Policy
1. Scope and Applicability
This policy applies to:
- All users of our web and mobile applications;
- Event organizers, ticket buyers, and fundraiser participants;
- All personal data processed by Kolleti, Inc., a company incorporated and operating in Kenya.
This policy is designed to comply with:
- Kenya’s Data Protection Act, 2019;
- The General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA);
- Applicable international data privacy standards.
2. Data We Collect
We may collect the following types of data:
- Personal Identification Data: Name, phone number, email, ID number.
- Financial Data: Payment details (excluding full card numbers), transaction history.
- Event Interaction Data: Tickets purchased, events attended, fundraising activity.
- Usage Data: Device information, IP address, geolocation, browser information, and log data.
- Communication Data: Messages sent through our platform, support inquiries.
3. How We Use Your Data
We use your data for the following purposes:
- To process ticket sales, payments, and fundraising contributions.
- To manage your account and preferences.
- To provide customer support and resolve issues.
- To personalize your experience and offer relevant promotions or discounts.
- To send event reminders, confirmations, and transactional notifications.
- To analyze trends and improve our services.
- To comply with legal and regulatory obligations.
4. Lawful Basis for Processing
We only process your data when we have a legal basis to do so, including:
- Your consent, where required.
- Contractual necessity (e.g., ticket delivery).
- Legitimate interest, such as fraud prevention or service improvement.
- Legal obligations, such as tax compliance or law enforcement requests.
5. Data Sharing and Disclosure
Kolleti may share your data:
- With payment processors and financial institutions (e.g., Paystack, Flutterwave, M-Pesa).
- With event organizers (limited to relevant attendee information).
- With service providers (e.g., analytics tools, email platforms).
- When required by law, court order, or government regulation.
We do not sell or rent your personal data to third parties.
6. Data Storage and Transfers
- Your data may be stored in Kenya or securely transferred and processed in data centers outside Kenya, subject to adequate protection measures.
- We implement standard contractual clauses and encryption to safeguard international transfers.
7. Your Rights
Under Kenya’s DPA and other applicable laws, you have the right to:
- Access your personal data.
- Request correction or deletion.
- Object to or restrict processing.
- Withdraw consent at any time.
- Lodge a complaint with the Office of the Data Protection Commissioner (ODPC) in Kenya.
To exercise your rights, contact us at: privacy@kolleti.com
8. Data Retention
We retain personal data only as long as necessary to fulfill the purposes described above, or as required by law (e.g., for tax or compliance reasons). After that, data is securely deleted or anonymized.
9. Security Measures
Kolleti implements industry-standard security protocols to protect your data, including:
- SSL encryption
- Role-based access controls
- Regular security audits
- Secure payment gateways
10. Children’s Privacy
Kolleti does not knowingly collect or process personal data from individuals under 18 without parental consent. If we become aware of such data, we will delete it immediately.
11. Changes to This Policy
We may update this Data Policy occasionally. Material changes will be communicated via email or platform notification. Please review this policy regularly to stay informed.
12. Contact Us
If you have any questions or concerns about this policy or our data practices, please contact:
Kolleti, Inc.
support@kolleti.com