Privacy Policy
GIBEKA FINANCIAL CONSULTING — WEBSITE PRIVACY POLICY
Effective Date: 1 January 2026 Last Updated: 1 January 2026 Version: 1.0
1. INTRODUCTION & SCOPE
GiBeKA Financial Consulting ("the Company," "we," "us," or "our") is committed to protecting the privacy and personal data of every individual who interacts with our website, services, programmes, and communications. This Privacy Policy explains how we collect, use, store, share, protect, and dispose of your personal data, and it sets out your rights in relation to that data.
This Policy applies to:
-
All visitors to our website at www.gibeka.com and any associated subdomains
-
All individuals who enquire about, register for, or use any of our services, programmes, or products
-
All subscribers to our newsletters, blog updates, or any other communications
-
All individuals who contact us through any channel including email, telephone, WhatsApp, social media, or web forms
-
All clients, prospective clients, event attendees, and workshop participants
-
This Policy does not apply to third-party websites, platforms, or services that may be linked to or from our website. We encourage you to read the privacy policies of any third-party sites you visit, as we have no control over their practices.
By accessing our website or engaging with our services in any capacity, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of our website and services.
2. LEGAL FRAMEWORK & GOVERNING LEGISLATION
This Privacy Policy is drafted in compliance with the following legislation and frameworks:
Kenyan Law:
-
The Data Protection Act, 2019 (Kenya) — the primary legislation governing the collection, use, processing, and storage of personal data in Kenya, administered by the Office of the Data Protection Commissioner (ODPC)
-
The Kenya Information and Communications Act (Cap. 411A)
-
The Computer Misuse and Cybercrimes Act, 2018 (Kenya)
-
The Consumer Protection Act, 2012 (Kenya)
International Frameworks:
-
The EU General Data Protection Regulation (GDPR) 2016/679 — applied as an international best-practice standard for data protection
-
The African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention)
-
The OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data
Where Kenyan law and international frameworks differ, we apply the higher standard of protection in favour of the data subject.
3. DEFINITIONS
For the purposes of this Policy, the following definitions apply:
-
"Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to name, identification number, location data, email address, telephone number, IP address, or any factor specific to the physical, economic, cultural, or social identity of that person
-
"Data Subject" means the individual to whom the personal data relates
-
"Data Controller" means GiBeKA Financial Consulting, which determines the purposes and means of processing personal data
-
"Data Processor" means any third party that processes personal data on behalf of the Company
-
"Processing" means any operation performed on personal data, including collection, recording, storage, retrieval, use, disclosure, erasure, or destruction
-
"Consent" means any freely given, specific, informed, and unambiguous indication of agreement to the processing of personal data
-
"Sensitive Personal Data" means data relating to racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, genetic data, financial data, criminal records, or any other data designated as sensitive under applicable law
4. DATA CONTROLLER INFORMATION
The Data Controller responsible for your personal data is:
GiBeKA Financial Consulting Nairobi,
Kenya Email: info@gibeka.com
Phone: +254 792 601 888
Website: www.gibeka.com
For all data protection enquiries, requests, or complaints, please contact us at the email address above with the subject line: "Data Protection Enquiry."
5. CATEGORIES OF PERSONAL DATA WE COLLECT
We collect personal data in the following categories, depending on the nature of your interaction with us:
5.1 Identity & Contact Data
-
Full name
-
Email address
-
Telephone number (including WhatsApp contact)
-
Postal address or city of residence
-
Country of residence or domicile
5.2 Professional & Demographic Data
-
Job title, employer, or professional background (where voluntarily provided)
-
Industry or sector
-
General income bracket or financial goals (where relevant to service delivery)
5.3 Technical & Usage Data
-
IP address and device identifiers
-
Browser type and version
-
Operating system
-
Pages visited on our website and time spent on each
-
Referring URLs and exit pages
-
Date and time of website visits
-
Cookie identifiers (see Section 13 on Cookies)
5.4 Communication Data
-
Content of emails, messages, or enquiries sent to us
-
Records of telephone conversations (where consent has been obtained)
-
Social media messages or comments directed to our official accounts
5.5 Transaction & Programme Data
-
Details of services, programmes, or consultancy engagements requested or procured
-
Payment reference details (note: we do not store full payment card data)
-
Programme enrolment history and attendance records
-
Survey or feedback responses
5.6 Consent & Preference Data
-
Records of consents given or withdrawn
-
Communication preferences and marketing opt-in or opt-out status
We do not intentionally collect sensitive personal data unless it is strictly necessary for service delivery and you have provided explicit, informed consent for its collection. We do not collect personal data from children under the age of 18 without the verifiable consent of a parent or guardian.
