SUNESIS CONSULTING PRIVACY NOTICE
This Privacy Notice explains how the Sunesis Consulting Limited collects, manages, and uses your personal data before, during, and after we provide you with our services.
“Personal Data” means any information that can be used to identify a person or relating to an identified or identifiable natural person (the data subject).
“Data Subject” means an individual or a natural person.
This Privacy Notice adheres to the Data Protection Act, 2019’s principle of transparency. This Notice gives you information about:
- How and why your data will be used for the research;
- What your rights are under the Kenya Data Protection Act, 2019;
- How long we will store your data;
- Who else we will share your data with; and
- How to contact Sunesis Consulting Limited
What Data Do We Collect?
The data we collect will vary from project to project. For training and marketing purposes, we only collect your name and email address. For recruitment purposes, we collect data such as your name, phone number, and email address.
Why Are We Processing Your Data?
Sunesis Consulting Limited is a company that offers a myriad of services, including but not limited to conducting trainings and data analytics. We are contracted to provide our service by other companies or directly to individuals.
In order to provide these services, we need to collect your information for identification purposes and to keep you informed about our latest products and services.
How Do We Use Your Personal Data?
We use your personal data for identification & research purposes whenever we are conducting data analytics for your company. We will always tell you about the information we wish to collect from you and how we will use it. We will not use your personal data for automated decision making about you or for profiling purposes.
We adhere to the principles as outlined in the Kenya’s Data Protection Act, 2019, and its Regulations.
Who Do We Share Your Data With?
The data we collect is sometimes shared with third parties for various reasons. They include:
- Marketing ERP (Hubspot) – Marketing Purposes
- Training (Accredible Platform) – Issuing of certificates after completion of a training
- HR Consultant – Recruitment purposes
How Do We Keep Your Data Secure?
We take a robust approach to protecting your information with secure electronic and physical storage areas with controlled access. Access to your personal data is strictly controlled on a need-to-know basis, and data is stored and transmitted securely using methods such as encryption and access controls for physical records where appropriate.
Alongside these technical measures, there are comprehensive policies and processes in place to ensure that those who process your personal information (such as trainers, data analysts, marketers, and/or contracted processors) are aware of their obligations and responsibilities.
By default, people are only granted access to the information they require to perform their duties. Mandatory data protection and information security training is provided to staff, and expert advice is availed if needed.
How Long Do We Keep Your Data For?
Your personal data will only be retained for as long as is necessary to fulfill the cited purpose of the research. The length of time we keep your personal data will depend on several factors, including the significance of the data, funder requirements, and the nature of the study. Specific details are provided in the attached Participant Information Sheet.
What Are Your Rights As Our Data Subjects?
When you provide personal data to us, you have certain rights available to you in relation to that data. These rights are outlined below and can be exercised by contacting the Data Protection Officer, indicating which right you wish to exercise:
- Your right of access – You have the right to ask us for copies of your personal information.
- Your right to rectification – You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
- Your right to erasure – You have the right to ask us to erase your personal information in certain circumstances.
- Your right to object to processing – You have the right to object to the processing of your personal data in certain circumstances.
- Your right to data portability – You have the right to ask that we transfer the information you gave us to another company, or to you, in certain circumstances.
You are not required to pay any charge for exercising your rights. If you make a request, we have fourteen days to respond to you.
In case of any concerns, kindly contact the undersigned:
Finance and Administration Assistant,
Sunesis Consulting Limited.
P.O. Box 51269 – 00100