1. This Policy

Welcome to the Onyango & Company Advocates' Privacy Policy.

This policy outlines how we handle your Personal Data. As we continuously strive to improve our practices.

This Policy is directed towards individuals external to our firm, including individual clients, representatives of client organizations, visitors to our Site, and other service users (referred to collectively as "you").

We may modify or update this Policy to reflect changes in our Personal Data processing practices or adjustments in relevant laws. We urge you to carefully review this Policy and revisit this page to stay informed about any revisions we may make.

2. Definitions

  • Applicable Law means the Data Protection and Privacy Act, 2019 and the Data Protection and Privacy Regulations, 2020.
  • Controller means the entity that decides how and why Personal Data are processed.
  • Cookie means a small file that is placed on your device when you visit a website (including our Site).
  • Data Protection Authority means the Personal Data Protection Office (PDPO) at the National Information and Technology Authority (NITA-U).
  • Personal Data means information that is about any individual, or from which any individual is directly or indirectly identifiable, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier.
  • Process, Processing or Processed means anything that is done with any Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • Processor means any person or entity that Processes Personal Data on behalf of the Controller (other than employees of the Controller).
  • Sensitive Personal Data means Personal Data about political opinions, religious or philosophical beliefs, physical or mental health status, sexual life, financial information, or any other information that may be deemed to be sensitive under applicable law.
  • Site means Onyango & Company Advocates website.

3. Collection of Personal Data

We may collect Personal Data about you from the following sources:

  • Data you provide: We may obtain your Personal Data when you provide it to us (e.g., where you contact us via email or telephone, or by any other means, or if you provide us with your business card).
  • Relationship data: We may collect or obtain your Personal Data in the ordinary course of our relationship with you (e.g., in the course of corresponding with you).
  • Data you make public: We may collect or obtain your Personal Data that you choose to make public, including via social media (e.g., we may collect information from your social media profile(s), if you make a public post).
  • Site data: We may collect or obtain your Personal Data when you visit any of our Sites or use any features or resources available on or through a Site.
  • Registration details: We may collect or obtain your Personal Data when you use, or register to use, any of our Sites, or services.
  • Content and advertising information: If you choose to interact with any third party content or advertising on a Site, we may receive Personal Data about you from the relevant third party.
  • Third party information: We may collect or obtain your Personal Data from third parties who provide it to us (e.g., credit reference agencies; law enforcement authorities; etc.).

4. Creation of Personal Data

We may create Personal Data about you, such as records of your communications and interactions with us, including attendance at events we hold or interviews in the course of applying for a job with us. We may record telephone calls, meetings, and other interactions in which you are involved, in accordance with applicable law.

5. Categories of Personal Data we may Process

We may Process the following categories of Personal Data about you:

  • Personal details: given name(s); preferred name; and photograph.
  • Demographic information: gender; date of birth / age; nationality; salutation; title; and language preferences.
  • Identifier information: passport or national identity number; utility provider details; bank statements; tenancy agreements.
  • Contact details: correspondence address; telephone number; email address; and details of your public social media profile(s).
  • Matter details: details of individuals instructing Onyango & Company Advocates; Personal Data included in correspondence, transaction documents, evidence or other materials that we Process in the course of providing services and legal advice.
  • Attendance records: details of meetings and other events organised by, in partnership with or on behalf of Onyango & Company Advocates that you have attended.
  • Consent records: records of any consents you may have given, together with the date and time, means of consent and any related information (e.g., the subject matter of the consent).
  • Payment details: billing address; payment method; bank account number or credit card number; cardholder or accountholder name; card or account security details; card ‘valid from’ date; and card expiry date; invoice records; payment records; payment amount; payment date; and records of cheques.
  • Data relating to our Website: device type; operating system; browser type; browser settings; IP address; language settings; dates and times of connecting to a Site; and other technical communications information; usage data; aggregate statistical information.
  • Employer details: where you interact with us in your capacity as an employee, the name, address, telephone number and email address of your employer, to the extent relevant.
  • Views and opinions: any views and opinions that you choose to send to us, or publicly post about us on social media platforms.

6. Sensitive Personal Data

We may have to Process your Sensitive Personal Data in the ordinary course of our business. Where it becomes necessary to process your Sensitive Personal Data for any reason, we rely on one of the following legal bases:

  • Compliance with applicable law: We may Process your Sensitive Personal Data where the Processing is required or permitted by applicable law (e.g., to comply with our diversity reporting obligations);
  • Establishment, exercise or defence of legal rights: We may Process your Sensitive Personal Data where the Processing is necessary for the establishment, exercise or defence of legal rights; or
  • Consent: We may Process your Sensitive Personal Data where we have, in accordance with applicable law, obtained your express consent prior to processing your Sensitive Personal Data (this legal basis is not used in relation to Processing that we are legally required to carry out).

7. Purposes of Processing and legal bases for Processing

We Process Personal Data for the following purposes:

  • Providing our Site and services to you;
  • Conducting compliance checks;
  • Operating our business;
  • Communicating with you;
  • Managing our IT systems;
  • Conducting surveys;
  • Ensuring the security of our premises and systems;
  • Conducting investigations where necessary;
  • Compliance with applicable law;
  • Improving our Sites, and services; and
  • Recruitment and dealing with job applications.

