Privacy Policy
Last updated: May 2026
Zira Technologies ("Zira," "we," "us," or "our") operates the Zira HR platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
1. Information We Collect
We collect information you provide directly to your organization when setting up employee records, including names, contact details, national ID numbers, KRA PIN, bank account details, statutory numbers (NSSF, SHIF), employment history, payroll data, and performance records. We also collect account credentials and workspace configuration data during registration and use of the platform.
2. How We Use Your Information
We use collected information solely to operate and deliver the Zira HR platform services: payroll computation, statutory deductions, leave management, employee records management, reporting, compliance monitoring, and audit logging. We do not sell personal data to third parties. Aggregated, anonymized data may be used for platform improvement.
3. Data Sharing and Disclosure
We may share data with third-party service providers essential to platform operation (cloud hosting via Vercel, database via Neon, email delivery via Resend). Statutory data may be reported to Kenyan government authorities as required by law (KRA, NSSF, SHIF). We do not share data for marketing purposes.
4. Data Security
We implement encryption in transit (TLS 1.3) and at rest, tenant-isolated architecture, role-based access controls, audit logging of all sensitive actions, and regular security reviews. Customer data is stored on servers located in the United States and Europe via our cloud infrastructure providers.
5. Data Retention
We retain personal data for the duration of your organization's active subscription plus 90 days following cancellation, after which it is securely deleted. Statutory records may be retained longer to comply with Kenyan employment and tax laws. You may request data deletion by contacting your workspace administrator or our support team.
6. Your Rights
Under the Kenyan Data Protection Act (2019), you have rights to access, correct, delete, and port your personal data. You also have the right to object to processing and to lodge a complaint with the Office of the Data Protection Commissioner (ODPC). To exercise these rights, contact your workspace administrator or email privacy@zirahr.com.
7. International Data Transfers
Your data may be processed outside Kenya through our cloud infrastructure providers who maintain compliance with international data protection standards. We ensure appropriate safeguards are in place through data processing agreements with our sub-processors.
8. Cookies
We use essential cookies for authentication and session management. Analytics cookies are used only with your consent. You can manage cookie preferences through your browser settings. See our Cookie Policy for more details.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to workspace administrators via email and through the platform. Continued use of the platform after changes constitutes acceptance of the updated policy.
10. Contact
For privacy-related inquiries, contact our Data Protection Officer at privacy@zirahr.com or write to Zira Technologies, Nairobi, Kenya.