Data Protection Compliance Pack
Triplona International Limited
Trading as Triplona · Registered in Kenya · Website: triplona.com
Version 1.1 · Effective 12 August 2026
This pack is maintained by Triplona International Limited to support registration with the Office of the Data Protection Commissioner (Kenya) under the Data Protection Act, 2019, and to demonstrate alignment with GDPR principles for international users. It is not a legal certification.
Contents
- Data Protection Policy
- Records of Processing Activities (ROPA)
- Data Retention Schedule
- Technical and Organizational Measures (TOMs)
- Data Breach Response Plan
- Data Inventory
- Data Subject Rights Request Procedure
- Cross-Border Transfer Register
1. Data Protection Policy
Triplona International Limited acts as a Data Controller in respect of personal data collected through the Triplona marketplace at triplona.com. This policy sets out the principles the company follows when handling that data.
1.1 Principles
- Lawfulness, fairness and transparency.
- Purpose limitation — data is collected for specified, explicit purposes.
- Data minimisation — only what is necessary is collected.
- Accuracy — users may correct their data at any time.
- Storage limitation — data is retained only as long as necessary (see §3).
- Integrity and confidentiality — protected by technical and organisational measures (see §4).
- Accountability — this pack, our audit log and internal procedures evidence compliance.
1.2 Lawful bases
- Contract — to create accounts, publish listings, enable messaging and process subscriptions.
- Legal obligation — to comply with Kenya Revenue Authority, Financial Reporting Centre and equivalent regulators.
- Legitimate interests — fraud prevention, moderation, service improvement, security.
- Consent — marketing emails, non-essential cookies, optional profile data.
1.3 Roles
- Data Controller: Triplona International Limited.
- Data Protection contact: hello@triplona.com.
- Processors: hosting, database, email delivery and AI providers under written data-processing terms (see §8).
1.4 Sensitive personal data
Sensitive personal data is collected only where required for host identity verification (e.g. reference to a government-issued ID number). It is stored in a private bucket, accessible only to authorised admin staff via signed URLs, and is never shared with other marketplace members.
1.5 Review
This policy is reviewed at least annually and whenever there is a material change to processing activities, systems, or the law.
2. Records of Processing Activities (ROPA)
Kept under section 24 of the Kenya Data Protection Act, 2019 and Article 30 GDPR.
| Activity | Categories of data subjects | Categories of data | Purpose | Lawful basis | Retention |
|---|---|---|---|---|---|
| Account registration | Travellers, providers | Name, email, phone, password hash, country, roles | Create and secure accounts | Contract | Life of account + 30 days |
| Host verification | Providers | Government ID reference, business registration, KRA PIN, uploaded documents | Verify identity and business | Contract; legal obligation | Life of account + 7 years (regulatory) |
| Listings & content | Providers | Photos, descriptions, prices, availability | Publish marketplace listings | Contract | Life of listing + 90 days |
| Messaging | Travellers, providers | Chat messages, timestamps, read state | Enable communication between members | Contract; legitimate interests (safety) | 3 years after last message |
| Reviews & ratings | Travellers, providers | Rating, review text, reviewer name | Public reputation signal | Contract; legitimate interests | Life of account |
| Subscriptions & boosts | Providers | Plan, amount, currency, gateway reference, status | Bill provider subscriptions | Contract; legal obligation (tax) | 7 years |
| Job applications | Applicants | Name, contact, CV, answers, AI score | Recruitment | Legitimate interests; consent | 12 months, then anonymised |
| Support tickets | All users | Message content, contact info, attachments | Provide support | Contract; legitimate interests | 3 years |
| Security & audit logs | All users; admins | IP country, event type, actor, timestamps | Fraud, abuse and security | Legitimate interests; legal obligation | 24 months |
| Marketing emails | Opted-in users | Email, first name, preferences | Renewal reminders, campaigns | Consent (revocable) | Until unsubscribe + 30 days |
| Cookies (essential) | Visitors | Session token, consent choice | Sign-in and preferences | Legitimate interests | Session or 12 months |
3. Data Retention Schedule
| Data category | Retention period | Trigger for deletion |
|---|---|---|
| Account profile | Duration of account | Account deletion request + 30-day cool-off |
| Verification documents | Account life + 7 years | Regulatory retention period lapses |
| Chat messages | 3 years after last activity | Automatic purge |
| Financial records (subscriptions, invoices) | 7 years | Statutory tax retention lapses |
| Audit and security logs | 24 months | Rolling deletion |
| Job applications | 12 months | Automatic anonymisation |
| Marketing preferences | Until unsubscribe + 30 days | User opts out |
| Cookies (essential) | Session or up to 12 months | Session end or expiry |
| Cookies (analytics, if used) | Up to 12 months | Consent withdrawn or expiry |
| Backups | 35 days rolling | Backup rotation |
4. Technical and Organizational Measures
4.1 Technical safeguards
- HTTPS/TLS 1.2+ enforced for all traffic; HSTS enabled on production domain.
- Passwords stored as salted hashes by the managed authentication provider — never in plaintext.
- Row-Level Security (RLS) on every user-facing database table.
- Role-based access control with granular admin permissions (view, moderate, delete, manage admins, etc.).
- Signed URLs for private buckets (verification documents, chat photos, job CVs).
- Encrypted-at-rest storage (managed cloud provider) and encrypted daily backups.
- Audit log of sensitive changes (roles, admin grants, memberships, verifications, settings).
- Session management with automatic expiry and revocation on password change.
