Legal
Data protection
Last updated September 2026.
1. Scope
This page describes how Sysmera Limited approaches data protection in the platforms we build and operate for clients, such as OriginTrace. It is separate from our website privacy notice, which covers this website’s own contact form.
2. Our role: processor and controller
Depending on the engagement, Sysmera acts as a data processor on behalf of the cooperative, association, research institute or programme owner who owns the register, or as a joint controller with them. Which applies is set out in the data-processing agreement for each programme.
3. What is collected, and how
Our field platforms collect farmer and household identity data, consent records, plot GPS boundaries, photographs and agronomic monitoring data, gathered by trained enumerators on offline-first Android devices with the data subject’s consent. Only the data a programme needs is collected, and it is used only for the purposes the programme owner and Sysmera have agreed.
4. Lawful basis and law that applies
Personal data is processed under the Kenya Data Protection Act, 2019 and, where a programme operates outside Kenya, the equivalent law of that country, on the basis of the consent given by each farmer or household at registration.
5. Security and hosting
Programme data is held on dedicated hosting with daily backups and offsite copies, in-country where a programme’s data rules require it. Access is limited to the people who need it to run the programme.
7. Rights of farmers and other data subjects
Anyone registered on a platform we operate can ask the programme owner or Sysmera what data is held about them, ask for it to be corrected, and withdraw consent, through the channel the programme has agreed with its cooperative or association. Requests can also be sent to data.protection@sysmera.com.