Introduction
Carata respects your privacy and is committed to protecting your personal data. This policy explains how we collect, use, and share your data when you use our services in compliance with the General Data Protection Regulation (GDPR) and the Kenya Data Protection Act.
1. Data We Collect
We collect:
- Personal data (name, contact information, location, etc.)
- Transactional data (purchase history, delivery requests)
- Usage data (device information, IP address, browsing behavior)
2. Purpose of Data Collection
We use your data to:
- Provide our services (order fulfillment, delivery)
- Improve user experience
- Send marketing communications (with your consent)
- Ensure security and prevent fraud
3. Legal Basis for Processing
Your data is processed based on:
- Performance of a contract (e.g., delivery services)
- Compliance with legal obligations
- Legitimate interests (e.g., improving our services)
- Consent (for marketing or specific services)
4. Data Sharing
We may share your data with:
- Service providers (e.g., delivery partners)
- Regulatory authorities (if required by law)
- Third-party partners for marketing, only with your consent
5. Data Security
We implement appropriate security measures to prevent unauthorized access, alteration, or misuse of your data. However, no system is 100% secure, and we cannot guarantee absolute security.
6. Data Retention
We retain your personal data only as long as necessary to fulfill the purposes outlined or to comply with legal requirements.
7. Your Rights
Under GDPR and Kenya’s Data Protection Act, you have the right to:
- Access, correct, or delete your data
- Withdraw consent at any time
- Object to data processing
- Request data portability
8. Cross-Border Data Transfers
If data is transferred outside Kenya or the European Economic Area, we ensure it is protected through appropriate safeguards (e.g., standard contractual clauses).
9. Cookies
We use cookies to improve our website’s functionality and user experience. You can control cookie settings through your browser.
10. Children’s Privacy
Our services are not intended for children under 18. We do not knowingly collect data from minors.
11. Changes to This Policy
We may update this policy periodically. Significant changes will be communicated via email or a notice on our website.
12. Contact Us
If you have any questions or wish to exercise your data rights, please get in touch with us at:
Address: House 6, ZippTom Properties, Gandhi Avenue, Nairobi West, Nairobi, Kenya.
Email: privacy@carata.co