Effective Date: 25 August 2026
Last Updated: 25 August 2026
Metrix Dyx is a digital survey, market research, field-audit and data collection platform operated by Foresight.
This Privacy Policy explains how personal information is collected, used, stored, disclosed and protected when you use Metrix Dyx, including its web applications, mobile applications, APIs and related services.
We respect your privacy and are committed to handling personal data in accordance with applicable data protection laws, including the Constitution of Kenya, the Data Protection Act, 2019, the Data Protection (General) Regulations, 2021, and other applicable data protection requirements.
This Privacy Policy should be read together with any applicable terms of use, contractual agreements or client-specific privacy notices.
Metrix Dyx is operated by Foresight.
For questions concerning this Privacy Policy or the processing of personal data through Metrix Dyx, please contact us using the contact information provided at the end of this policy.
Depending on how Metrix Dyx is used, Foresight may act as:
a Data Controller, where Foresight determines the purposes and means of processing personal data; or
a Data Processor, where Foresight processes personal data on behalf of a client or other organisation that determines the purposes and means of processing.
Where a client uses Metrix Dyx to conduct surveys, audits, research or field activities, that client may be the Data Controller for information collected through the client's surveys and programmes.
The distinction between controllers and processors is recognised under Kenya's data protection framework.
Depending on how Metrix Dyx is configured and used, the platform may collect different categories of information.
This may include:
name;
username;
email address;
telephone number;
organisation;
job title or role;
account credentials;
user permissions;
login and account activity information.
Metrix Dyx may collect information submitted through surveys, questionnaires, polls and field audits.
This may include:
survey responses;
questionnaire answers;
outlet or account information;
product information;
product availability;
pricing information;
stock information;
ratings;
comments;
observations;
audit results;
dates and times of visits;
auditor or field-agent information;
survey metadata.
The exact information collected depends on the survey configured by the relevant organisation.
Where Metrix Dyx is used for market research or field audits, information may be collected about businesses and outlets, including:
business or outlet name;
account information;
outlet type;
channel;
physical or business location;
products and brands available;
pricing;
stock levels;
promotional activity;
business observations.
Some of this information may relate to businesses rather than identifiable individuals. Where information relates to an identifiable natural person, it may constitute personal data and will be handled accordingly.
Where enabled by a survey, Metrix Dyx may allow users to upload photographs or other evidence.
Such evidence may include:
shelf photographs;
product photographs;
promotional photographs;
outlet photographs;
documents or other uploaded evidence.
Users should not upload personal or sensitive information unless the survey or activity specifically requires it and the user has appropriate authority to do so.
When you access Metrix Dyx, we may collect technical information necessary to operate, secure and maintain the service, such as:
IP address;
browser type;
device type;
operating system;
application version;
login information;
timestamps;
system and diagnostic logs;
security and authentication events.
Where the mobile application provides access to device features such as camera, storage or location, the relevant permissions will be requested where required.
We may process personal data for purposes including:
providing and operating Metrix Dyx;
authenticating users;
managing user accounts and permissions;
administering surveys and questionnaires;
collecting and storing survey responses;
conducting market research and field audits;
analysing survey results;
generating reports and dashboards;
producing statistical and analytical outputs;
managing organisations, accounts, outlets and field activities;
maintaining system security;
detecting and preventing unauthorised access, fraud or misuse;
troubleshooting and improving the platform;
maintaining backups and business continuity;
communicating with users;
providing customer and technical support;
complying with applicable legal obligations; and
protecting our legal rights and interests.
We will not use personal data for purposes that are incompatible with the purposes for which it was collected unless permitted by applicable law or otherwise appropriately authorised.
The principles of purpose limitation, data minimisation, accuracy and storage limitation are recognised under Kenya's data protection framework.
Depending on the circumstances, personal data may be processed on one or more lawful bases permitted under applicable law.
These may include:
consent;
performance of a contract;
compliance with a legal obligation;
legitimate interests;
performance of a task carried out in the public interest, where applicable; or
processing for research, statistical or analytical purposes where permitted by law.
The appropriate lawful basis will depend on the nature and circumstances of the processing.
Where processing relies on consent, the relevant person may withdraw consent where permitted by law. Withdrawal of consent does not necessarily affect the lawfulness of processing carried out before consent was withdrawn.
Metrix Dyx is designed to allow organisations to configure and conduct their own surveys, audits and research activities.
Where an organisation uses Metrix Dyx to collect information from respondents, employees, field agents, customers, businesses or other individuals, that organisation may determine:
what information is collected;
why the information is collected;
how the information is used;
who may access the information;
how long the information should be retained; and
whether the information may be shared with other parties.
In such circumstances, the organisation may be the Data Controller and Foresight may process the information on the organisation's behalf.
If your information was collected through a specific organisation's survey, you may also need to contact that organisation regarding requests concerning your personal data.
We may disclose or provide access to personal data where reasonably necessary for the purposes described in this Privacy Policy.
This may include sharing information with:
Where Metrix Dyx is used on behalf of a client, authorised users of that client may access survey information according to the permissions configured by the client.
We may use third-party service providers to support the operation of Metrix Dyx, including providers of:
hosting;
cloud infrastructure;
database services;
security services;
backups;
communications;
technical support;
analytics;
application infrastructure.
Such providers should only receive information necessary to provide the relevant service and should be subject to appropriate contractual and security requirements.
We may disclose information where required or permitted by applicable law, regulation, court order, regulatory requirement or lawful government request.
If Foresight undergoes a merger, acquisition, restructuring, sale of assets or similar transaction, personal data may be transferred as part of that transaction, subject to applicable legal requirements and appropriate safeguards.
We do not sell personal data to third parties.
Personal data may, where necessary, be processed or stored using service providers located outside Kenya.
