Privacy Policy
This Privacy Policy explains how Esposearch Limited may collect, use, store, disclose and protect personal information when you use Esposearch.net, purchase services, request projects, communicate with us or otherwise interact with Esposearch.
Please read this Policy to understand how your personal information may be handled.
A practical framework for how personal information is handled.
Esposearch processes information needed to operate the website, provide services, administer projects and transactions, support customers, coordinate technicians, maintain security and meet lawful business obligations.
Available privacy rights and legal requirements can differ by jurisdiction and processing context. This Policy therefore distinguishes Esposearch’s own business processing from customer-controlled website data handled during service delivery.
We Collect for Defined Purposes
Information should be processed for website operation, services, support, transactions, security and lawful administration.
We Limit Access
Personal information should be available only to people and providers who reasonably need it for the relevant purpose.
We Use Third-Party Services
Hosting, payments, communication, analytics, AI, security and other providers may process information where functionality requires it.
You May Have Privacy Rights
Depending on applicable law, rights may include access, correction, deletion, restriction, portability, objection or other available choices.
Privacy Policy navigation
1. Scope of This Privacy Policy
This Privacy Policy applies to personal information processed in connection with Esposearch.net and Esposearch activities involving website visitors, prospective customers, customers, account users, people purchasing services, people requesting Custom Projects, people contacting support, Live Chat users, Academy participants where applicable, technicians and independent contractors, applicants, suppliers and professional contacts.
Some services used through Esposearch.net are provided by independent third parties. Those providers may process personal information under their own privacy policies and legal responsibilities.
2. Who We Are
Esposearch Limited operates Esposearch.net as a specialist WordPress & AI services agency. Esposearch Limited is a private limited company incorporated in Kenya on 13 May 2021 under the Companies Act, 2015.
Public Company Number: PVT-9X••••27
Registered Address: K.K. Building, Church Road, P.O. Box 222, Gilgil, Nakuru County, Kenya 20116
Website: https://esposearch.net/
Email: admin@esposearch.net
Kenya is Esposearch Limited’s principal legal and business base. The fact that Esposearch serves international customers does not by itself mean that Esposearch has an office or establishment in another country.
3. Our Privacy Roles
Esposearch may have different privacy roles depending on the activity.
Esposearch as a controller
Esposearch generally determines why and how personal information is processed for its own website, customer accounts, enquiries, transactions, business records, marketing where used, technician administration, analytics, security, compliance and service administration.
Esposearch as a processor or service provider
During some customer projects, Esposearch may process personal information contained in a customer-controlled website, database, CRM, WooCommerce store, mailing system or other environment on the customer’s instructions. Where applicable, that processing should follow the confirmed project scope, lawful customer instructions, confidentiality requirements and any required data-processing terms.
4. Information We May Collect
Depending on how you interact with Esposearch, personal information may include:
- Identity information: name, username, organization and account identifiers.
- Contact information: email address and business contact details.
- Account information: profile information, settings, authentication and account activity.
- Service and project information: services selected, project requirements, website URLs, quotations, communications, deliverables and support history.
- Technical information: IP address, browser, device, operating system, logs, session information and security events.
- Transaction information: order information, transaction identifiers, amount, currency, payment status and billing information made available through the transaction process.
- Communications: email, Live Chat, support messages, enquiries and feedback.
- Professional information: where relevant to technicians, contractors or applicants, skills, experience, capability information, work history and engagement records.
- Compliance and business records: invoicing, contractual records, dispute records, accounting information and documentation required by law.
Esposearch should not collect a category of personal information merely because it appears in this list. Actual collection depends on the relevant interaction, service and system in use.
5. Sensitive Personal Information
Esposearch does not generally seek sensitive personal information unless it is reasonably necessary for a legitimate, lawful purpose. You should avoid sending unnecessary health information, biometric information, government identifiers, financial credentials, passwords, political or religious information, or similarly sensitive data through ordinary website or support channels.
