Privacy Policy for Yard
Published: 1 August 2026 | Last updated: 1 August 2026
This policy explains how Hamilton Technologies Limited ("Hamilton", "we", "us") handles personal data in connection with Yard, our service business management platform for trade businesses. It is written to meet our obligations under the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021, which are overseen by the Office of the Data Protection Commissioner (ODPC).
Who to contact
Data controller: Hamilton Technologies Limited, company number [company registration number], [registered office address, Nairobi]
ODPC registration: [data controller / processor registration number]
Data protection contact: support@hamilton.ke · [phone]
1. Our two roles
Yard is used by businesses to run their own operations, so who is responsible for what depends on the data:
We are a data processor for the data a business puts into Yard about its own technicians and clients. The business that entered the data is the data controller: it decides what to record, why, and for how long, and it is responsible for informing those people. We process it only on that business's instructions, under the data processing terms in Annex A of our Terms of Service. If you are a technician or a client and want to know why your data is held, contact the business you worked for or bought from; we will pass your request on to them.
We are a data controller for the data we need to run Yard as a product: account and login data for owners and supervisors, billing records, support correspondence, security and audit logs, and product usage analytics. The rest of this policy describes that processing, and also tells technicians and clients what happens to their data while it is in our systems.
2. Personal data we handle
2.1 Account users (owners and supervisors). Name, email address, password (stored only as a salted hash), business and role memberships, supervisor invitation status and reporting line, national identification number where a business records it for a supervisor, and account preferences.
2.2 Technicians (recorded by a business; technicians are not users of Yard). Name, national identification number, date of birth, phone number, the supervisor they are assigned to and the history of those assignments, the jobs performed, and commission and payout figures.
2.3 Clients of a business. Name, phone number, job details and location or description as entered, order times and status history, amount paid and payment mode (cash, card or mobile money).
2.4 Billing data. Business name and address, KRA PIN, contact person, invoices and payment references. We do not store full card numbers; card and mobile money payments are handled by our payment provider.
2.5 Technical and usage data. IP address, device and app version, timestamps, pages and API endpoints used, error diagnostics, and audit records of who created or changed an order, technician, supervisor or service.
2.6 Communications. Support emails and messages, and (where you have opted in) marketing preferences.
We do not ask for special categories of personal data — such as health, biometric or genetic data — and businesses must not enter them into Yard.
3. Why we use it, and our lawful basis
Where we act as a controller, we rely on the lawful bases set out in section 30 of the Data Protection Act, 2019:
| Purpose | Lawful basis |
|---|---|
| Creating and managing accounts; providing the Service to a business under our Terms | Performance of a contract |
| Invoicing, collecting fees, keeping tax records | Contract; legal obligation (Tax Procedures Act) |
| Security, fraud prevention, audit logging, abuse investigation | Legitimate interests in protecting the Service and its users |
| Support, service notices, diagnosing faults | Contract; legitimate interests |
| Improving Yard using aggregated, de-identified usage data | Legitimate interests |
| Marketing emails about Yard to business contacts | Consent (withdrawable at any time) |
| Responding to lawful requests from courts or regulators | Legal obligation |
We do not sell personal data, and we do not use it for automated decision-making that produces legal effects for anyone. Commission and payout figures are arithmetic based on rates a business configures; a person always decides what is paid.
4. Who we share it with
We share personal data only with: the business whose account the data belongs to, and its authorised users according to their role; our service providers acting on our instructions (hosting, email delivery, SMS, error monitoring, payment processing, accounting); our professional advisers under duty of confidentiality; and courts, regulators or law enforcement where we are legally required to. If our business is reorganised, sold or merged, data may transfer to the acquirer subject to this policy. A current list of our processors is published at [subprocessor list URL].
Yard enforces tenant isolation: one business cannot see another business's technicians, clients or orders.
5. Where data is stored, and transfers outside Kenya
Yard is hosted on Google Cloud Platform in the europe-west1 region (Belgium), so personal data in Yard is stored and processed outside Kenya. Our support and engineering teams access it from Kenya.
We make these transfers in accordance with sections 48 and 49 of the Data Protection Act, 2019 and Part VI of the Data Protection (General) Regulations, 2021, on the following basis:
— The destination is within the European Union, where processing is subject to the EU General Data Protection Regulation, which provides a level of protection comparable to Kenyan law;
— our contract with the hosting provider contains appropriate data protection safeguards, including data processing terms, security commitments and restrictions on onward transfer;
— data is encrypted in transit and at rest, and access is limited to authorised personnel; and
— we have documented a transfer assessment recording the above, which we will make available to the ODPC or to a business customer on request.
Where a business customer needs data residency in Kenya for a category of data subject to Kenyan localisation requirements, contact us at support@hamilton.ke before entering that data.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and business data | While the account is active; deleted or anonymised within 90 days after the 30-day post-termination export window |
| Archived (soft-deleted) technician, supervisor and service records | Retained while the account is active so historical orders and payouts stay intact; deleted with the account |
| Order, payment and payout records | Per the business's own retention decision; we hold them for the life of the account |
| Invoices and tax records | 7 years (Tax Procedures Act, 2015) |
| Security and audit logs | [12] months |
| Backups | [35] days, then overwritten |
| Support correspondence | 24 months after the ticket closes |
7. How we protect it
We use encryption in transit (TLS) and at rest, salted password hashing, JSON Web Token sessions and time-limited single-use supervisor invitation links, role-based access control with tenant isolation, least-privilege administrative access protected by multi-factor authentication, audit logging of order and record changes, managed backups, and regular patching and access reviews. No system is perfectly secure, so we also keep an incident response process and review our measures periodically.
8. If something goes wrong
If a personal data breach occurs, we will notify the Data Commissioner within 72 hours of becoming aware of it where the breach carries a real risk of harm, as required by section 43 of the Act, and notify affected data subjects and business customers without undue delay. Where we act as a processor for a business, we will notify that business within 48 hours so it can meet its own obligations.
9. Your rights
Under section 26 of the Act you have the right to be informed of how your data is used; to access your data; to object to its processing; to have inaccurate or misleading data corrected; and to have it deleted where we have no lawful reason to keep it. You may also withdraw consent where we rely on it, ask us to restrict processing while a dispute is resolved, and request a portable copy of data you gave us.
To exercise a right, email support@hamilton.ke. We may ask for enough information to verify your identity. We respond free of charge within 7 days of receiving a request where practicable, and in any event within the timeframes set by the Data Protection (General) Regulations, 2021, telling you if we need longer and why.
If your data is in a business's Yard account — for example as a technician or a client — that business decides these questions, and we will forward your request to it and support it in responding.
10. Children
Yard is not intended for anyone under 18. Accounts require an adult, and the Service rejects a technician record whose date of birth indicates the person is under 18. If you believe we hold a child's data, contact us and we will delete it.
11. Cookies and similar technologies
The Yard web application uses strictly necessary cookies and local storage to keep you signed in and to remember interface preferences. [If analytics or marketing cookies are used on hamilton.ke or the Yard site, name the tools here and describe the consent banner.] The mobile applications use device identifiers only for crash reporting and app updates.
12. Complaints
Please raise any concern with us first at support@hamilton.ke — we would rather fix it directly. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner: [confirm current ODPC address, phone and complaints portal at odpc.go.ke].
13. Changes to this policy
We will post any update here with a new version number and effective date, and for material changes we will notify account users by email or in the Service at least 30 days in advance.
14. Contact
Hamilton Technologies Limited · [registered office address, Nairobi] · support@hamilton.ke