

PRIVACY POLICY
[OONTZTOPIA LIMITED ]
Website:www,oontztopia.com | Effective date: 18th July 2026 | Version: 1.0
1. Introduction and who we are
[Oontztopia Everywhere Limited ] (“we”, “us” or “our”) is a [company incorporated under the Companies Act, 2015] with its registered office at Applewood Adams, Ngong Rd P.O BOX 00100, Nairobi, Kenya. We operate the website www.oontztopia.com (the “website”).
We are committed to protecting your personal data and respecting your privacy in accordance with the Constitution of Kenya, 2010 (Article 31, which guarantees the right to privacy), the Data Protection Act, No. 24 of 2019 (the “Act” or “DPA”) and the Data Protection (General) Regulations, 2021.
For the purposes of the Act, we are the data controller of the personal data described in this policy, meaning we determine the purpose and means of processing your personal data.
This privacy policy is issued in discharge of our duty under section 29 of the Act to inform you, before or at the time we collect your personal data, of your rights, the fact and purpose of collection, the recipients of your data, our contact details, the security measures we adopt, whether collection is mandatory or voluntary, and the consequences of failing to provide the data requested.
2. Scope of this policy
This policy applies to personal data we collect through the website, including when you browse the website, submit an enquiry, register a user account, purchase event tickets, goods or services, subscribe to our newsletter, or instruct us to act for you. It also applies to personal data we receive by email, telephone or through our social media pages linked to the website.
It does not apply to third-party websites that may be linked from the website. We are not responsible for the privacy practices of those websites and you should review their privacy policies separately.
3. Key definitions (section 2 of the Act)
Personal data — any information relating to an identified or identifiable natural person.
Sensitive personal data — data revealing a person's race, health status, ethnic social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details (including names of children, parents, spouse or spouses), sex or sexual orientation.
Processing — any operation performed on personal data, including collection, recording, organisation, structuring, storage, use, disclosure or destruction.
Data controller — a person who, alone or jointly, determines the purpose and means of processing personal data.
Data processor — a person who processes personal data on behalf of a data controller.
Data subject — the natural person who is the subject of the personal data — in this policy, you.
4. The personal data we collect
Depending on how you interact with the website, we may collect the following categories of personal data:
Identity data — name, title, date of birth, national ID / passport number, KRA PIN, photographs.
Contact data — postal address, email address, telephone numbers, county of residence.
Account data — username, password, account preferences, profile information and any content you upload to your account.
Financial data — bank account details, M-PESA number, payment card details (processed by our payment service providers), billing information.
Transaction data — details of orders, purchases, payments made and received, and products or services obtained from us.
Technical data — internet protocol (IP) address, browser type and version, device identifiers, time zone, operating system, and data collected through cookies and similar technologies.
Usage data — information about how you use the website, pages visited, links clicked and search queries.
Marketing and communications data — your preferences for receiving marketing from us and your communication preferences.
In line with the principle of data minimisation in section 25(d) of the Act, we collect only the personal data that is adequate, relevant and limited to what is necessary for the purposes described in this policy.
Where the collection of any personal data is mandatory under law and you decline to provide it, we may be unable to provide the relevant product or service to you. Where collection is voluntary, we will indicate so at the point of collection (section 29(g)–(h) of the Act).
5. How we collect your personal data (section 28)
Section 28(1) of the Act requires us to collect personal data directly from you, and this is how we collect most of it: when you complete forms on the website, create an account, place an order, correspond with us, subscribe to our newsletter or give us instructions.
We may collect personal data indirectly only in the circumstances permitted by section 28(2) of the Act, including), where you have deliberately made it public, where you have consented to collection from another source, or where indirect collection would not prejudice your interests. We also collect technical and usage data automatically through cookies and similar technologies as you use the website.
6. Purposes and lawful bases for processing (section 30)
Section 30(1) of the Act prohibits the processing of personal data unless the data subject consents, or the processing is necessary on one of the statutory grounds listed in section 30(1)(b). The table below sets out the purposes for which we process your personal data and the lawful basis we rely on for each purpose. Further processing will be in accordance with the purpose of collection, as required by sections 25(c) and 30(2) of the Act.
Purpose / activity
Responding to enquiries submitted through the website contact form, telephone, email or WhatsApp.
Creating and administering a user account on the website.
Processing and fulfilling orders, taking payment and arranging delivery.
Operating, securing, maintaining and improving the website; analytics.
Detecting, preventing and investigating fraud, misuse or unlawful activity.
Keeping statutory records and responding to lawful requests from courts, regulators or the Office of the Data Protection Commissioner.
Sending newsletters, marketing and promotional communications.
Personal data involved
Identity data; contact data; content of the enquiry.
Identity data; contact data; account data (username, password).
Identity data; contact data; transaction data; financial data; delivery address.
Identity data; contact data; marketing preferences.
Technical data; usage data; cookie data.
Identity data; transaction data; technical data.
Any of the categories described in this policy.
