This policy explains what personal information we collect on this website, how we use and protect it, and the rights and choices available to you under the Data Protection Act, 2019 (Kenya) and other applicable law.
On this page
- Who we are
- Information we collect
- Sensitive health information
- How we use your information
- Legal bases for processing
- Sharing your information
- Cookies and similar technologies
- International transfers
- How long we keep your information
- How we protect your information
- Your rights
- Children's privacy
- Donor privacy
- Changes to this policy
- Contact us
Last updated:
Who we are
This website is operated by VIYA Health Kenya, a country programme of VIYA Health Foundation, a United States nonprofit organization, working with its partner organization Health X Partners. For the purposes of the Data Protection Act, 2019 (Kenya), VIYA Health Kenya is the data controller for personal information collected through this website.
References to "we", "us" or "our" in this policy mean VIYA Health Kenya and, where the context requires, VIYA Health Foundation.
Information we collect
We collect information you give us directly, including:
- Contact details — name, email address, phone number and delivery address when you place an order, contact us, or join our community;
- Order information — the products you buy and your delivery preferences (payment card and mobile-money details are processed by our payment providers and are not stored by us);
- Messages — questions and feedback you send via our contact forms, email or WhatsApp.
We also collect some information automatically when you browse, such as device type, browser, approximate location and the pages you visit. See our Cookie Policy for details.
Sensitive health information
We know that sexual and reproductive health is personal. Browsing this website, reading our content or buying a product can reveal information about your health interests, which is treated as sensitive personal data under the Data Protection Act, 2019.
We minimise what we collect, never use health-related information for advertising to you elsewhere, and never sell it. Product purchases are delivered in discreet packaging, and order records are restricted to the staff and service providers who need them to fulfil your order.
How we use your information
We use personal information to:
- process and deliver your orders, including payment and customer support;
- respond to your questions and messages;
- send you updates, health information and community news only if you have opted in — every message includes a way to unsubscribe;
- understand how the website is used so we can improve our content and services;
- meet our legal, regulatory and security obligations.
Legal bases for processing
We process personal information only where the Data Protection Act, 2019 allows it, including where:
- you have given consent (for example, subscribing to communications) — which you may withdraw at any time;
- processing is necessary to perform a contract with you (for example, fulfilling an order);
- we have a legal obligation (for example, tax and accounting records);
- we have a legitimate interest that does not override your rights (for example, keeping the website secure).
International transfers
Some of our service providers and VIYA Health Foundation are located outside Kenya, including in the United States. Where personal information is transferred outside Kenya, we do so in accordance with the Data Protection Act, 2019, using appropriate safeguards such as contractual protections and transferring only what is necessary.
How long we keep your information
We keep personal information only as long as needed for the purposes described in this policy: order records for as long as required by tax and consumer law, communications preferences until you unsubscribe, and enquiry messages for as long as needed to resolve them. When information is no longer needed, we delete or anonymise it.
How we protect your information
We use technical and organisational safeguards appropriate to the sensitivity of the data, including encryption in transit (HTTPS), access controls, and vetted service providers. No internet service can be guaranteed 100% secure, but we work to protect your information and will notify you and the Office of the Data Protection Commissioner of any breach as required by law.
Your rights
Under the Data Protection Act, 2019 you have the right to:
- be told how your personal information is being used;
- access the personal information we hold about you;
- have inaccurate information corrected;
- request deletion of information we no longer have grounds to keep;
- object to processing, including for direct marketing;
- request portability of data you provided to us.
To exercise any of these rights, contact us using the details below. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) in Kenya at odpc.go.ke.
Children's privacy
This website provides health information for the public, but our shop and communications are intended for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
Donor privacy
Donations in support of our work are made to VIYA Health Foundation. Donor information is never sold, rented or traded. Donors may opt out of having their information shared beyond the Foundation and may request that we discontinue contact at any time.
Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page shows when it was most recently revised. Significant changes will be highlighted on this page.
Contact us
For privacy questions or to exercise your rights, reach us via the contact page or by phone or WhatsApp on +254 701 727 174.