Where personal data is transferred outside Kenya, we will apply appropriate safeguards and comply with applicable requirements governing cross-border transfers.
Kenya's data protection framework places requirements on transfers of personal data outside Kenya, including the need for appropriate safeguards or other lawful grounds.
We take reasonable technical and organisational measures to protect personal data against:
unauthorised access;
unauthorised disclosure;
loss;
misuse;
alteration;
destruction; and
other unlawful or unauthorised processing.
Security measures may include:
authentication and access controls;
role-based permissions;
encrypted communications;
secure server infrastructure;
logging and monitoring;
backups;
controlled administrative access;
security updates;
operational procedures for handling security incidents.
No internet-based system can be guaranteed to be completely secure. Users are responsible for protecting their passwords and access credentials and should notify the appropriate administrator if they suspect unauthorised access.
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including where necessary to:
provide the Metrix Dyx service;
satisfy contractual requirements;
maintain business and technical records;
resolve disputes;
enforce agreements;
comply with legal obligations;
maintain backups and business continuity; or
support legitimate research or statistical purposes where applicable.
Retention periods may therefore differ depending on the type of information and the organisation responsible for the relevant survey or programme.
Where a client controls the survey data, the client's retention requirements may determine how long that information remains available through Metrix Dyx.
When personal data is no longer required, it will be deleted, anonymised or otherwise disposed of in accordance with applicable requirements and our retention procedures.
We take reasonable steps to ensure that personal data processed through Metrix Dyx is accurate and, where necessary, kept up to date.
Where you identify inaccurate or misleading personal information, you may request that it be corrected, subject to applicable law.
Subject to applicable law and any relevant limitations, you may have the right to:
be informed about the processing of your personal data;
access your personal data;
request correction of inaccurate or misleading personal data;
request deletion or erasure of personal data in appropriate circumstances;
object to the processing of your personal data;
request restriction of processing in appropriate circumstances;
request portability of personal data where applicable; and
withdraw consent where processing is based on consent.
The Office of the Data Protection Commissioner identifies these rights within Kenya's data protection framework.
Some rights are subject to legal conditions and exemptions. For example, deletion may not be available where continued processing is required by law or is otherwise permitted under applicable legislation.
To exercise a data protection right or make a privacy enquiry, please contact us using the contact details below.
To help us protect your information, we may need to verify your identity before responding to a request.
If your information was collected through a Metrix Dyx survey operated by one of our clients, we may direct your request to the relevant Data Controller or assist in forwarding the request where appropriate.
We will handle requests within the periods required by applicable law.
Metrix Dyx is primarily intended for business, research, survey and field-audit activities.
Unless specifically designed and authorised for a particular purpose, Metrix Dyx should not be used to collect personal data from children.
Where a survey is specifically intended to collect information relating to children, the organisation responsible for the survey must ensure that the collection and processing complies with applicable laws and safeguards.
Additional requirements may apply to children's personal data under Kenyan data protection law.
Metrix Dyx may be configured for different types of research and data collection. Users and client organisations should avoid collecting sensitive personal data unless it is genuinely necessary, legally permitted and appropriately safeguarded.
Where sensitive personal data is processed, additional legal requirements and safeguards may apply.
Metrix Dyx may use cookies or similar technologies where necessary to:
maintain authentication sessions;
remember user preferences;
maintain application functionality;
improve security;
monitor application performance; and
understand how the service is used.
Where non-essential cookies or similar technologies are introduced, appropriate notices or controls will be provided where required.
Metrix Dyx may contain links to websites or services operated by third parties.
This Privacy Policy does not govern the privacy practices of those third-party services.
We encourage users to review the privacy policies of external services before providing personal information to them.
We maintain procedures for identifying, assessing and responding to suspected personal-data security incidents.
Where a personal-data breach occurs, we will take reasonable steps to contain and investigate the incident and make notifications required by applicable law.
Depending on the nature of the incident, notification obligations may apply to the relevant Data Controller, Data Processor, regulatory authorities and/or affected individuals.
Privacy and data protection should be considered when new features, surveys, integrations and data-processing activities are introduced into Metrix Dyx.
We seek to apply principles such as:
data minimisation;
purpose limitation;
appropriate access controls;
security by design;
controlled retention;
transparency; and
appropriate privacy safeguards.
The Office of the Data Protection Commissioner encourages data controllers and processors to implement data protection mechanisms consistent with the Data Protection Act and the Data Protection (General) Regulations.
We may update this Privacy Policy from time to time to reflect:
changes to Metrix Dyx;
changes to how information is processed;
changes to applicable law;
changes to our service providers; or
improvements to our privacy practices.
When we make material changes, we may update the effective date displayed at the beginning of this policy and provide additional notice where appropriate.
The current version will be made available at:
https://foresight.co.ke/privacy.html
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how your personal data is being processed, please contact:
Foresight
Metrix Dyx Privacy Team
Website: https://foresight.co.ke/
Privacy Policy: https://foresight.co.ke/privacy.html
Email: info@foresight.co.ke
Telephone: +254727611915
Postal Address: 8457 - 00300, Nairobi
Please replace the bracketed contact details before publishing this policy.
If you are dissatisfied with how your personal data has been handled, we encourage you to contact us first so that we can investigate and attempt to resolve your concern.
You may also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC), which is responsible for regulating the processing of personal data and protecting data-subject rights in Kenya.
The ODPC provides information concerning data-subject rights and complaints through its official website.
This Privacy Policy is intended to operate in accordance with the laws of Kenya, including applicable data protection and privacy legislation.
Where Metrix Dyx is used in another jurisdiction, additional privacy requirements may apply depending on the nature of the processing and the location of the relevant individuals.
End of Privacy Policy