Privacy Policy
1. Introduction
TrustOps Portal respects your privacy and is committed to protecting personal data collected through this website.
This Privacy Policy explains how we collect, use, store, disclose and protect personal data when you visit the TrustOps Portal website, submit a demo request, contact us, download materials, interact with website forms or communicate with us about TrustOps services.
TrustOps Portal is positioned as an assurance, continuity and compliance center that helps organizations access approved records relating to backup assurance, recovery evidence, data hosting statements, audit documents, service continuity records and approved requests across supported ABNO and Lolla products.
This Privacy Policy applies to the public website. Where a client or authorized user accesses the secured TrustOps Portal application, additional portal terms, user access rules, client agreements, data processing terms or product-specific privacy notices may also apply.
2. Who We Are
TrustOps Portal is operated by ABNO Softwares International Ltd, Lolla Technologies Ltd and/or the relevant product-owning or contracting entity within the ABNO/Lolla ecosystem.
For website privacy purposes, the responsible entity may act as a data controller where it determines why and how website visitor, demo request and enquiry data is processed. Where TrustOps Portal is used to process client-controlled records under a contract, the relevant ABNO/Lolla entity may act as a data processor or service provider depending on the applicable agreement.
Kenya's Data Protection Act, 2019 establishes the Office of the Data Protection Commissioner and provides for regulation of personal data processing, data subject rights and obligations of data controllers and processors.
3. Scope of This Privacy Policy
This Privacy Policy applies to personal data collected through:
- the TrustOps Portal website
- demo request forms
- contact forms
- newsletter or update forms, where enabled
- website analytics tools
- cookies and similar technologies
- website chat or enquiry tools, where enabled
- event, webinar or assurance demo registration forms
- downloadable resources or gated content
- email or phone communication initiated through the website.
This Privacy Policy does not replace any signed client agreement, data processing agreement, SLA, subscription agreement, CICS addendum, cloud continuity agreement, product privacy policy or portal user agreement.
4. Personal Data We May Collect
We may collect the following categories of personal data.
| Category | Examples |
|---|---|
| Identity Data | Full name, job title, organization name |
| Contact Data | Work email, phone number, WhatsApp number |
| Organization Data | Institution/company name, organization type, department, role |
| Demo Request Data | Product of interest, assurance need, preferred demo mode, preferred date/time |
| Communication Data | Messages, enquiries, support-related website submissions |
| Technical Data | IP address, browser type, device type, operating system, pages visited, time spent |
| Usage Data | Website interactions, clicked links, forms started/submitted |
| Marketing Preference Data | Consent to receive updates, demo follow-up preference |
| Security Data | Security logs, spam prevention signals, form abuse indicators |
| Optional Context Data | Information you voluntarily submit about audits, hosting, backup, compliance or assurance needs |
We do not intentionally ask website visitors to submit passwords, production credentials, raw database files, backup files or highly sensitive system exports through public website forms. TrustOps website copy already requires security messaging that users should not submit passwords, credentials, raw backup files or highly sensitive data through forms.
5. Information You Should Not Submit Through the Website
Please do not submit the following through general website forms:
- passwords
- database credentials
- cloud credentials
- raw database backups
- confidential system exports
- payment card details
- national ID copies unless specifically requested through an approved secure process
- other clients' data
- highly sensitive personal data unrelated to your enquiry.
If sensitive information is required for a legitimate support, audit, data custody or continuity request, we will provide approved secure instructions through the appropriate official channel.
6. How We Collect Personal Data
We may collect personal data when you:
- visit the website
- request a TrustOps demo
- submit a contact form
- ask for assurance information
- register for a webinar or event
- download resources
- communicate with us by email, phone or WhatsApp after using the website
- interact with website analytics, cookies or tracking tools
- respond to marketing or service communication
- use security-protected website forms.
We may also receive limited personal data from your organization where your organization nominates you as a contact, approver, ICT representative, auditor, finance contact or executive contact.
7. Why We Use Personal Data
We may use personal data for the following purposes:
| Purpose | Explanation |
|---|---|
| Responding to enquiries | To contact you about questions submitted through the website |
| Demo scheduling | To arrange TrustOps Portal demos and walkthroughs |
| Product relevance | To understand which ABNO/Lolla product or assurance area is relevant |
| Client qualification | To determine whether you are an existing client, prospect, auditor or stakeholder |
| Assurance communication | To explain backup assurance, recovery evidence, data hosting or audit evidence services |
| Security | To prevent spam, abuse, unauthorized access and misuse of website forms |
| Website improvement | To understand how visitors use the website and improve user experience |
| Marketing communication | To send relevant updates where permitted or requested |
| Legal compliance | To comply with applicable legal, regulatory, contractual or audit obligations |
| Record keeping | To maintain records of enquiries, demo requests and consent choices |
| Internal routing | To direct requests to Customer Success, CloudOps, Legal/Compliance, Finance or Sales |
TrustOps Portal is designed to help leadership, ICT teams and auditors access clear evidence on backup assurance, recovery readiness, data hosting and compliance matters.