Where sensitive information is genuinely required, it should be processed only for the applicable purpose and in accordance with legal requirements that apply to the circumstances.
6. How Information Is Collected
Esposearch may collect information:
- Directly from you through registration, checkout, service purchases, Custom Project requests, Live Chat, email, support, Academy participation or technician/contractor engagement.
- Automatically through server logs, cookies, analytics, security systems and website-performance technologies.
- From third parties such as payment providers, hosting or infrastructure providers, authorized customer representatives, referral sources, authentication services or publicly available professional/business sources where lawful and relevant.
Esposearch does not state that it purchases personal-data marketing lists unless such a practice is actually adopted and disclosed.
7. WordPress Service & Project Data
Delivering WordPress and related website services may require information about a customer website, including the website URL, WordPress configuration, themes, plugins, hosting environment, error logs, screenshots, website content, technical documentation and project communications.
Some customer-controlled websites may contain personal information about the customer’s own users, customers, employees, subscribers or other individuals. Esposearch should access only the information reasonably necessary for the agreed work and follow the customer’s lawful instructions where Esposearch acts on the customer’s behalf.
Additional rules concerning customer-submitted project materials are described in Content Privacy.
8. Account & Authentication Data
Where an Esposearch account is used, Esposearch may process registration details, username or account identifiers, security-related information, account settings and activity needed to provide or protect account functionality.
You are responsible for keeping credentials confidential and should notify Esposearch if you reasonably suspect unauthorized account access. Esposearch may process security logs or authentication information to investigate misuse, protect accounts and maintain website integrity.
9. Technician, Freelancer & Contractor Data
Esposearch may engage technicians, consultants and other service personnel on a Freelancer / independent-contractor basis. In that context, Esposearch may process identity and contact information, professional experience, skills, capability evidence, contractual records, payment and tax-administration information, assignment information, communications and service-performance records.
When a technician or Freelancer is assigned customer work, they may receive limited customer, website or project information that is reasonably necessary for the assignment. They must not use that information for unrelated purposes and may be subject to contractual confidentiality, Esposearch instructions and applicable data-protection obligations.
This personnel model does not give customers a right to select or directly manage individual technicians.
10. Payment & Transaction Data
Payment processing may involve independent payment providers. Depending on the payment method and integration, the provider may collect payment credentials directly, while Esposearch may receive transaction identifiers, amount, currency, order status, billing information and payment-provider response information.
Esposearch does not make a blanket statement that it never handles payment credentials because the technical handling can depend on the payment method and integration in use. Payment providers operate under their own privacy, security and legal terms.
Esposearch may retain transaction and accounting records where reasonably necessary for service administration, financial reporting, taxation, dispute handling or legal compliance.
11. Website Access & Credentials
Customer services may require authorized access to WordPress, hosting, domain or DNS controls, WooCommerce, analytics, Search Console, email systems, APIs or related services.
Customers should provide only the access reasonably necessary for the agreed work, use temporary or restricted credentials where practical, avoid posting credentials publicly and revoke or change access after completion where appropriate.
No internet-based system or credential-handling process can be guaranteed completely secure.
12. Live Chat & Customer Support
Live Chat and support interactions may involve your name, contact details, website URL, conversation content, technical details, support context and device or session information processed by the chat or support technology in use.
Live Chat is intended primarily for service guidance and general support. Do not use it to send passwords, full payment-card information, secret API keys or unnecessary sensitive identity information.
For formal privacy-rights requests, email or the Contact page is preferable because Esposearch may need a clearer record of the request and proportionate identity verification.
13. Cookies & Similar Technologies
Esposearch.net may use cookies or similar technologies for purposes such as essential website operation, authentication, preferences, shopping or transaction functionality, security, fraud prevention, analytics, performance, customer support/chat and marketing technologies where implemented.
Where applicable law requires consent before non-essential technologies are used, the website implementation should provide the required notice, consent or controls. The presence of this Privacy Policy alone does not create compliant cookie consent.
