Data Protection
1. Our Data Protection Commitment
TrustOps Portal is built around one principle:
Proof builds trust. Data protection preserves it.
TrustOps Portal helps organizations access approved assurance records relating to backup assurance, recovery evidence, data hosting statements, audit documents, cloud continuity, tenant assurance and service coverage across supported ABNO and Lolla products.
Because TrustOps handles sensitive assurance, audit and continuity information, we are committed to protecting personal data, client records, system evidence and confidential service information through lawful, controlled and accountable processing.
2. What This Page Explains
This Data Protection page explains how TrustOps Portal approaches:
- personal data protection
- client data confidentiality
- data controller and data processor responsibilities
- data security
- user access control
- data sharing
- cross-border processing
- data subject rights
- retention
- breach handling
- audit and accountability.
This page should be read together with the Privacy Policy, Terms of Use, applicable client agreements and any product-specific data processing terms.
3. Our Legal and Compliance Position
TrustOps Portal is designed to operate in line with applicable data protection laws, including the Kenya Data Protection Act, 2019, and where applicable, other relevant privacy and data protection laws.
Kenya's Data Protection Regulations require data controllers and processors to develop, publish and regularly update a policy reflecting personal data handling practices, including the nature of personal data collected, rights, complaints, lawful purpose, transfers, retention and children's data where applicable.
Where TrustOps Portal supports clients outside Kenya or handles cross-border matters, additional contractual, legal or regulatory requirements may apply.
4. Controller and Processor Roles
Depending on the context, ABNO/Lolla may act as:
| Role | When It Applies |
|---|---|
| Data Controller | When we determine why and how personal data is processed, such as website enquiries, demo requests, marketing communication or user access administration |
| Data Processor | When we process client-controlled data on behalf of a client under a service agreement |
| Joint or Separate Controller | Where both ABNO/Lolla and the client independently determine certain purposes, subject to the relevant agreement |
Where ABNO/Lolla acts as a processor for a client, processing should be governed by written contractual terms. Kenya's Data Protection Regulations require a controller engaging a processor to use a written contract that addresses processing details, instructions, confidentiality, security measures, return/deletion and audit provisions.
5. Data Protection Principles We Follow
TrustOps Portal is guided by the following principles:
| Principle | What It Means for TrustOps |
|---|---|
| Lawfulness, Fairness and Transparency | We process data for lawful, clear and explained purposes |
| Purpose Limitation | We use data only for the purpose for which it was collected or lawfully required |
| Data Minimization | We collect only what is necessary |
| Accuracy | We aim to keep records accurate and up to date |
| Storage Limitation | We retain data only as long as reasonably necessary |
| Confidentiality and Integrity | We protect data against unauthorized access, loss, misuse or disclosure |
| Accountability | We maintain records, approvals, logs and controls to show responsible handling |
TrustOps Portal is designed as a controlled assurance platform, not a raw database access portal or uncontrolled backup download portal.
6. What Data We Protect
TrustOps Portal may protect different categories of information, depending on how the website or portal is used.
| Data Category | Examples |
|---|---|
| Website Visitor Data | IP address, browser type, pages visited, cookies, analytics data |
| Contact and Enquiry Data | Name, work email, phone number, organization, message |
| Demo Request Data | Product of interest, assurance need, role, preferred demo date |
| Client Representative Data | ICT contact, finance contact, executive contact, auditor contact |
| Portal User Data | User account, role, organization, login records, permissions |
| Assurance Records | Backup reports, recovery evidence, hosting statements, audit evidence |
| Request Records | Backup assurance request, data copy request, recovery test request |
| Audit Trail Data | Logins, downloads, approvals, document access, request activity |
| Custody Records | Secure data copy recipient, release approval, transfer record |
| Service Coverage Data | SLA, cloud continuity, CICS, subscription or optional service status |
7. Information You Should Not Submit Through Public Forms
For security reasons, users should not submit the following through general website forms:
- passwords
- database credentials
- cloud credentials
- raw database files
- raw backup files
- highly sensitive system exports
- production access keys
- confidential third-party data
- unnecessary personal data.