6. HOW WE COLLECT PERSONAL DATA
We collect personal data through the following means:
Directly from you, when you:
-
Complete a contact form, consultation request, or assessment on our website
-
Subscribe to our newsletter, blog, or mailing list
-
Enrol in or enquire about a programme, training, or workshop
-
Send us an email, WhatsApp message, or telephone call
-
Engage with us on social media platforms
-
Attend a webinar, event, or speaking engagement and register your details
-
Respond to a survey or feedback request
Automatically, through technology, when you:
-
Visit our website (via cookies, web analytics, and similar tracking technologies)
-
Open or interact with our email communications (via email tracking pixels, where applicable)
From third parties, including:
-
Social media platforms where your public profile data is available
-
Referrals from existing clients or professional contacts (limited to your name and contact details)
-
Event platforms through which you register for engagements we participate in
7. LEGAL BASIS FOR PROCESSING PERSONAL DATA
In accordance with Section 30 of Kenya's Data Protection Act, 2019 and Article 6 of the GDPR, we process your personal data on one or more of the following lawful bases:
Legal BasisApplication
-
Consent - Where you have explicitly opted in to receive communications, newsletters, or marketing content
-
Contract Performance - Where processing is necessary to deliver a service, programme, or consultancy you have requested or contracted
-
Legitimate Interests - Where we have a legitimate business interest in processing your data that does not override your fundamental rights — such as website analytics, service improvement, and fraud prevention
-
Legal Obligation - Where processing is required to comply with applicable Kenyan or international law
-
Vital Interests - In exceptional circumstances where processing is necessary to protect life or safety
Where we rely on consent as our legal basis, you have the right to withdraw that consent at any time without affecting the lawfulness of processing that occurred before withdrawal.
8. PURPOSES FOR WHICH WE USE YOUR PERSONAL DATA
We use the personal data we collect for the following specific and legitimate purposes only:
-
Service Delivery — To respond to your enquiries, process registrations, deliver programmes, and fulfil any consultancy or advisory engagement you have requested
-
Client Communication — To communicate with you about services you have purchased or expressed interest in, including appointment scheduling, programme updates, and follow-up correspondence
-
Marketing & Communications — To send you newsletters, insights, blog updates, and promotional content about our services, where you have given your consent to receive such communications
-
Website Improvement — To analyse how our website is used, identify technical issues, and improve the user experience for all visitors
-
Legal Compliance — To comply with applicable laws, regulations, court orders, or the instructions of competent regulatory authorities
-
Fraud Prevention & Security — To detect, investigate, and prevent fraudulent, unauthorised, or illegal activity on our website or in relation to our services
-
Record Keeping — To maintain accurate business records as required by law or professional standards
-
Feedback & Research — To conduct satisfaction surveys, gather feedback, and improve our service quality
We will not use your personal data for any purpose that is incompatible with the purposes listed above without first obtaining your consent or establishing a new lawful basis for processing.
9. DATA SHARING & DISCLOSURE
We do not sell, rent, trade, or otherwise transfer your personal data to third parties for commercial gain. We may share your personal data only in the following limited and controlled circumstances:
9.1 Service Providers & Data Processors
We engage trusted third-party service providers to assist in operating our website and delivering our services. These may include:
-
Website hosting and cloud storage providers
-
Email marketing and communication platforms
-
Payment processing services
-
Website analytics providers (e.g., Google Analytics)
-
Event management platforms
All such third parties are required to process your data only on our documented instructions and in compliance with applicable data protection law. We maintain data processing agreements with all relevant processors.
9.2 Legal & Regulatory Authorities
We may disclose personal data to government bodies, law enforcement agencies, courts, or regulators where we are required to do so by law, court order, or enforceable governmental request — including the Office of the Data Protection Commissioner (Kenya).
9.3 Professional Advisers
We may share personal data with our legal counsel, auditors, or compliance advisers where strictly necessary and subject to confidentiality obligations.
9.4 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of business assets, personal data may be transferred to a successor entity, subject to the same level of data protection as described in this Policy. Affected individuals will be notified prior to any such transfer.