Cookie statements should be reviewed against the technologies actually deployed on Esposearch.net and updated if the site’s providers or advertising practices materially change.
14. Analytics & Website Performance
Esposearch may process website-usage and technical data to understand traffic, page usage, user journeys, errors, compatibility, security events and performance. This information may help identify problems, improve website structure and support service reliability.
Where third-party analytics or monitoring providers are used, they may process information under their own terms, privacy arrangements and international-transfer mechanisms.
15. Marketing Communications
Where permitted by applicable law, Esposearch may send newsletters, service updates, relevant offers or other marketing communications. Where required, marketing will be based on an appropriate legal basis and users should have available unsubscribe or opt-out mechanisms.
Transactional messages, account notices, security alerts, project communications and service-delivery messages are not necessarily optional marketing where they are reasonably necessary for the requested service or relationship.
16. How We Use Personal Information
Esposearch may use personal information to:
- operate, secure and improve Esposearch.net;
- create and manage accounts;
- process service purchases and transaction records;
- review service requirements and administer Custom Projects;
- communicate with customers and provide support;
- coordinate technicians and service delivery;
- deliver WordPress and AI website services;
- administer payments, tax and accounting records;
- detect fraud, misuse and security incidents;
- troubleshoot technical systems;
- administer Academy offerings where applicable;
- resolve disputes and enforce agreements;
- comply with legal obligations and defend legal rights; and
- send marketing where lawfully permitted.
Esposearch should not use personal information for an unrelated purpose without an appropriate legal basis, notice or other requirement where applicable law requires one.
17. Legal Bases for Processing
Where applicable law requires Esposearch to identify a legal basis for processing, the basis may depend on the activity. Examples can include:
- Contract: processing reasonably necessary to enter into or perform a service agreement.
- Legal obligation: processing needed for tax, accounting, court, regulatory or other lawful duties.
- Legitimate interests: where applicable and not overridden by individual rights, such as operating, securing and improving services, administering business relationships or preventing fraud.
- Consent: where consent is the appropriate legal basis and can lawfully be relied upon.
- Other lawful grounds: where another basis is genuinely applicable to the circumstances.
Not every legal basis applies to every processing activity.
18. Data Minimization & Accuracy
Esposearch aims to collect and use information that is reasonably necessary for the relevant website function, service, transaction, project, support request, legal obligation or legitimate business purpose.
Customers should avoid submitting unnecessary personal data when providing website databases, exports, support files or project materials. Where practical, test, masked or demo data should be used instead of unnecessary production personal information.
Esposearch also seeks to maintain personal information that is reasonably accurate, current and relevant for the purpose for which it is used, subject to information supplied by users and lawful retention requirements.
19. Sharing & Categories of Recipients
Depending on the activity, Esposearch may disclose or make personal information available to assigned technicians or contractors, hosting and infrastructure providers, payment providers, communication providers, security or fraud-prevention providers, analytics providers, professional advisers, accountants, auditors, regulators, courts, law-enforcement bodies where legally required, or a lawful business successor.
Sharing should be limited to information reasonably necessary for the relevant purpose. Esposearch does not state that it “never shares” personal information because service delivery and website operation can require carefully controlled third-party processing.
Sale, Sharing & Targeted Advertising
Esposearch does not intend to sell personal information as a standalone commercial product.
However, privacy laws in some jurisdictions define “sale,” “sharing,” targeted advertising or similar concepts more broadly than an ordinary commercial sale. Esposearch should evaluate actual analytics, advertising and third-party technology practices before making jurisdiction-specific representations.
If Esposearch later conducts processing that creates a statutory opt-out right, the website should implement the disclosures and controls required by the applicable law. This Policy does not create a fake “Do Not Sell” control where one is not legally required or technically implemented.
