Last updated: 24 September 2026
This Privacy Policy explains how Joseph Wenani handles personal information associated with JosephWenani.com. It covers visiting the website, reading articles, submitting enquiries, subscribing to updates, and discussing or receiving professional services through the Agency page. It also covers related email, telephone and messaging correspondence with me. “Personal information” means information that identifies you or can reasonably be linked to you.
I am based in Kenya and generally decide why and how information collected for my own website and business is used. In that context, I act as a data controller. Where a client asks me to work on personal information in its systems solely under its instructions, that client may be the controller and I may act as a processor. The project agreement should set out the applicable roles where needed.
This policy is intended to reflect the Kenya Data Protection Act, 2019, its applicable regulations and other relevant law. The Terms of Use cover general use of the website and do not replace this policy.
1. Information I receive
Information you submit. If you use a contact form, email me, call, send a message or request services, I may receive your name, email address, telephone number, business or organisation name, website address, the content of your enquiry, attachments and the correspondence that follows. You control what additional information you put in your message.
Subscription information. If a newsletter or update subscription is available and you sign up, I may receive your name, email address, subscription preferences and a record of when you subscribed or unsubscribed.
Project and business information. A prospective or existing client may provide project requirements, budget and timelines, business contact information, technical documentation, account access details, contracts and support requests. Work on a live system may expose information in databases, backups, server logs, customer accounts or other client-controlled systems. Billing records may include invoices, amounts, dates and payment references. The extent of access depends on the agreed project.
Technical information. A visit may generate IP addresses, browser and device details, referring pages, pages requested, timestamps, error reports and security logs through the website, its host or security tools. If analytics are enabled, they may also generate usage information such as page views and approximate visit duration. An IP address or online identifier can be personal information even if you do not enter your name.
Please provide only information relevant to your request. Do not send passwords, M-Pesa PINs, full payment-card details, medical records or other unnecessary sensitive material through an ordinary website form or email. If technical access is necessary, I can agree on a more appropriate method for the project.
2. Purposes and lawful grounds for using information
I use information for the following purposes, as applicable:
| Purpose | Typical information | Possible lawful ground |
|---|---|---|
| Responding to enquiries and preparing quotes | Contact details, messages and project requirements | Steps requested before a contract, or a legitimate interest in answering an enquiry |
| Delivering work and support | Client contacts, project files and necessary system access | Performance of a contract; a separate client instruction may apply to processor work |
| Sending subscribed updates | Subscription details and communication preferences | Consent or another lawful ground applicable to that communication |
| Operating and protecting the website | Technical logs, IP addresses and suspicious request patterns | Legitimate interests in reliability and security, or a legal obligation where applicable |
| Improving content and usability | Usage information, where the relevant tools are enabled | Legitimate interests or consent where a technology requires it |
| Invoicing, record keeping and legal matters | Agreements, invoices, transaction references and correspondence | Contractual necessity, legal obligation or legitimate interests in establishing and protecting rights |
The appropriate ground depends on the particular activity and applicable law. Where I rely on consent, you may withdraw it for future processing. Withdrawal does not undo processing already carried out lawfully. I will not use a general service enquiry as permission to send unrelated marketing indefinitely.
3. Contact forms and correspondence
Information sent through the website, email, phone or a messaging service is used to understand and answer your request, follow up on a project, provide support and keep a reasonable record of what was agreed. If you ask for a quote, your information may be used to clarify the scope, estimate costs and prepare a proposal. Sending an enquiry does not by itself create a client contract.
Emails and messages can contain attachments and metadata, including sender details and message times. Please avoid sharing confidential material before we agree on how it will be handled. Communications on services such as WhatsApp are also subject to the provider’s own privacy practices.
4. Newsletters and marketing choices
If you choose to subscribe, I use your subscription details to send the articles, resources, announcements or updates described at sign-up. Where a message includes an unsubscribe link, you can use it at any time. You can also contact me using the details in section 17 to stop these messages or withdraw consent. I may retain a limited suppression record so your choice continues to be respected.
