Legal

Compliance.

How Axene meets data protection, financial, deliverability, and intellectual property obligations - and how to reach our compliance team.

Compliance contact: [email protected]

1. Jurisdiction

Axene Solutions is a Kenyan company headquartered in Ruiru, Kiambu County. Our infrastructure runs primarily in Kenya and on cloud regions in Africa and Europe. Our operations are governed by Kenyan law; cross-border data flows are subject to applicable bilateral and regional frameworks.

2. Data protection

We comply with the Kenya Data Protection Act, 2019 and we apply GDPR-equivalent standards by design for users in the EU/EEA. Practical commitments:

  • Data minimisation - we collect what we need to operate, and nothing else.
  • Purpose limitation - data collected for one purpose is not silently repurposed.
  • Storage limitation - we retain personal data only as long as necessary or legally required.
  • Encryption - TLS 1.2+ in transit, AES-256 at rest for databases and backups.
  • Access controls - least-privilege access, MFA on production systems, audit logging.
  • Subprocessor list - kept up to date and disclosed on request.

To exercise your rights (access, correction, deletion, portability, objection, withdraw consent), email [email protected]. See the Privacy Policy for full details.

3. Data Protection Officer

Our DPO can be reached at [email protected]. The role is responsible for monitoring our compliance with the Kenya Data Protection Act and equivalent frameworks, advising on Data Protection Impact Assessments (DPIAs), and serving as the contact point for the Office of the Data Protection Commissioner (ODPC).

4. Payments and financial regulation

Where we handle payments for Mailer plans, custom projects, or business automations, we use third-party payment processors and do not store raw card numbers on Axene systems. If a project requires payment acceptance, we scope the compliance model up front and keep card handling outside our infrastructure wherever possible.

  • PCI DSS scope - cardholder data stays with the payment processor; Axene systems only see transaction metadata.
  • AML / KYC - where required by a payment flow, verification happens through the processor or merchant account owner.
  • Sanctions screening - applied by the relevant payment provider or by Axene during project scoping when needed.
  • M-Pesa & mobile money - handled through the payment stack selected for the project, not by raw card storage on Axene infrastructure.

5. Email deliverability and anti-spam

Axene Mailer enforces sender authentication and anti-abuse policies that exceed the minimums set by Gmail, Yahoo, and Microsoft for bulk senders.

  • SPF, DKIM, DMARC required for every sending domain. We block unauthenticated relays.
  • One-click unsubscribe (RFC 8058 List-Unsubscribe headers) on marketing mail.
  • Spam-rate ceilings per Google Postmaster Tools - accounts that exceed thresholds are throttled and reviewed.
  • Bounce and complaint handling - automatic suppression list, no resending to confirmed bad addresses.
  • Affiliate / list rental traffic is prohibited. Senders must own or lawfully manage their own opted-in list.

6. Intellectual property notices (DMCA-equivalent)

If you believe content hosted on an Axene service infringes your copyright or trademark, send a written notice to [email protected] including:

  • Identification of the work allegedly infringed.
  • The URL or other location of the allegedly infringing material.
  • Your contact information (name, email, postal address, phone).
  • A statement that you have a good-faith belief the use is not authorised.
  • A statement, under penalty of perjury, that the information is accurate and that you are the rights holder or authorised to act on their behalf.
  • Your physical or electronic signature.

We respond to valid notices promptly. The reported party may file a counter-notice; if we receive one, we'll forward it and, absent legal action, may restore the content after a holding period.

7. Law enforcement requests

Lawful process should be served on [email protected]. We require a Kenyan court order, a duly authorised subpoena, or equivalent process under an applicable treaty before we disclose non-public user data. Requests for content data require a higher legal standard than requests for subscriber metadata.

Emergency disclosure: if there is an imminent risk of death or serious bodily harm, we will disclose minimum necessary information without prior process and follow up with the requesting agency for legalisation.

We don't accept law enforcement requests by phone, social media, or to non-legal addresses.

8. Security disclosures

We welcome responsible disclosure of security vulnerabilities. Email details to [email protected] with subject prefix "[security]". We acknowledge within 48 hours and aim to resolve critical issues within 7 days. We do not currently run a paid bug bounty, but we credit researchers in release notes when permitted.

9. Tax and invoicing

Axene invoices in Kenyan Shillings (KES). VAT is charged where applicable. Tax invoices and receipts are available from your account dashboard or on request to [email protected].

10. Contact