9.5 Consent-Based Sharing
With your explicit prior consent, we may share your data with other specified parties for purposes clearly explained at the time of obtaining your consent.
In all cases of data sharing, we apply the principle of minimum necessary disclosure — sharing only the data that is strictly required for the stated purpose.
10. INTERNATIONAL DATA TRANSFERS
Our primary operations are based in Kenya. Where personal data is transferred outside Kenya — for example, to cloud service providers or platform partners operating in other jurisdictions — we ensure that such transfers comply with Section 49 of the Kenya Data Protection Act, 2019, which requires that the recipient country provides an adequate level of data protection, or that appropriate safeguards are in place, including:
-
Standard contractual clauses approved by the Data Protection Commissioner
-
Binding corporate rules where applicable
-
Explicit consent of the data subject
-
Other mechanisms recognised under applicable law
11. DATA RETENTION
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law. The following general retention periods apply:
Category of DataRetention Period
-
Client and programme records: 7 years from the end of the client relationship or programme completion
-
Marketing and subscription records : Until consent is withdrawn, plus 12 months for deactivation processing
-
Website analytics data: 26 months from collection, in line with standard analytics practice
-
Enquiry and correspondence records: 3 years from the date of last correspondence
-
Financial transaction records : 7 years in accordance with Kenyan tax and financial record-keeping requirements
-
Job application records (where applicable): 6 months from the conclusion of the recruitment process
Upon expiry of the applicable retention period, personal data is securely deleted, anonymised, or destroyed using industry-standard methods that prevent its recovery or reconstruction.
12. YOUR RIGHTS AS A DATA SUBJECT
Under the Kenya Data Protection Act, 2019 and applicable international frameworks, you have the following rights in relation to your personal data:
12.1 Right of Access
You have the right to request confirmation of whether we hold personal data about you, and to receive a copy of that data, together with information about how it is processed. (DPA Kenya, Section 26)
12.2 Right to Rectification
You have the right to request correction of any personal data we hold about you that is inaccurate, incomplete, or out of date. (DPA Kenya, Section 26(b))
12.3 Right to Erasure
You have the right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, where consent has been withdrawn, or where processing is unlawful. This right is subject to applicable legal obligations to retain records. (DPA Kenya, Section 26(d))
12.4 Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances — for example, while the accuracy of the data is being contested. (DPA Kenya, Section 26(e))
12.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible. (DPA Kenya, Section 26(f))
12.6 Right to Object
You have the right to object to the processing of your personal data where it is based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will cease such processing immediately. (DPA Kenya, Section 26(c))
12.7 Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
12.8 Right Not to Be Subject to Automated Decision-Making
You have the right not to be subject to decisions made solely by automated processing — including profiling — that produce legal or similarly significant effects, without human review.
12.9 Right to Lodge a Complaint
You have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya if you believe your rights under the Data Protection Act have been infringed. The ODPC can be contacted at www.odpc.go.ke.
To exercise any of the above rights, please contact us in writing at info@gibeka.com with the subject line "Data Subject Rights Request." We will respond within 30 days of receiving your request. In complex or high-volume cases, we may extend this period by a further 30 days, in which case we will notify you of the extension and the reason for it.
We will not charge a fee for processing data subject rights requests unless they are manifestly unfounded, repetitive, or excessive, in which case we reserve the right to charge a reasonable administrative fee or decline to respond.
13. COOKIES & TRACKING TECHNOLOGIES
13.1 What Are Cookies?
Cookies are small text files placed on your device by a website when you visit it. They are widely used to make websites function efficiently, improve user experience, and provide information to website owners.
13.2 Types of Cookies We Use
Cookie Type, Purpose and Duration
-
Strictly Necessary : Essential for the website to function — enabling navigation, form submissions, and security features / Session / short-term
-
Analytics & Performance: Collecting anonymised data on how visitors use our website to improve functionality and content / Up to 26 months
-
Functional : Remembering your preferences, such as language settings or previously entered information/ Up to 12 months
-
Marketing & Targeting: Tracking visits across websites to deliver relevant advertising (only with your explicit consent)/ Up to 12 months
13.3 Third-Party Cookies
Our website may use third-party services such as Google Analytics, social media plugins, or embedded content that set their own cookies. We do not control these cookies. Please refer to the respective third parties' privacy and cookie policies for further information.
