Privacy and data use

Privacy Policy

This Privacy Policy explains how Dholuo AI collects, uses, stores, shares, and protects your personal data when you visit this website, contact us, submit a support form, make a contribution, or otherwise interact with the project.

Effective date: 08 April 2026 Applies to website visitors, supporters, contributors, and contacts Kenya-focused privacy notice

1. Who we are

Dholuo AI is a project focused on Dholuo language technology, including speech, translation, data collection, community participation, supporter communications, and related digital services.

For the purposes of this website and supporter workflows, the project acts as the party responsible for deciding how your personal data is collected and used in connection with the site, the support form, supporter communications, and related project administration.

Project contact: Douglas Assesa

Email: hello@dholuo.digital

Phone / WhatsApp: +254 734 220 002

Location: Nairobi, Kenya

Important: This page is a public privacy notice. It should be kept aligned with how the project actually operates in practice, including form handling, data storage, supporter messaging, payment processing, and third-party services.

2. Data we collect

Depending on how you interact with the website, we may collect the following categories of personal data:

2.1 Information you provide directly

  • Full name.
  • Phone number and WhatsApp number.
  • Email address.
  • County or location information you submit.
  • Contribution amount or support details you choose to provide.
  • Messages, questions, or other information you send through forms, email, or WhatsApp.
  • Any contributor application, transcription, recording, or project participation information you submit in future workflows.

2.2 Payment and transaction information

  • Contribution amount, transaction reference, payment status, time submitted, and limited payment metadata required to confirm and manage the transaction.
  • Phone number used for payment initiation where mobile money or similar payment prompts are used.
  • We do not intentionally store full bank card data, card numbers, PINs, or payment credentials on this website.

2.3 Technical and usage information

  • IP address, browser type, device type, operating system, pages viewed, referral source, and approximate usage logs.
  • Date and time of visits, clicks, submissions, or other site activity.
  • Cookies or similar technologies used for site functionality, analytics, security, or preference management.

2.4 Sensitive or special categories

We do not ask for unnecessary sensitive personal data through the supporter form. Please do not send sensitive information unless we specifically request it for a lawful and clearly explained purpose.

3. How we use your data

We may use your personal data for the following purposes:

  • To receive, record, confirm, and manage support submissions or contributions.
  • To initiate or verify payment requests through approved payment channels.
  • To communicate with you about your submission, contribution, support request, or related project updates.
  • To respond to your questions, requests, or feedback.
  • To maintain project records, accounting records, reconciliation records, fraud prevention logs, and internal administration.
  • To improve the website, forms, contribution workflows, supporter communications, and project operations.
  • To publish aggregated progress updates that do not identify you personally unless you have clearly agreed to be publicly named.
  • To comply with legal, regulatory, tax, audit, security, or enforcement obligations.

3.1 Lawful basis and fair processing

Where required, we rely on your consent, your request for us to provide a service or process a contribution, our legitimate need to administer and secure the project, and our legal obligations under applicable law.

We aim to process personal data only for specific, clear, and legitimate purposes, and not to use it in a way that is incompatible with the purpose for which it was collected.

No sale of personal data: We do not sell supporter personal data to data brokers or unrelated advertisers.

4. Payments and contribution processing

If you make a contribution through a mobile money flow, payment gateway, or another processor, some transaction information may be handled by that third-party provider in order to complete, confirm, reconcile, and secure the payment.

We may receive limited payment metadata such as payer name, payer phone number, transaction reference, amount, date, payment status, or processor response details where necessary to confirm the contribution and keep proper records.

Payment providers operate under their own terms and privacy notices. You should also review the privacy notices of any payment service you use during checkout or support submission.

We do not ask for or store mobile money PINs, one-time passwords, or full card credentials on this website.

5. Sharing and third-party processors

We may share personal data only where reasonably necessary, including with:

  • Hosting, email, messaging, analytics, form, backup, or cloud service providers supporting the website and project administration.
  • Payment processors, mobile money channels, or transaction service providers needed to initiate, confirm, or reconcile payments.
  • Technical contractors, developers, or administrators acting under confidentiality and access controls.
  • Professional advisers, auditors, or legal service providers where reasonably necessary.
  • Public authorities, regulators, or law enforcement where disclosure is legally required or permitted.

We do not share your personal data with third parties for unrelated direct marketing without a valid lawful basis and, where required, your consent.

6. How long we keep data

We keep personal data only for as long as it is reasonably necessary for the purpose for which it was collected, including project administration, supporter communications, transaction records, security, dispute handling, legal compliance, and audit requirements.

Retention periods may vary depending on the type of record. For example:

  • Support form submissions and contact messages may be kept for operational follow-up and project administration.
  • Transaction and reconciliation records may be kept for accounting, tax, anti-fraud, and audit purposes.
  • Technical logs may be kept for security, troubleshooting, and abuse prevention for a limited period.

When data is no longer needed, we will delete it, anonymize it, or securely archive it where retention is required by law or legitimate recordkeeping needs.

7. Security

We take reasonable technical and organizational steps to protect personal data against unauthorized access, misuse, alteration, loss, accidental disclosure, and unlawful destruction.

These measures may include:

  • Restricted access to project records and administrative systems.
  • Password protection, server controls, and role-based access where available.
  • Transport security and secure submission methods where supported.
  • Processor and platform selection intended to reduce unnecessary data exposure.
  • Periodic review of form handling, storage practices, and payment-related workflows.

No website, transmission method, or storage system can be guaranteed to be completely secure. If we become aware of a material data incident affecting your information, we will take appropriate steps in line with applicable law and operational requirements.

8. Your privacy rights

Subject to applicable law and lawful limitations, you may have rights relating to your personal data, including the right to be informed, the right to access your data, the right to object to certain processing, and the right to request correction or deletion of false or misleading data.

Where applicable, you may also request erasure, portability, or restriction in line with the law and the nature of the processing involved.

To exercise your rights, contact us using the details in this policy. We may need to verify your identity before acting on a request.

How to make a request: Email us with the subject line Privacy Request and include enough information for us to identify the relevant record and respond appropriately.

9. Cookies and similar technologies

This website may use cookies, server logs, and similar technologies to keep the site functioning, improve performance, understand usage patterns, support security, and remember preferences.

We do not use cookies as a blank cheque to collect unnecessary personal information. Where non-essential cookies or tracking tools are introduced, this notice should be updated and any required consent steps should be implemented.

You can usually control cookies through your browser settings, although disabling some cookies may affect site functionality.

10. Children and minors

This website is not intended to collect personal data from children without appropriate authority, notice, or lawful basis. Where a child’s data must be processed for a specific project activity, appropriate consent and safeguarding steps should be used.

If you believe a child has provided personal data improperly through this site, please contact us so we can review and, where appropriate, remove the information.

11. International data transfers

Some of the service providers we use for hosting, email, cloud storage, analytics, forms, or related functions may store or process data outside Kenya.

Where cross-border processing occurs, we aim to use providers, controls, and contractual or organizational safeguards that are appropriate to the nature of the data and the purpose of processing.

12. Contact and complaints

If you have a privacy question, want to exercise your rights, or believe your data has been misused, please contact us first so we can review the issue and respond.

Email: hello@dholuo.digital

Phone / WhatsApp: +254 734 220 002

Location: Nairobi, Kenya

If you are not satisfied with the response, you may also have the right to raise the matter with the Office of the Data Protection Commissioner in Kenya.

Policy updates: We may update this Privacy Policy from time to time to reflect legal, operational, technical, or project changes. The updated version will be posted on this page with a revised effective date.