We respect your privacy
At KCDF, we respect your privacy as a donor, supporter, and/or user of our website. We are strongly committed to keeping any personal information we obtain from you or about you secure and to being transparent about the ways in which we use it.
This Policy is intended to help you understand the types of information we gather and cookies we use when you use our website (www.kcdf.or.ke). It also describes our practices for protecting, using, and sharing such information, and the choices you have regarding use.
Types of Personal Information We Collect and How We Collect Them
Our primary goals in collecting personal information from users of our website are to further our charitable purposes (for example by taking donations), to thank you for your support, and to share information about our work. For the purposes of the KENYA DATA PROTECTION (GENERAL) REGULATIONS, 2021, KCDF is a “controller” of your personal information collected through the website or otherwise provided to us (for example by you via email).
Personal information is collected (1) directly from you when you provide it to us; (2) from third parties where you have given your permission for it to be shared with us and (3) indirectly as you navigate through the website.
We may share personal information with third-party service providers we work with to perform these functions on our behalf, such as processing credit card payments and sending postal mail and email. If you choose to share where you heard about KCDF, we may share that information with specific third parties that are identified.
In connection with seeking employment or any other opportunity with KCDF, you may decide to submit, through our sites or otherwise, personal information (including your name, address, telephone number, e-mail address and any other personally identifiable information requested on our online and offline forms, as well as an electronic or paper copy of your resume/CV). All information entered into any online or offline forms related to employment or volunteering is held in confidence and will be viewed only for human resources purposes by KCDF and third parties that assist us with certain functions. This information may be used to assess your qualifications as an employee or volunteer for KCDF, or to analyze general patterns in applications for positions or hiring at KCDF.
When you make a donation to us via a third party, they may provide us with details of your donation and, where you have given that third party permission, they may share with us other personal information such as your name, location, mailing address, and contact details.
When you use our website, we may collect information about you through tracking technologies such as cookies and web beacons. This may include information about your browsing actions such as the frequency with which you visit various parts of the website. We use the information collected primarily to inform our efforts to provide an enhanced experience on the website.
From time to time, we may also obtain information about you from third-party sources, such as public databases, social media platforms, or third-party data providers. We take steps to ensure that such third parties are legally or contractually permitted to disclose such information to us.
The Purposes for which We Use Personal Information
- To provide you with the information or services you have requested, and communicate with you in general.
- To analyze, evaluate and improve our work, programmes, services, activities or information.
- To provide updates on our work and request donations
- To invite you to talks and events hosted by us.
- To thank donors for their support.
- >To administer any financial transaction between us.
- To recruit employees and volunteers.
- To ensure we are not contacting people who have told us not to.
- To satisfy legal obligations which are binding on us.
- For research purposes.
- For the prevention of fraud or misuse of services.
- And for the establishment, defense or enforcement of legal claims.
How We Use and Transfer Personal Information
KCDF engages third-party vendors to assist us with such functions as hosting our donor personal information database, sending emails, modeling our data, and processing online and mail donations and credit card payments. In addition, KCDF consults advisors in making organizational decisions and developing long-term plans. These companies and advisors have access to donors’ personal information as needed to perform their functions. KCDF requires that they keep such personal information confidential and that they not use such information for purposes other than the functions they are assisting us with.
We do not sell, rent, or give personal donor information to any other party not under the employ of, or in a direct advisory or vendorship role to KCDF. We may disclose to third parties aggregate statistics regarding donations but these statistics do not include any personally identifying information. The information given includes total number of donors and total amount of donations for specific periods.
Lawful Basis for Processing Personal Information
Where the KENYA DATA PROTECTION (GENERAL) REGULATIONS, 2021 applies to our operations, we are required to rely on one or more lawful bases to collect and use your personal information. Where this is the case, we rely on the following lawful bases:
- Consent: We may ask for your consent to use your personal information for certain purposes, for example, by asking you to agree to receive email marketing from us. You always have the right to withdraw your consent.
- Legitimate interests: We may process personal information on the basis that there is a legitimate interest, either to us or to a third party, and the processing is reasonably necessary to further that interest. Where we process your personal information on this basis, we do so after careful consideration of whether the same objective could be achieved through other means and whether you would expect us to process your personal information, and whether you would consider it reasonable to do so (in other words, we check that our use is fair, balanced and does not unduly impact your rights). Our legitimate interests, for example, include the pursuit of our charitable purposes, and administration – so for instance we will rely on the legitimate interest ground to communicate with you in most instances such as to process your donations.
- Contract: We may process your personal information where we have a contract with you, in order to fulfil that contract, or to take steps at your request prior to entering into one.
- Legal obligation: We may rely on this basis where the processing of your personal information is necessary for us to comply with a legal obligation to which we are subject (for example, reporting to tax authorities).
Disclosure of Personal Information to third parties
- to comply with law or regulation,
- to our professional advisors (e.g. lawyers), where necessary to protect our interests,
- to protect your safety or security (including fraud protection),
- to protect the security of our website and any property that belongs to us, our personnel or other users, and/or
- in the event that we transfer or receive any business or assets (in which case we will disclose personal information to the prospective transferor or transferee) or if substantially all of our assets are acquired by a third party (in which case personal information held by us may be one of the transferred assets), as part of a restructure or otherwise.
Otherwise, we will generally inform you and ask for your consent before we share your personal information with a third party.
Personal Information Protection and Security
All personal information is stored securely. We endeavor to protect your personal information and employ both appropriate technical and procedural methods, such as commercially reasonable administrative, technical, and physical safeguards against accidental or unlawful destruction or loss, or unauthorized disclosure, access or use.
To prevent unauthorized access to data we have several security protocols, internal policies, and technologies. These include website SSL encryption, password management, multi-factor authentication, and other techniques.
Please be aware that, despite our best efforts, no security measures are perfect or impenetrable and any transmission of personal information is at your own risk.
Data Retention Period
Personal information that we process shall not be kept for longer than is necessary in connection with the purposes for which it was collected and/or is used.
In some cases, we may keep your personal information for longer, for instance where we are required to do so in accordance with legal or regulatory requirements (such as tax and accounting).
In specific circumstances, we may also retain your personal information for longer so that we have an accurate record of your dealings with us in the event of any complaints or challenges.
Your Individual Rights
In general, please note that we will honor your requests to exercise your rights to the extent possible and required under applicable law. Certain of these rights (including those set out in section 3, including 3.1 and 3.2 below) may only be available to you if you are located within Kenya when you access our website or otherwise engage with us.
- Of access to the personal information we hold.
- To rectification of any personal information we hold.
- To erasure of your personal information.
- To restrict the processing of your personal information.
- To data portability of your personal information.
- To object to processing; and
- To not be subject to automated decision-making including profiling
Please note that you also have the right to lodge a complaint with your local data protection authority about how we use your personal information. Please always consider raising your concern with us first by contacting us using the contact details in section 2.
Accessing your Personal Information
Individuals can find out if we hold any of their personal information by making a “subject access request” under the Kenya Data Protection (General) Regulations, 2021 If we do hold personal information about you, we will (subject to entitlement and exemptions):
- Give you a description of it;
- Tell you why we are holding it;
- Tell you to who it could be disclosed;
- and Let you have a copy of the information in an intelligible form
Withdrawing your consent.