8. Legal Basis for Processing
Where applicable, we may process personal data based on one or more of the following lawful bases:
| Legal Basis | When It May Apply |
|---|---|
| Consent | When you request a demo, subscribe to updates or agree to be contacted |
| Contractual necessity | When processing is required to respond to a client or prospective client request |
| Legitimate interests | To operate the website, respond to enquiries, improve services and protect security |
| Legal obligation | To comply with law, regulation, audit, tax, security or data protection obligations |
| Public interest or official request | Where applicable for lawful regulatory or public-sector compliance processes |
If you withdraw consent, this will not affect processing already carried out lawfully before withdrawal.
9. Demo Request Forms
When you submit a TrustOps demo request, we may collect details such as your name, work email, phone number, organization, role, product of interest, assurance need, deployment model, preferred demo mode and message.
We use this information to:
- respond to your request
- schedule a demo
- tailor the demo to your organization's needs
- route the request internally
- determine whether CloudOps, Customer Success, Legal/Compliance, Finance or Sales should be involved
- maintain a record of your enquiry.
The website copy recommends demo routing based on conditions such as existing client status, product interest, audit evidence, backup export or data residency needs.
10. Cookies and Similar Technologies
The TrustOps Portal website may use cookies or similar technologies to:
- make the website function properly
- remember user preferences
- understand website traffic
- improve content and layout
- measure campaign performance
- protect forms from spam and abuse
- support website security.
Cookies may be:
| Cookie Type | Purpose |
|---|---|
| Strictly Necessary Cookies | Required for website functionality and security |
| Analytics Cookies | Help us understand website usage and improve the website |
| Preference Cookies | Remember choices such as language or display preferences |
| Marketing Cookies | Help measure campaigns or show relevant content, where used |
| Security Cookies | Help prevent spam, fraud or abuse |
Where required, we will request cookie consent before using non-essential cookies.
You can also control cookies through your browser settings. Disabling some cookies may affect website functionality.
11. Analytics and Website Performance
We may use analytics tools to understand how visitors use the website.
Analytics may collect information such as:
- pages visited
- time spent on pages
- referring website
- approximate location derived from IP address
- device and browser type
- clicked links
- form interaction statistics.
We use analytics to improve website clarity, performance, content and user experience. We do not use website analytics to expose client backup records, raw databases, cloud credentials or confidential TrustOps Portal evidence.
12. Marketing Communication
Where permitted, we may use your contact details to send:
- demo follow-up messages
- TrustOps Portal updates
- product or assurance information
- event or webinar invitations
- service announcements
- relevant ABNO/Lolla product information.
You may opt out of marketing communication at any time by using the unsubscribe link, contacting us, or requesting removal from marketing lists.
We may still send non-marketing service, legal, security or transactional messages where necessary.
13. Sharing of Personal Data
We may share personal data only where appropriate and necessary.
| Recipient | Purpose |
|---|---|
| ABNO/Lolla internal teams | To respond to enquiries, route demo requests and provide service information |
| Customer Success | To coordinate demos, onboarding and client communication |
| Sales / Business Development | To respond to prospective client enquiries |
| CloudOps / Product Teams | To respond to technical assurance, hosting, backup or data residency enquiries |
| Legal/Compliance | To review sensitive, audit, data custody or regulatory enquiries |
| Finance | To review commercial coverage, billing or optional service enquiries |
| Website hosting providers | To operate the website |
| Analytics providers | To understand website performance |
| Email/SMS/communication providers | To send messages and confirmations |
| Professional advisers | Lawyers, auditors or consultants where necessary |
| Regulators or authorities | Where legally required |
| Client-authorized representatives | Where your organization has authorized sharing |
We do not sell personal data to advertisers.
14. International Transfers
Your personal data may be processed or stored in countries outside Kenya where our service providers, hosting providers, cloud providers, communication tools or internal teams operate.
Where personal data is transferred internationally, we will take reasonable steps to ensure appropriate safeguards are applied in line with applicable law and contractual requirements.