- Account lockout after 5 failed sign-ins in 30 minutes and admin-approved unlock.
- WAF, DDoS protection and TLS termination provided by the hosting edge network.
- AI-assisted moderation (Watchtower) for chat and listing content.
- Regular dependency scans and automated security-linting.
4.2 Organisational safeguards
- Published Privacy Policy, Terms & Conditions and Trust & Governance page.
- Staff and contractors bound by confidentiality obligations before access is granted.
- Least-privilege access: verification data is visible only to admin roles with the specific permission.
- Host verification procedure with ID reference and business-document review.
- Documented retention procedures (see §3) and automated deletion jobs where feasible.
- Incident response process (see §5).
- User rights procedure (see §7).
- Annual review of this pack and quarterly review of admin access.
5. Data Breach Response Plan
- Detect & contain (0–2 hours). Any staff member who suspects a breach must notify hello@triplona.com immediately. The on-call admin isolates the affected system, rotates credentials, and preserves logs.
- Assess (2–24 hours). Determine the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed.
- Notify regulator (within 72 hours). If the breach is likely to result in a risk to the rights and freedoms of natural persons, notify the Office of the Data Protection Commissioner (Kenya) and, where applicable, other competent authorities within 72 hours of becoming aware.
- Notify data subjects. Where the risk is high, notify affected users in clear and plain language without undue delay, describing the nature of the breach and remedial steps.
- Record. Every incident, whether or not notifiable, is entered into an internal breach register with root cause and remedial action.
- Review. A post-incident review updates the TOMs and this plan where needed.
Breach reporting contact: hello@triplona.com. Regulator: Office of the Data Protection Commissioner, Kenya (odpc.go.ke).
6. Data Inventory
Travellers
Name, email, phone, country, profile photo, messages, reviews, favourites, referral history.
Providers
Name, email, phone, business/trading name, company registration number, KRA PIN (where applicable), government ID reference, uploaded verification documents, business logo, listings, subscription records, boost history, payout method reference.
Employees & contractors
Employment records, payroll details, contact information, statutory identifiers (KRA PIN, NSSF, NHIF where applicable). Held separately from marketplace data.
Applicants (careers)
Name, email, phone, CV/resume, cover answers, AI-assisted score, application status history.
Visitors
Approximate country (from IP), device type, pages viewed, consent choice.
7. Data Subject Rights Request Procedure
Under the Kenya Data Protection Act, 2019 and GDPR, data subjects may request:
- Access to their personal data.
- Correction of inaccurate data (self-service in Account settings).
- Deletion of their account and associated personal data (self-service, subject to a 3-day admin cool-off).
- Restriction of, or objection to, certain processing.
- Withdrawal of marketing consent (via the unsubscribe link on every marketing email).
- Data portability — export of their data in a machine-readable format.
Requests may be made from within the app (Account → Delete account / Export data) or by email to hello@triplona.com. We verify the requester's identity through their registered email before acting. We respond within 30 days and may extend once by a further 60 days for complex requests, notifying the requester of the reason.
8. Cross-Border Transfer Register
Triplona is a global marketplace. Personal data collected through triplona.com is transferred outside Kenya and is stored and processed by the providers listed below. Transfers rely on documented safeguards (standard contractual clauses and, for EU-hosted infrastructure, the EU adequacy framework). This register is reviewed whenever a processor is added, removed or replaced, and is declared to the Office of the Data Protection Commissioner (Kenya).
| Processor / service | Purpose | Hosting jurisdiction | Safeguard |
|---|---|---|---|
| Supabase (Postgres database, Auth, Storage, automated backups) — via Lovable Cloud | Accounts, listings, messages, verification documents, chat photos, job CVs, audit logs, backups | Amazon Web Services, Frankfurt, Germany (EU, eu-central-1) | EU adequacy; vendor SCCs; AES-256 at rest; TLS in transit |
| Cloudflare Workers (application runtime, SSR, server functions, public API routes) | Serve the website; execute server-side logic | Global edge (stateless; includes a Nairobi PoP). No personal data stored on the edge. | TLS in transit; vendor SCCs; no persistent storage at the edge |
| Cloudflare (CDN, DNS, WAF, DDoS, TLS termination) | Deliver static assets, terminate TLS, absorb attacks | Global edge | Transit only; vendor SCCs |
| Lovable Emails (auth & transactional email delivery from notify.triplona.com) | Sign-in, reset, activity, renewal and campaign emails | European Union / United States | Vendor SCCs; TLS in transit |
| Lovable AI Gateway → Google Gemini | ID / KRA PIN document scanning, moderation, drafting, translation | Google data centres, European Union / United States | Vendor SCCs; content processed at request time; not used to train models |
| Google Maps Platform | Location search, maps and geocoding | Google global infrastructure | Vendor SCCs |
| Kenyan bank and mobile-money providers | Provider subscription and boost payments only (customer↔host booking money never touches the platform) | Kenya | Local processing; no cross-border transfer |
ODPC declaration: Based on the current infrastructure, Triplona International Limited declares to the Office of the Data Protection Commissioner (Kenya) that personal data is transferred outside Kenya — primarily to the European Union (Germany) for storage and to the EU / United States for email delivery and AI processing — under the safeguards listed above.
Sign-off
Approved on behalf of Triplona International Limited.
Name & title

Signature
Date
Signed electronically. An electronic signature applied by an authorised officer is valid under the Kenya Information and Communications Act and the Business Laws (Amendment) Act, 2020.
End of pack · Triplona International Limited · v1.1 · 12 August 2026