Back to Home

Privacy Policy

Effective: 22 August 2026 · Last updated: 31 August 2026

1. Introduction

Welcome to Bohari IMS (operated by Cogitus OS Limited, "we", "us", or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our inventory and cost-control platform, including our website at https://bohari.co.ke, mobile applications (iOS and Android), and all related services (collectively, the "Platform").

By accessing or using the Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please do not use the Platform.

Bohari IMS operates as a multi-tenant platform, meaning your employer or organization ("Company") manages its own workspace. Your Company is the data controller for the business and personal data in its workspace, and we act as a data processor on their behalf.

2. Information We Collect

Bohari IMS is an inventory system, not an HR system: we do not maintain employee records, payroll data, or candidate/recruiting data. The personal data we process is limited to the accounts of the people your Company invites to use the Platform, plus the business data those accounts create.

2.1 Staff Account Data

  • Full name
  • Work email address
  • Phone number (optional, where provided)
  • Role and permissions within your Company's workspace
  • Profile photograph / avatar (optional)

2.2 Business & Inventory Data

  • Item catalog, units of measure, and stock ledger entries
  • Stocktakes (physical counts), waste records, and stock adjustments
  • Recipes, sub-recipes, and yield/costing data
  • Sales imports and menu-item-to-recipe mappings
  • Purchase orders, goods receipts, supplier invoices, and cash purchases
  • Supplier records and negotiated prices
  • Variance reports comparing theoretical and actual stock usage
  • Compliance documents and statutory-obligation records (e.g. licences, permits, filings)

2.3 Location Data

  • Outlet and storage-location identifiers configured by your Company
  • IP address at time of web-based sign-in

2.4 Device & Technical Data

  • IP address, browser type, and user agent string
  • Mobile device platform (iOS / Android)
  • Push notification tokens
  • Error diagnostics and crash reports, used to detect and fix faults
  • Session identifiers and authentication tokens

2.5 AI Interaction Data

  • Prompts and messages sent to the AI chat assistant, where enabled by your Company
  • AI-generated responses
  • Feature usage logs, token counts, and AI provider used

2.6 Files & Documents

  • Delivery notes, supplier invoices, and receipt photographs captured during procurement
  • Compliance documents and evidence of filing

3. How We Use Your Information

We process your personal data for the following purposes:

3.1 Platform Operations

  • Providing and maintaining the inventory management platform
  • Recording and valuing stock movements, and reconciling stocktakes
  • Processing purchase orders, goods receipts, and supplier invoices
  • Computing recipe costs and usage variance
  • Generating reports and dashboards over your Company's inventory data

3.2 Communication

  • Sending transactional emails (password resets, invoice and approval notifications)
  • Push notifications for approvals and workflow reminders
  • In-app notifications for workflow events

3.3 Security & Authentication

  • Verifying identity via password, Google sign-in, or biometric authentication (mobile)
  • Two-factor authentication (TOTP), including one-time and backup recovery codes
  • Fraud detection and abuse prevention (rate limiting, audit logging)

3.4 AI-Powered Features

  • A chat assistant over your company's inventory, procurement and variance data
  • Report and document summarization, where enabled

3.5 Compliance & Legal

  • Maintaining audit trails for all data changes
  • Complying with applicable tax and data protection laws
  • Responding to legal requests and regulatory obligations
  • Document expiration tracking and compliance monitoring

5. Data Sharing & Third-Party Services

We do not sell your personal data. We share data only as necessary to provide the Platform:

5.1 Your Employer (Data Controller)

Your Company administrators and authorized managers can access data within the Platform according to role-based permissions. Each Company's data is strictly isolated, and no Company can access another Company's data.

5.2 AI Service Providers

When AI features are enabled by your Company, prompts may be sent to:

  • OpenAI (GPT models)
  • Anthropic (Claude models)
  • Google (Gemini models)
  • Azure OpenAI Service

PII redaction is applied before any data is sent to AI providers. Companies can configure which fields are redacted and may disable AI features entirely.

