ICT Authority

ICTA

Boardroom Governance

Legal

License & Terms

Effective 1 January 2026 · Last updated 20 June 2026

License Valid

This software license is valid through 31 December 2030. Renewal will be communicated six months prior to expiry.

Proprietary Government Software

Ownership

This Boardroom Governance Portal (the “Software”) is the exclusive property of the Information & Communication Technology Authority of Kenya (“ICTA”). It is licensed — not sold — for internal Government of Kenya use. Redistribution, sublicensing, reverse engineering, decompilation, or external deployment without written authorization from the ICT Authority is strictly prohibited. All intellectual property rights, including patents, trademarks, copyrights, and trade secrets, remain vested in ICTA.

Deployment, Hosting & Data

Infrastructure

The Software is operated on-premise within ICTA infrastructure and synchronized with the Zimbra Collaboration Suite for calendar reconciliation. All booking, check-in, and audit data is the property of ICTA and is retained in accordance with the Government of Kenya Records Management Policy and the Public Archives and Documentation Service Act. Backups are encrypted at rest and replicated to an off-site ICTA facility. No data is transmitted to third-party cloud services without explicit written approval from the Director-General.

Acceptable Use Policy

Conduct

Authorized users (Secretariat, Organizers, Administrators, and designated guests) agree to use the Software only for legitimate boardroom scheduling, check-in, and oversight activities. All actions are immutably audit-logged with actor, timestamp, and IP address. Misuse — including fraudulent bookings, unauthorized access attempts, data exfiltration, or credential sharing — may result in immediate revocation of access and disciplinary action under the Public Service Code of Conduct and Chapter 6 of the Constitution of Kenya.

Security & Access Control

Protection

Access is granted on a principle of least privilege. Passwords must meet NIST SP 800-63B guidelines (minimum 12 characters, mixed case, digits, and symbols). Multi-factor authentication is enforced for all Administrator accounts. Session tokens expire after 24 hours of inactivity. All API endpoints are rate-limited and protected by Row-Level Security (RLS) policies. Security incidents should be reported immediately to .

License Validity & Renewal

Term

This license is granted for a term commencing 1 January 2026 and expiring 31 December 2030. Either party may terminate with 90 days written notice. Upon termination, all user access is revoked and data is archived per the retention schedule. The license auto-renews for successive one-year terms unless either party provides written notice of non-renewal at least six months prior to expiry. Renewal fees, if any, are subject to the ICT Authority procurement regulations.

Privacy & Data Subject Rights

GDPR / Data Protection

The Software processes personal data (names, email addresses, phone numbers, and meeting attendance records) in compliance with the Kenya Data Protection Act, 2019. Data subjects have the right to access, rectify, and request deletion of their personal data. Data Protection Impact Assessments (DPIAs) are reviewed annually. The ICTA Data Protection Officer (DPO) can be reached at .

Data Retention & Deletion

Retention

Booking records are retained for seven (7) years to support audit and compliance requirements. Audit logs are retained for ten (10) years. Personal data of deactivated users is anonymized after twelve (12) months unless a legal hold is in effect. Hard deletes are executed by the ICTA System Administrator only and require dual authorization.

Open Components & Attribution

Third Party

The Software incorporates open-source components used under their respective licenses (MIT, Apache 2.0, BSD-3-Clause). Notable components include React, TanStack Router & Query, Tailwind CSS, shadcn/ui, Lucide icons, and the Supabase client libraries. Full attribution and source code availability are provided on request from the Secretariat. Proprietary ICTA code is not open-source and may not be redistributed.

Disclaimer of Warranty

Liability

The Software is provided “as is” without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, or non-infringement. ICTA does not warrant that the Software will be uninterrupted, timely, secure, or error-free. In no event shall ICTA be liable for any indirect, incidental, special, consequential, or punitive damages arising out of or related to the use of the Software.

Governing Law & Dispute Resolution

Jurisdiction

This license shall be governed by and construed in accordance with the laws of the Republic of Kenya. Any dispute arising under this license shall first be subject to mediation by a mutually agreed mediator. If mediation fails within 60 days, the dispute shall be resolved through arbitration in Nairobi under the Arbitration Act, 1995. The parties agree to submit to the exclusive jurisdiction of the Kenyan courts.

Amendments & Updates

Changes

ICTA reserves the right to amend these terms at any time. Material changes will be notified via in-app banner and email to all active users at least 30 days before taking effect. Continued use of the Software after the effective date of any amendment constitutes acceptance of the revised terms. A complete version history is maintained in the audit log and is available to Administrators on request.

Contact & Escalation

Support

Questions regarding this license, data subject requests, security disclosures, or general inquiries should be addressed to the ICT Authority Secretariat at or by post to ICT Authority, Telposta Towers, 12th Floor, Kenyatta Avenue, Nairobi. Emergency security issues should be reported to .


© 2026 ICT Authority · All rights reserved · License valid through 2030