NEXORA ICT Consulting
Back to Home

GDPR Compliance Statement

Last Updated: March 2024

1. Introduction

Nexora ICT Consulting is committed to complying with the General Data Protection Regulation (GDPR) (EU) 2016/679. This statement outlines our commitment to data protection and privacy rights for all individuals.

2. Data Protection Principles

We adhere to the following GDPR principles:

  • Lawfulness, fairness, and transparency: We process personal data lawfully, fairly, and transparently.
  • Purpose limitation: We collect data for specified, explicit, and legitimate purposes.
  • Data minimization: We only collect data that is adequate, relevant, and limited to what is necessary.
  • Accuracy: We keep personal data accurate and up to date.
  • Storage limitation: We retain personal data only as long as necessary.
  • Integrity and confidentiality: We process data securely to ensure protection against unauthorized or unlawful processing.

3. Data Subject Rights

Under GDPR, you have the following rights:

3.1 Right to Access

You have the right to request copies of your personal data.

3.2 Right to Rectification

You have the right to request correction of inaccurate personal data.

3.3 Right to Erasure

You have the right to request deletion of your personal data under certain conditions.

3.4 Right to Restrict Processing

You have the right to request restriction of processing your personal data.

3.5 Right to Data Portability

You have the right to request transfer of your data to another organization.

3.6 Right to Object

You have the right to object to the processing of your personal data.

4. Data Protection Measures

We implement appropriate technical and organizational measures including:

  • Encryption of sensitive data
  • Regular security assessments
  • Access controls and authentication
  • Data breach response procedures

5. Data Processing Agreements

We have Data Processing Agreements (DPAs) with all third-party processors to ensure GDPR compliance throughout the data processing chain.

6. Data Breach Notification

In the event of a data breach, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.

7. International Data Transfers

When transferring data outside the EEA, we ensure adequate safeguards are in place, such as Standard Contractual Clauses.

8. Data Protection Officer

Our Data Protection Officer (DPO) can be contacted at:

Data Protection Officer
Nexora ICT Consulting
Lion Place, Westlands
Nairobi, Kenya
Email: dpo@nexora-ict.com
Phone: +254(0)795576429

9. Supervisory Authority

You have the right to lodge a complaint with the relevant data protection authority.

10. Contact Us

For GDPR-related inquiries:

Nexora ICT Consulting
Lion Place, Westlands
Nairobi, Kenya
Email: gdpr@nexora-ict.com
Phone: +254(0)795576429

© 2025 Nexora ICT Consulting. All rights reserved.