Privacy Policy
BackND, getbacknd.com
Last updated: 14 August 2026
Effective from: 14 August 2026
This policy explains what personal information BackND holds, why we hold it, who else can see it, how long we keep it, and what you can make us do about it.
It is written under the Data Protection Act, 2019 of Kenya (“the Act”) and the Data Protection (General) Regulations, 2021. The regulator is the Office of the Data Protection Commissioner (“ODPC”).
We have tried to write this in plain words. Where a legal term matters, we use it and then say what it means in the same breath.
The short version
- We find businesses that might want our help, and we email them. Most people reading this got one of those emails.
- We only use work contact details, for work reasons. No home addresses. No ID numbers. No bank details.
- We got your details from places anyone can look at, like your company website or your public LinkedIn page.
- Tell us to stop and we stop. Straight away, and forever. One line back to us is enough. You do not have to give a reason.
- You can ask to see what we hold, ask us to fix it, or ask us to delete it.
- Email [email protected] for any of this.
The rest of this page is the detail.
1. Who we are
BackND is the trading name of GETBACKEND LIMITED, a company registered in Kenya (no. PVT-WQ1P898E) and run by Levi Leshan. We build and run “backend” systems for other businesses: things like answering new inquiries fast, chasing follow-ups, and keeping records tidy.
| Name | GETBACKEND LIMITED, trading as BackND |
| Company registration | PVT-WQ1P898E, incorporated in Kenya on 31 August 2026 |
| Registered office | Hardrock Gardens, Likoni Lane, Kilimani, Nairobi |
| Postal address | P.O. Box 8281-00100, G.P.O Nairobi |
| Website | https://getbacknd.com |
| Email for privacy questions | [email protected] |
| Where we are based | Nairobi, Kenya |
| ODPC registration | Not yet registered. On legal advice taken on 7 September 2026 we are registering later. This line carries the number once it is issued. |
We wear two hats. Which one we are wearing changes who you should talk to.
Hat one: we are the “data controller”
A data controller is the one who decides why and how information gets used. When we decide, we are responsible, and you deal with us.
We are the controller when:
- We look for businesses to sell to, and store their contact details.
- We send our own marketing emails and follow-ups.
- Someone fills in the contact form on getbacknd.com.
- Someone emails, calls or messages us.
If you got a cold email from BackND, this is the hat we are wearing. Sections 2 to 9 are the ones that apply to you.
Hat two: we are the “data processor”
A data processor only follows instructions. Somebody else decides; we do the work. We do not get to use that information for anything of our own.
We are the processor when we run a system for a client. For example, when a client’s customer fills in a form on the client’s website, our system records it and writes the reply, but the information belongs to the client, and the client decides what happens to it.
If you gave your details to one of our clients, they are the controller, not us. Section 10 explains this and tells you how to reach them through us.
2. What we collect
2a. Business contact details (when we are the controller)
When we build a list of businesses to approach, we record:
| What | Example |
|---|---|
| Business name | “Kreston KM & Co. LLP” |
| Industry | “Accounting Firms” |
| Website | krestonkm.com |
| Location | Nairobi |
| Your name | The name of the person who decides things |
| Your job title | “Managing Partner” |
| Work email address | A work address, at the business’s own domain |
| Business phone number | The number on the company website |
| Public LinkedIn page | The link, not the private contents |
| Our own notes | Why we think you might need us, and a score out of 10 |
| Where we got it | The website, directory or tool we found it in |
All of this is about you at work, not you at home.
2b. What we deliberately do not collect
We do not collect, and will not accept:
- National ID numbers or KRA PINs
- Dates of birth
- Home addresses
- Bank or card details
- Health information
- Anything about your race, religion, politics, health, marital status or family
Under the Act, most of that list is “sensitive personal data” and carries much stricter rules. We stay out of it on purpose. The less we hold, the less harm a mistake can do.
If someone sends us this kind of information anyway, we delete it and tell them.
2c. When you contact us
If you use the form on getbacknd.com or write to us, we keep your name, your business name, your email address, which channel your own leads arrive on (a dropdown), and your message.
2d. Communication logs
We keep a record of the emails we send you and what happened next: the subject line, the date, and the outcome: “no reply”, “replied”, or “opted out”.
We keep the “opted out” record on purpose, and we keep it forever. It is the only way to be sure we never contact you again. Deleting it would mean a future list could pick your name up again by accident. See section 6.
3. Where we get it
We do not buy consumer lists, and we do not guess at private addresses.
We get business contact details from:
- Company websites: the “About us”, “Our team” and “Contact” pages.
- Public business directories and listings.
- Public LinkedIn company and profile pages: what anyone can see.