20. Service Providers & Processors
External vendors may process personal information on Esposearch’s behalf or as independent controllers, depending on the provider and service. Where appropriate to Esposearch’s role and the risk involved, Esposearch may use contractual, organizational or technical measures intended to limit processing to appropriate purposes and protect information.
Vendor relationships should be reviewed proportionately to risk. If enterprise customers require more detailed transparency, Esposearch may provide or maintain additional service-provider or subprocessor information where appropriate.
21. International Processing & Data Transfers
Esposearch serves customers in multiple countries and may use service providers operating in jurisdictions different from Kenya or from the location of the individual. Personal information may therefore be processed or stored outside your country.
Depending on the legal framework, appropriate measures may include contractual safeguards, recognized transfer mechanisms, adequacy arrangements, consent where valid, or another legally permitted approach. Esposearch does not represent that every destination country provides identical privacy protection.
22. AI & Personal Information
Esposearch’s use of AI
Where Esposearch uses AI tools to support drafting, analysis, technical work, customer support or service delivery, customer or personal information should be submitted only where appropriate to the task and consistent with relevant confidentiality, provider terms and privacy obligations.
Customer AI implementations
When Esposearch implements AI functionality for a customer-controlled website, the customer may remain responsible for its own users’ privacy notices, lawful basis and related legal obligations, while Esposearch may act as a processor or service provider for the project where applicable.
AI providers may have their own retention, model-improvement, security and international-processing practices. The applicable provider and configuration should therefore be assessed when a project materially involves personal information.
Automated Decision-Making & Profiling
Esposearch does not intend to rely solely on automated processing to make decisions that produce legal or similarly significant effects on individuals unless such processing is lawfully implemented and appropriate notices, rights and safeguards are provided where required.
If Esposearch later introduces materially significant automated decision-making, profiling or AI-assisted screening, the relevant processing should be reviewed before deployment for applicable transparency, objection, human-review and other requirements.
23. Data Retention
Esposearch retains personal information for periods reasonably necessary for the purpose for which it was collected and for related legal, accounting, contractual, dispute-resolution, fraud-prevention, security or legal-claims needs.
Retention can depend on the data category, service relationship, transaction history, legal requirements, applicable limitation periods, project needs and security considerations. Esposearch does not use one arbitrary retention period for every category of information.
When information is no longer reasonably required, it should be deleted, anonymized or otherwise handled in accordance with applicable obligations and legitimate record-keeping needs.
24. Security Safeguards
Esposearch seeks to use reasonable administrative, organizational and technical safeguards appropriate to the circumstances. Measures can include access controls, authentication, least-privilege practices, backups, security monitoring, confidentiality obligations, software maintenance and use of security-conscious service providers.
Security practices may evolve as systems, risks and services change. This Policy does not disclose detailed internal security architecture.
25. Personal-Data Breaches
If Esposearch becomes aware of a personal-data breach affecting information for which it has responsibility, Esposearch may investigate, contain, document and remediate the incident and may notify affected customers, individuals, controllers or regulators where applicable law requires notification.
The appropriate response depends on Esposearch’s privacy role, the type of information, the nature of the incident and applicable law. This Policy does not hard-code one notification deadline for every jurisdiction or circumstance.
26. Privacy Rights Under Kenyan Law
Where Kenya’s data-protection law applies, an individual may have rights including the right to be informed about the use of personal data, access personal data, object to processing, seek correction of false or misleading information and seek deletion in applicable circumstances. Additional rights such as portability or restriction may also apply where provided by law.
Privacy rights are subject to the conditions, exceptions and verification requirements of the applicable law. Esposearch may need information reasonably necessary to verify identity and locate the relevant records before responding to a request.
27. Jurisdiction-Specific Privacy Rights
United Kingdom and European Economic Area
Where UK GDPR, EU GDPR or related law applies, individuals may have rights such as access, rectification, erasure, restriction, objection, portability, withdrawal of consent and rights concerning certain automated decisions, subject to applicable conditions and exceptions.