An unsubscribe request stops the relevant promotional or newsletter messages; it does not necessarily stop necessary communications about an active project, an invoice, security issue or a request you have made. Any separate direct-marketing activity must have an appropriate lawful basis, and you may object to direct marketing.
5. Cookies, analytics and website features
Cookies and similar technologies can store or read small pieces of information on your device. A website may use them to operate essential functions, remember preferences, measure traffic or load external features. Strictly necessary technologies may support security, forms and normal website operation. Optional analytics, advertising or embedded-content technologies should be handled according to the consent rules that apply to them.
If analytics are enabled, they may show how visitors reach and use the site, such as pages viewed, approximate location inferred from an IP address, device type and navigation patterns. This helps identify broken pages and improve content and performance. Videos, maps, social posts, widgets and other embedded content may allow the provider to collect information or set its own cookies when the feature loads. External providers apply their own privacy policies.
You can usually block or delete cookies through your browser settings, although some features may then fail to work. Where the law requires prior consent for a particular optional technology, that technology should not be activated until you make the relevant choice. The specific cookies and providers in use depend on the website’s actual configuration.
6. Professional services and access to client systems
Agency work may involve website development, applications, integrations, migrations, maintenance, technical support or other agreed digital services. To perform a task, I may need access to a hosting account, code repository, database, existing application or related records. Access and use should be limited to the agreed purpose, with suitable permissions and confidentiality safeguards. Clients should, where possible, provide a dedicated temporary account with only the permissions needed and revoke it when the work is complete.
Personal data belonging to a client’s customers or staff is not automatically governed solely by my role as operator of this website. If I handle that data on the client’s instructions, the client and I should define the instructions, security measures, confidentiality duties, retention and deletion arrangements in a suitable project or data-processing agreement. Data accessed for a project should not be reused for an unrelated purpose.
7. AI-assisted work and automated processing
I may use AI tools to assist with research, drafting, coding, testing, troubleshooting or agreed software integrations. This does not mean every enquiry or client file is submitted to an AI provider. Before using an external AI service for client or personal information, I should assess necessity, confidentiality, the provider’s terms, location and security arrangements, and any agreement or consent required for that project. Where practical, identifying or sensitive details should be removed before information is submitted.
Automated spam and security checks may assess suspicious requests. The website is not intended to make decisions with significant legal or similarly serious effects about visitors solely through automated processing. If a future service introduces such decisions, its processing and applicable safeguards should be explained before it is used.
8. Payments and financial records
If you pay for professional services through a bank, mobile-money operator or payment provider, that provider may independently process the information needed to complete the transaction under its own terms. Offering clients payment integrations does not mean that this website itself collects or stores visitors’ card numbers or M-Pesa PINs.
I may keep a name or business name, invoice, amount, payment date, transaction reference and related correspondence for accounting, tax, contract administration, fraud prevention or resolving disputes. Please use an agreed payment channel and do not put complete payment credentials in a contact message.
9. Sharing information and external services
Information may be disclosed only where there is an appropriate purpose and lawful basis. Depending on the website and project setup, recipients may include:
- Service providers for hosting, email, forms, newsletter delivery, security, backups, analytics and communications, receiving information necessary for their tasks.
- Payment providers and banks processing a payment.
- Professional advisers, such as accountants or lawyers, where relevant to an engagement or legal matter.
- Regulators, courts or other competent authorities when disclosure is required by law or necessary to respond to a lawful request.
Information may also be disclosed where reasonably necessary to investigate fraud or abuse, manage a security incident or establish, exercise or defend legal rights. If the business changes ownership, relevant records may be transferred subject to applicable privacy obligations. I do not sell contact-form submissions or subscriber lists to data brokers.
Links to third-party sites, social networks, videos, maps, WhatsApp and payment services lead to independently operated services. Their collection and use of information are governed by their own policies. This website’s policy does not control those services.
