LEGAL TERMS & POLICIES
Effective Date: January 2026
Last Updated: January 2026
Governing Law: Republic of Kenya
1. INTRODUCTION & LEGAL STATUS
This Legal Terms document ("Legal Terms") forms an integral and binding part of Sibasi Ltd's contractual framework and applies to all customers, users, partners, and counterparties engaging with Sibasi Ltd ("Sibasi", "we", "us", or "our").
These Legal Terms supplement and form an extension of:
In the event of conflict, Kenyan law prevails, and the hierarchy of documents shall be:
- Signed contract (if any)
- These Legal Terms
- Terms of Use
- Privacy Policy
2. CORPORATE STRUCTURE & AFFILIATES
Sibasi Ltd is a company incorporated in the Republic of Kenya and may operate through:
- Regional offices
- Affiliated or subsidiary entities
- Authorized partners and distributors
References to "Sibasi" include Sibasi Ltd and its affiliates acting within the scope of their authorization.
Nothing herein creates a partnership, agency, or joint venture unless expressly agreed in writing.
PART A — DATA PROCESSING AGREEMENT (DPA)
3. DATA PROTECTION ROLES
- Client is the Data Controller
- Sibasi acts as Data Processor when processing personal data on documented Client instructions
Sibasi does not determine the purpose or means of processing Client data except as required to deliver agreed services.
4. CLIENT INSTRUCTIONS & RESPONSIBILITY
Client warrants that:
- It has lawful authority to process all data
- Data subjects have been informed and consent obtained where required
- Instructions provided to Sibasi are lawful
Sibasi is not responsible for unlawful instructions or Client misuse of systems.
5. DATA SECURITY MEASURES
Sibasi implements commercially reasonable administrative, technical, and organizational safeguards, including:
- Encryption in transit and at rest (where feasible)
- Role-based access control
- Logical environment segregation
- Monitoring and logging
- Backup and disaster recovery
No system is perfectly secure; absolute security is not guaranteed.
6. SUB-PROCESSORS
Sibasi may engage sub-processors to deliver services.
All sub-processors are contractually bound to confidentiality and data protection obligations.
A current sub-processor list is provided in Part E.
7. DATA BREACH NOTIFICATION
Sibasi will notify Client of a confirmed personal data breach without undue delay after becoming aware, where legally required.
Client remains responsible for regulatory notifications unless otherwise agreed.
8. DATA RETURN & DELETION
Upon termination, Sibasi will delete or return Client data in accordance with contractual terms, subject to legal retention requirements.
PART B — SERVICE LEVEL AGREEMENT (SLA)
9. SERVICE AVAILABILITY
Unless expressly agreed in writing:
- Services are provided on an "as-available" basis
- No guaranteed uptime is provided
10. EXCLUDED EVENTS
Sibasi is not liable for service interruptions caused by:
- Cloud provider outages (Azure, AWS, Google Cloud)
- Internet or telecommunications failures
- Force majeure events
- Client misconfiguration or misuse
- Third-party services or integrations
11. REMEDIES
Where an SLA is expressly agreed:
- Client's sole remedy is service credits
- No refunds or damages apply
PART C — ACCEPTABLE USE POLICY (AUP)
12. PROHIBITED USE
Clients and users must not:
- Use services unlawfully
- Upload malicious code
- Attempt unauthorized access
- Abuse system resources
- Infringe IP or privacy rights
13. REVERSE ENGINEERING & IP PROTECTION
Clients shall not, directly or indirectly:
- Reverse engineer, decompile, or disassemble systems
- Inspect source code, algorithms, or internal logic
- Conduct benchmarking without written consent
- Develop competing products using Sibasi systems
Violation constitutes material breach.
PART D — SECURITY & TRUST STATEMENT
14. SECURITY POSTURE
Sibasi adopts a defense-in-depth approach:
- Secure development lifecycle practices
- Access controls and audit logs
- Cloud security best practices
- Incident response readiness
Security measures vary by service model and contract scope.
15. STAFF & GOVERNANCE
- Confidentiality agreements for all staff
- Security awareness training
- Segregation of duties
- Ethical and operational governance frameworks
PART E — SUB-PROCESSOR DISCLOSURE LIST
16. CORE SUB-PROCESSORS
| Category | Purpose |
|---|
| Cloud Infrastructure | Hosting & storage |
| Identity & Access | Authentication |
| Monitoring | Performance & security |
| Support Tools | Service delivery |
Sibasi may update sub-processors without notice unless where legally required.
PART F — INCIDENT RESPONSE & BREACH POLICY
17. INCIDENT RESPONSE
Sibasi maintains internal procedures to:
- Detect and contain incidents
- Assess impact
- Mitigate harm
- Prevent recurrence
18. CLIENT COOPERATION
Client agrees to cooperate during investigations and mitigation efforts.
PART G — INTELLECTUAL PROPERTY & OWNERSHIP
19. SIBASI OWNERSHIP
All platforms, software, methodologies, frameworks, tools, configurations, documentation, and derivatives remain exclusive intellectual property of Sibasi, unless expressly agreed otherwise.
Clients receive a limited, non-exclusive, non-transferable license for internal use only.
20. CLIENT DATA OWNERSHIP
Clients retain ownership of their data and grant Sibasi a limited license to process such data solely to provide services.
PART H — THIRD-PARTY & PARTNER SERVICES
21. PARTNER ECOSYSTEM
Sibasi solutions may integrate with or rely on third-party platforms and partners, including cloud providers, distributors, and software partners.
Such partners operate under their own agreements.
Sibasi:
- Does not control third-party platforms
- Is not liable for their actions, outages, or compliance
- Disclaims warranties relating to partner services
PART I — LIMITATION OF LIABILITY & RISK ALLOCATION
22. LIMITATION OF LIABILITY
To the maximum extent permitted by law:
- No liability for indirect or consequential damages
- No liability for data loss (unless expressly agreed)
- Aggregate liability capped at fees paid in preceding 6 (six) months
23. INDEMNITY
Client indemnifies Sibasi against claims arising from:
- Client data
- Client misuse
- Third-party integrations enabled by Client
- Breach of these Legal Terms
PART J — GOVERNING LAW & FINAL PROVISIONS
24. GOVERNING LAW
These Legal Terms are governed exclusively by the laws of the Republic of Kenya.
25. SEVERABILITY
Invalid provisions do not affect enforceability of remaining terms.
26. CONTACT