Canada
Where PIPEDA or applicable provincial privacy law applies, individuals may have rights relating to transparency, access, correction, consent and challenging an organization’s compliance, subject to the law that applies.
Australia
Where the Australian Privacy Act and Australian Privacy Principles apply, individuals may have rights or processes relating to transparency, access, correction, complaints and appropriate handling of personal information, including relevant cross-border requirements.
United States
Privacy rights vary by state. If Esposearch becomes subject to an applicable U.S. state privacy law, qualifying individuals may have rights such as access or knowledge, correction, deletion, opt-out rights for legally defined sale/sharing or targeted advertising, limits on certain sensitive-information uses, and protection against unlawful discrimination or retaliation for exercising covered rights.
28. Exercising Your Privacy Rights
To make a formal privacy request, email admin@esposearch.net or use the Contact page. Describe the nature of your request and provide enough account, order or transaction context to help Esposearch identify the relevant records.
Esposearch may need to verify identity before fulfilling certain requests. Verification should be proportionate to the sensitivity of the information and the risk of unauthorized disclosure.
Do not send passwords, full payment-card information or unnecessary government identifiers through ordinary email or Live Chat merely to verify a privacy request.
29. Children & Young People
Esposearch’s commercial WordPress and AI website services are not directed specifically at young children. However, Academy, educational, CSR or other program activities may have different participation rules.
Where a program permits participation by a minor, additional notices, consent, guardian involvement or other protections may apply depending on the program and applicable law. If you believe personal information relating to a child has been submitted inappropriately, contact Esposearch for review.
30. Third-Party Websites & External Services
Esposearch.net may link to software vendors, hosting providers, payment services, training providers, social platforms or other external websites. Esposearch does not control their privacy practices, security, availability or legal terms.
Review the external provider’s own privacy policy before providing personal information to that provider.
31. Business Transfers & Legal Disclosures
Personal information may be transferred or reviewed as part of a lawful merger, acquisition, restructuring, financing, sale of assets or similar business transaction, subject to applicable confidentiality and legal requirements.
Esposearch may also disclose information where reasonably necessary to comply with law or lawful process, respond to a competent authority, investigate fraud or misuse, protect users or systems, establish or defend legal claims, or protect Esposearch’s legal rights.
This does not create an unrestricted right to disclose personal information to authorities or third parties without an appropriate legal basis.
33. Changes to This Privacy Policy
Esposearch may update this Privacy Policy to reflect changes in services, technologies, providers, legal requirements, processing practices or security needs. The revised page should display an updated date.
Where applicable law requires additional notice for a material change, Esposearch should use an appropriate method of notice. Updating this page does not by itself remove rights or obligations that applicable law does not permit Esposearch to change unilaterally.
34. Privacy Questions & Requests
For privacy questions or formal privacy-rights requests, contact:
Esposearch Limited
Private Limited Company incorporated in Kenya
Public Company Number: PVT-9X••••27
Registered Address: K.K. Building, Church Road, P.O. Box 222, Gilgil, Nakuru County, Kenya 20116
Website: https://esposearch.net/
Email: admin@esposearch.net
Contact: https://esposearch.net/contact/
Live Chat may be used for general privacy clarification. For formal access, correction, deletion, objection, portability or similar rights requests, email or the Contact page is preferable. Do not send sensitive verification information through Live Chat unless Esposearch provides an appropriate secure process.
Where applicable law gives you a right to complain to a competent privacy or data-protection authority, you may exercise that right. In Kenya, the Office of the Data Protection Commissioner is the national data-protection authority.
Use the right document for the question you need answered.
Need clarification about your personal information?
If you have a general question about how Esposearch handles information, contact us for clarification. For formal access, correction, deletion or other privacy-rights requests, email Esposearch and provide enough information for us to identify the relevant account, transaction or project.
For general privacy clarification, you may also . Do not submit sensitive identity-verification information through chat.