Privacy Policy.

How Centipid Technologies collects, uses, protects, and shares information from venue operators, their customers, and visitors to our platform — in plain language, without the confusion.

Section 1

Overview & Plain Language Summary

The Short Version

Centipid operates in two capacities: as a data controller for our own platform users (venue operators and their staff), and as a data processor on behalf of venue operators for data collected from their WiFi customers. We do not sell personal data to anyone. WiFi portal data belongs to the venue operator. End users can always opt out. We comply with the Kenya Data Protection Act 2019, the Nigeria Data Protection Act 2023, the Ghana Data Protection Act 2012, and the EU General Data Protection Regulation (GDPR).

This Privacy Policy explains how Centipid Technologies Limited ("Centipid", "we", "us", "our") handles personal data across two distinct contexts:

  • Platform Users — businesses, venue operators, and individuals who create and manage a Centipid account to operate WiFi marketing campaigns.
  • WiFi End Users — customers, guests, and visitors who connect to a WiFi network operated through the Centipid platform at a physical venue (restaurant, hotel, gym, etc.).

If you are a WiFi end user and want to understand what data was collected about you at a specific venue, you should contact that venue directly. Centipid processes this data on the venue's behalf. This policy explains how we do so and what protections are in place.

Section 2

Who We Are

Centipid Technologies Limited is a technology company incorporated in Kenya. We build and operate a WiFi marketing and analytics platform that allows venue operators to capture leads, run automated marketing campaigns, collect reviews, and manage WiFi access through guest captive portals.

DetailInformation
CompanyCentipid Technologies Limited
RegistrationRegistered in Kenya under the Companies Act (Cap. 486)
Principal OfficeI&M Bank Building, Upperhill, Nairobi, Kenya
Data Protection Officer[email protected]
Privacy Enquiries[email protected]
Applicable LawsKenya DPA 2019, NDPR 2023, Ghana DPA 2012, GDPR, CASL, CAN-SPAM
Section 3

Data Controller vs. Data Processor

Under applicable data protection laws, there is an important distinction between a data controller (who decides why and how data is processed) and a data processor (who processes data on behalf of a controller). Centipid acts in both capacities, depending on the context.

When Centipid is the Data Controller

For data relating to our platform users — including account registration data, billing information, support correspondence, and usage analytics of the Centipid platform itself — Centipid is the data controller. We decide the purposes and means of processing this data.

When Centipid is a Data Processor

For data collected from WiFi end users through captive portals operated by our venue operator customers, Centipid acts as a data processor. The venue operator (our customer) is the data controller. They determine what data to collect, what consent language to use, and what marketing they send. Centipid processes this data strictly on their documented instructions.

Important for venue operators

As the data controller for your WiFi customers' data, you are legally responsible for ensuring valid consent is obtained, that your privacy notice is visible on your captive portal, and that you honour any data subject requests from your customers. Centipid provides the tools and infrastructure; you bear the controller responsibility. Our Data Processing Agreement (DPA) is available on request.

Section 4

Information We Collect

4a. WiFi Portal Data (Collected on Behalf of Venue Operators)

When a person connects to a Centipid-powered WiFi network, the captive portal may collect the following, depending on the venue operator's configuration:

Data TypeHow CollectedRequired?
Email addressDirect entry or social login (Google, Facebook)Configurable
Full nameDirect entry or social loginConfigurable
Phone numberDirect entry + OTP verificationConfigurable
Date of birthOptional field shown on portalOptional
GenderOptional field shown on portalOptional
Custom fieldsVenue operator may add custom form fields (Professional+ plans)Configurable
MAC addressDevice identifier captured at login for session managementTechnical — automatic
Device type & OSUser-agent string from device browserTechnical — automatic
Session dataLogin time, session duration, data usage, reconnection eventsTechnical — automatic
Location (venue)WiFi access point identifier — identifies which venue/zone was visitedTechnical — automatic
Marketing consentConsent checkbox state recorded with timestamp at loginRequired for marketing

4b. Platform Account Data (Centipid as Controller)

When you create and use a Centipid account, we collect:

  • Registration information — name, email address, business name, country, phone number.
  • Billing and payment data — payment method (card last four digits, M-Pesa number, or Paystack/Flutterwave reference). Full card numbers are processed by our payment providers (Paystack, Flutterwave, Stripe) and are never stored by Centipid.
  • Business information — venue details, industry type, number of locations, WiFi hardware configuration.
  • Communication records — emails, support tickets, live chat conversations, and WhatsApp support messages.
  • Verification documents — for Enterprise accounts, we may request business registration documents or identification to verify your business.