5.3 Infrastructure & Service Providers

  • Google Cloud Platform: Cloud hosting (Cloud Run, Cloud SQL, Cloud Storage) in the us-central1 region
  • Firebase: Web hosting and Android push notification delivery (Firebase Cloud Messaging)
  • Expo (Expo Application Services): Mobile app builds, over-the-air updates, and push notification relay. Receives the device push token and notification payloads to deliver them to Apple and Google
  • Apple: iOS push notification delivery (Apple Push Notification service)
  • Google Cloud Error Reporting: Backend fault detection. Receives error messages and stack traces from our servers, together with the request path and, where known, the company identifier. It receives no names, email addresses or inventory data
  • Sentry: Crash reporting for the web and mobile applications, where enabled. Receives stack traces plus the company identifier and role only — no names, email addresses, item names, quantities or prices
  • Resend / SMTP providers: Transactional email delivery

5.4 Authentication Providers

If you choose to sign in with Google, we receive your name and email address from that provider solely to locate or create your account. Google verifies your identity and does not receive your Company's inventory data.

On iOS you may sign in with Apple. Apple verifies your identity and sends us an account identifier, and your name and email address if you choose to share them. If you use Apple's Hide My Email, we receive only the relay address Apple generates. Apple does not receive your Company's inventory data.

5.5 Company-Configured Integrations

Your Company may enable additional integrations that share data with third parties:

  • Accounting systems: Procurement and cost-of-goods journal entries may be synced to your Company's accounting software
  • Webhooks: Your Company may configure webhooks that send event notifications (e.g., goods receipt posted, stock count closed) to external systems. The Company controls which events are shared and with whom

5.6 Legal & Regulatory

We may disclose your data when required by law, court order, or governmental regulation, or to protect our rights, safety, or property.

6. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption at rest: Sensitive values are encrypted using AES-256-GCM with unique initialization vectors. This covers two-factor authentication secrets and backup codes and third-party integration tokens and AI provider API keys. Other data is further protected through multi-tenant isolation, permission-based access control, and value masking
  • Encryption in transit: All data transmitted over HTTPS/TLS
  • Password security: Passwords are hashed using bcrypt with 12 salt rounds; we never store plain-text passwords
  • Multi-tenant isolation: Every database query is scoped to your Company; cross-tenant data access is architecturally prevented
  • Authentication: JWT-based sessions with optional two-factor authentication (TOTP) and biometric lock (mobile)
  • Audit logging: Every data modification is recorded with the actor, timestamp, IP address, and before/after values
  • Rate limiting: Brute-force protection on login and registration endpoints
  • Security headers: HSTS, Content Security Policy, X-XSS-Protection, and X-Content-Type-Options
  • Signed file URLs: Documents are served via HMAC-signed URLs to prevent unauthorized access
  • Secure mobile storage: Authentication tokens on mobile devices are stored in the OS secure enclave (iOS Keychain / Android EncryptedSharedPreferences)

7. Data Retention

We retain your data according to the following principles:

  • Active accounts: Data is retained for the duration of your access to your Company's workspace
  • Stock ledger: Movement history is append-only and retained as an immutable financial and operational record
  • Audit logs: Retained indefinitely for compliance and legal purposes
  • Compliance documents: Retained per your Company's configured obligations
  • AI conversation logs: Retained per Company AI audit settings
  • Data exports: Exported files are available for a limited period after generation

Your Company, as the data controller, may configure retention policies within the Platform. When a Company account is terminated, all associated data is permanently deleted.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your data, subject to legal retention requirements
  • Right to restrict processing: Request limitation on how we process your data
  • Right to data portability: Receive your data in a machine-readable format via the Platform's data export tools
  • Right to object: Object to processing based on legitimate interest
  • Right to withdraw consent: Withdraw previously given consent (e.g., AI features, push notifications) at any time through the Platform settings
  • Right to account deletion: Request deletion of your user account

To exercise any of these rights, contact your Company's administrator through the Platform, or reach us directly at support@bohari.co.ke.