Lawful basis under section 30(1), DPA 2019
Consent (s. 30(1)(a)); steps taken at the data subject's request prior to entering into a contract (s. 30(1)(b)(i)).
Performance of a contract (s. 30(1)(b)(i)).
Performance of a contract (s. 30(1)(b)(i)); compliance with a legal obligation, e.g. tax and accounting laws (s. 30(1)(b)(ii)).
Express consent, as required for commercial use of personal data by section 37(1)(a).
Legitimate interests (s. 30(1)(b)(vii)); consent for non-essential cookies (s. 30(1)(a)).
Legitimate interests (s. 30(1)(b)(vii)); compliance with a legal obligation (s. 30(1)(b)(ii)).
Compliance with a legal obligation (s. 30(1)(b)(ii)); public interest (s. 30(1)(b)(iv)).
7. Consent and withdrawal of consent (section 32)
Where we rely on your consent, it must be express, unequivocal, free, specific and informed. Under section 32(1) of the Act, we bear the burden of proving that you consented to the processing of your personal data for a specified purpose.
You have the right to withdraw your consent at any time (section 32(2)). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal (section 32(3)). You may withdraw consent by [contacting us using the details in section 21 below / using the unsubscribe link in our emails / adjusting your account settings]. We will not make the performance of a contract conditional on consent to processing that is not necessary for that contract (section 32(4)).
8. Sensitive personal data (sections 44 to 47)
We process sensitive personal data only where the data protection principles in section 25 of the Act are satisfied (section 44) and one of the permitted grounds in section 45 applies — principally where the processing is necessary for the establishment, exercise or defence of a legal claim, for carrying out obligations or exercising rights of the controller or of the data subject, or where you have manifestly made the data public.
9. Children's personal data (section 33)
The website is not intended for use by children (persons under 18 years of age) and we do not knowingly collect personal data relating to children through it. Under section 33 of the Act, we will not process a child's personal data unless consent is given by the child's parent or guardian and the processing protects and advances the rights and best interests of the child. We apply appropriate age-verification and consent mechanisms where processing of children's data cannot be avoided. If you believe a child has provided personal data to us through the website, please contact us and we will delete it.
10. Cookies and similar technologies
Cookies are small text files placed on your device when you visit the website. We use strictly necessary cookies (required for the website to function, including security and session management), and, with your consent, analytics/performance cookies and marketing cookies.
On your first visit, our cookie banner allows you to accept or decline non-essential cookies. You may also configure your browser to refuse cookies, although parts of the website may not function properly if you do.
11. Direct marketing and commercial use of data (section 37)
Section 37(1) of the Act prohibits the use of personal data for commercial purposes unless we have sought and obtained your express consent, or we are authorised to do so under written law and you were informed of that use when the data was collected. We will only send you newsletters, offers and other marketing communications where you have expressly opted in and accepted this policy.
Every marketing message we send will contain a simple means of opting out, and you may opt out at any time free of charge. Where we use personal data for commercial purposes, we will, where possible, anonymise it so that you are no longer identifiable (section 37(2)). We do not sell your personal data.
12. Automated decision-making and profiling (section 35)
You have the right not to be subjected to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or significantly affects you (section 35(1)). [We do not make any such decisions through the website.] [OR: Where we make such a decision — e.g. automated credit or fraud screening — we will notify you in writing as soon as reasonably practicable, and you may ask us to reconsider the decision or to take a new decision that is not based solely on automated processing (section 35(3)).]
13. Who we share your personal data with
We do not disclose your personal data to third parties except as described in this policy. In accordance with our duty under section 29(d) of the Act, the categories of recipients are:
Service providers (data processors) — IT, website hosting, cloud storage, email and payment service providers who process personal data on our behalf under written contracts imposing confidentiality and security obligations consistent with sections 41 and 42 of the Act.
Professional advisers — auditors, accountants, insurers, bankers and external advocates or consultants, where necessary and subject to duties of confidentiality.
Couriers — delivery and logistics providers, to fulfil your orders.
Parties connected with legal matters — courts, tribunals, opposing parties and their advocates, correspondent counsel, and registries, to the extent necessary for the conduct of your matter.
Regulators and authorities — the ODPC, the Kenya Revenue Authority, the Financial Reporting Centre, law enforcement agencies and other public bodies, where disclosure is required by law.
Business transferees — a purchaser or successor in the event of a merger, acquisition or reorganisation of our business, subject to this policy.
We require all third parties to respect the security of your personal data, to treat it in accordance with the law, and to use it only for the purposes for which it was disclosed.
14. Transfer of personal data outside Kenya (sections 48 and 49)
Some of our service providers (for example, cloud hosting and email providers) may store or process personal data on servers located outside Kenya. Under section 25(h) of the Act, personal data may not be transferred outside Kenya unless there is proof of adequate data protection safeguards or your consent has been obtained.
We will transfer your personal data outside Kenya only where the conditions in section 48 of the Act are satisfied — that is, where appropriate safeguards for the security and protection of the data are in place (including transfer to jurisdictions with commensurate data protection laws), or where the transfer is necessary for the performance of a contract with you, for a matter of public interest, for the establishment, exercise or defence of a legal claim, to protect your vital interests, or for compelling legitimate interests that are not overridden by your rights and freedoms.
