Legal

Privacy Policy

Last updated: July 23, 2026

Auto Dev Labs ("we", "us", "our") operates the platform available at autodevlab.org and provides enterprise-grade 2FA infrastructure, B2B communication APIs and cloud integrations to businesses. This Privacy Policy explains what personal data we collect, why we collect it, how we secure it, and the rights you have as a data subject under the Kenya Data Protection Act, 2019 and the regulations issued by the Office of the Data Protection Commissioner (ODPC).

1. Data Controller

Auto Dev Labs is the data controller for information collected through our website, dashboard and APIs. Our registered business address is Mirage Towers, Westlands, Nairobi, Kenya. You can reach our Data Protection Officer at support@autodevlab.org.

2. Information We Collect

  • Account data: business name, contact person, corporate email address, phone number and billing information.
  • Technical data: API keys, webhook endpoints, IP addresses, device identifiers and request logs.
  • Communication metadata: aggregated 2FA delivery statistics, message status codes and timestamps. We do not read the content of end-user OTP or transactional messages beyond what is required to deliver them.
  • Support data: messages you send us through the contact form, email or ticketing system.

3. Lawful Basis and Purpose

We process personal data on the following bases as defined in Section 30 of the Kenya Data Protection Act:

  • Performance of a contract — to provision your account, deliver API traffic and issue invoices.
  • Legitimate interest — to secure our infrastructure, detect fraud and improve reliability.
  • Legal obligation — to comply with tax, anti-money-laundering and telecommunications regulations.
  • Consent — for optional marketing communications, which you can withdraw at any time.

4. Data Storage and Security

All personal data is stored in access-controlled databases hosted in ISO 27001 certified data centres. Data at rest is encrypted using AES-256 and data in transit is protected by TLS 1.3. Access to production systems is restricted to authorised engineers, protected by hardware-backed 2FA and audited continuously. Secrets, API keys and webhook signing keys are stored in a dedicated key management service and never written to application logs.

5. Data Retention

Account records are retained for the duration of your subscription and for seven (7) years after termination in order to satisfy Kenyan tax and financial reporting rules. Message delivery logs are retained for twelve (12) months, after which they are irreversibly anonymised.

6. Sharing and Cross-Border Transfers

We share personal data only with vetted sub-processors that provide hosting, payment processing, mobile network delivery and customer support. Where data is transferred outside Kenya, we rely on adequacy decisions, Standard Contractual Clauses or the explicit consent of the data subject, and we notify the ODPC where required.

7. Your Rights

As a data subject you have the right to:

  • access the personal data we hold about you;
  • request correction or deletion of inaccurate or outdated information;
  • object to or restrict processing;
  • request portability of your data in a machine-readable format;
  • lodge a complaint with the Office of the Data Protection Commissioner.

8. Contact

To exercise any of these rights, contact us at contact@autodevlab.org. We respond to verified requests within thirty (30) days.