Public legal document
Reja Privacy Policy
- Version
- 1.2
- Effective
- 26 August 2026
- Updated
- 26 August 2026
This Privacy Policy explains how Reja Technologies Limited ("Reja", "we", "us", or "our") handles personal data through the Reja website, the Reja mobile application (Android package africa.reja.mobile), dashboards, APIs, and related business services.
When a client organization uses Reja to manage its workforce, customers, routes, orders, collections, or other operations, that organization normally determines why the data is processed and Reja acts as its service provider or processor. Requests about client-controlled data should normally be directed to the relevant organization first.
1. Who this policy covers
This Policy covers website visitors, prospective and current client contacts, organization administrators, authorized mobile and dashboard users, support contacts, and other people whose information Reja processes while operating and securing its services. Reja's business services are not directed to children.
2. Data we process
- Identity and contact data: names, business contact details, employer, role, account identifiers, and communications.
- Account and security data: authentication events, permissions, organization membership, device and session identifiers, IP addresses, and audit records.
- Operational and commercial data: customers, contacts, visits, tasks, orders, quotations, invoices, collections, returns, inventory, routes, forms, signatures, photographs, notes, integrations, and support history.
- Location data: precise or approximate device location, timestamps, route and stop context, and location events when a location-enabled workflow is active.
- Usage and diagnostic data: screens or features used, timestamps, app version, device and operating-system characteristics, crash stack traces, and normalized API performance measurements.
3. Background location in the Reja mobile app
Reja collects location data to enable active route progress, delivery tracking, field-activity verification, route adherence, and operational safety even when the app is closed or not in use. Background location is requested only after Reja displays an in-app explanation and the user grants the relevant Android device permissions.
While background tracking is active, Android displays a persistent notification. Location events are transmitted securely to Reja and made available to authorized users of the user's organization according to its configured features, permissions, and operational policies. Reja does not sell location data and does not use it for advertising.
A user may decline the permission, revoke it in Android settings, or ask their organization administrator to disable a location-enabled workflow. Some route, delivery, visit, or verification functionality may then be unavailable.
4. Why we process data
- To authenticate users and provide configured CRM, field-sales, delivery, route, inventory, finance, reporting, and support workflows.
- To synchronize authorized offline work and maintain operational records across devices.
- To protect users, clients, and Reja through access controls, security monitoring, fraud prevention, auditability, and incident response.
- To diagnose faults, measure reliability, improve usability, and provide customer support.
- To meet contractual, accounting, tax, regulatory, dispute, and lawful disclosure obligations.
5. Analytics, crash reporting, and diagnostics
Production releases may use Google Firebase services to collect limited analytics, crash-reporting, and performance information. This may include screen or workflow names, interaction and session timestamps, app version and build number, deployment environment, device and operating-system characteristics, crash stack traces, and normalized API request paths, methods, statuses, durations, and response sizes.
Reja does not intentionally include authentication credentials, request or response bodies, customer contact details, free-text notes, or precise GPS coordinates in analytics events or API performance traces. Crash reports may contain incidental technical context supplied by the operating system. An authorized client administrator may contact Reja to discuss disabling optional remote diagnostics for their organization.
6. AI-assisted features
Where enabled, Reja may use automated or AI-assisted processing to extract information, classify records, draft suggestions, identify anomalies, or support analytics. Results should be reviewed by an authorized person. Reja does not use client-controlled personal data to train a general-purpose model unless the governing agreement and a valid lawful basis expressly permit it.
7. Sharing and service providers
Data may be shared with authorized personnel of the relevant client organization, Reja personnel who need it, and vetted providers that support hosting, storage, authentication, communications, monitoring, crash reporting, payments, mapping, or integrations. It may also be disclosed to professional advisers, transaction counterparties subject to safeguards, or public authorities where lawfully required. Reja does not sell personal data.
8. International transfers
Data may be processed outside the country where it was collected. Reja assesses applicable transfer requirements and uses safeguards required by law, which may include contractual protections, adequacy mechanisms, or another recognized transfer mechanism.
9. Retention and deletion
Reja keeps data only for as long as reasonably needed for the stated purposes, client retention settings, contractual commitments, security and audit needs, disputes, and legal obligations. Device caches and offline queues are operational copies and are cleared or replaced under the app's security and workspace rules.
Users may request access, correction, deletion, restriction, objection, or portability where applicable. For client-controlled records, Reja may refer the request to the relevant organization or assist that organization in responding. Requests can be sent to contact@reja.africa.
10. Security
Reja uses risk-appropriate measures including tenant and role controls, encryption in transit, protected storage, audit logging, backup and recovery controls, and incident procedures. No system can be guaranteed completely secure. Suspected security or privacy incidents should be reported promptly to Reja.
11. Choices and permissions
Android permissions can be reviewed or revoked in the device's system settings. Marketing recipients may opt out through the message mechanism or by contacting Reja. Service messages required to administer an account are distinct from marketing.
12. Changes and contact information
Reja may update this Policy to reflect legal, security, product, or operational changes. The version and date above identify the current edition. Material changes will be communicated through reasonable channels where required.
Questions, rights requests, or complaints may be sent to Reja Technologies Limited, Nairobi, Kenya at contact@reja.africa. You may also complain to the Office of the Data Protection Commissioner in Kenya or another competent supervisory authority.