Skip to main content
Platform Data

When Rexius builds the workflow, data has to move with purpose.

This page gives clients a practical view of the information that may pass through Rexius business systems and service workflows, and the responsibilities that sit around it.

This is not the MHPSS data notice.

MHPSS is operated on a dedicated platform with its own privacy and confidentiality information because the data context is different.

Where data appears

Different services create different records.

The important question is not whether Rexius has data. It is what the record is for, who should see it and what happens after the purpose is complete.

ERP & digital systems

Users, roles, approvals, invoices, finance records, HR or payroll workflow data, inventory, procurement, customer records, reports, audit logs and system configuration — according to the agreed implementation.

Commerce & after-sales

Order details, customer contact information, product records, payment references, receipts, delivery information, loyalty or support records needed to complete and support a transaction.

Consulting engagements

Business contacts, briefs, working documents, financial or operational records supplied for the assignment, agreed deliverables, project notes and invoice information.

Rexius Escapes

Guest contacts, requested dates, traveller counts, booking preferences, confirmations, payment references and itinerary or communication details needed for the agreed experience.

Curves BD x Rexius

Client contacts, order information, style preferences and measurements or fitting notes voluntarily provided where needed for custom work.

MHPSS requests

MHPSS requests should be made through mhpss.rexiuslited.co.ke. The dedicated MHPSS privacy notice explains that service's data practices.

Processing principles

The controls should follow the real risk.

01

Purpose before collection

We should be able to explain why a piece of information is needed for the service or system.

02

Access follows responsibility

People should only have the level of access needed for the role or task assigned to them.

03

Records should be traceable

Where the system supports it, approvals, changes and important actions should leave an audit trail.

04

Client instructions matter

For client-owned systems, the client remains responsible for its source data, user decisions and lawful business use, while Rexius follows the agreed technical and service scope.

05

Retention has a reason

Data is not kept merely because storage is available. Operational, contractual, accounting, security and legal needs guide retention.

06

No resale of client data

Rexius does not sell client platform data or customer communication data as a separate commercial product.

Client responsibilities

A secure system still depends on good user decisions.

Clients remain responsible for the accuracy and lawfulness of the data they enter, who they authorise as users, the decisions made from their records and the protection of their own credentials. Project agreements can assign additional responsibilities.

Questions or requests

Need to understand a specific implementation?

Data architecture, hosting, backups, roles, exports and retention can differ by client system. Use the project documentation or contact Rexius for the controls applicable to your implementation.