such as our hosting, email, and GPS platform providers. They are bound by contract to protect the data and to use it only for the purposes we specify.
- Courts, regulators, auctioneers, and law-enforcement agencies — where required by law or under a lawful engagement.
- Professional advisers — such as lawyers and auditors, under a duty of confidentiality.
We do not disclose investigation material to third parties beyond the instructing client and lawful authorities, except where the law requires it.
7. International transfers
Some of our providers may process data outside Kenya. Where personal data is transferred outside Kenya, we do so only where the conditions in sections 48 and 49 of the Data Protection Act, 2019 are met — that is, where we have confirmed appropriate safeguards are in place, or where the transfer is necessary for one of the grounds the Act permits. We remain accountable for data transferred on our behalf.
8. Data retention
We retain personal data only for as long as necessary for the purposes set out above, to meet legal, regulatory, and evidentiary obligations, and to support evidence integrity in active matters. Retention periods vary by data type — enquiry data is held for a short period, while case files and evidence connected to legal proceedings are retained for as long as those proceedings and any appeal or limitation period require. When data is no longer needed we securely delete or anonymise it.
9. Your rights
Under the Data Protection Act, 2019 you have the right to:
- be informed of how your personal data is used;
- access the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request deletion of your data, and to object to or restrict its processing, where the law permits;
- withdraw consent at any time, without affecting processing carried out before withdrawal;
- not be subject to a decision based solely on automated processing that significantly affects you (see section 12); and
- lodge a complaint with the Office of the Data Protection Commissioner (see section 14).
To exercise any of these rights, contact us at management@raygun.co.ke. We may ask you to verify your identity before we act, so that we do not disclose data to the wrong person. We will respond within the timeframes set by the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021, and we do not charge a fee for routine requests.
Some rights may be limited — for example where the data is held under a lawful engagement, forms part of an active investigation or legal proceeding, or where disclosure would prejudice the prevention or detection of crime. Where we rely on such a limitation we will tell you, unless the law prevents us from doing so. If we process your data as a processor on a client’s behalf, we will forward your request to that client and support them in responding.
10. Cookies
Cookies are small text files placed on your device when you visit our website. We use:
- Essential cookies — required for the site to function, including security and basic navigation. These cannot be switched off.
- Analytics cookies — to understand how visitors use the site so we can improve it. These are set only if you accept them.
You can accept or decline non-essential cookies through the consent banner shown on your first visit, and you can change or clear cookies at any time through your browser settings. We do not use advertising or cross-site tracking cookies on this website.
11. Security
We apply organisational and technical safeguards to protect personal data against unauthorised access, alteration, loss, or disclosure, including:
- Access control — access to case files, tracking data, and evidence is restricted to authorised personnel on a need-to-know basis, under role-based permissions.
- Encryption in transit — this website and our platforms are served over HTTPS, and sensitive material is transmitted through protected channels.
- Confidentiality obligations — all staff and contractors are bound by written confidentiality undertakings.
- Evidence protection — chain-of-custody and handling procedures preserve the integrity of investigation material.
- Physical security — controlled access to our premises, storage yards, and recovered assets.
- Training — staff receive data-protection and confidentiality training appropriate to their role.
- Vendor management — providers are assessed before engagement and bound by contractual data-protection terms.
No system is completely secure, but we work to reduce risk and to respond promptly to any incident.
12. Automated decision-making
Our monitoring systems generate automated alerts — for example tamper, geofence, or movement alerts on a tracked asset. These alerts are signals for review, not decisions. No recovery, investigation, or reporting action is taken on the basis of automated processing alone; a member of our team assesses each alert and acts on client instruction and applicable law.
13. Personal data breaches
We maintain procedures to identify, contain, assess, and remediate personal data breaches. Where a breach presents a real risk of harm to a data subject, we will notify the Office of the Data Protection Commissioner without undue delay and, in any case, within 72 hours of becoming aware of it, as required by section 43 of the Data Protection Act, 2019 — and we will communicate with affected individuals where the Act requires. Every incident is investigated for root cause, and our controls are updated to reduce the chance of recurrence.
14. Complaints
If you have a concern about how we handle your personal data, please contact us first at management@raygun.co.ke so we can resolve it. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya at odpc.go.ke.
15. Children
Our services are directed at businesses and are not intended for children. We do not knowingly collect personal data from a child through this website. Where information about a minor arises in the course of an engagement, it is processed only where the law permits and with the safeguards the Data Protection Act, 2019 requires.
16. Changes & contact
We may update this policy from time to time to reflect changes in our practices or in applicable law. The effective date above reflects the latest version, and we will highlight material changes on this page. For any privacy question or request, contact us at management@raygun.co.ke or +254 730 599 999.
17. Key terms
- Personal data — any information relating to an identified or identifiable natural person.
- Processing — any operation performed on personal data, including collection, storage, use, disclosure, and erasure.
- Data controller — the person or entity that determines the purpose and means of processing personal data.
- Data processor — a person or entity that processes personal data on behalf of a controller.
- Data subject — the individual to whom the personal data relates.
- ODPC — the Office of the Data Protection Commissioner, Kenya’s data protection regulator.
This policy is provided for transparency and general information. It should be reviewed by qualified legal counsel before you rely on it for compliance purposes.