Skip to main content
AK Amasakha–KioiAdvocates
Practice areas The firm Partners Insights Contact
Book a consultation
Practice areas The firm Partners Insights Contact Book a consultation

Privacy by design

Privacy & data protection.

A clear account of what we collect, why we use it, who may receive it and the choices available to you.

Your privacy matters.Rights requests and privacy questions: [email protected].

Privacy and Data Protection Notice

Last updated: September 4, 2026

1. Scope of this notice

Amasakha–Kioi Advocates respects privacy and handles personal data in accordance with the Constitution of Kenya, the Data Protection Act, 2019, and applicable regulations. This notice applies to this website, our secure staff account area, consultation enquiries, email correspondence and related administration. A client engagement may include an additional matter-specific privacy notice.

2. Data controller and contact

Amasakha–Kioi Advocates is the data controller for the processing described here. Our office is at The Avalon, Ngong Road, Nairobi, Kenya. Privacy questions, rights requests and complaints may be sent to [email protected]. Please write “Data protection request” in the subject line and do not include confidential matter details in the first message.

3. Data we process

Depending on how you interact with us, we may process:

  • identification and contact data, such as your name, email address and telephone number;
  • information you include in an enquiry, consultation request or later legal correspondence, which may include sensitive personal data where relevant to a legal matter;
  • preliminary conflict-check and matter-administration information;
  • for authorised staff accounts, name, work email, optional profile photograph, short-lived hashed sign-in codes and account preferences;
  • when you appreciate a legal insight, a random browser-generated identifier stored locally on your device and a non-reversible server-side hash associated with that article; this is not connected to an account, email address or advertising profile;
  • security and connection information, such as sign-in time, IP address, browser or device information, session records and application security logs; and
  • correspondence and records created when you exercise a data protection right or raise a complaint.

Please do not send identity documents, financial details, health information, case evidence or other highly sensitive information before we confirm a secure method and that we can act for you. An enquiry alone does not create an advocate–client relationship.

4. How we collect data

We collect data directly when you email us, communicate with the firm, use an authorised account or exercise a right. Our server and security services also generate limited technical records when protecting authenticated services. Public information may be used for a preliminary conflict check where lawful and necessary; if we collect personal data indirectly, we will provide any notice required by law.

5. Purposes and lawful bases

We identify and document one applicable lawful basis for each processing operation before it begins:

  • Responding to an enquiry and arranging a consultation: steps requested before a possible engagement.
  • Conflict, suitability and risk checks: our legitimate interests in operating an ethical legal practice and, where applicable, compliance with legal and professional duties.
  • Providing legal services: performance of our engagement and compliance with legal or professional obligations. Additional conditions are applied where sensitive personal data is necessary for legal claims or authorised legal practice.
  • Staff account administration, passwordless verification and service security: our legitimate interests in controlling access, preventing misuse, investigating incidents and maintaining reliable services.
  • Article appreciation counts: our legitimate interests in understanding which public legal perspectives readers find useful, using a pseudonymous and data-minimised mechanism without advertising tracking.
  • Legal, regulatory and professional record-keeping: compliance with an applicable legal or professional obligation.
  • Optional processing based on consent: the specific purpose explained when consent is requested. You may withdraw consent without affecting earlier lawful processing.

We do not use personal data from this website for unrelated direct marketing and we do not sell personal data.

6. Service providers and recipients

Access is limited to authorised firm personnel and professional advisers who need the information for an approved purpose and are subject to confidentiality duties. Where necessary, data may also be disclosed to courts, regulators, law-enforcement bodies, counterparties or other recipients required or authorised by law or by an engagement.

The website and account area use carefully selected service providers for hosting and deployment (Laravel Forge and DigitalOcean), object storage (DigitalOcean Spaces), transactional email (Resend), and application monitoring (Laravel Nightwatch). These providers act under applicable terms and receive only the data necessary to provide and secure their services. Google Maps is optional and remains inactive until you choose to load it; opening it allows Google to process technical data under Google's own terms and privacy notice.