4c. Platform Usage Data & Analytics

When you use the Centipid dashboard, we automatically collect:

  • Log data — IP address, browser type, pages visited within the dashboard, actions taken, timestamps.
  • Device data — operating system, screen resolution, browser version.
  • Feature usage analytics — which features you use, how often, and in what sequence. Used to improve the platform.
  • Error and crash reports — automatically collected to diagnose and fix platform issues.
Section 5

How We Use Your Data

For Platform Users (Centipid as Controller)

  • Providing the service — operating your account, processing payments, configuring portals, delivering campaigns.
  • Customer support — responding to enquiries, diagnosing technical issues, onboarding assistance.
  • Platform improvements — analysing usage patterns to improve features, fix bugs, and build new functionality.
  • Security and fraud prevention — monitoring for suspicious account activity, preventing abuse of the platform.
  • Legal compliance — maintaining records as required by applicable law, responding to lawful requests from authorities.
  • Product communications — sending product updates, new feature announcements, and account notifications. You may opt out of non-essential communications at any time.

For WiFi End User Data (Centipid as Processor)

Centipid processes WiFi end user data solely on the documented instructions of the venue operator (data controller). This includes:

  • Authenticating the user's WiFi session and managing network access.
  • Storing captured lead data in the venue operator's Centipid account.
  • Sending marketing campaigns (email, SMS, WhatsApp) on behalf of the venue operator, subject to the end user's consent.
  • Generating visit analytics, segmentation, and campaign performance reports for the venue operator.

We do not use WiFi end user data for Centipid's own marketing, we do not build profiles across multiple venues, and we do not share it with third parties except as necessary to deliver the service (sub-processors listed below).

Section 7

Sharing & Disclosure

We do not sell personal data. We share data only in the following circumstances:

Sub-Processors

We use trusted third-party service providers ("sub-processors") to operate our platform. All sub-processors are bound by data processing agreements and may only process data for the purposes specified:

Sub-ProcessorPurposeLocation
DigitalOceanCloud infrastructure, servers, and database hostingUSA (EU/Africa region available)
Stripe / Paystack / FlutterwavePayment processingUSA / Nigeria / USA
Africa's TalkingSMS delivery for campaign messagesKenya
WhatsApp Business APIWhatsApp campaign message deliveryUSA (Meta)
Mailgun / SendGridEmail campaign deliveryUSA
SentryError monitoring and crash reportingUSA
CloudflareDDoS protection, CDN, WAFUSA / Global
Google AnalyticsWebsite analytics (centipidmarketing.com only — not portal)USA

Business Transfers

If Centipid is acquired, merges with another company, or transfers its assets, personal data may be transferred to the acquiring entity. We will notify affected users by email and provide an opportunity to delete accounts before any such transfer is completed.

Legal Obligations

We may disclose personal data when required to do so by law, court order, or regulatory authority, or when we believe disclosure is necessary to protect the rights, property, or safety of Centipid, our customers, or the public. We will notify affected individuals unless legally prohibited from doing so.

Section 8

International Data Transfers

Centipid serves customers globally and our infrastructure involves sub-processors in the United States and Europe. Personal data may therefore be transferred outside the country in which it was collected.

Where data is transferred outside the EEA or a country with an adequate level of protection, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs) — for transfers to sub-processors in countries without an adequacy decision.
  • Adequacy decisions — where applicable, we rely on formal adequacy determinations by relevant supervisory authorities.
  • Data Processing Agreements — all sub-processors are bound by contractual obligations equivalent to those in this policy.

Customers who require data residency within specific jurisdictions (e.g., Kenya or Nigeria) should contact us. We can accommodate this for Enterprise plan customers on request.

Section 9

Data Retention

Data CategoryRetention PeriodBasis
Platform account dataDuration of account + 90 days after deletion requestService delivery
WiFi end user lead data (Starter)3 months from capturePlan limit
WiFi end user lead data (Starter Plus)6 months from capturePlan limit
WiFi end user lead data (Professional)12 months from capturePlan limit
WiFi end user lead data (Scale / Enterprise)24 months from capture or customPlan limit
Billing and invoice records7 years from invoice dateKenya tax / accounting law
Marketing campaign logs12 months from send dateDeliverability and compliance
Support conversation records3 years from last interactionLegitimate interest
Session / audit logs90 days rollingSecurity and fraud prevention
Backup copiesPurged within 30 days of primary deletionTechnical

When an account is closed, we export a final data snapshot for the account holder upon request, then permanently delete all personal data from production systems within 30 days and from backup systems within 90 days.

