Data Protection Policy
Effective Date: June 01, 2024
DataAWARE360 ("we," "us," or "our") is committed to protecting the
privacy and personal data of our
users in compliance with Kenya's Data Protection Act and other applicable data protection laws.
This
Data Protection Policy outlines the measures we take to safeguard personal data and ensure its
proper handling.
1. Data Protection Principles
We adhere to the following data protection principles:
- Lawfulness, Fairness, and Transparency: We process personal data lawfully,
fairly, and in a transparent manner.
- Purpose Limitation: We collect personal data for specified, explicit, and
legitimate purposes and do not process it further in ways that are incompatible with those
purposes.
- Data Minimization: We collect only the personal data that is necessary for
the
purposes for which it is processed.
- Accuracy: We take reasonable steps to ensure personal data is accurate and,
where necessary, kept up to date.
- Storage Limitation: We keep personal data in a form that permits
identification
for no longer than necessary for the purposes for which it is processed.
- Integrity and Confidentiality: We process personal data in a manner that
ensures its security, including protection against unauthorized or unlawful processing and
against accidental loss, destruction, or damage.
2. Data Processing Activities
We collect and process personal data for the following purposes:
- Providing and Improving Services: To deliver and improve our services,
personalize user experience, and develop new features.
- Communications: To communicate with users, respond to inquiries, and
provide
customer support.
- Marketing and Promotions: To send promotional materials and updates about
our
products and services, with user consent.
- Compliance: To comply with legal obligations and protect our rights and
interests.
Types of personal data we collect include:
- Personal Identification Information: Name, email address, phone number, and
postal address.
- Usage Data: Information about how users interact with our website and
services.
- Technical Data: Device type, operating system, and other technology used to
access our website.
- Communications Data: Records of interactions with us, including emails and
chat
logs.
3. Data Security Measures
We implement appropriate technical and organizational measures to
ensure the security of personal
data, including:
- Encryption: Encrypting data during transmission and at rest to protect
against
unauthorized access.
- Access Controls: Restricting access to personal data to authorized
personnel
only.
- Regular Security Audits: Conducting regular security audits and assessments
to
identify and mitigate potential risks.
- Employee Training: Providing regular training to employees on data
protection
and security best practices.
4. Data Breach Response Plan
In the event of a data breach, we have a response plan to:
- Contain the Breach: Take immediate steps to contain the breach and prevent
further unauthorized access or data loss.
- Assess the Impact: Evaluate the nature and extent of the breach and the
potential impact on individuals.
- Notify Affected Individuals: Inform affected individuals about the breach
and
provide guidance on how to protect themselves.
- Report to Authorities: Notify the relevant data protection authority as
required by law.
- Review and Mitigate: Review the incident to determine the root cause and
implement measures to prevent future breaches.
5. Data Retention Policies
We retain personal data only as long as necessary for the purposes
for
which it was collected, in
accordance with our data retention policies:
- Service-Related Data: Retained for the duration of the user’s account and
as
required to fulfill contractual obligations.
- Legal Compliance: Retained as required by law, such as for tax and
accounting
purposes.
- Marketing Data: Retained until users opt out of receiving marketing
communications or withdraw their consent.
- Deletion Requests: Personal data is deleted or anonymized upon user
request,
subject to certain legal exceptions.
Contact Us
If you have any questions or concerns about this Data Protection
Policy
or our data practices, please
contact us at:
DataAWARE360
support@dataaware360.com
+254 734 877 508
By using our website and services, you acknowledge that you have
read,
understood, and agree to this
Data Protection Policy. Thank you for trusting DataAWARE360 with your personal information.