Privacy and Data Protection Notice
Last updated: September 4, 2026
1. Scope of this notice
Amasakha–Kioi Advocates respects privacy and handles personal data in accordance with the Constitution of Kenya, the Data Protection Act, 2019, and applicable regulations. This notice applies to this website, our secure staff account area, consultation enquiries, email correspondence and related administration. A client engagement may include an additional matter-specific privacy notice.
2. Data controller and contact
Amasakha–Kioi Advocates is the data controller for the processing described here. Our office is at The Avalon, Ngong Road, Nairobi, Kenya. Privacy questions, rights requests and complaints may be sent to [email protected]. Please write “Data protection request” in the subject line and do not include confidential matter details in the first message.
3. Data we process
Depending on how you interact with us, we may process:
- identification and contact data, such as your name, email address and telephone number;
- information you include in an enquiry, consultation request or later legal correspondence, which may include sensitive personal data where relevant to a legal matter;
- preliminary conflict-check and matter-administration information;
- for authorised staff accounts, name, work email, optional profile photograph, short-lived hashed sign-in codes and account preferences;
- when you appreciate a legal insight, a random browser-generated identifier stored locally on your device and a non-reversible server-side hash associated with that article; this is not connected to an account, email address or advertising profile;
- security and connection information, such as sign-in time, IP address, browser or device information, session records and application security logs; and
- correspondence and records created when you exercise a data protection right or raise a complaint.
Please do not send identity documents, financial details, health information, case evidence or other highly sensitive information before we confirm a secure method and that we can act for you. An enquiry alone does not create an advocate–client relationship.
4. How we collect data
We collect data directly when you email us, communicate with the firm, use an authorised account or exercise a right. Our server and security services also generate limited technical records when protecting authenticated services. Public information may be used for a preliminary conflict check where lawful and necessary; if we collect personal data indirectly, we will provide any notice required by law.
5. Purposes and lawful bases
We identify and document one applicable lawful basis for each processing operation before it begins:
- Responding to an enquiry and arranging a consultation: steps requested before a possible engagement.
- Conflict, suitability and risk checks: our legitimate interests in operating an ethical legal practice and, where applicable, compliance with legal and professional duties.
- Providing legal services: performance of our engagement and compliance with legal or professional obligations. Additional conditions are applied where sensitive personal data is necessary for legal claims or authorised legal practice.
- Staff account administration, passwordless verification and service security: our legitimate interests in controlling access, preventing misuse, investigating incidents and maintaining reliable services.
- Article appreciation counts: our legitimate interests in understanding which public legal perspectives readers find useful, using a pseudonymous and data-minimised mechanism without advertising tracking.
- Legal, regulatory and professional record-keeping: compliance with an applicable legal or professional obligation.
- Optional processing based on consent: the specific purpose explained when consent is requested. You may withdraw consent without affecting earlier lawful processing.
We do not use personal data from this website for unrelated direct marketing and we do not sell personal data.
6. Service providers and recipients
Access is limited to authorised firm personnel and professional advisers who need the information for an approved purpose and are subject to confidentiality duties. Where necessary, data may also be disclosed to courts, regulators, law-enforcement bodies, counterparties or other recipients required or authorised by law or by an engagement.
The website and account area use carefully selected service providers for hosting and deployment (Laravel Forge and DigitalOcean), object storage (DigitalOcean Spaces), transactional email (Resend), and application monitoring (Laravel Nightwatch). These providers act under applicable terms and receive only the data necessary to provide and secure their services. Google Maps is optional and remains inactive until you choose to load it; opening it allows Google to process technical data under Google's own terms and privacy notice.
7. International transfers
Some technology providers may process or support data outside Kenya. Before a transfer, we assess the destination, recipient and purpose, document the lawful transfer mechanism, and require appropriate contractual, organisational and technical safeguards where applicable. You may ask for information about the relevant safeguard by contacting us.
8. Retention and deletion
We keep personal data only while it is reasonably necessary for the documented purpose, including conflict management, an active engagement, security, dispute resolution, and legal or professional record-keeping. Our retention schedule assigns each record category a purpose, review point and deletion, anonymisation or preservation action. Relevant factors include the status of an enquiry or matter, limitation periods, professional obligations, legal holds, security needs and instructions from a competent authority.
When the purpose ends and no lawful reason requires continued retention, data is securely deleted or anonymised. One-time sign-in codes expire after 10 minutes, are stored only as non-reversible hashes and are deleted after successful use or replacement. Authorised account data is reviewed when access ends; expired web sessions are removed under the configured session lifecycle. Article-appreciation records are deleted automatically when the related article is deleted and are otherwise reviewed with the article. Backup copies are isolated from routine use and expire under the approved backup schedule. Matter-specific retention information is provided through the engagement process where appropriate.
9. Cookies and similar technologies
Our public marketing and legal pages are designed to work without advertising cookies, analytics cookies or a server session. If you use the optional “Appreciate” control on an article, your browser stores a random identifier and the articles you appreciated in local storage so the control remains consistent on that device. The server stores only a keyed, non-reversible hash of that identifier; it is not used across other sites or for advertising. You may remove the browser copy through your browser’s site-data controls. The secure account area uses strictly necessary session and security cookies for authentication, request protection and account continuity. These cookies are not used for advertising. The optional Google Map is not contacted until you activate it.
10. Security and confidentiality
We use proportionate technical and organisational safeguards, including work-domain-only passwordless verification, hashed single-use codes, encrypted transport in production, restricted account creation, security headers, monitoring, backups and incident procedures. Personnel and service providers receive access only where necessary and are subject to confidentiality requirements. No internet or storage system can be guaranteed completely secure.
If you believe personal data may have been compromised, email [email protected] promptly without including sensitive details. We assess incidents, contain risk, preserve evidence and make any notifications required by Kenyan law.
11. Your data protection rights
Subject to the law and any applicable legal-professional restriction, you may ask us to:
- confirm whether we process your personal data and provide access to it;
- correct inaccurate or misleading personal data;
- erase data that we are no longer entitled to retain;
- restrict or object to particular processing;
- provide portable data where the right applies; or
- explain and review a decision based solely on automated processing, if one is ever introduced.
You may also withdraw consent where consent is the basis used. We may ask for proportionate information to verify identity and authority before responding. We will acknowledge, assess and respond within the period required by law, or explain any lawful limitation.
12. Complaints and the regulator
Please contact us first so we can investigate and respond. You also have the right to complain to the Office of the Data Protection Commissioner (ODPC) through www.odpc.go.ke or the contact channels published by that office. Exercising a right or making a complaint will not result in adverse treatment.
13. Children
This website is directed to adults seeking legal information or services and does not knowingly solicit personal data directly from children. Where a matter requires a child's data, we apply the additional safeguards, authority or consent required by law and act in the child's best interests.
14. Automated decision-making
We do not use website or enquiry data to make decisions based solely on automated processing that produce legal or similarly significant effects. If that changes, we will provide advance information about the logic, significance, consequences and available human review.
15. Changes to this notice
We review this notice when our services, providers or legal obligations change and at least as part of our periodic privacy review. Material changes will be highlighted where appropriate. The date at the top shows the current version.