Suswa Labs

Privacy notice

Last updated 10 September 2026

This website sets no cookies, runs no JavaScript, and loads nothing from third parties. There is no analytics, no tracking pixel, and no advertising technology. Nothing about your visit is stored by us.

Who we are

Suswa Labs LLC, a Delaware limited liability company, is the controller for personal data described in this notice. Engineering operations are conducted from Nairobi, Kenya. Privacy enquiries: privacy@suswalabs.com.

Visiting this website

The site is static content served from Amazon CloudFront. To deliver a page, the network necessarily processes your IP address in transit — that is how the internet works. We have not enabled access logging, so we do not retain a record of your visit and cannot produce one.

When you email us

WhatWhyHow long
Your name, email address, and whatever you write to us To answer your enquiry and, if it becomes one, to manage the engagement Enquiries that do not proceed: 12 months. Client correspondence: 7 years, for tax and contractual records

For enquiries our lawful basis under the UK GDPR and EU GDPR is legitimate interest — responding to someone who contacted us about our services. For clients it is performance of a contract, and for retained records, legal obligation.

Data we handle for clients

In the course of an engagement we may process data belonging to a client, including personal data. Where that happens we act as a processor and the client remains the controller. We work to the client's instructions under a written agreement, and:

Who else is involved

We keep sub-processors to a minimum. Amazon Web Services provides hosting and content delivery for this website and for the systems we build. Professional advisers — accountants and lawyers — may see contractual and billing records where necessary. Where an engagement is transacted through AWS Marketplace, AWS processes the billing relationship and the applicable AWS terms govern that part.

International transfers

We are a US entity operating from Kenya, so personal data you send us is processed outside the UK and EEA. Where we act as a processor for a client subject to the UK or EU GDPR, transfers are covered by the standard contractual clauses or the UK international data transfer addendum in the engagement agreement, together with the technical measures described above.

Your rights

Subject to the applicable law, you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, or object to processing based on legitimate interest. You may also ask for a copy in a portable format.

Write to privacy@suswalabs.com. We respond within 30 days. If your request concerns data we hold as a processor for a client, we will tell you and forward it to that client, who is the controller.

If you are in the UK you may complain to the Information Commissioner's Office; in the EEA, to your national supervisory authority. We would appreciate the chance to put it right first.

Security

Data is encrypted in transit and at rest. Access is limited to those who need it for the engagement. We do not store client credentials; access is via cross-account IAM roles that the client controls and can revoke at any time.

Changes

Material changes will be reflected in the date at the top of this page. We do not have a mailing list to notify.