1. Scope and roles
This Privacy Policy explains how Sirmillion handles personal information when people visit the website, create or use platform accounts, contact the team or interact with Sirmillion’s platform-subscription services.
For data an ISP tenant enters about its own internet customers and staff, the ISP generally determines why and how that information is used, while Sirmillion processes it to provide the platform. The ISP remains responsible for its notices, lawful basis and customer rights obligations.
2. Information we collect
Account information may include name, business or ISP name, email address, telephone number, role, authentication records and profile image. Tenant operations may include customer contacts, service addresses, packages, subscriptions, invoices, payments, support records and staff activity.
Technical data may include tenant hostname, session identifiers, request metadata, security events, device or browser information, router status, RADIUS events and network-operation audit records. Contact inquiries include the information submitted in the contact form.
3. Information we do not request in forms
Do not submit plaintext router passwords, M-Pesa consumer secrets, private keys, payment PINs or unrelated sensitive personal information through registration, contact or support text fields.
Where production integrations require credentials, they must be handled only through the designated secure configuration workflow.
4. How information is used
We use information to create and secure accounts, resolve tenant context, provide billing and network workflows, process platform subscriptions, respond to inquiries, diagnose incidents, prevent abuse, maintain audit history and improve reliability.
Operational events may be used to perform authorized automation such as reconciling a payment, renewing a subscription, authorizing network access, sending a notification or recording a support action.
5. Legal and operational grounds
Information is processed as necessary to provide requested platform services, perform agreements, protect accounts and systems, meet legal obligations and pursue legitimate operational interests such as fraud prevention and service improvement. Where consent is the appropriate basis, it may be withdrawn subject to legal and contractual limits.
6. Sharing and service providers
Information may be shared with service providers needed to operate Sirmillion, such as hosting, database, communications, monitoring and payment providers. Payment providers receive the information required to process and report a transaction.
We may disclose information where required by law, to protect rights and security, or as part of a legitimate organizational transaction subject to appropriate safeguards. Sirmillion does not sell personal information.
7. Tenant isolation and security
Sirmillion uses tenant-bound sessions, role and permission controls, database scoping, encrypted transport, audit records and operational safeguards appropriate to the service. Network credentials should be encrypted and access limited to authorized workflows.
No system can guarantee absolute security. Account owners must use strong unique passwords, protect connected systems, maintain appropriate permissions and report suspected compromise promptly.
8. Retention
Information is retained only as long as reasonably needed for the service, security, dispute handling, audit, backup and legal obligations. Retention periods vary by record type. Expired platform access does not necessarily cause immediate deletion because records may be required for restoration, security or legal purposes.
10. Access, correction and deletion
Depending on applicable law and the context, individuals may request access, correction, deletion, restriction or portability of personal information and may object to certain processing. Identity and authority must be verified before fulfilling a request.
Internet customers should normally direct requests about their ISP service records to the ISP that provides their service. Sirmillion will support verified tenant requests as required by the platform relationship and applicable law.
11. International processing and children
Service providers may process information in more than one country. Appropriate contractual, technical and organizational safeguards should be used where cross-border protections are required.
Sirmillion platform accounts are intended for authorized business users, not children. ISP tenants remain responsible for lawful handling of any customer information involving minors.
12. Updates and contact
This policy may be updated as Sirmillion’s services, providers and legal requirements evolve. The effective date will be revised and material changes communicated through reasonable channels.
Privacy questions or verified rights requests can be submitted through the Sirmillion contact page. Do not include passwords, private keys or payment secrets.