This policy explains how iLuvion collects, uses, stores and protects your personal data, and the rights the law gives you over it.
Last updated: 11 July 2026
This Privacy Policy is issued by iLuvion (referred to as “iLuvion”, the “Company”, “we”, “us” or “our”). iLuvion is the controller of, and responsible for, the personal data described in this policy. We operate from Kenya and provide AI, cloud and technology services to organisations worldwide.
In this policy, “you” and “your” refer to our customers, individuals associated with our customers, business contacts, suppliers, job applicants, and visitors to any iLuvion website.
If you have any questions about this policy, wish to exercise any of your legal rights, or wish to make a complaint about how we handle your personal data, please contact us:
A complaint may relate to any aspect of how we collect, use, store or share your personal data, or how we respond to your data protection rights. We operate a data protection complaints handling process: we will acknowledge your complaint within thirty (30) days of receipt, aim to resolve it without undue delay, and may contact you if we require further information to investigate your concerns.
You have the right to lodge a complaint at any time with the relevant supervisory authority. In Kenya this is the Office of the Data Protection Commissioner (www.odpc.go.ke). If you are in the United Kingdom this is the Information Commissioner’s Office (ico.org.uk), and if you are in the European Economic Area it is your local data protection authority. We would, however, appreciate the opportunity to address your concerns in the first instance.
This policy governs the situations in which iLuvion is a data controller of your information — that is, where we determine how and why your information is processed. Where we design, build or operate systems on behalf of a client and process personal data inside those systems, we act as a data processor on that client’s instructions; the client is the data controller for that data, and their own privacy policy and our contract with them govern its handling.
Our website may contain links to third-party websites. Clicking those links may allow third parties to collect or share data about you. We do not control those websites and are not responsible for their privacy practices; each is governed by its own privacy policy, which we encourage you to read.
Please keep us informed if your personal data changes during your relationship with us, so that the records we hold remain accurate.
We collect and process the following categories of personal data:
We may also create Aggregated Data, such as statistical data derived from technical data, for any purpose. Aggregated Data does not reveal your identity and is not personal data in law.
Special Categories of Personal Data: we do not collect special categories of personal data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, and genetic or biometric data), and we do not collect information about criminal convictions or offences, except where the law requires it in relation to staff.
We are committed to the principle of data minimisation: we collect and process only the personal data that is necessary for the specific purposes set out in this policy. In practice this means we:
Notably, our website does not use advertising trackers or third-party analytics, does not operate accounts or logins, and our online AI Readiness Scorecard runs entirely in your browser — your answers and score are not transmitted to us unless you choose to share them.
We use your personal data to:
We ensure we always have a lawful basis for processing your personal data under the Kenya Data Protection Act, 2019 and, where applicable, the EU/UK General Data Protection Regulation. That basis will be one or more of the following:
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason compatible with the original purpose. If you would like an explanation of how a new purpose is compatible with the original one, please contact us. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis that allows us to do so. We may process your personal data without your knowledge or consent only where required or permitted by law.
We take a restrained approach to marketing. We do not buy marketing lists, we do not add you to a mailing list simply because you contacted us, and we will never share your personal data with any other company for its own marketing purposes. You may receive communications from us about our services if you have requested them or if you are an existing client and have not opted out. You can ask us to stop at any time by contacting info@iluvion.io, and we will action your request within one month.
We do not set cookies of our own and we use no analytics or advertising cookies. Strictly necessary, short-lived cookies may be set by the security layer of our infrastructure purely to protect the website from automated attacks. Your browser can be set to refuse cookies, though security-related features of the site may then behave differently.
We do not sell, rent or trade your personal data. We share it only on a need-to-know basis, and only with parties that implement appropriate confidentiality and security measures:
We may also disclose personal data where we reasonably believe disclosure is necessary to protect our rights, your safety or the safety of others, to investigate fraud, or to comply with a judicial proceeding, court order or other lawful process. Unless prohibited by law, we will use reasonable efforts to notify you of any such demand so that you may seek a protective order or other appropriate remedy.
We serve clients worldwide, and the infrastructure and service providers we use operate globally, so your personal data may be stored or processed in countries other than your own, including countries whose data protection laws differ from those of Kenya, the UK or the EEA. Whenever we transfer your personal data across borders, we ensure a similar degree of protection is afforded to it by relying on one or more of the following safeguards:
Security is central to what we do, and we apply to your data the same standards we build for our clients. We maintain appropriate technical and organisational measures to prevent your personal data from being accidentally lost, or used, accessed, altered or disclosed in an unauthorised way. Our website is served exclusively over encrypted connections, with modern browser security policies enforced on every page. Access to personal data is limited to those who have a business need to know it, under an identity-first, least-privilege model, and anyone processing it on our behalf is subject to a duty of confidentiality.
We maintain procedures to deal with any suspected personal data breach, and we will notify you and any applicable regulator of a breach where we are legally required to do so.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting or reporting requirements. In determining retention periods we consider the amount, nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes of processing and whether those purposes can be achieved by other means. As a guide, we retain:
We may anonymise personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use that information indefinitely without further notice to you. When personal data is no longer needed, we delete it securely.
You have rights under data protection law in relation to your personal data. You have the right to:
To exercise any of these rights, contact info@iluvion.io. No fee is payable, unless your request is clearly unfounded, repetitive or excessive, in which case we may charge a reasonable fee or decline the request with a written explanation and a reminder of your right to complain to the supervisory authority. We aim to respond to all legitimate requests within one month; if a request is complex or you have made several, we will notify you and keep you updated.
We may need to request specific information from you to confirm your identity before acting on a request concerning your personal data. This is a security measure to ensure personal data is not disclosed to anyone who has no right to receive it. We may also contact you for further information to speed up our response.
Any changes we make to this privacy policy in the future will be posted on this page, and the “Last updated” date above will be revised. The version published here is always the one that applies. Please check back from time to time to stay aware of any updates.