Data Protection & Privacy Policy
Introduction
​
The CPF Group Foundation ("The Foundation," "we," "us," or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy outlines how we collect, use, disclose, and protect your personal data in accordance with the Kenya Data Protection Act, 2019 (the "Act"). (Section 3 - Obligation to comply with data protection principles)
​
Data Collection
We collect personal data that you voluntarily provide to us when you interact with The Foundation. This includes situations where you:
​
-
Register for an account or service: The Foundation offers various services that may require you to create an account. During registration, we may collect data such as your name, email address, username, and password. (Section 18 - Collection of personal data)
-
Participate in our programs, events, or surveys: We may collect your personal data when you register for or participate in Foundation activities such community events, workshops, conferences, online courses, or surveys. This data may include your name, contact information, professional affiliation, and any relevant responses or feedback you provide. (Section 18 - Collection of personal data)
-
Contact us for inquiries or support: The Foundation offers various channels for contacting us, such as email forms, phone calls, or live chat. When you reach out to us with a question or request support, we may collect your name, contact information, and the nature of your inquiry to effectively address your needs. (Section 18 - Collection of personal data)
-
​
The specific types of personal data we collect will depend on the nature of your interaction with The Foundation. We strive to collect only the data necessary to provide you with the requested services or support your inquiries. (Section 18(2) - Purpose limitation)
​
Data Use
​
The Foundation utilizes your personal data for legitimate purposes that directly benefit you and support our mission. These purposes include:
-
Service Delivery and Account Management: We use your data to provide, operate, and maintain our services. This may involve processing your account information to grant access to online platforms, registering you for events, or fulfilling your service requests. (Section 18(2) - Purpose limitation)
-
Communication and Updates: The Foundation may use your contact information to send you important updates about our services, program announcements, or relevant news related to our work. However, we will only send you marketing or promotional communications with your explicit consent. (Section 31 - Direct marketing)
-
Website and Service Improvement: The Foundation analyzes user data to understand how visitors interact with our website and services. This data helps us identify areas for improvement, personalize your user experience, and ensure the functionality and effectiveness of our offerings. (Section 18(2) - Purpose limitation)
-
Compliance with Legal Obligations: In certain situations, The Foundation may be required to disclose your personal data to comply with legal or regulatory requirements. This may involve responding to court orders, subpoenas, or lawful requests from government authorities. (Section 37 - Disclosure of personal data)
Data Protection
​
The Foundation takes data security seriously and adheres to the principles outlined in the Act. We implement robust technical and organizational measures to safeguard your personal data from unauthorized access, disclosure, alteration, or destruction. These measures include:
-
Secure Storage: We store your personal data on secure servers using encryption technologies to prevent unauthorized access. (Section 23 - Security safeguards)
-
Access Controls: We restrict access to your personal data to authorized personnel who have a legitimate business need to access it. (Section 23 - Security safeguards)
-
Data Retention: The Foundation retains your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or to comply with legal requirements. (Section 20 - Data retention period)
Your Rights
​
The Act grants you certain rights regarding your personal data. The Foundation respects your rights and provides mechanisms for you to exercise them:
-
Right to Access: You have the right to request a copy of the personal data The Foundation holds about you. This allows you to verify the accuracy of your data and understand how it is being used. (Section 33 - Right of access)
-
Right to Rectification: If you discover any inaccuracies in your personal data, you have the right to request that The Foundation rectify them. We encourage you to keep your information updated to ensure its accuracy. (Section 35 - Right to rectification)
-
Right to Object: You have the right to object to the processing of your personal data for marketing purposes or in situations where processing no longer serves a legitimate purpose, as stipulated in Section 34 of the Act. (Section 34 - Right to object)
-
Right to Data Portability: Under certain circumstances, you have the right to request that The Foundation transfer your personal data to another data controller in a structured, commonly used, and machine-readable format, as outlined in Section 36 of the Act. (Section 36 - Right to data portability)
To exercise any of these rights, you can contact The CPF Group Foundation using the contact information provided on our website or through the designated channels outlined in the Act (Section 32 - Manner of exercising rights). We will respond to your requests within a reasonable timeframe as required by law (Section 42 - Timeframes for responding to requests).
​