Privacy Policy

Last updated: August 2026

1. Introduction

Auschidys Disability Africa (“we”, “us”, or “our”) is committed to protecting your privacy and handling your personal data in accordance with the Kenya Data Protection Act, 2019 (No. 24 of 2019) and the regulations issued by the Office of the Data Protection Commissioner (ODPC). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you interact with us through our website, programmes, events, or other services.

The Data Protection Act, 2019 gives effect to the constitutional right to privacy under Article 31(c) and (d) of the Constitution of Kenya. Its objectives are to regulate the processing of personal data, provide for the rights of data subjects, establish obligations for data controllers and processors, and create the legal and institutional framework for data protection in Kenya.

We act as the Data Controller for the personal data we collect, meaning we determine the purpose and means of processing your personal data. This Privacy Policy should be read alongside our Cookie Policy, which provides further information about how we use cookies on our website.

By engaging with us, you consent to the collection and processing of your personal data as described in this policy. Where required by law, we will ask for your explicit consent before processing your data for specific purposes.

2. Personal Data We Collect

We may collect the following categories of personal data:

2.1 Information You Provide to Us

  • Contact Information: name, email address, telephone number, postal address.
  • Demographic Information: age, gender, location, county of residence.
  • Donation and Payment Information: financial details required to process donations (processed securely through our payment partners).
  • Programme Participation Data: information about your involvement in our programmes, including any disability-related information you choose to share.
  • Communications: any correspondence you send to us via email, phone, or through our website.

2.2 Information Collected Automatically

When you visit our website, we may automatically collect:

  • Device and Browser Information: IP address, browser type, operating system, and device identifiers.
  • Usage Data: pages visited, time spent on the site, referring URLs, and other analytics data.
  • Cookie Data: as detailed in our Cookie Policy.

2.3 Sensitive Personal Data

Under the Data Protection Act, 2019, sensitive personal data includes information revealing a person’s race, health status, ethnic social origin, and other special categories of data. We may collect disability and health-related information when you participate in our programmes. We only collect such data with your explicit consent and for the specific purposes outlined in this policy.

3. How We Collect Personal Data

We collect personal data in the following ways:

  • Directly from you: when you fill in forms on our website, register for our programmes, make a donation, subscribe to our newsletter, or contact us.
  • Through our partners: when you are referred to us by schools, healthcare providers, community organisations, or government agencies.
  • Automatically: through cookies and similar technologies when you use our website.
  • From public records: where permitted by law and where the data is contained in a public record.

We collect personal data directly from the data subject wherever practicable.

4. Legal Basis for Processing

Under Section 30 of the Data Protection Act, 2019, we process personal data only on the following lawful bases:

  • Consent: you have given explicit, free, specific, and informed consent for the processing of your personal data for one or more specified purposes.
  • Contractual Necessity: processing is necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into a contract.
  • Legal Obligation: processing is necessary for compliance with a legal obligation to which we are subject.
  • Vital Interests: processing is necessary to protect the vital interests of the data subject or another person.
  • Public Interest: processing is necessary for the performance of a task carried out in the public interest.
  • Legitimate Interests: processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your fundamental rights and freedoms.

5. How We Use Your Personal Data

We use your personal data for the following purposes:

  • To deliver our programmes: enrolling participants, providing services, and monitoring programme outcomes.
  • To process donations: managing contributions, issuing receipts, and communicating with donors.
  • To communicate with you: responding to enquiries, sending newsletters, sharing programme updates, and providing information about our work.
  • To improve our services: analysing data to understand the needs of our beneficiaries and improve our programmes.
  • To comply with legal obligations: meeting our reporting and regulatory requirements.
  • To ensure website functionality: managing your preferences, remembering settings, and improving user experience.

We collect, store, and use personal data only for purposes that are lawful, specific, and explicitly defined.

6. Data Sharing and Disclosure

We may share your personal data with:

  • Service Providers: third-party vendors who help us operate our website, process donations, and deliver our programmes (e.g., payment processors, IT service providers).
  • Partner Organisations: schools, healthcare providers, government agencies, and other organisations with whom we collaborate to deliver services.
  • Legal and Regulatory Authorities: where required by law or to protect our rights and interests.

When we share personal data with third parties, we ensure that appropriate contractual safeguards are in place, in accordance with the Data Protection Act, 2019.

We do not sell your personal data to third parties for commercial purposes.

7. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.

When determining the appropriate retention period, we consider:

  • The amount, nature, and sensitivity of the personal data.
  • The potential risk of harm from unauthorised use or disclosure.
  • The purposes for which we process the data and whether we can achieve those purposes through other means.
  • Applicable legal requirements.

