01
Scope and roles
- This notice covers the public website, intake forms, Sufrone Client Workspace, Sufrone Operations, support workflows, billing records, provider events, and managed-system operations.
- For prospects and Sufrone's own operations, Sufrone may decide why and how information is used. For client systems, the exact controller, processor, and sub-processor roles must be confirmed in the signed proposal, service agreement, or data-processing terms.
- Clinical-core, regulated financial, identity, biometric, and other sensitive functions require explicit legal, data-protection, provider, access, and delivery boundaries before production use.
02
Information Sufrone collects
- Public intake details such as organization name, contact person, email, phone, website, budget range, current stack, timeline, and the problem described.
- Assessment context and any deliberately selected industry path, implementation technology, engineering capability, Advantage Engine module, managed-service interest, budget, timing, or current-system information submitted with a request.
- Self-registration profile details such as organisation type, industry, requested capabilities, requested products, email-verification state, workspace access history, and the resulting prospect workspace.
- Operational records created after qualification, including contacts, opportunities, assessment notes, proposals, onboarding tasks, work orders, Advantage Engine deployments, connector instances, managed systems, tickets, invoices, payment references, health signals, provider events, and admin audit logs.
- Authentication, security, and diagnostic metadata needed to protect administrative access, signed client-workspace sessions, support workflows, provider webhooks, and system reliability.
03
How information is used
- To assess environments, qualify requests, scope engineering work, produce proposals, onboard clients, operate approved technology, provide support, issue invoices, monitor managed systems, and maintain continuity.
- To keep a clear account history so client work is not dependent on memory, private chat threads, or a single manual spreadsheet.
- To reconcile payments, investigate provider callbacks, handle support issues, maintain audit trails, and protect the platform from misuse.
- To improve Sufrone's operating process without selling client or prospect data.
04
Sharing and providers
- Sufrone does not sell client or prospect data.
- Information may be processed through approved infrastructure, email, payment, analytics, monitoring, support, or professional-adviser providers only where needed to operate the service, respond to a request, comply with obligations, or deliver contracted work.
- Client-authorized integrations may send data to systems selected by the client, such as payment providers, email providers, analytics tools, ERP, CRM, support, or automation platforms.
05
Retention, access, and offboarding
- Prospect and client records are kept only as long as needed for qualification, delivery, support, billing, security, audit history, legal obligations, or legitimate continuity of the account.
- Invoices, payment records, audit logs, and security records may need to be retained longer than general support notes because they prove business, tax, security, or contractual activity.
- Offboarding should define data export, credential handover, backup retention, deletion timing, and any records Sufrone must retain after service ends.
- A client or contact can request review, correction, export, or deletion of relevant information through the company contact channel, subject to identity checks, contractual obligations, and records Sufrone must keep.
06
Security and legal review
- The platform is designed around least-needed access, signed sessions, provider signature verification, secret hygiene, admin audit logs, and reviewable operational records.
- Client contracts should define data roles, hosting location, backup retention, access approval, incident handling, breach-notification duties, subprocessors, and offboarding responsibilities.
- Before public production launch, this notice must either be reviewed with a Kenyan advocate or released under a recorded founder exception while legal review remains open.
For privacy questions, client data requests, or launch review, contact Sufrone through the company inbox before submitting sensitive production or regulated-sector data.
Contact Sufrone