Last updated: 26 July 2026
1. Who we are
kTech Solutions (Company Registration No. RCBS2015I1284), of Sigatoka, Fiji, operates the website at ktechsol.net and provides information and communications technology services to public sector, regulated and commercial clients across the Pacific.
This Privacy Policy explains what personal information we collect through this Website, why we collect it, how we handle it, and the choices available to you. It also explains, in outline, how we treat personal information entrusted to us by clients in the course of delivering services.
2. Legal framework
Section 24 of the Constitution of the Republic of Fiji 2013 confers on every person the right to personal privacy, including the privacy of communications and the right not to have personal information unlawfully required, collected or disclosed. We treat that right as the foundation of this Policy.
Our practices are also informed by the Information Act 2018, the Cybercrime Act 2021, the Electronic Transactions Act 2008, sector-specific confidentiality obligations applying to our clients, and recognised international standards for information security and data governance.
Where a client is subject to a data protection regime of another jurisdiction, or to sectoral rules governing official information, we will comply with such additional obligations as are agreed in the applicable services agreement.
3. Information we collect through this Website
3.1 Information you give us
When you submit our contact form we collect the information you enter, namely: your name, company or organisation, telephone number, email address, subject, and the content of your message. Providing this information is voluntary; however, we cannot respond to an enquiry without at least a means of contacting you.
If you correspond with us by email or telephone we will hold a record of that correspondence.
3.2 Information collected automatically
Our web server records standard technical information in its access logs, including IP address, date and time of request, pages requested, referring page, and browser and operating system identifiers. These logs are generated by the hosting infrastructure for security, diagnostic and capacity purposes.
Where anti-automation protection is enabled on our forms, the provider of that service processes technical signals — such as IP address and browser characteristics — for the sole purpose of distinguishing human visitors from automated traffic.
3.3 What we do not do
We do not currently operate advertising networks, behavioural tracking, profiling, or third-party analytics that identify individual visitors on this Website. We do not sell, rent or trade personal information. We do not make automated decisions producing legal or similarly significant effects.
Should this change, this Policy will be updated before the change takes effect.
4. Purposes for which we use personal information
We use personal information collected through the Website only for the following purposes:
- to respond to enquiries and to provide information requested by you;
- to prepare proposals, quotations and expressions of interest;
- to establish, administer and perform a contract for services;
- to maintain the security, integrity and availability of the Website and our systems;
- to detect, prevent and investigate fraud, misuse and unlawful activity; and
- to comply with legal, regulatory, taxation and record-keeping obligations.
We will not use personal information collected for one purpose for an unrelated purpose without your consent, unless required or authorised by law.
5. Basis on which we collect
We collect personal information through this Website with your knowledge and consent, given by your act of submitting it to us, and only such information as is reasonably necessary for the purposes described above. Where we collect information in performance of a contract or to meet a legal obligation, we rely on that basis.
You may withdraw consent to further contact at any time by writing to the address in clause 13. Withdrawal does not affect the lawfulness of prior processing, nor our ability to retain records we are required by law to keep.
6. Disclosure of personal information
We do not disclose personal information except:
- to our personnel and subcontractors who require it to perform the purposes described in clause 4, and who are bound by confidentiality obligations;
- to service providers who host our infrastructure or supply security and anti-automation services, acting on our instructions;
- to professional advisers, auditors or insurers where reasonably required;
- where required or authorised by law, by a court of competent jurisdiction, or by a regulatory or law-enforcement authority; or
- with your consent.
Where we engage a service provider, we take reasonable steps to satisfy ourselves that the provider is capable of protecting the information to a standard consistent with this Policy.
7. Cross-border disclosure
Some of the infrastructure and security services supporting this Website may be operated by providers located outside Fiji, or may route or store data outside Fiji. Where this occurs, we take reasonable steps to ensure the information is handled consistently with this Policy and the protections available under Fiji law.
For client engagements, hosting location and data residency are determined in the applicable services agreement. Where a client requires that data remain within Fiji, or within a specified jurisdiction, that requirement will be recorded in the agreement and given effect in the solution design.
8. Retention
We retain personal information only for as long as is necessary for the purposes for which it was collected, or for such longer period as is required by law — including retention obligations arising under taxation, corporate and contractual record-keeping requirements.
Enquiries which do not result in an engagement are ordinarily retained for a period sufficient to allow follow-up and then securely deleted. Server access logs are retained on a rolling basis for security and diagnostic purposes.
9. Security
We apply technical and organisational measures appropriate to the sensitivity of the information we hold, including access control on a need-to-know basis, encryption of data in transit, hardened server configuration, patching, monitoring, logging and backup.
Unauthorised access to, or interference with, data held on our systems may constitute an offence under the Cybercrime Act 2021 (Fiji), and we will refer suspected offences to the appropriate authorities.
No method of transmission or storage is entirely secure. While we take reasonable steps to protect personal information, we cannot guarantee absolute security. Where we become aware of a breach of security likely to cause harm, we will act promptly to contain and remediate it and will notify affected persons and any relevant authority where required or appropriate.
10. Personal information held on behalf of clients
In delivering services we may host, process or access personal information belonging to a client’s staff, customers or citizens. In relation to that information we act as a processor on the client’s documented instructions, and not as the controller.
Such information is handled in accordance with the applicable services agreement, which governs permitted use, confidentiality, security controls, sub-processing, breach notification, data residency, audit rights, and return or destruction on termination. Individuals with an enquiry about information held in a client’s system should approach that organisation directly; we will support our client in responding.
11. Your rights
Subject to any lawful exception, you may:
- request confirmation of whether we hold personal information about you, and request access to it;
- request correction of information that is inaccurate, incomplete, out of date or misleading;
- request deletion of information we are not required to retain;
- withdraw consent to further contact; and
- make a complaint about our handling of your personal information.
We will acknowledge a request promptly and respond within a reasonable period. We may need to verify your identity before acting on a request. We do not charge for making a request, though a reasonable charge may apply where a request is manifestly excessive or repetitive.
12. Cookies and similar technologies
This Website does not set advertising or tracking cookies on ordinary visits. Cookies or equivalent local storage may be used where strictly necessary for the operation of the Website — for example, to maintain a session, to record acceptance of a notice, to support page caching, or to operate anti-automation protection on forms.
Most browsers allow you to refuse or delete cookies. Restricting strictly necessary cookies may affect the functioning of parts of the Website.
13. Children
This Website is directed to organisations and business users. We do not knowingly collect personal information from children. Where we become aware that we have inadvertently collected such information without appropriate authority, we will delete it.
14. Changes to this Policy
We may update this Policy to reflect changes in our practices, in the services we provide, or in applicable law. The current version is always published on this page with the date of last revision shown at the top. Material changes will be brought to the attention of clients with whom we have an ongoing engagement.
15. Contact and complaints
Enquiries, access and correction requests, and complaints concerning privacy may be directed to:
kTech Solutions
Privacy Enquiries
Company Registration No. RCBS2015I1284
Sigatoka, Fiji
Email: hello@ktechsol.net
Telephone: +679 921 3005
If you are not satisfied with our response, you may seek recourse through the appropriate authority or the courts of Fiji.