10. Processing outside Kenya
Some hosting, email, cloud, communications, analytics or AI providers may store or access information outside Kenya. If personal data is transferred internationally, the transfer must meet the applicable requirements of Kenyan data-protection law, including a relevant safeguard or other permitted condition. The destination and arrangements depend on the providers actually used and any client agreement. A provider’s presence outside Kenya does not, by itself, tell you which legal protection applies to a particular transfer.
11. Retention and deletion
I keep information only while it serves a legitimate purpose or must be retained under a legal obligation. The exact period depends on the kind of record:
- Enquiries: kept for follow-up, correspondence history, protection against abuse or potential claims for a reasonable period.
- Subscriptions: kept while you remain subscribed; a minimal opt-out record may remain afterwards.
- Client and financial records: kept as needed for delivery, support, contractual obligations, tax and accounting rules, disputes and legal claims.
- Security and technical logs: kept for the normal period needed for monitoring, investigation and troubleshooting.
- Backups: deleted information may remain temporarily until routine backup copies expire or are replaced.
When a record is no longer needed, I will delete, anonymise or securely dispose of it where reasonably possible. A deletion request may not require immediate removal of records that must lawfully be retained. Retention for a client-controlled system should also follow the relevant project agreement and the client’s lawful instructions.
12. Security and personal-data incidents
I use technical and organisational measures appropriate to the information and systems involved. Depending on the system, these may include encrypted website connections, limited access, authentication, updates, backups and security monitoring. Access to client systems should be limited to the people and period needed for the agreed work. No internet service, email system or storage method can be guaranteed completely secure.
If I become aware of a suspected personal-data breach, I will investigate its scope, take reasonable steps to contain it, assess the risk to affected individuals and meet applicable notification duties. Where Kenyan law requires notification to the ODPC or affected people, that notification will be made within the applicable legal timeframe. If I am processing data on a client’s behalf, I will also follow the incident notification duties in the applicable agreement and law.
13. Your data-protection rights
Subject to the circumstances and applicable law, you may have the right to:
- Be informed about what information is collected and why.
- Access information held about you.
- Correct information that is inaccurate, incomplete or misleading.
- Request deletion when there is no valid reason to keep it.
- Object to certain processing, including direct marketing.
- Restrict processing in applicable circumstances.
- Receive or transfer eligible information in a portable form where the law provides.
- Withdraw consent where consent is the basis for a particular activity.
Rights concerning certain decisions made solely by automated processing may also apply where relevant. Some requests have legal limits: for example, an invoice may need to be retained for tax purposes even if you ask for deletion. I will consider each request under the law rather than assuming every request has the same outcome.
To make a request, use one of the contact methods in section 17, describe the information or interaction involved and say what you want me to do. I may need to verify your identity before disclosing or changing personal information, so that somebody else cannot obtain or erase your records. Please do not send unnecessary identity documents with your first message.
14. Complaints
If you have a privacy concern, you can contact me so I can review it and respond. You may also lodge a complaint with Kenya’s Office of the Data Protection Commissioner where applicable. Contacting me first does not take away your right to approach the regulator.
15. Children and sensitive information
The website provides general technology content and professional information. It is not designed to solicit unnecessary personal information from children. Where processing a child’s information requires parental or guardian involvement under applicable law, that requirement must be observed. If you believe a child has submitted information inappropriately, please contact me so the matter can be reviewed.
Please avoid using the website’s general enquiry channels to send health data, identity documents, financial credentials or other sensitive information unless it is necessary for an agreed purpose and an appropriate method has been arranged. If sensitive information is required for a legitimate project, additional safeguards and terms may be necessary.
16. Updates to this policy
This policy may change if the website’s features, service providers, business practices or legal obligations change. The current version will be published at josephwenani.com/privacy/ with an updated date. If a change materially affects the handling of information already collected, I will provide any additional notice required by law.
17. Contact Joseph Wenani
For a privacy question, rights request, complaint or newsletter opt-out, contact Joseph Wenani, Kenya:
- Email: wenani.richard.joseph@gmail.com
- Telephone: 0745900173
- Contact page: josephwenani.com/contact/
Please include enough detail to identify your enquiry, but avoid sending unnecessary sensitive information.