Once personal data is no longer required, we will securely delete or anonymise it.

8. Data Security

We are committed to ensuring the security of your personal data. We implement appropriate technical and organisational measures to protect your data from unauthorised access, loss, misuse, or disclosure, in accordance with Section 32 of the Data Protection Act, 2019.

These measures include:

  • Encryption: protecting data in transit and at rest.
  • Access Controls: restricting access to personal data to authorised personnel only.
  • Staff Training: ensuring our team understands their data protection obligations.
  • Security Policies: maintaining and regularly reviewing our data protection and security policies.

Despite our efforts, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we strive to protect your personal data to the best of our ability.

9. Data Protection Principles

Our processing of personal data is guided by the following principles established under the Data Protection Act, 2019:

Principle Description
Lawfulness, Fairness, and Transparency We process personal data lawfully, fairly, and in a transparent manner.
Purpose Limitation We collect personal data for specified, explicit, and legitimate purposes and do not process it further in a manner incompatible with those purposes.
Data Minimisation We collect only the personal data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
Accuracy We take reasonable steps to ensure that personal data is accurate and, where necessary, kept up to date.
Storage Limitation We keep personal data in a form which permits identification of data subjects for no longer than is necessary.
Integrity and Confidentiality We process personal data in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
Accountability We are responsible for and able to demonstrate compliance with the above principles.

10. Your Rights as a Data Subject

Under Section 26 of the Data Protection Act, 2019, you have the following rights regarding your personal data:

10.1 Right to be Informed

You have the right to be informed of the use to which your personal data is to be put.

10.2 Right to Access

You have the right to request access to your personal data held by us.

10.3 Right to Rectification

You have the right to request the correction of false or misleading personal data about you.

10.4 Right to Erasure

You have the right to request the deletion of false or misleading data about you or data that is no longer required for the purposes for which it was collected.

10.5 Right to Object

You have the right to object to the processing of all or part of your personal data.

10.6 Right to Data Portability

You have the right to request the transfer of your personal data to another data controller in a structured, commonly used, and machine-readable format.

10.7 Right to Withdraw Consent

You have the right to withdraw your consent to the processing of your personal data at any time, where processing is based on consent.

10.8 Right to Restriction of Processing

You have the right to request the restriction of processing of your personal data in certain circumstances.

11. How to Exercise Your Rights

To exercise any of your rights as a data subject, please contact us using the details provided in Section 17. We will respond to your request within 30 days as required under the Data Protection Act, 2019.

We may need to verify your identity before processing your request. Where requests are manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on the request.

12. Data Protection Impact Assessments

Where our processing activities are likely to result in a high risk to your rights and freedoms, we conduct Data Protection Impact Assessments (DPIAs) in accordance with Part VIII of the Data Protection (General) Regulations, 2021. This ensures that privacy risks are identified and mitigated before processing begins.

13. Cross-Border Data Transfers

We may transfer your personal data to countries outside Kenya, where such transfer is necessary for the purposes outlined in this policy. In such cases, we ensure that appropriate safeguards are in place, in accordance with Part VII of the Data Protection (General) Regulations, 2021. These safeguards may include:

  • Transfers based on an adequacy decision by the Data Commissioner.
  • Transfers based on appropriate safeguards, such as standard contractual clauses.
  • Transfers based on your explicit consent, where you have been informed of the risks.

14. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Office of the Data Protection Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

15. Complaints

If you believe that we have infringed your rights under the Data Protection Act, 2019, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC).

Office of the Data Protection Commissioner
Britam Tower – 12th Floor, Upper Hill
P. O. Box 30920 – 00100 GPO, Nairobi, Kenya
Email: info@odpc.go.ke
Phone: 0207801800

You may also contact us directly first, and we will do our best to resolve your concerns.

16. Children’s Privacy

We are committed to protecting the privacy of children. Where we collect personal data from children (under the age of 18), we do so with the consent of a parent or guardian, or as part of our legitimate programme activities. If you believe we have collected personal data from a child without appropriate consent, please contact us.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Any changes will be posted on this page with an updated “Last updated” date.

We encourage you to review this policy periodically to stay informed about how we protect your privacy. Where significant changes are made, we will notify you through our website or by other appropriate means.

18. Contact Us

If you have any questions about this Privacy Policy, our data protection practices, or wish to exercise your rights as a data subject, please contact us:

Auschidys Disability Africa
Athi River, Kenya
Email: info@auschidys.org
Phone: +254 720901815
Website: www.auschidys.org


This Privacy Policy reflects our commitment to transparency and the protection of your privacy in accordance with the Kenya Data Protection Act, 2019 (No. 24 of 2019) and the Data Protection (General) Regulations, 2021.