The TrustOps website form guidance already requires users not to submit passwords, credentials, raw backup files or highly sensitive data through public forms.
Where sensitive data transfer is required, it must follow an approved secure process.
8. How We Protect Data
TrustOps Portal applies reasonable technical and organizational controls, which may include:
- role-based access control
- user authentication
- MFA for sensitive or privileged access where supported
- client-level access separation
- controlled Evidence Room access
- document approval workflows
- access logs and audit trails
- secure document handling
- encryption where supported
- secure transfer channels
- backup export custody controls
- internal approval workflows
- staff confidentiality obligations
- periodic access reviews
- incident escalation procedures.
The TrustOps UX and governance model is built around role-based workspaces, clear evidence, controlled requests and avoidance of technical confusion or unsafe exposure.
9. Role-Based Access
TrustOps Portal access is role-based.
This means users only see information appropriate to their role and organization.
| User Type | Typical Access |
|---|---|
| Client Executive | High-level assurance status and approved evidence |
| Client ICT | Technical assurance, backup, recovery and hosting information |
| Client Finance | Service coverage and billing-related visibility where enabled |
| Client Auditor | Read-only approved evidence |
| Client Approver | Approval of selected requests |
| CloudOps | Backup, recovery and hosting records |
| Legal/Compliance | Custody, approval and compliance records |
| Finance/Admin | Commercial coverage and optional service status |
| CEO/CTO/Governance | Risk, exceptions and oversight dashboards |
Clients and auditors do not receive access to cloud consoles, production database credentials, raw backups or other clients' data through ordinary portal use.
10. Shared SaaS Tenant Protection
Some products operate on shared SaaS platforms where multiple clients use the same platform and data is separated at tenant level.
For such products:
- clients receive tenant-level assurance
- platform backups are managed centrally
- tenant data exports may be provided only through approved controls
- raw full platform database backups are not released to individual clients
- other tenants' data must never be exposed.
This aligns with TrustOps' architecture distinction between dedicated database assurance and shared SaaS tenant assurance.
11. Secure Data Copy and Backup Export Protection
Backup export, secure data copy and tenant data export are treated as sensitive custody processes.
They may require:
- formal request
- valid purpose
- authorized requestor
- approved recipient
- defined data scope
- deployment model confirmation
- Legal/Compliance review where sensitive
- Finance confirmation where billable
- encryption
- secure transfer
- custody acceptance
TrustOps record.
No backup or client data copy should be released casually through ordinary email, WhatsApp, personal drives or unapproved channels.
12. Data Sharing
We may share personal data or client-related information only where appropriate, lawful and necessary.
Possible recipients include:
| Recipient | Purpose |
|---|---|
| ABNO/Lolla internal teams | Support, assurance, demo, compliance and service delivery |
| CloudOps/Product teams | Backup, hosting, recovery and technical assurance |
| Customer Success | Client communication and request handling |
| Legal/Compliance | Data custody, audit, legal and privacy review |
| Finance | Service coverage, billing and optional service review |
| Authorized client representatives | Approved records for their organization |
| Authorized auditors | Read-only approved evidence |
| Service providers | Hosting, communication, analytics, security and website operations |
| Regulators or authorities | Where legally required |
Data sharing must be controlled and documented where sensitive. Kenya's Data Protection Regulations provide that personal data sharing requests should specify the purpose, retention duration and safeguards, and that routine data sharing may require agreements.
13. International Transfers
TrustOps-related services may involve cloud hosting, communication tools, analytics platforms, support teams or infrastructure providers located outside Kenya.
Where personal data is transferred or accessed internationally, we apply reasonable safeguards based on the applicable law, contract and risk profile.
Where special data residency requirements apply, they must be verified, recorded and contractually addressed. TrustOps must not claim that data is locally hosted, Kenya-hosted, replicated or DR-ready unless this has been verified and recorded.
14. Data Retention
We retain personal data and assurance records only for as long as necessary for lawful, contractual, audit, security, service or legitimate business purposes.