- Contact-finding tools we pay to use. These check whether a work email address at a company domain is real and still working.
- You, when you fill in our form, reply to us, or hand us a card.
- Referrals, when someone suggests we speak to you.
The legal detail. Section 32 of the Act says information should normally be collected from you directly. It allows collection from elsewhere where the information is already in a public record or where you have deliberately made it public, which is the case for a work email or job title published on your own company website or public LinkedIn page.
Regulation 6(3) then gives us 14 days to tell you. Where we collect your details from somewhere other than you, we must let you know within 14 days that we have them. We do this in the first email we send you: it says who we are, where we got your details, and how to make us stop. If we are not going to email you within 14 days, we should not be holding your details at all, so they get deleted instead.
4. How we use it
As controller
| Why | What it means in practice |
|---|---|
| Finding businesses to approach | Building a list of businesses in industries we serve |
| Working out if we can help | Reading your public website and scoring the fit out of 10 |
| Direct marketing | Sending you an email about what we do |
| Following up | Usually one follow-up, then we stop |
| Answering you | Replying, quoting, running a demo |
| Keeping records | Knowing who we contacted, and who told us to stop |
| Running our business | Contracts, invoices, tax records |
“Direct marketing” means contacting you to sell you something. That is exactly what our emails are, and we are not going to call it anything else. You have a specific right to stop it (section 6).
AI, and what it does and does not do
We use AI, so you should know where.
- AI helps draft the wording of emails and replies. It writes; it does not decide anything about you.
- A person reads and approves every outbound marketing email before it sends. Our own rule is that nothing goes out without that.
- Automated replies. In the systems we run for clients, an inquiry gets a reply within seconds without a person seeing it first. It is a reply, not a decision.
- Scoring. We score how well a business fits what we do, from 0 to 10. It is about a business, not a judgement about you personally, and nothing follows from it except whether we write to you.
No automated decision is made about you that has a legal effect on you, or any effect close to it, the thing section 35 of the Act is concerned with. If you disagree, tell us and a person will look at it.
5. Our legal basis
The Act says we must have a lawful reason for every use. Ours are:
| What we do | Our reason under the Act |
|---|---|
| Contacting business decision-makers about a business service | Legitimate interests, section 30(1)(b)(v) |
| Replying to you, quoting, running a demo | Steps toward a contract, section 30(1)(b)(i) |
| Contracts, invoices, tax records | Legal obligation, section 30(1)(b)(ii) |
| Newsletters and anything you sign up for | Your consent, section 30(1)(a) |
| Running a client’s system | Contract with that client, on their instructions |
About “legitimate interests”
This means we have a real business reason, and we have weighed it against the bother it causes you. Our reason is that we sell a business service to businesses. We keep the balance fair by:
- Only ever using work contact details, at the company’s own domain.
- Only writing about work matters.
- Saying plainly who we are, with a real name and a working reply address.
- Sending a small number of emails: usually one, and one follow-up.
- Stopping the moment you say stop, permanently.
The legal detail, stated honestly
We would rather set this out than hide it.
Section 37 of the Act deals with using personal data for commercial purposes and points to express consent. Regulation 15 of the Data Protection (General) Regulations, 2021 goes further. It says direct marketing is permitted where the controller collected the data from you, told you marketing was one of the purposes, has your consent, and gives you an easy way out.
We do not have your consent, and we did not get your details from you. We got them from your company’s public website or public LinkedIn page. So we do not claim to meet Regulation 15 in full, and we are not going to pretend otherwise on a page whose whole job is to be straight with you.
What we rely on instead is legitimate interests under section 30(1)(b)(v), which the Act does provide as a lawful basis, together with the strictest reading we can manage of everything else Regulation 15 asks for:
- We tell you where we got your details. Every first email says so, and Regulation 6(3) requires us to do that within 14 days of collecting them.
- Every marketing message we send carries a clear line telling you how to stop, as Regulation 17(1) requires. You do not have to hunt for it.
- Opting out takes one word and costs nothing, per Regulation 16.
- We keep the volume low and we do not chase.
We are taking written legal advice on this point. If the advice is that we must move to consent only, we will, and we will update this page and say that is what happened. If you think we have this wrong, we would genuinely like to hear it: [email protected].
Withdrawing consent
Where we rely on consent, you can pull it back at any time and it is as easy to pull back as it was to give. Withdrawing it does not make what we did before unlawful, but it stops us going forward.
6. Your right to make us stop
This is the section most people want.
You can tell us to stop marketing to you at any time, for any reason or no reason, and we must do it. It is free. This is your right under section 26(c) of the Act, and for direct marketing it is absolute: we do not get to weigh it against anything.
