Quick Summary
Here's what this document covers in plain language:
- We collect only what we need — your name, email, phone when you contact us, plus basic analytics
- We never sell your information to anyone
- We use industry-standard security to protect your data
- You can request, correct, or delete your data at any time
- We comply with the Kenya Data Protection Act 2019 and GDPR
This summary is for convenience only. The full text below is the binding version.
1. Introduction
Your privacy matters to us. This policy explains what information we collect when you visit our website, how we use it, and your rights regarding your data.
Our Commitment
We are committed to collecting only what we need, protecting your information, being transparent about our practices, respecting your privacy rights, and complying with the Kenya Data Protection Act 2019 and GDPR.
Questions about this policy? Email us at privacy@chach-a.com
2. Who We Are
Chacha Technologies
Nairobi, Kenya
Contact: privacy@chach-a.com
Phone: +254 796 280 700
3. Information We Collect
3.1 Information You Give Us Directly
When you contact us or request a quote:
- Name
- Email address
- Phone number
- Company name (if applicable)
- Project details
- Any information you include in your message
When you subscribe to our newsletter:
- Email address
- Name (optional)
- Communication preferences
3.2 Information Collected Automatically
When you visit our website:
- IP address
- Browser type and version
- Device type
- Pages visited
- Time spent on pages
- Referring website
- General location (city/country level)
3.3 Cookies and Tracking
We use:
- Essential cookies — site functionality
- Analytics cookies (e.g., analytics and session replay tools) — to understand site usage
- No advertising or tracking cookies
You can disable cookies in your browser, but some features may not work properly.
3.4 Information We DON'T Collect
We never collect:
- Payment card details (processed securely by payment providers)
- Sensitive personal data (unless relevant to a project, with consent)
- Information from children under 18
4. How We Use Your Information
4.1 To Provide Services
- Respond to inquiries
- Prepare quotes and proposals
- Deliver contracted services
- Communicate about projects
- Provide customer support
Legal Basis: Contract performance, legitimate interests
4.2 To Improve Our Website
- Analyze site usage
- Fix technical issues
- Improve user experience
- Optimize content
Legal Basis: Legitimate interests
4.3 To Communicate With You
- Send project updates
- Share relevant case studies (if subscribed)
- Industry insights (if subscribed)
- Service announcements
Legal Basis: Consent (newsletters), legitimate interests (service updates)
What We DON'T Do
We never sell your data, share it with advertisers, spam you, or use it for unrelated purposes.
5. How We Share Your Information
5.1 We May Share With
Service Providers (with data processing agreements):
- Hosting provider (secure servers)
- Email service (newsletters, transactional emails)
- Analytics providers (anonymized data)
- Payment processors (mobile money providers, banks — they handle data securely)
Legal Requirements:
- If required by Kenyan law
- Court orders or legal process
- To protect our legal rights
- To prevent fraud or harm
5.2 We NEVER Share With
- Third-party marketers
- Data brokers
- Advertising networks
- Anyone else not listed above
5.3 International Transfers
Some service providers may be outside Kenya (e.g., cloud hosting). When transferring data internationally, we ensure adequate protection through GDPR-compliant measures, approved providers, and data processing agreements.
6. How We Protect Your Information
6.1 Security Measures
- SSL encryption on our website
- Secure servers with encryption at rest
- Regular security updates
- Access controls (only authorized staff)
- Secure password policies
- Regular encrypted backups
6.2 Data Retention
We keep your data for the following periods:
- Contact inquiries: 2 years (unless you become a client)
- Client project data: Duration of project + 7 years (tax/legal requirements)
- Newsletter subscribers: Until you unsubscribe
- Analytics: 26 months
- Legal records: As required by law
6.3 What If There's a Breach?
If we discover a data breach:
- We'll notify affected individuals within 72 hours
- Report to the Data Commissioner (if required)
- Take immediate steps to secure data
- Investigate and prevent recurrence
7. Your Privacy Rights
Under the Kenya Data Protection Act and GDPR, you have the right to:
- Access — Request a copy of your personal data we hold
- Correction — Ask us to correct inaccurate information
- Deletion("Right to be Forgotten") — Request deletion of your data (with exceptions for legal obligations)
- Restriction — Ask us to limit how we use your data
- Portability — Receive your data in a machine-readable format
- Object — Object to processing based on legitimate interests
- Withdraw Consent — Unsubscribe from marketing at any time
- Complain — Lodge a complaint with the Office of the Data Protection Commissioner (Kenya) or your local data protection authority (EU)
8. How to Exercise Your Rights
To exercise any of your rights:
Email: privacy@chach-a.com
Subject:"Privacy Rights Request — [Your Name]"
Include:
- Which right you're exercising
- Your contact information
- Proof of identity (to prevent unauthorized access)
We'll respond within 30 days (Kenya DPA) or 1 month (GDPR). No fee unless the request is excessive or repeated.
To unsubscribe from emails, click the "unsubscribe" link in any email or contact us at privacy@chach-a.com
10. Third-Party Links
Our website may link to external sites (portfolio examples, social media, client sites). We are not responsible for their privacy practices, content, or security. Please review their privacy policies separately.
11. Children's Privacy
Our services are for businesses, not children under 18. We do not knowingly collect data from children. If you believe we've collected child data, contact us immediately at privacy@chach-a.com and we'll delete it promptly.
12. Changes to This Policy
We may update this policy to reflect new practices, comply with new laws, or improve clarity.
When we update:
- We'll change the "Last Updated" date
- Notify subscribers of major changes
- Post prominent notice on our website for 30 days
Continued use after changes constitutes acceptance.
13. Contact Us
Privacy Questions:
Email: privacy@chach-a.com
Phone: +254 796 280 700
General Contact:
Email: info@chach-a.com
Website: www.chach-a.com
Office:
Nairobi, Kenya
Regulatory Authorities
If you're not satisfied with our response:
- Kenya: Office of the Data Protection Commissioner — www.odpc.go.ke
- EU (if applicable): Your local data protection authority