Esthrema

Privacy Policy

Last updated: August 11, 2026

1. Overview & Who We Are

Esthrema ("Esthrema," "we," "us," or "our") is a business systems engineering practice operated from Nairobi, Kenya, and operating internationally on a remote basis. Esthrema is not yet formally incorporated; for the purposes of applicable data protection law, its operator acts as the data controller for the personal data described in this Policy.

This Policy explains what personal data we collect through esthrema.com and in the course of our sales and client relationships, why we collect it, who we share it with, and the choices and rights available to you. It applies to visitors, enquirers, prospective clients we contact directly, and clients, regardless of where you are located.

2. Information We Collect

The information we collect depends on how you interact with us:

We do not knowingly collect payment card details, government ID numbers, or other sensitive category data through the Site.

3. How We Collect It

We collect information directly from you (via forms, email, calls, or messaging apps), from your use of the Site, and — where we conduct outreach to businesses that may benefit from our services — from publicly available business contact information (e.g., a business's public Instagram or website contact details) that we use to initiate first contact.

5. How We Use Information

6. Cold Outreach & Marketing

As part of our sales process, we may initiate contact with businesses we believe could benefit from our services, including via direct message on platforms such as Instagram, or by email. Where required by applicable law (such as GDPR or PECR for EU/UK recipients, or CAN-SPAM for other jurisdictions), such outreach will identify Esthrema as the sender and provide a way to opt out.

You can stop receiving outreach or marketing messages from us at any time by replying "stop," unsubscribing via any link provided, or emailing info@esthrema.com. We will honor opt-out requests promptly and will not use unsubscribe requests as a basis for further contact beyond confirming the request.

7. Cookies & Analytics

The Site does not hardcode an analytics tracking ID by default. Where Google Analytics 4 (or a similar tool) is enabled, it may use cookies or similar browser storage to collect usage data such as pages viewed and general location. You can control cookies through your browser settings, and where required by law, we will request consent before enabling non-essential analytics or advertising cookies for visitors in jurisdictions that require it (e.g., the EU/UK).

8. Third-Party Services & Sharing

We do not sell personal data. We share information with service providers who process it on our behalf to help us operate, including:

Provider / CategoryPurpose
GoHighLevel (CRM & automation)Receiving and managing website lead submissions, client communications, and automated workflows
Vercel (hosting)Hosting the website, serverless form endpoint, and related security/diagnostic logs
Upstash Redis (if configured)Durable form rate limiting using hashed request identifiers
Google Analytics (if enabled)Website usage analytics
WhatsApp Business / MetaMessaging with leads and clients who contact us via WhatsApp or Instagram
Email & calendar providersCorrespondence and scheduling

These providers are only permitted to use your information as necessary to provide their service to us. We may also disclose information where required by law, to protect our rights, or in connection with a business transfer (e.g., if Esthrema is later incorporated, sold, or restructured).

9. International Data Transfers

Esthrema operates from Kenya and works with international clients and service providers, which means personal data may be processed in countries other than your own, including the United States and countries within the EU/UK, where our hosting, CRM, and communication tools are based. Where we transfer personal data of individuals in the EU/UK outside those regions, we rely on the safeguards made available by our service providers (such as standard contractual clauses or equivalent mechanisms), to the extent applicable.

10. Data Retention

We retain enquiry and lead data for as long as reasonably necessary to respond to your enquiry, pursue a potential engagement, and for a limited period afterward for record-keeping, unless you ask us to delete it sooner. Client data collected in connection with an active engagement is retained for the duration of the engagement and for a reasonable period afterward to support ongoing systems, warranty, or legal obligations, after which it is deleted or anonymized unless a longer period is required by law.

11. Your Privacy Rights

Depending on where you are located, you may have some or all of the following rights over your personal data. To exercise any of these, contact us at info@esthrema.com; we will respond within the timeframe required by applicable law.

11.1 Kenya — Data Protection Act, 2019

If you are in Kenya, you have the right to be informed of the use of your data, to access it, to object to its processing, to correction or deletion of inaccurate or misleading data, and to lodge a complaint with the Office of the Data Protection Commissioner (ODPC).

11.2 EU / UK — GDPR

If you are in the EU or UK, you have the right to access, rectify, or erase your data, restrict or object to processing, request data portability, withdraw consent at any time, and lodge a complaint with your local data protection authority.

11.3 California — CCPA/CPRA

If you are a California resident, you have the right to know what personal information we collect and how it is used, to request deletion or correction of your personal information, and to opt out of the "sale" or "sharing" of personal information. Esthrema does not sell personal information and does not share it for cross-context behavioral advertising. We will not discriminate against you for exercising these rights.

11.4 Other Jurisdictions

If your local law provides similar rights not listed above, we will honor requests consistent with that law to the extent applicable to our operations.

12. Data Security

We use reasonable technical and organizational measures appropriate to the sensitivity of the data we handle, such as restricting access to lead and client data to those who need it and using reputable third-party providers with their own security safeguards. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Children's Privacy

The Site and our services are directed at businesses and are not intended for individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

14. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date above reflects the most recent revision. Material changes will be reflected on this page.

15. Contact & Complaints

For privacy questions or to exercise your rights, contact info@esthrema.com. If you are not satisfied with our response, you may lodge a complaint with your local data protection authority — in Kenya, the Office of the Data Protection Commissioner (ODPC).