Privacy Policy
Last updated: August 11, 2026
1. Overview & Who We Are
Esthrema ("Esthrema," "we," "us," or "our") is a business systems engineering practice operated from Nairobi, Kenya, and operating internationally on a remote basis. Esthrema is not yet formally incorporated; for the purposes of applicable data protection law, its operator acts as the data controller for the personal data described in this Policy.
This Policy explains what personal data we collect through esthrema.com and in the course of our sales and client relationships, why we collect it, who we share it with, and the choices and rights available to you. It applies to visitors, enquirers, prospective clients we contact directly, and clients, regardless of where you are located.
2. Information We Collect
The information we collect depends on how you interact with us:
- Website form submissions: name, email address, optional phone or WhatsApp number, the page URL, submission source, browser submission time, and server receipt time. If a future form asks for company name, message content, or project details, we may also collect the information you choose to provide in those fields.
- Direct outreach responses: if we contact you first (for example, via Instagram DM or email) and you respond, we retain that conversation and any contact details you share.
- Client onboarding: business details, project requirements, and any content, credentials, or business data you share with us to build or connect a system (e.g., CRM exports, calendar access, brand assets).
- Technical and security data: if analytics are enabled, general usage data such as pages visited, device/browser type, and approximate location derived from IP address. Our hosting, form security logs, and rate-limit systems may also record basic request metadata, such as timestamps, status codes, origin headers, and hashed rate-limit identifiers, to detect abuse and diagnose delivery failures.
We do not knowingly collect payment card details, government ID numbers, or other sensitive category data through the Site.
3. How We Collect It
We collect information directly from you (via forms, email, calls, or messaging apps), from your use of the Site, and — where we conduct outreach to businesses that may benefit from our services — from publicly available business contact information (e.g., a business's public Instagram or website contact details) that we use to initiate first contact.
4. Legal Bases for Processing
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:
- Consent — where you submit a form or opt in to communications;
- Legitimate interests — for responding to enquiries, following up on leads (including outreach we initiate to businesses), and improving our services, balanced against your rights;
- Contract performance — where processing is necessary to prepare or perform a Service Agreement with you; and
- Legal obligation — where we must retain or disclose information to comply with the law.
5. How We Use Information
- Responding to enquiries and preparing proposals or system demonstrations;
- Managing lead follow-up and client relationships through our CRM;
- Designing, building, and maintaining the websites, automations, and booking systems we deliver;
- Improving our website and service offering; and
- Meeting legal, accounting, or security obligations.
6. Cold Outreach & Marketing
As part of our sales process, we may initiate contact with businesses we believe could benefit from our services, including via direct message on platforms such as Instagram, or by email. Where required by applicable law (such as GDPR or PECR for EU/UK recipients, or CAN-SPAM for other jurisdictions), such outreach will identify Esthrema as the sender and provide a way to opt out.
You can stop receiving outreach or marketing messages from us at any time by replying "stop," unsubscribing via any link provided, or emailing info@esthrema.com. We will honor opt-out requests promptly and will not use unsubscribe requests as a basis for further contact beyond confirming the request.
9. International Data Transfers
Esthrema operates from Kenya and works with international clients and service providers, which means personal data may be processed in countries other than your own, including the United States and countries within the EU/UK, where our hosting, CRM, and communication tools are based. Where we transfer personal data of individuals in the EU/UK outside those regions, we rely on the safeguards made available by our service providers (such as standard contractual clauses or equivalent mechanisms), to the extent applicable.
10. Data Retention
We retain enquiry and lead data for as long as reasonably necessary to respond to your enquiry, pursue a potential engagement, and for a limited period afterward for record-keeping, unless you ask us to delete it sooner. Client data collected in connection with an active engagement is retained for the duration of the engagement and for a reasonable period afterward to support ongoing systems, warranty, or legal obligations, after which it is deleted or anonymized unless a longer period is required by law.
11. Your Privacy Rights
Depending on where you are located, you may have some or all of the following rights over your personal data. To exercise any of these, contact us at info@esthrema.com; we will respond within the timeframe required by applicable law.
11.1 Kenya — Data Protection Act, 2019
If you are in Kenya, you have the right to be informed of the use of your data, to access it, to object to its processing, to correction or deletion of inaccurate or misleading data, and to lodge a complaint with the Office of the Data Protection Commissioner (ODPC).
11.2 EU / UK — GDPR
If you are in the EU or UK, you have the right to access, rectify, or erase your data, restrict or object to processing, request data portability, withdraw consent at any time, and lodge a complaint with your local data protection authority.
11.3 California — CCPA/CPRA
If you are a California resident, you have the right to know what personal information we collect and how it is used, to request deletion or correction of your personal information, and to opt out of the "sale" or "sharing" of personal information. Esthrema does not sell personal information and does not share it for cross-context behavioral advertising. We will not discriminate against you for exercising these rights.
11.4 Other Jurisdictions
If your local law provides similar rights not listed above, we will honor requests consistent with that law to the extent applicable to our operations.
12. Data Security
We use reasonable technical and organizational measures appropriate to the sensitivity of the data we handle, such as restricting access to lead and client data to those who need it and using reputable third-party providers with their own security safeguards. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Children's Privacy
The Site and our services are directed at businesses and are not intended for individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date above reflects the most recent revision. Material changes will be reflected on this page.
15. Contact & Complaints
For privacy questions or to exercise your rights, contact info@esthrema.com. If you are not satisfied with our response, you may lodge a complaint with your local data protection authority — in Kenya, the Office of the Data Protection Commissioner (ODPC).