Section 10

Security Measures

We implement technical and organisational measures appropriate to the risk of processing personal data. These include:

  • Encryption in transit — all data is transmitted over TLS 1.2 or higher. WiFi portal pages served over HTTPS.
  • Encryption at rest — database storage is encrypted using AES-256. Backups are encrypted.
  • Access controls — internal access to personal data is limited to employees who need it for their role, authenticated by multi-factor authentication.
  • Network security — all services are protected by Cloudflare WAF, DDoS mitigation, and rate limiting. WireGuard VPN for internal infrastructure access.
  • Penetration testing — regular third-party security assessments of our infrastructure and application code.
  • Incident response — we maintain a documented data breach response procedure. We will notify affected individuals and supervisory authorities within 72 hours of becoming aware of a qualifying breach.
  • Employee training — all staff with access to personal data receive data protection training on joining and annually.
Report a Security Issue

If you discover a potential security vulnerability in our platform, please contact us at [email protected] before disclosing publicly. We respond to all responsible disclosure reports within 24 hours.

Section 11

Your Rights

Depending on your location, you have the following rights in relation to your personal data. To exercise any of these rights, contact us at [email protected]. We respond within 30 days (or such shorter period as required by law).

Right to Access

Request a copy of the personal data we hold about you, including the purposes we process it for.

Right to Rectification

Ask us to correct inaccurate or incomplete data we hold about you.

Right to Erasure

Request deletion of your personal data where we no longer have a lawful basis to process it.

Right to Restrict

Ask us to restrict processing while a dispute is resolved, rather than deleting your data.

Right to Portability

Receive your data in a structured, machine-readable format (CSV or JSON) to transfer to another provider.

Right to Object

Object to processing based on legitimate interests, including profiling and direct marketing.

Automated Decisions

Right not to be subject to decisions made solely by automated processing that significantly affect you.

Withdraw Consent

Where processing is based on consent, withdraw it at any time. Withdrawal doesn't affect prior lawful processing.

WiFi End Users

If you connected to a Centipid-powered WiFi network and want to exercise your rights, you should contact the venue (the data controller) directly. Venue contact details are typically available on their captive portal or website. You may also email us at [email protected] and we will direct your request to the appropriate venue operator within 5 business days.

You can opt out of marketing messages at any time using the unsubscribe link in any email or by replying STOP to any SMS. WhatsApp campaigns include instructions for opting out. Opt-out requests are processed within 24 hours.

Supervisory Authority

If you believe your rights have not been respected, you have the right to lodge a complaint with the relevant supervisory authority in your country — including the Office of the Data Protection Commissioner (Kenya), the Nigeria Data Protection Commission (NDPC), or the Data Protection Commission (Ghana).

Section 12

Cookies & Tracking Technologies

We use cookies and similar technologies on centipidmarketing.com and the Centipid dashboard. We do not use third-party advertising cookies. Our captive portal pages use minimal session cookies necessary to authenticate the WiFi session.

Cookie TypePurposeDuration
Session cookiesMaintaining your login session in the dashboardSession
Authentication tokens"Remember me" functionality for dashboard login30 days
CSRF tokensSecurity — preventing cross-site request forgery attacksSession
Preference cookiesStoring dashboard display preferences (timezone, language)1 year
Analytics (Google Analytics)Marketing website only — page views, source tracking2 years (opt-out available)
Portal session cookieTracks WiFi authentication state for the end user's sessionSession or as configured

You can control cookies through your browser settings. Disabling cookies may affect the functionality of the Centipid dashboard. The captive portal session cookie is strictly necessary for WiFi authentication and cannot be disabled without affecting network access.

Section 13

Children's Privacy

Centipid's platform is not directed at children under the age of 13 (or 16 where required by applicable law). We do not knowingly collect personal data from children. If you are a venue operator and believe that children may use your WiFi, you are responsible as data controller for implementing age-appropriate consent mechanisms on your captive portal.

If we become aware that we have collected personal data from a child without appropriate parental consent, we will delete that data promptly. Contact [email protected] if you have concerns.

Section 14

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Send an email notification to all registered platform users at least 14 days before the changes take effect.
  • Display a notice on the Centipid dashboard when you next log in.

For significant changes that affect the legal basis or purposes of processing, we will seek fresh consent where required. Your continued use of the platform after the effective date constitutes acceptance of the updated policy.

Section 15

Contact & Data Protection Officer

For any questions, concerns, or requests relating to this Privacy Policy or to your personal data, please contact us:

Get in touch about privacy

We take data protection seriously. Our Data Protection Officer responds to all enquiries within 5 business days. For urgent matters — including suspected breaches — please mark your subject line URGENT.