In accordance with section 49(1) of the Act, we will transfer sensitive personal data outside Kenya only with your consent and upon confirmation of appropriate safeguards.
15. Data security (sections 41 and 42)
As required by sections 29(f), 41 and 42 of the Act, we have implemented appropriate technical and organisational measures, adopting a data-protection-by-design-and-by-default approach, to safeguard the integrity and confidentiality of your personal data. These measures include [encryption of data in transit (TLS/SSL) and at rest; pseudonymisation where appropriate; access controls and role-based permissions; firewalls and secure servers; staff confidentiality undertakings and training; regular security reviews, backups and testing of safeguards].
By default, we process only the personal data necessary for each specific purpose, having regard to the amount collected, the extent of processing, the storage period and accessibility (section 41(3)).
16. Personal data breaches (section 43)
Where personal data has been accessed or acquired by an unauthorised person and there is a real risk of harm to you, we will notify the Data Commissioner without delay and in any event within seventy-two hours of becoming aware of the breach, and will communicate the breach to you in writing within a reasonably practical period (section 43(1)).
Our communication will describe the nature of the breach, the measures we have taken or intend to take, and the steps you can take to mitigate any adverse effects (section 43(5)). We keep an internal record of all personal data breaches, their effects and the remedial action taken (section 43(8)).
17. Data retention (section 39)
We retain personal data only for as long as is reasonably necessary to satisfy the purpose for which it was collected, unless longer retention is required or authorised by law, is reasonably necessary for a lawful purpose, is authorised or consented to by you, or is for historical, statistical, journalistic, literature and art or research purposes (section 39(1)).
18. Your rights as a data subject
Under section 26 and Part IV of the Act, you have the following rights in relation to your personal data:
Right to be informed — to be informed of the use to which your personal data is to be put (s. 26(a)) — which this policy fulfills.
Right of access — to access your personal data in our custody (s. 26(b)).
Right to object — to object to the processing of all or part of your personal data, unless we demonstrate a compelling legitimate interest that overrides your interests, or the processing is for the establishment, exercise or defence of a legal claim (ss. 26(c) and 36).
Right to rectification — to correction of false or misleading data, and to rectification without undue delay of data that is inaccurate, outdated, incomplete or misleading (ss. 26(d) and 40(1)(a)).
Right to erasure — to deletion of false or misleading data, and to erasure or destruction of data we are no longer authorised to retain or that is irrelevant, excessive or unlawfully obtained (ss. 26(e) and 40(1)(b)).
Right to restriction — to restrict processing where accuracy is contested, the data is no longer required, the processing is unlawful, or you have objected and verification is pending (s. 34).
Right to data portability — to receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller; we will comply with portability requests at reasonable cost within thirty days (s. 38).
Automated decisions — not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or significantly affects you (s. 35).
Right to withdraw consent — to withdraw consent at any time where processing is based on consent (s. 32(2)).
You may exercise any of these rights by contacting us using the details in section 21. Under section 27 of the Act, your rights may be exercised on your behalf — for a minor, by a person with parental authority or a guardian; for a person with a disability, by a duly authorised guardian or administrator; or otherwise by a person you have duly authorised. We may need to verify your identity (or your authority) before acting on a request. We will respond within a reasonable time and in accordance with any timelines prescribed under the Act and the Data Protection (General) Regulations, 2021.
19. Complaints and remedies (sections 56 and 65)
If you have any concern about how we handle your personal data, we encourage you to contact us first so that we can attempt to resolve it. You are, however, entitled under section 56 of the Act to lodge a complaint with the Data Commissioner at any time:
Office of the Data Protection Commissioner (ODPC), P.O. Box 30920–00100, Nairobi, Kenya; website: www.odpc.go.ke; email: info@odpc.go.ke.
You also have the right to seek compensation from a data controller or data processor if you suffer damage — including financial loss or distress — by reason of a contravention of the Act (section 65), and a right of appeal against determinations of the Data Commissioner (section 64).
20. Changes to this policy
We may update this policy from time to time to reflect changes in the law, guidance issued by the ODPC, or our processing activities. The current version will always be posted on the website with its effective date. Where a change materially affects your rights or the purposes of processing, we will bring it to your attention [by email / by a prominent notice on the website] and, where required by the Act, seek fresh consent. We will make reasonable efforts to notify you through suitable communication channels.
21. Contact us
Questions, requests and complaints about this policy or our handling of your personal data should be directed to:
Oontztopia, Applewood Adams,Ngong Rd], P.O. Box 00100, Nairobi, Kenya. Email: oontztopia@gmail.com.
Governing law: This policy is governed by the laws of Kenya. Statutory references are to the Data Protection Act, No. 24 of 2019 (Laws of Kenya), as revised, and the Data Protection (General) Regulations, 2021 (Legal Notice No. 263 of 2021).