9. International Data Transfers

The Platform is hosted on Google Cloud Platform in the United States (us-central1 region). If you are located outside the United States, your data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards recognized under applicable data protection laws to ensure your data is protected during international transfers.

AI service providers (OpenAI, Anthropic, Google) may process prompts in various jurisdictions. PII is redacted before transmission to these providers.

10. Cookies & Local Storage

The Platform does not use third-party tracking cookies. We use browser local storage and session storage for essential functionality:

  • Authentication token: Stored in localStorage (if "Remember Me" selected) or sessionStorage for session authentication
  • Company context: Selected company identifier for multi-tenant navigation
  • UI preferences: Sidebar state and layout preferences

On mobile, authentication tokens are stored in the device's secure enclave (not in plain-text storage), and offline stock-capture data may be cached locally on your device until it syncs.

11. Children's Privacy

The Platform is designed for business use and is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@bohari.co.ke and we will promptly delete it.

12. Kenya Data Protection Act Compliance

For users and Companies based in Kenya, we comply with the Data Protection Act, 2019 and regulations issued by the Office of the Data Protection Commissioner (ODPC). This includes:

  • Registration with the ODPC as a data processor (ODPC Registration No. 659-2062-E512)
  • Processing data only for specified, explicit, and legitimate purposes
  • Collecting only data that is adequate, relevant, and not excessive
  • Implementing appropriate technical and organizational security measures
  • Notifying the ODPC and affected individuals in the event of a data breach
  • Conducting Data Protection Impact Assessments (DPIAs) for high-risk processing

13. GDPR Compliance (EU/EEA Users)

For users in the European Union or European Economic Area, we comply with the General Data Protection Regulation (GDPR). Your Company is the data controller, and we act as the data processor under a Data Processing Agreement (DPA). We provide:

  • Lawful basis for all processing activities (see Section 4)
  • Data Protection Impact Assessments for high-risk processing
  • 72-hour breach notification to supervisory authorities
  • Data portability in machine-readable formats
  • Right to erasure ("right to be forgotten") subject to legal retention
  • Appointment of a Data Protection Officer upon request

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by:

  • Posting the updated policy on the Platform with a new "Last Updated" date
  • Sending an in-app or email notification for significant changes
  • Requesting renewed consent where required by law

Your continued use of the Platform after changes are posted constitutes acceptance of the updated Privacy Policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

How to Delete Your Account and Data

Bohari IMS (operated by Cogitus OS Limited) is workplace software. Your employer (your “Company”) is the data controller for the workspace data associated with your account, and we act as the data processor on their behalf. You can request deletion of your account, or of specific data, at any time using the steps below.

Request account deletion

  1. Email support@bohari.co.ke from your registered email address with the subject “Account Deletion Request”.
  2. We verify your identity to protect your account before acting on the request.
  3. If you are a current user of your Company's workspace, deletion is coordinated with your Company’s administrator, because your Company may require your account for records it is required to keep. You may also ask your administrator to initiate the request on your behalf.
  4. We acknowledge requests within 7 days and complete verified deletions within 30 days, unless a longer period is required by law.

Request deletion of specific data (without closing your account)

You can ask us to delete certain data without deleting your entire account, for example AI chat history or locally cached offline data. Email support@bohari.co.ke with the subject “Data Deletion Request”, describing the data you want removed.

Some data can also be removed directly in the app: you can delete individual AI assistant conversations, and clear saved offline data from your Profile settings in the mobile app.

What is deleted

  • Profile and identity data (name, work email and phone number, profile photo)
  • Login credentials and authentication data (password, two-factor secrets, connected Google identifiers, session tokens)
  • Device push notification tokens registered to your account
  • AI assistant conversation history
  • Personal preferences and locally cached/offline data on your device

What is retained, and for how long

  • Stock ledger entries you posted: kept as immutable operational records, attributed to your account id rather than your personal profile once it is deleted
  • Audit logs: retained for compliance, security, and legal purposes

Once the applicable legal retention period expires, retained data is securely deleted or anonymized.

Questions about deletion? Contact us at support@bohari.co.ke.

© 2026 Cogitus OS Limited. All rights reserved.