Kenya's Data Protection Regulations require controllers/processors to retain personal data only as long as reasonably necessary and to establish retention schedules with time limits, periodic review and actions after review.
Indicative retention may include:
| Record Type | Indicative Retention |
|---|---|
| Website enquiry | Up to 24 months |
| Demo request | Up to 36 months or longer if converted into client record |
| Portal access logs | According to security/audit requirements |
| Evidence download logs | According to audit and contract requirements |
| Backup export custody records | Up to 7 years or longer where legally required |
| Client assurance records | Contract life plus applicable retention period |
| Legal/compliance records | As required by law, contract, dispute or legal hold |
15. Data Subject Rights
Depending on applicable law, individuals may have rights relating to their personal data, including rights to access, correction, objection, restriction, erasure and portability.
Kenya's Data Protection Regulations provide for access to personal data, rectification of inaccurate data, portability and erasure in defined circumstances.
The ODPC also summarizes data subject rights as including the right to be informed, access personal data, object to processing, correct false or misleading data and delete false or misleading data.
To exercise your rights, contact us using the contact details below.
We may need to verify your identity before acting on a request.
16. Marketing and Communication Controls
Where we use personal data for marketing or product communication, we aim to do so lawfully and respectfully.
Marketing communication may include:
- TrustOps demo follow-up
- product updates
- webinar invitations
- assurance service information
- relevant ABNO/Lolla updates.
Kenya's Data Protection Regulations require direct marketing communications to provide an opt-out mechanism that is visible, clear, easy to use and accessible.
Users may opt out of marketing communication at any time. Service, security, legal or transactional communication may still be sent where necessary.
17. Data Protection by Design and Default
TrustOps Portal aims to apply data protection by design and by default.
This means privacy and security should be built into the portal, workflows and evidence handling from the beginning, not added later.
Kenya's Data Protection Regulations require controllers/processors to embed data protection mechanisms into processing and design technical and organizational measures to safeguard and implement data protection principles.
For TrustOps, this means:
- role-based access from the start
- client segregation by default
- no raw backup exposure by default
- evidence approval before publication
- sensitive request workflows
- secure custody records
- clear deployment model classification
- controlled auditor access.
18. Data Breach and Incident Response
If a personal data breach or security incident is suspected, we will assess the incident and take appropriate action based on the nature, severity, affected data, client impact and legal requirements.
Possible actions may include:
- internal investigation
- access restriction
- credential reset
- incident containment
- affected client notification where required
- regulator notification where legally required
- evidence preservation
- corrective action
- post-incident review.
Users should promptly report suspected unauthorized access, suspicious downloads, wrong evidence access, account compromise or data exposure.
19. Children's Data
TrustOps Portal is designed for organizations, institutions, businesses, auditors and professional users.
The public website is not directed at children.
If children's data is processed in client systems, such processing is governed by the relevant client agreement, product terms, applicable data protection law and any required safeguards.
20. Client Responsibilities
Clients using TrustOps Portal are responsible for:
- appointing authorized users
- removing users who leave or change roles
- protecting downloaded evidence
- controlling auditor access
- protecting any data copy received
- using official channels for sensitive requests
- ensuring their staff comply with internal data protection duties
- notifying ABNO/Lolla of unauthorized access concerns
- ensuring any onward sharing of evidence or exports is lawful and controlled.
21. Our Responsibilities
ABNO/Lolla shall aim to:
- process personal data lawfully and fairly
- protect TrustOps Portal records
- separate client access
- prevent unauthorized exposure of raw backups and credentials
- provide approved evidence only
- maintain audit trails where applicable
- control secure data copy and tenant export processes
- review sensitive requests
- maintain data protection practices
- respond to data subject requests where applicable
- update data protection documentation when necessary.
22. Contact Us
For data protection questions, privacy requests or concerns, contact:
TrustOps Portal Team
Email: info@abnosoftwares.com
Phone: +254 (0)705 597336
Website: trustopsportal.com
For product-specific support, clients should use their official support channel.
