WA
Legal

Privacy Policy

Last updated: September 26, 2026

This is a general-purpose privacy policy describing how Quepath ("Quepath", "we", "us") handles information across this website. It is provided as a starting point and has not been reviewed by a lawyer — please have it checked against your specific legal obligations before relying on it.

1. Information we collect

We collect information in a few ways:

  • Contact & feedback forms — name, email address, and the message you send us.
  • Free security tools — the domain, URL, or email address you submit to be scanned, the resulting report, and, if you request an emailed copy of your report, the email address you provide and whether you opted in to updates. Passwords checked with the Password Exposure tool are never stored or transmitted in full — only a partial hash is sent, following the k-anonymity method used by Have I Been Pwned.
  • Technical data — IP address, browser user agent, and timestamps, logged automatically for security and abuse-prevention purposes.
  • Account data — if you're a client with portal (QMS) access, your name, email, and the quotations/documents associated with your account.

2. How we use it

We use the information above to respond to enquiries, deliver the security reports and PDFs you request, operate the client portal, improve our tools, prevent spam and abuse, and — only if you opt in — send occasional product or security updates. We do not sell your data.

3. Third-party services

Some features rely on third-party services, which receive limited data necessary to perform their function:

  • Public DNS-over-HTTPS resolvers (e.g. Google's DNS service) — to look up DNS/SPF/DKIM/DMARC records for the domain you submit.
  • Have I Been Pwned — for the Password Exposure and breach-check tools, using their privacy-preserving k-anonymity API.
  • XposedOrNot — for the email breach/dark-web exposure check.
  • Google Fonts — to load the site's typefaces.

4. Cookies

We use a small number of strictly necessary cookies to keep you logged in and to protect forms from cross-site request forgery. If analytics is enabled, an analytics cookie may also be set to distinguish visitors — see the cookie banner on your first visit for details.

5. Data retention

Scan reports, contact messages, and feedback are retained for as long as reasonably useful for support and record-keeping, and can be deleted on request. Client portal data is retained for the duration of the business relationship and as required for our own accounting and legal obligations.

6. Your rights

You can ask us what data we hold about you, request a correction, or request deletion, by emailing info@quepath.co.ke.

7. Security

We apply reasonable technical measures — HTTPS, security headers, rate limiting, and access controls — to protect the data we hold. No method of transmission or storage is 100% secure, but we work to keep it that way.

8. Children's privacy

Our services are intended for businesses and professionals, not children. We do not knowingly collect data from anyone under 16.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "last updated" date above.

10. Contact

Questions about this policy? Reach us at info@quepath.co.ke or via our Contact page.