7. International transfers

Some technology providers may process or support data outside Kenya. Before a transfer, we assess the destination, recipient and purpose, document the lawful transfer mechanism, and require appropriate contractual, organisational and technical safeguards where applicable. You may ask for information about the relevant safeguard by contacting us.

8. Retention and deletion

We keep personal data only while it is reasonably necessary for the documented purpose, including conflict management, an active engagement, security, dispute resolution, and legal or professional record-keeping. Our retention schedule assigns each record category a purpose, review point and deletion, anonymisation or preservation action. Relevant factors include the status of an enquiry or matter, limitation periods, professional obligations, legal holds, security needs and instructions from a competent authority.

When the purpose ends and no lawful reason requires continued retention, data is securely deleted or anonymised. One-time sign-in codes expire after 10 minutes, are stored only as non-reversible hashes and are deleted after successful use or replacement. Authorised account data is reviewed when access ends; expired web sessions are removed under the configured session lifecycle. Article-appreciation records are deleted automatically when the related article is deleted and are otherwise reviewed with the article. Backup copies are isolated from routine use and expire under the approved backup schedule. Matter-specific retention information is provided through the engagement process where appropriate.

9. Cookies and similar technologies

Our public marketing and legal pages are designed to work without advertising cookies, analytics cookies or a server session. If you use the optional “Appreciate” control on an article, your browser stores a random identifier and the articles you appreciated in local storage so the control remains consistent on that device. The server stores only a keyed, non-reversible hash of that identifier; it is not used across other sites or for advertising. You may remove the browser copy through your browser’s site-data controls. The secure account area uses strictly necessary session and security cookies for authentication, request protection and account continuity. These cookies are not used for advertising. The optional Google Map is not contacted until you activate it.

10. Security and confidentiality

We use proportionate technical and organisational safeguards, including work-domain-only passwordless verification, hashed single-use codes, encrypted transport in production, restricted account creation, security headers, monitoring, backups and incident procedures. Personnel and service providers receive access only where necessary and are subject to confidentiality requirements. No internet or storage system can be guaranteed completely secure.

If you believe personal data may have been compromised, email [email protected] promptly without including sensitive details. We assess incidents, contain risk, preserve evidence and make any notifications required by Kenyan law.

11. Your data protection rights

Subject to the law and any applicable legal-professional restriction, you may ask us to:

  • confirm whether we process your personal data and provide access to it;
  • correct inaccurate or misleading personal data;
  • erase data that we are no longer entitled to retain;
  • restrict or object to particular processing;
  • provide portable data where the right applies; or
  • explain and review a decision based solely on automated processing, if one is ever introduced.

You may also withdraw consent where consent is the basis used. We may ask for proportionate information to verify identity and authority before responding. We will acknowledge, assess and respond within the period required by law, or explain any lawful limitation.

12. Complaints and the regulator

Please contact us first so we can investigate and respond. You also have the right to complain to the Office of the Data Protection Commissioner (ODPC) through www.odpc.go.ke or the contact channels published by that office. Exercising a right or making a complaint will not result in adverse treatment.

13. Children

This website is directed to adults seeking legal information or services and does not knowingly solicit personal data directly from children. Where a matter requires a child's data, we apply the additional safeguards, authority or consent required by law and act in the child's best interests.

14. Automated decision-making

We do not use website or enquiry data to make decisions based solely on automated processing that produce legal or similarly significant effects. If that changes, we will provide advance information about the logic, significance, consequences and available human review.

15. Changes to this notice

We review this notice when our services, providers or legal obligations change and at least as part of our periodic privacy review. Material changes will be highlighted where appropriate. The date at the top shows the current version.

AK Amasakha–KioiAdvocates

Strategic legal counsel for a changing Africa.

[email protected]

Explore

Practice areasOur partnersLegal insightsVisit us

Legal

Privacy & data protectionTerms of use
© 2026 Amasakha–Kioi Advocates. All rights reserved. The Avalon, Ngong Road, Nairobi, Kenya