Privacy Policy
Effective Date: August 27, 2026
Domain Scope: ramco-group.com and associated digital properties of Ramco Group Limited.
- Overview and Data Controller Identity
Ramco Group Limited and its affiliated operating entities (“Ramco Group”, “we”, “us” or “our”) act as Data Controllers for personal data collected through ramco-group.com and related corporate services.
This Privacy Policy describes how we collect, use, disclose, retain and protect your personal data in compliance with:
- The Kenya Data Protection Act, 2019 (Act No. 24 of 2019)
- The Kenya Data Protection (General) Regulations, 2021
- The Kenya Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021
- The Kenya Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021
- International privacy frameworks, including the EU General Data Protection Regulation (GDPR) for international visitors
- Information We Collect
We collect personal data that you provide directly, data collected automatically during website visits, and information obtained from verified commercial channels.
2.1 Information You Provide Directly
- Commercial and Business Inquiries: Full name, business email address, direct phone number, company name, job title, and the content of your message.
- Vendor and Procurement Applications: Contact details, tax identification numbers (KRA PIN), business registration certificates, director identity records, and bank account information.
- Recruitment and Job Applications: CVs, cover letters, academic transcripts, professional certifications, government identification numbers, employment history, and referee contact details submitted via our career’s portal.
- Newsletter and Event Subscriptions: Email address and communication preferences.
2.2 Information Collected Automatically
- Technical and Network Data: Internet Protocol (IP) address, browser type and version, operating system, device manufacturer, screen resolution and time zone setting.
- Usage and Telemetry Data: Uniform Resource Locators (URLs) visited, clickstream activity, page response times, download errors and duration of page visits.
- Cookies and Tracking Technologies: Data collected through cookies as described in our Cookie Policy.
- Lawful Bases for Processing
In accordance with Section 30 of the Kenya Data Protection Act, 2019, and Article 6 of the GDPR, we process personal data under the following lawful bases:
Processing Activity | Categories of Personal Data | Lawful Basis (Kenya DPA 2019 / GDPR) |
Responding to commercial inquiries and quotation requests | Name, business email, telephone, company name | Contractual Necessity (Steps prior to entering a contract) |
Processing customer orders and supply chain contracts | Financial data, commercial contacts, delivery addresses | Performance of a Contract |
Supplier and vendor onboarding, due diligence, and KYC | Registration records, KRA PIN, bank details, identification | Legal Obligation and Contractual Necessity |
Processing job applications and career candidate evaluation | CVs, educational history, referee data, identity numbers | Legitimate Interests and Consent |
Distributing corporate newsletters and marketing updates | Name, email address | Consent (Withdrawable at any time) |
Website security, DDoS prevention, and fraud monitoring | IP address, access logs, device parameters | Legitimate Interests (Securing digital infrastructure) |
Statutory tax reporting and regulatory compliance | Transaction records, payment histories, invoice data | Legal Obligation (Kenyan tax and corporate laws) |
- Intra-Group Sharing and Third-Party Disclosures
Ramco Group operates across diversified industrial verticals, including Print & Packaging, Hardware & Building Materials, Manufacturing, Office & IT Distribution, Renewable Energy and Real Estate. We share personal data under strict data governance protocols.
4.1 Intra-Group Transfers
We share personal data with our corporate parent entity and regional subsidiaries (such as Ramco Printing Works, ASL Limited, Sai Office Supplies, Platinum Packaging, and Kentainers) when necessary to fulfil your commercial orders, service inquiries or group-wide recruitment evaluations. All Group companies adhere to centralised data protection standards.
4.2 Third-Party Service Providers
We engage verified third-party vendors who process personal data on our behalf under binding Data Processing Agreements (DPAs):
- Cloud Infrastructure Providers: Enterprise cloud hosting and data storage services, such as Microsoft Azure, AWS and Google Cloud.
- Enterprise Software Vendors: Customer relationship management (CRM) and enterprise resource planning (ERP) platforms.
- Professional Advisors: External legal counsel, statutory auditors, tax consultants and financial institutions.
4.3 Legal and Regulatory Disclosures
We disclose personal data when required by law, court order or formal request from statutory bodies, including the Office of the Data Protection Commissioner (ODPC), the Kenya Revenue Authority (KRA), the Ethics and Anti-Corruption Commission (EACC) or law enforcement agencies.
