Privacy Policy & Data Protection Notice
At Gara Consultancy, protecting the privacy, confidentiality, and security of your personal and business data is a core commitment. This document explains how we collect, handle, protect, and process your information in full accordance with the laws of Kenya.
Zero 3rd-Party Sharing
We never sell, rent, lease, or share your data with third-party advertisers, data brokers, or marketing networks.
No Promotional Abuse
Your contact details are strictly used to fulfill your requested advisory consultations, store setups, and technical quotes.
KDPA 2019 & ODPC Standard
Structured in full compliance with the Kenya Data Protection Act No. 24 of 2019 and guidance of the Data Protection Commissioner.
01Data Controller & Scope of Operations
Gara Consultancy (“we”, “our”, “us”) operates as a specialist e-commerce advisory and engineering firm based in Nairobi, Kenya. We provide e-commerce store architecture (Shopify, WooCommerce, custom headless storefronts), Safaricom Daraja M-Pesa automated payment integrations, Google Ads / Performance Marketing management, E-Commerce SEO, and Conversion Rate Optimization (CRO) audits.
In the context of the Kenya Data Protection Act, 2019 (Act No. 24 of 2019), Gara Consultancy acts as the Data Controller and, where applicable, the Data Processor for the personal and corporate information collected through our website (https://garaconsultancy.co.ke) and related consultation inquiry channels.
Entity Name: Gara Consultancy
Principal Location: Nairobi, Kenya
Primary Data Contact Email: enquiry@garaconsultancy.co.ke
Direct Telephone: +254 110 403 666
02Our Principles Under Kenyan Data Security Law
Under Section 25 of the Kenya Data Protection Act, 2019, personal data must be processed in accordance with constitutional values of privacy. We adhere to the following mandatory principles:
- Lawfulness, Fairness & TransparencyData is processed with valid lawful basis and full user awareness.
- Purpose LimitationCollected solely for defined commerce consulting and technical setups.
- Data MinimizationWe collect only what is strictly necessary to evaluate and service your request.
- Integrity & ConfidentialitySecured with high-grade encryption and restricted technical access controls.
03The Nature of Data We Collect
Because our business specializes in B2B and DTC e-commerce consulting, we collect information solely when you voluntarily provide it through our website forms, direct consultation calls, or email correspondence:
A. Contact & Professional Identity Information
Full Name, Work/Business Email Address, Phone Number (for direct and WhatsApp communication), and Company or Registered Business Name.
B. E-Commerce Store & Technical Project Specifications
Store Website URL, social storefront links, primary service interest (e.g. Ecommerce Store Development, Google Ads Management, Payment Integration, Ecommerce SEO, CRO Audits), estimated catalog SKU volume, current ad budget ranges, and specific technical obstacles (such as Daraja STK Push errors or checkout drop-offs).
C. Technical Browsing Metadata
Standard web server diagnostic logs (IP address, browser user-agent, operating system, timestamp) collected purely for website operational uptime, cybersecurity threat defense, and performance optimization.
04Purpose & Lawful Grounds for Processing
Under Section 30 of the Kenya Data Protection Act 2019, we process personal data only when a recognized lawful basis exists:
| Processing Purpose | Data Categories | Lawful Basis (KDPA 2019) |
|---|---|---|
| Responding to your Quick Enquiry or Consultation Form | Name, Email, Phone, Company, Project Goal | Consent (Sec 30(1)(a)) & Pre-contractual steps (Sec 30(1)(b)) |
| Scoping e-commerce architecture, API integrations, & quote preparation | Website URL, SKU count, payment gateway choice | Contractual performance (Sec 30(1)(b)) |
| Issuing invoices, project receipts & accounting compliance | Company Name, KRA PIN, billing email, phone | Legal obligation under Kenyan Tax Law (Sec 30(1)(c)) |
| Securing website infrastructure against malicious attacks | Server logs, IP address, request headers | Legitimate interests (Sec 30(1)(b)) |
Zero 3rd-Party Sharing & No Promotional Resale
1. No Third-Party Sales or Brokerage: Gara Consultancy does not sell, rent, barter, trade, lease, or distribute your personal contact information or business data to any third-party marketing companies, advertising brokers, data aggregators, or external commercial entities under any circumstances.
2. No Unsolicited Marketing / Spam: We will never use your submitted phone number or email address for spam campaigns, third-party promotional broadcasts, or unrequested newsletters. All communications from our team are strictly contextual to the services you requested.
3. Confidentiality & Client Non-Disclosure (NDA): Any proprietary business metrics, store revenue numbers, or customer records shared with us during discovery audits or store migrations are treated with strict confidentiality under non-disclosure obligations.
06Data Security & Encryption Standards
In adherence to Section 41 of the Kenya Data Protection Act, we implement robust technical and organizational security controls to protect your data from accidental loss, unauthorized access, alteration, destruction, or disclosure:
- SSL/TLS 1.3 Encryption: All data transmitted between your browser and our servers is secured using modern cryptographic transport protocols.
- Role-Based Access Control: Only authorized senior consultants and technical leads assigned to your project have access to your submitted specifications.
- Secure Transactional Dispatch: Inquiries are relayed through verified enterprise mail transport protocols with TLS encryption.
07Data Retention Periods
We do not retain personal data longer than necessary for the purpose for which it was collected:
- • General Inquiries & Consultations: Retained for a maximum of 12 months following last communication, after which records are securely purged.
- • Active Client Projects & Contracts: Retained for the duration of the engagement and up to 7 years post-contract to comply with Kenyan commercial and statutory tax audit obligations (KRA).
- • Technical Credentials & API Keys: Any temporary credentials or sandbox tokens provided during M-Pesa or store development are purged immediately upon client sign-off.
08Your Rights Under Section 26 of the Kenya Data Protection Act
As a data subject in Kenya, you have legally enforceable rights concerning your personal information:
You have the right to be informed of the use to which your personal data is put (as fulfilled by this policy).
You have the right to request a copy of the personal data we hold about you.
You can request the correction of inaccurate, out-of-date, incomplete, or misleading data.
You have the right to request deletion of your personal data where there is no ongoing legal justification for its retention.
You may object to the processing of all or part of your personal data at any time.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
To exercise any of these rights, email us directly at enquiry@garaconsultancy.co.ke. We will respond within 14 business days with zero administrative fees.
09Cookies & Essential Tracking
Our website utilizes basic functional cookies and privacy-respecting telemetry (Google Analytics 4 with IP anonymization) strictly to measure page load speeds, diagnostic errors, and aggregate traffic patterns across Kenya. We do not use intrusive cross-site fingerprinting or behavior profiling scripts. You can disable cookies at any time via your browser settings without affecting core website readability.
10Regulatory Authority & Lodging Complaints
If you have concerns about how your data has been handled or believe our processing violates the Kenya Data Protection Act 2019, you have the right to contact our compliance desk directly or lodge a formal complaint with the statutory regulatory authority in Kenya:
Gara Consultancy Compliance Desk
Email: enquiry@garaconsultancy.co.ke
Telephone: +254 110 403 666
Location: Nairobi, Kenya
Office of the Data Protection Commissioner (ODPC)
Authority: ODPC Kenya
Address: P.O. Box 30920-00100, Nairobi, Kenya
Email: info@odpc.go.ke / complaints@odpc.go.ke
Website: www.odpc.go.ke
11. Updates to This Policy
We may periodically update this Privacy Policy to reflect operational changes, new regulatory advisories issued by the ODPC, or amendments to Kenyan data security legislation. Any revisions will be published on this page with an updated effective date.
Have a question about our data protection practices?
Our senior team is available to clarify any aspect of our privacy standards.