8. Disclosure of Personal Data to third parties

We may disclose your Personal Data to entities, for legitimate business purposes such as ensure proper service delivery, in accordance with applicable law and subject to applicable professional and regulatory requirements regarding confidentiality and professional secrecy. In addition, we may disclose your Personal Data to:

  • legal and regulatory authorities, upon request.
  • accountants, auditors, lawyers and other outside professional advisors to Onyango & Company Advocates, subject to binding contractual obligations of confidentiality;
  • any relevant party, law enforcement agency or court, to the extent necessary for the establishment, exercise or defence of legal rights;

If we engage a third party Processor to Process your Personal Data, the Processor will be subject to binding contractual obligations to:

  • only Process the Personal Data in accordance with our prior written instructions; and
  • use measures to protect the confidentiality and security of the Personal Data, together with any additional requirements under applicable law.

9. International transfer of Personal Data

We may transfer your Personal Data to recipients in other countries for purposes of providing our services. This shall at all times be done in accordance with the applicable law.

10. Data security

We prioritize the security of your Personal Data. To safeguard your information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, and other unlawful or unauthorized forms of processing, we have implemented appropriate technical and organizational security measures, as required by applicable law.

However, it's essential to recognize that the internet operates within an open system. Therefore, while we employ all reasonable measures to protect your Personal Data, we cannot guarantee the absolute security of data transmitted to us over the internet.

Any transmission of Personal Data via the internet is undertaken at your own risk. You are responsible for ensuring that any Personal Data you transmit to us are done so securely.

11. Data accuracy

We take every reasonable step to ensure that your Personal Data are kept accurate and up-to-date and are erased or rectified if we become aware of inaccuracies.

12. Data minimisation

We take every reasonable step to ensure that your Personal Data that we Process are limited to the Personal Data reasonably necessary in connection with the purposes set out in this Policy.

13. Data retention

We are committed to ensuring that your Personal Data is processed only for the minimum period necessary, as outlined in this Policy.

Our criteria for determining the duration of retention for your Personal Data are as follows: We will maintain copies of your Personal Data in a format that allows for identification only for as long as it is essential to fulfil the purposes outlined in this Policy, unless longer retention is mandated by applicable law. Specifically, we may retain your Personal Data for the duration required to establish, exercise, or defend any legal rights.

Rest assured, we adhere to stringent standards to ensure that your Personal Data is handled responsibly and in compliance with relevant regulations.

14. Your legal rights

Subject to the applicable law, you have a number of rights regarding our Processing of your Relevant Personal Data, including:

  • the right not to provide your Personal Data to us (however, please note that we may be unable to provide you with the full benefit of our Sites, or our services, if you do not provide us with your Personal Data);
  • the right to request access to, or copies of, your Personal Data, together with information regarding the nature, Processing and disclosure of those Personal Data;
  • the right to request rectification of any inaccuracies in your Personal Data;
  • the right to request, on legitimate grounds:
  • erasure of your Personal Data; or
  • restriction of Processing of your Personal Data;
  • the right to have certain Personal Data transferred to another Controller, in a structured, commonly used and machine-readable format, to the extent applicable;
  • where we Process your Personal Data on the basis of your consent, the right to withdraw that consent (noting that such withdrawal does not affect the lawfulness of any Processing performed prior to the date on which we receive notice of such withdrawal, and does not prevent the Processing of your Personal Data in reliance upon any other available legal bases); and
  • the right to lodge complaints with a Data Protection Authority regarding the Processing of your Personal Data by us or on our behalf.
  • the right to object, on grounds relating to your particular situation, to the Processing of your Relevant Personal Data by us or on our behalf; and
  • the right to object to the Processing of your Relevant Personal Data by us or on our behalf for direct marketing purposes.

Nothing in this Policy affects any of your other statutory rights.

To exercise one or more of the rights described in this Policy, or to ask a question about these rights or any other provision of this Policy, or about our processing of your Personal Data, please use the contact details provided in Section (….) below.

15. Cookies and similar technologies

When you visit a Site or use an App we may place Cookies onto your device, or read Cookies already on your device, subject always to obtaining your consent, where required, in accordance with applicable law. We use Cookies to record information about your device, your browser and, in some cases, your preferences and browsing habits. We may Process your Personal Data through Cookies and similar technologies.

For further information, please see our Cookies Policy.

16. Indirect marketing

We may Process your Personal Data to contact you via email, telephone, direct mail or other communication formats to provide you with information regarding services that may be of interest to you. If we provide services to you, we may send information to you regarding our services and other information that may be of interest to you, using the contact details that you have provided to us and always in compliance with applicable law.

You may unsubscribe from our promotional email list at any time by simply clicking on the unsubscribe link included in every promotional email we send. After you unsubscribe, we will not send you further promotional emails, but we may continue to contact you to the extent necessary for the purposes of any services you have requested.

17. Contact details

If you have any comments, questions or concerns about data privacy, including the processing of personal data carried out by us, or on our behalf, please visit our contact us page.