Every marketing email we send you carries a line telling you this. That is not a courtesy, it is Regulation 17(1). If you ever get a message from us that does not have one, that message is defective and we want to know.
How:
- Reply to any email from us with “stop”, “remove me”, or anything that means the same. One word is fine.
- Or email [email protected].
We act on it within 14 days at the outside (Regulation 8(3)), and in practice the same day we see it.
What happens:
- We mark you as opted out.
- We stop. No “just one more”.
- Your details go on a permanent do-not-contact list, which every future list is checked against, including any win-back campaign later on.
- We do not pass your objection off to anyone else to ignore.
Why we keep your email address after you ask us to stop. It sounds backwards, but the do-not-contact list only works if your address stays on it. If we wiped you completely, a fresh list could scrape your details again next year and you would hear from us again. So we keep the minimum: enough to recognise you and skip you, and nothing else. If you would rather we erase you completely and accept that risk, say so and we will.
7. Your other rights
Under sections 26 and 40 of the Act, you can:
| Your right | What it means |
|---|---|
| Be told | To know we hold your information and what we do with it. That is this page. |
| See it | To ask for a copy of everything we hold about you. |
| Fix it | To have anything wrong or misleading corrected. |
| Delete it | To have it erased. Also called “erasure”. |
| Object | To tell us to stop, including all marketing (see section 6). |
| Take it with you | To get your information in a normal computer format you can hand to someone else. |
| Complain | To take us to the ODPC if we get it wrong. |
How to use any of them: email [email protected]. Say which one you want. You do not need a lawyer, a form, or a reason.
How fast we must act. The law sets different clocks for different requests, and these are the real ones:
| Your request | We must act within | Rule |
|---|---|---|
| See what we hold | 7 days | Regulation 9(4) |
| Delete it | 14 days | Regulation 12(3) |
| Stop marketing to you | 14 days | Regulation 8(3) |
| Fix something wrong | 14 days | Regulation 12(3) |
What we will do:
- We will acknowledge you within 2 working days, then meet the deadline above.
- We will ask you to confirm you are who you say you are, so we do not hand your information to a stranger.
- It is free. If a request is repetitive or excessive we may say so, but we will explain why rather than just charge you.
- If we say no, we will tell you why, and tell you how to complain.
When we delete, we delete. Marking a record “deleted” while the information sits there is not erasure and we do not count it as such.
One honest limit. Records of what changed and when (audit logs and backups) may hold traces after the main record is gone. Backups are overwritten on a 30-day cycle. Audit records are kept because the Act expects us to be able to show what we did. We will tell you if this applies to your request.
8. How long we keep things
| What | How long | Then |
|---|---|---|
| Business contact details of a prospect we never reached | 12 months from when we collected it | Deleted |
| Business contact details of a prospect we contacted | 24 months from the last contact | Deleted |
| Do-not-contact record (name, email, that you opted out) | Kept indefinitely | Kept, it is how we honour your objection |
| Contact form messages and our replies | 24 months | Deleted |
| Someone who became a client | For the contract, plus 7 years for tax and accounting law | Deleted |
| Encrypted backups | 30 days | Overwritten |
| Records held for a client | Whatever that client instructs (see section 10) | Per their instruction |
If you ask us to delete sooner, we will, unless a law makes us keep it.
These periods are enforced by code, not by good intentions. Deletion runs automatically: daily in the systems we operate, and as a scheduled purge over our prospect records. It is a real delete, not a record flagged “deleted” with your details still sitting in it. We can demonstrate this on request, and we run it in a preview mode that reports exactly what is about to go before anything does.
9. Who else sees it
We do not sell your information. We never have and we will not.
We use other companies to run our systems. They are “data processors”: they act on our instructions and cannot use your information for themselves. Each one is bound by contract terms at least as strict as this policy.
| Company | What it does | What it can see | Where |
|---|---|---|---|
| Railway | Runs our systems and our database | Records stored in our systems | Amsterdam, Netherlands |
| Resend | Sends our email | Names and content in the messages | Netherlands |
| Netlify | Hosts getbacknd.com and receives contact form submissions | What you type into the form | United States |
| Anthropic (Claude) | Drafts wording for replies | The inquiry text being replied to | United States |
| Google (Gmail) | Our own mailbox | Emails to and from us | United States |
| Cloudflare | Forwards email sent to our domain | Email in transit | Global |
| GitHub | Stores our encrypted backups | Nothing readable. Scrambled files only | United States |
| Meta (WhatsApp) | WhatsApp messaging, for clients who use it | WhatsApp messages | United States |
| Contact-finding services | Check whether a work email address is real | A name and a company domain | Varies |
We also share information where the law requires it: a court order, a lawful request from a regulator, or to establish or defend a legal claim.
