Privacy Policy Privacy Policy Statement Last Updated: November 19, 2025 Refugee Legal Networks (“we”, “us”, “our”) is committed to protecting your privacy and ensuring compliance with the Kenya Data Protection Act, 2019 (DPA). This Privacy Policy explains how we collect, use, store, and protect personal data through our web platform and checkout services. ________________________________________ 1. Data Controller Information For the purposes of the Kenya Data Protection Act, the Data Controller is: Refugee Legal Networks Ltd Address: Elysee Plaza, 4th Floor, Kilimani Road, Nairobi, Kenya. Email: info@refugeelegalnetworks.org Phone: (+254) 0116 451806 If we appoint a Data Protection Officer (DPO), their contact details will also be included here. ________________________________________ 2. Personal Data We Collect We collect the following categories of personal data when you make payments, purchase items or use our e-commerce checkout: a) Identification & Contact Information • Full name • Email address • Phone number • Billing and shipping address b) Payment Information Processed securely by third-party payment providers (e.g., MPesa, card processors). We do not store your full card, MPesa, or bank details. c) Transactional Information • Order details • Billing information • Donation receipts (if applicable) d) System & Usage Data • IP address • Browser type • Device identifiers • Web analytics and cookies ________________________________________ 3. Lawful Basis for Processing (as per DPA 2019) We process your personal data based on: • Performance of a contract – to process purchases or donations • Consent – for marketing communications • Legal obligation – for financial records, reporting, and audits • Public interest / NGO mandate – where relevant to our charitable goals • Legitimate interest – improving user experience and security ________________________________________ 4. How We Use Your Personal Data Your information may be used to: • Process, confirm, and deliver your orders • Provide customer support • Send receipts and donation acknowledgments • Improve website functionality and security • Maintain accurate financial and audit records • Send newsletters or campaign updates (only if you opt in) ________________________________________ 5. Sharing Your Personal Data We do not sell or rent your data. We may share personal data with: • Payment processors (MPesa, card processors, PayPal, etc.) • IT service providers and system hosts • Legal or regulatory authorities, when required by law All third parties are bound by data protection obligations under the DPA. ________________________________________ 6. Data Transfer Outside Kenya If data is stored or processed outside Kenya, we ensure: • Adequate safeguards • Compliance with the Data Protection (General) Regulations • Processing only in jurisdictions with appropriate data protection standards ________________________________________ 7. Data Retention We retain personal data only as long as necessary for: • Completing transactions • Compliance with the NGO Coordination Board and financial regulations • Legal and audit requirements After the retention period, data is securely deleted or anonymized. ________________________________________ 8. Data Security Measures We employ appropriate technical and organizational measures, including: • Encrypted payment processing • Secure servers and firewalls • Access controls and staff confidentiality obligations • Regular security reviews ________________________________________ 9. Your Rights Under the Kenya Data Protection Act You have the right to: • Access your personal data • Request correction of inaccurate data • Request deletion of your data (subject to legal retention limits) • Object to processing • Withdraw consent for marketing • Request data portability (where applicable) • Lodge a complaint with the Office of the Data Protection Commissioner (ODPC) Requests can be submitted to: info@refugeelegalnetworks.org ________________________________________ 10. Cookies and Tracking We use cookies to: • Maintain secure checkout sessions • Improve user experience • Analyze website performance You can manage cookie settings through your browser. ________________________________________ 11. Children’s Data Our web and e-commerce platform is not intended for children under 13. We do not knowingly collect children’s data without appropriate consent. ________________________________________ 12. Changes to This Policy We may update this Privacy Policy to reflect legal or operational changes. The updated version will always be posted with a revised “Last Updated” date. ________________________________________ 13. Contact Information For questions or data requests: Refugee Legal Networks Ltd Email: info@refugeelegalnetworks.org Phone: (+254) 0116 451806 Address: Elysee Plaza, 4th floor, Kilimani Road, Nairobi, Kenya