13.4 Managing Cookies
You can control and manage cookies through your browser settings at any time. Most browsers allow you to refuse or delete cookies. Please note that disabling certain cookies may affect the functionality of our website. Where required by law, we will seek your consent before placing non-essential cookies on your device via a cookie consent banner.
14. DATA SECURITY
We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. Our security measures include, but are not limited to:
-
Encryption of data in transit using SSL/TLS protocols
-
Access controls ensuring personal data is accessible only to authorised personnel on a need-to-know basis
-
Secure hosting on reputable, compliant cloud infrastructure providers
-
Regular security reviews of our systems, processes, and data handling practices
-
Staff awareness — ensuring all personnel handling personal data understand their obligations under applicable law
-
Incident response procedures enabling prompt detection, containment, and reporting of data breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of the breach, in accordance with Section 43 of the Kenya Data Protection Act, 2019. Where the breach poses a high risk to you personally, we will also notify you directly without undue delay.
Notwithstanding the above, no method of transmission over the internet or electronic storage is entirely secure. We cannot guarantee absolute security, and we encourage you to exercise caution when sharing personal data online.
15. LINKS TO THIRD-PARTY WEBSITES
Our website may contain links to third-party websites, social media platforms, and external resources for your convenience and information. These links do not constitute an endorsement of those sites or their content. Once you leave our website, this Privacy Policy no longer applies. We have no control over and accept no responsibility for the privacy practices or content of any third-party websites. We encourage you to read the privacy policy of every website you visit.
16. CHILDREN'S PRIVACY
Our website and services are directed exclusively at adults aged 18 years and older. We do not knowingly collect personal data from individuals under the age of 18. If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us immediately at info@gibeka.com and we will take prompt steps to delete such data from our records.
17. DIRECT MARKETING & COMMUNICATIONS
We may use your contact details to send you marketing communications about our services, programmes, events, and publications — but only where you have given your prior consent, or where we have an existing relationship with you and you have not opted out.
Every marketing communication we send will include a clear and easy mechanism to unsubscribe or opt out at any time. You may also opt out by contacting us directly at info@gibeka.com with the subject line "Unsubscribe."
We will action all opt-out requests within 10 business days. Please note that opting out of marketing communications will not affect communications that are necessary for the delivery of a service you have contracted or requested.
18. AUTOMATED DECISION-MAKING & PROFILING
We do not use your personal data for fully automated decision-making processes that produce legal or similarly significant effects concerning you without human involvement. Any assessments or recommendations provided through our website tools are informational only and are followed by direct human engagement.
Where we use data analytics to understand website usage or service preferences, this is done on an aggregated and anonymised basis and does not constitute individual profiling for the purposes of applicable data protection law.
19. UPDATES & AMENDMENTS TO THIS POLICY
We reserve the right to update, amend, or replace this Privacy Policy at any time to reflect changes in law, regulatory guidance, our services, or our data processing practices. The most current version of this Policy will always be accessible on our website at www.gibeka.com, accompanied by the effective date and version number.
Where changes are material — meaning they significantly affect your rights or how we process your data — we will notify you by:
-
Posting a prominent notice on our website
-
Sending a notification to the email address we hold for you (where applicable)
Your continued use of our website or services following the publication of an updated Policy constitutes your acknowledgement of the changes. We encourage you to review this Policy periodically.
20. GOVERNING LAW & DISPUTE RESOLUTION
This Privacy Policy is governed by and shall be construed in accordance with the laws of the Republic of Kenya, including the Data Protection Act, 2019, and all applicable subsidiary legislation made thereunder.
Any dispute arising out of or in connection with this Policy that cannot be resolved informally shall first be referred to the Office of the Data Protection Commissioner (ODPC) in accordance with the Data Protection Act. Nothing in this Policy limits your right to seek judicial remedy in a court of competent jurisdiction in Kenya.
21. CONTACT US
For all privacy-related enquiries, requests, complaints, or concerns — including the exercise of your data subject rights — please contact us through any of the following channels:
Email: info@gibeka.com (preferred — please use subject line "Data Protection Enquiry")
Phone: +254 792 601 888
Website: www.gibeka.com/contact
We are committed to handling all privacy enquiries promptly, professionally, and in full compliance with applicable law.
This Privacy Policy was last reviewed and updated on 1 January 2026.
Version 1.0.
© 2026 GiBeKA Financial Consulting. All rights reserved.