Your information leaves Kenya
It has to, and we would rather say so than pretend otherwise. None of the hosting or email providers we use runs infrastructure in Kenya, and no African region is available from them.
Section 48 of the Act allows this where there are appropriate safeguards. Ours are:
- Our main systems and email are in the Netherlands, which has strong data protection law of its own.
- Every provider is under a written contract with data protection obligations at least as strict as ours.
- Backups are encrypted before they leave, so the company storing them holds a file it cannot read.
- We keep very little. No ID numbers, no bank details, no home addresses. What crosses a border is a work name, a job title and a work email.
10. When we are working for a client
Some of what we hold is not ours to decide about. When we run a system for a client, the client is the controller and we only follow instructions.
In those systems we may hold, on the client’s behalf: a person’s name, email, phone number, the message they sent, WhatsApp messages including voice notes, when it arrived and how they found the client. For one HR client we hold staff names, roles, managers and contract dates, and deliberately no ID numbers, no bank details and no home addresses.
In those systems we do not:
- Use the information for our own marketing
- Add anyone to our own prospect lists
- Move information between clients
- Keep it after the client tells us to delete it
If you dealt with one of our clients and want your information seen, fixed or deleted: ask that business directly. It is faster, because they decide. If you do not know who to ask, write to [email protected] and we will pass your request to them within 3 business days. We are not allowed to act on it ourselves without their instruction, and we will tell you that rather than leave you waiting.
11. How we protect it
- Everything travels over an encrypted connection (HTTPS).
- Named accounts. People who can reach client records log in as themselves, so every change has a name against it. No shared passwords.
- Passwords and keys are never stored in our code and never written into logs.
- Our logs record counts, not names. A log line says how many, not who.
- Backups are encrypted before they leave our systems, with the key held only by us.
- Each client’s information is kept separate from every other client’s.
- We only collect what the job needs. It is the cheapest security there is.
No system is perfectly safe, and we are not going to claim ours is.
12. If something goes wrong
If personal information is exposed, lost or accessed by someone who should not have it:
- We report it to the ODPC within 72 hours of finding out, where the Act requires it (section 43).
- We tell you directly where there is a real risk of harm to you, and tell you what to do about it.
- Where the information belongs to a client, we tell that client within 24 hours so they can make the report as controller.
We will not quietly sit on a breach.
13. Cookies and the website
getbacknd.com is a plain site. We do not use advertising cookies and we do not track you around the internet.
Our hosting provider keeps basic server logs (the pages requested, rough location, browser type) to keep the site up and to block abuse. Our contact form has a hidden “honeypot” field to catch spam robots. Humans never see it, so leaving it blank is what you do naturally.
We use Cloudflare Web Analytics, added on 8 September 2026. It counts page views so we know which pages people actually read. It sets no cookies, does not fingerprint your device, and cannot follow you to any other website. What it records is the page you looked at, the page you arrived from, your country, your browser and device type, and how quickly the page loaded. It does not store your IP address and there is nothing in it that identifies you.
14. Children
Our services are for businesses. We do not aim any of it at children and we do not knowingly collect information about anyone under 18. If we find we have, we delete it.
15. Complaining
Come to us first if you can. Email [email protected]. A real person reads it. We would rather fix it than have it escalate.
You do not have to. You can go straight to the regulator:
Office of the Data Protection Commissioner (ODPC)
| Office | Britam Tower, 12th and 13th Floor, Hospital Road, Upper Hill, Nairobi |
| Post | P.O. Box 30920-00100 G.P.O., Nairobi, Kenya |
| Phone | 020 780 1800 / 0796 954 269 / 0752 896 867 |
| [email protected] or [email protected] | |
| File a complaint | https://www.odpc.go.ke/file-a-complaint/ |
| Website | https://www.odpc.go.ke |
Complaining is free, and you can do it whether or not you came to us first.
16. Changes to this policy
If we change how we use personal information, we update this page and change the date at the top. If the change is significant, we will say what changed rather than quietly swap the text.
17. Contact
| For | Write to |
|---|---|
| Anything in this policy | [email protected] |
| Stopping our emails | Reply “stop” to any email, or [email protected] |
| Seeing, fixing or deleting your information | [email protected] |
We acknowledge within 2 working days, and meet the legal deadlines in section 7: 7 days to show you what we hold, 14 days to delete it or to stop marketing.
BackND is the trading name of GETBACKEND LIMITED, a company registered in Kenya. Governed by the laws of Kenya.