Privacy Policy
privacy policy
How Dotsavvy Limited collects, uses, shares and protects your personal data — and the rights you hold under Kenya’s Data Protection Act, 2019 and the EU General Data Protection Regulation (GDPR).
We collect only the personal data we need to answer your enquiries, send communications you have asked for, and consider job applications. We rely on a lawful basis for everything we do, we never sell your data, and you can exercise your rights — including access and erasure — at any time by writing to our Data Protection Officer. This page sets out the detail.
Dotsavvy Limited (“Dotsavvy”, “we”, “us”, “our”) is a digital agency incorporated in Kenya, with its registered office at Teja Spaces, Delta Riverside Office Park, Off Riverside Drive, Nairobi, Kenya. For the personal data we handle through this website and our own business activities, Dotsavvy is the data controller . When we process personal data on behalf of our clients while delivering our services, we act as a data processor under those clients’ instructions.
Dotsavvy is registered with the Office of the Data Protection Commissioner (ODPC) of Kenya as both a Data Controller and a Data Processor, and has appointed a Data Protection Officer (DPO) who oversees our compliance with this policy and the law.
This policy explains how we handle personal data under the Data Protection Act, 2019 of Kenya and its Regulations, and under the EU General Data Protection Regulation (GDPR) where we offer services to, or monitor the behaviour of, individuals in the European Economic Area (EEA). Where these frameworks set different standards, we apply the higher one. It applies to www.dotsavvyafrica.com and to the enquiries, subscriptions, applications and communications connected with it. It does not cover third-party websites we link to, which have their own policies.
We collect personal data in three ways:
We do not intentionally collect sensitive (special-category) data through this website; please do not send it to us unless it is genuinely necessary.
We use personal data to:
We do not sell your personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects on you.
We only process personal data where the law allows. Depending on the activity, we rely on one or more of the following bases:
Where we rely on legitimate interests, you have the right to object (see section 12). In rare cases we may also rely on vital interests or a public-interest task.
We use cookies and similar technologies to run the site, remember your preferences, measure performance and support marketing. Strictly necessary cookies are always active; all other categories are optional and set only with your consent, which you can give, refuse or change at any time via our cookie banner. Full detail — including each category and how to control it — is in our Cookie Policy .
We share personal data only where necessary, with:
We never sell your personal data or share it for third parties’ own marketing without your consent.
Some of our providers operate outside Kenya (and outside the EEA), so your data may be transferred across borders. When we transfer personal data internationally, we ensure a lawful basis and appropriate safeguards — such as transfer to a country recognised as providing an adequate level of protection, Standard Contractual Clauses or equivalent contractual protections, or your explicit consent. You may request details of the safeguards we use.
We keep personal data only for as long as necessary for the purposes described, after which we delete or anonymise it. Retention depends on the type of data and our obligations: enquiry and marketing data is kept while the relationship is active and for a reasonable period afterwards; recruitment data is kept for the duration of the process and a limited period thereafter, unless you agree we may keep it longer; and financial records are kept for the period required by tax law.
We maintain appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls on a need-to-know basis, regular backups, network protection and staff training. If a personal-data breach occurs that poses a risk to you, we will notify the ODPC within 72 hours where required, and affected individuals without undue delay.
Under the Data Protection Act, 2019 and the GDPR, you have the right to:
To exercise any right, contact our DPO (section 14). We respond within the statutory timeframe — generally within one month — and do not charge a fee, except for manifestly unfounded or excessive requests. We may ask you to verify your identity first.
If you have a concern about how we handle your data, please contact our DPO first so we can try to resolve it. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (Kenya) at odpc.go.ke, or — if you are in the EEA — with your local data-protection supervisory authority.
Children. This website is not directed at children under 18, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
Changes. We review this policy regularly and will post any updates here with a revised “last updated” date; we will highlight significant changes.
For any question about this policy, or to exercise your rights, contact our Data Protection Officer. A real person — not a bot — will respond.
Personal data — any information relating to an identified or identifiable natural person.
Processing — any operation performed on personal data, whether or not by automated means.
Data subject — the individual to whom personal data relates (you).
Data controller — the party that determines the purposes and means of processing.
Data processor — a party that processes personal data on behalf of a controller.
Sensitive (special-category) data — data such as health, ethnicity, religious belief or biometrics, which attracts additional protection.
Data you give us — your name, email address, phone number, company, and the content of your enquiry when you contact us or request a proposal; your details and preferences when you subscribe to our newsletter; and your CV, work history and qualifications when you apply for a role.
Data we collect automatically — your IP address, browser and device type, operating system, referring URLs, the pages you view, and approximate location (city/country), gathered through cookies and similar technologies (see section 7).
Data from other sources — where lawful, limited information from business partners, public professional profiles and analytics or advertising providers, to help us understand and reach our audience.
respond to enquiries and provide the information, proposals or services you request;
send our newsletter and marketing communications where you have subscribed or where otherwise permitted;
receive and assess job applications and manage recruitment;
operate, secure, maintain and improve the website and understand how it is used;
measure the effectiveness of our content, communications and campaigns;
meet our legal, regulatory, tax and accounting obligations; and
establish, exercise or defend legal claims, and prevent fraud and misuse.
Service providers (processors) — hosting, email delivery, analytics, CRM and recruitment tools — under contracts requiring them to protect your data and use it only on our instructions.
Professional advisers — lawyers, auditors and accountants, where reasonably required.
Authorities — where required by law, regulation, legal process or an enforceable governmental request.
Business transfers — in connection with a merger, acquisition or reorganisation, subject to this policy.
be informed about how your data is collected and used;
access the personal data we hold about you;
rectify inaccurate or incomplete data;
erase your data (the ‘right to be forgotten’) where applicable;
restrict processing in certain circumstances;
data portability — receive your data in a structured, commonly used format;
object to processing based on legitimate interests or to direct marketing;
not be subject to a decision based solely on automated processing that significantly affects you; and
withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.