Where the GDPR applies, Regulation (EU) 2016/679 governs personal data protection in the European Union and European Economic Area.
15. Data Security
We apply reasonable technical and organizational measures to protect personal data collected through the website.
These may include:
- access controls
- secure form handling
- HTTPS/secure transmission where configured
- role-based internal access
- spam and abuse prevention
- security monitoring
- restricted access to enquiry records
- staff confidentiality obligations
- controlled internal routing
- retention limits
- approved escalation processes for sensitive requests.
TrustOps Portal's website positioning emphasizes that the portal does not expose cloud credentials, raw database backups or production system access to unauthorized users.
No website or online transmission is completely risk-free. You should avoid submitting sensitive credentials or raw system data through public forms.
16. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Indicative retention periods:
| Data Type | Indicative Retention |
|---|---|
| General website enquiry | Up to 24 months |
| Demo request | Up to 36 months or longer if converted to client record |
| Marketing consent record | Until withdrawal plus reasonable compliance period |
| Website analytics | According to analytics configuration |
| Security logs | As needed for security and legal protection |
| Client-related enquiry | According to client agreement or service record policy |
| Legal/compliance enquiry | As required by law, contract or legal hold |
We may retain data longer where required for legal, contractual, audit, regulatory, dispute resolution, security or legitimate business reasons.
17. Your Data Protection Rights
Depending on applicable law, you may have rights over your personal data, including the right to:
- be informed about how your personal data is used
- access personal data held about you
- request correction of inaccurate or misleading data
- object to certain processing
- request deletion of false or misleading data
- withdraw consent where processing is based on consent
- request restriction or review of certain processing where applicable
- lodge a complaint with the relevant data protection authority.
The ODPC states that data subjects have rights including being informed of use, access, objection, correction and deletion of false or misleading data.
To exercise your rights, contact us using the details in Section 25.
We may need to verify your identity before responding.
18. Children's Data
The TrustOps Portal website is intended for organizations, institutions, businesses, auditors and professional users. It is not directed at children.
We do not knowingly collect children's personal data through the public website for marketing or demo purposes.
If we learn that children's personal data has been submitted through the website without appropriate authority, we may delete it or handle it according to applicable law and safeguarding requirements.
19. Client, Auditor and Institutional Contacts
Where your organization provides your details as an authorized contact, auditor, ICT officer, finance officer, approver or executive contact, we may use your data to:
- verify your role
- grant or manage appropriate communication
- respond to your organization's request
- coordinate assurance or demo discussions
- route matters to the right internal team
- maintain accountability records.
If you are no longer authorized to act for an organization, please notify us or ask your organization to notify us.
20. Links to Other Websites
The TrustOps Portal website may contain links to third-party websites, product websites, client login pages, cloud providers, webinar tools, payment providers or ABNO/Lolla product pages.
We are not responsible for the privacy practices of third-party websites. You should review their privacy policies before submitting personal data.
21. Portal and Client Agreement Records
This website Privacy Policy covers general website interaction.
If you become a TrustOps Portal user or a client representative, additional records may be processed, including:
- user account details
- access role
- organization/product assignment
- evidence room access logs
- document view/download logs
- request records
- approvals
- custody acceptance
- support or assurance activity.
Such processing may be governed by the TrustOps Portal Terms of Use, client agreements, data processing agreements, service terms and the applicable TrustOps governance policies.
22. Data Breach and Incident Handling
If we become aware of a personal data breach affecting website personal data, we will assess the incident and take appropriate steps according to applicable law, contract and internal incident procedures.
The ODPC's compliance function includes oversight of data processing and coordinates compliance mechanisms such as data protection impact assessment, inspections and audits.
Where legally required, we will notify affected persons, clients or regulators.
23. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Updates may be made to reflect:
- website changes
- new TrustOps services
- legal or regulatory changes
- security improvements
- new cookies or analytics tools
- changes in contact details
- changes in data processing practices.
The updated version will be posted on the website with a revised effective date.
24. Complaints
If you have a privacy concern, please contact us first so that we can review and respond.
You may also have the right to complain to the relevant data protection authority.
In Kenya, the Office of the Data Protection Commissioner is responsible for regulation and enforcement of the Data Protection Act.
25. Contact Us
For privacy questions, data subject requests or concerns about this Privacy Policy, contact:
TrustOps Portal Team
Email: info@abnosoftwares.com
Phone: +254 (0)705 597336
Website: trustopsportal.com
For product-specific support, clients should use their official support channel.