- Cross-Border Data Transfers
When transferring personal data outside Kenya, we comply with Sections 48 and 49 of the Kenya Data Protection Act, 2019. We ensure that one of the following safeguards applies:
- The destination country has received a formal adequacy finding from the ODPC.
- The transfer is governed by Standard Contractual Clauses (SCCs) approved by the ODPC or international supervisory bodies.
- The transfer is necessary for the performance of a contract entered into at your request.
- You have provided explicit consent after receiving clear notice of the transfer risks.
- Data Retention Schedules
We retain personal data only for the period necessary to fulfil the purposes outlined in this policy, unless a longer retention period is mandated by Kenyan statutory law:
- Commercial Contracts and Invoices: Retained for 7 years following transaction completion in compliance with the Kenyan Companies Act and tax regulations.
- Customer and Vendor Contact Data: Retained for the duration of the commercial relationship plus 3 years.
- General Website Inquiries: Retained for 12 months following inquiry resolution.
- Unsuccessful Job Applications: Retained for 6 months after the recruitment cycle concludes, or up to 2 years if you consent to inclusion in our talent pool.
- Server and Security Logs: Retained for 90 days, then overwritten or securely deleted.
- Data Subject Rights
Under Part IV of the Kenya Data Protection Act, 2019 and Chapter III of the GDPR, you hold the following rights:
- Right to Be Informed: You have the right to know how your personal data is collected, used and shared.
- Right of Access: You can request copies of the personal data we hold about you.
- Right to Rectification: You can request correction of inaccurate, misleading or incomplete records.
- Right to Erasure (Right to Be Forgotten): You can request deletion of personal data where no legal ground justifies continued processing.
- Right to Object: You can object to data processing based on legitimate interests or direct marketing.
- Right to Data Portability: You can request your data in a structured, commonly used and machine-readable format.
- Right to Restrict Processing: You can request suspension of processing while an accuracy or objection claim is verified.
- Right to Withdraw Consent: Where processing relies on consent, you may withdraw it at any time without affecting past processing legality.
How to Exercise Your Rights
To submit a Data Subject Access Request (DSAR), email our Data Protection Officer at privacy@ramco-group.com. We verify your identity and respond within the statutory 30-day window under the Kenya Data Protection Regulations.
- Technical and Organisational Security Measures
In accordance with Section 41 of the Kenya Data Protection Act, 2019, we implement technical and physical controls to safeguard personal data against unauthorised access, loss, alteration or destruction:
- Encryption: Transport Layer Security (TLS 1.3) protocols for data in transit and Advanced Encryption Standard (AES-256) for data at rest.
- Access Governance: Multi-Factor Authentication (MFA), strict Role-Based Access Control (RBAC) and principle of least privilege access rules.
- Audits and Vulnerability Management: Regular vulnerability scans, perimeter firewall configurations and independent third-party security audits.
- Incident Response: A formal incident management protocol. In the event of a reportable data breach involving high risk to your rights, we notify the ODPC within 72 hours and affected individuals without undue delay (Section 43 DPA 2019).
- Right to Lodge a Regulatory Complaint
If you believe that our processing of your personal data violates the Kenya Data Protection Act, 2019, you have the right to lodge a formal complaint with the supervisory authority:
- Authority: Office of the Data Protection Commissioner (ODPC)
- Physical Address: Britam Tower, 12th Floor, Hospital Road, Upper Hill, Nairobi, Kenya
- Postal Address: P.O. Box 30920-00100, Nairobi, Kenya
- Updates to This Privacy Policy
We update this Privacy Policy periodically to reflect changes in our operations and regulatory requirements. Revisions take effect upon publication on this page, with the “Last Updated” date updated accordingly.
- Contact Details
For inquiries, data requests or privacy concerns, please contact our Data Protection Officer:
- Entity: Ramco Group Limited
- Attention: Data Protection Officer
- Physical Address: Ramco Group Headquarters, Nine Grove, Grevillea Grove, off Westlands / Spring Valley Road, Nairobi, Kenya
- Postal Address: P.O. Box 18092-00500, Nairobi, Kenya
- Telephone: +254 739 808 080 / +254 20 205 4139
- Corporate Website: ramco-group.com