PARTY OF ACTION PRIVACY POLICY

🛡️ POA Party Privacy Policy

Effective date: 17 June 2025

This Privacy Policy explains how POA Party (“we”, “us”, “our”) collects, uses, shares, and protects personal data when you use our website and membership services, including the Join, Check Status, and Resign features available at ikopoa.co.ke. We process personal data in line with the Kenya Data Protection Act, 2019 (KDPA) and applicable regulations.

1) Who we are (Data Controller)

POA Party is the Data Controller responsible for determining how personal data is processed.

Contact (Privacy/DPO):
Email: info@ikopoa.co.ke
Phone: 0724237237


2) What we collect

We collect information you provide directly, as well as system-generated technical data created when you visit our website or submit forms. We may also derive certain attributes internally (e.g., age-eligibility flags).

A. Direct data you provide

Collected through our membership and related forms or when you contact us:

  • Names (Name, Other Names)

  • ID/Passport number

  • Date of birth (for 18+ eligibility)

  • Postal address

  • Mobile number

  • Sex

  • Ethnicity

  • PWD status and NCPWD number (if applicable)

  • Religion

  • Voter registration status (Registered / Not yet registered)

  • County, Constituency, and Ward of voter registration (if registered voter)

  • Special interest categories (Youth 18–35, Women, Persons with Disabilities, Marginalized Groups, Minority Groups, None)

  • Declarations and consents (e.g., confirmation you are not registered with another party)

  • Resignation details (if you resign)

  • Any information you choose to include in free-text fields or attachments

  • Party Membership Number (system-generated but stored as part of your record)

B. System-generated / automatic data

Created when you load pages or submit forms:

  • IP address (and approximate location inferred from IP)

  • Device and browser information: browser type and version, operating system, device type, screen size

  • User-Agent string

  • Referrer URL (the page that linked you to ours)

  • Pages/URLs visited and timestamps (date/time)

  • Form submission metadata (submission IDs, status codes)

  • Cookies and similar technologies for session management, security (e.g., CSRF), and analytics

  • Server and delivery logs (request/response codes; email/SMS/OTP send status and timestamps)

C. Data we derive or create

  • Eligibility flags (e.g., 18+ verified)

  • Internal deduplication results (e.g., ID already exists in POA records)

  • Party Membership Number (e.g., POA-YYYY-00001)

  • Audit trails of changes (who/when)


3) Why we process your data (purposes) & legal bases

We use your data to:

  • Process membership applications, verify eligibility (18+), generate your membership number, and manage your membership record

  • Handle “Check Status” and “Resign” requests and communicate outcomes

  • Prevent duplicates within POA and maintain accurate records

  • Communicate with you about applications, membership, and party matters

  • Secure our website and services, detect abuse/fraud, maintain logs and backups

  • Comply with legal/regulatory obligations and respond to lawful requests

  • Improve our services (usability, performance, analytics)

Legal bases under KDPA may include: consent, performance of a contract (membership administration), legal obligation, and legitimate interests (e.g., fraud prevention and service security), balanced against your rights.


4) Cookies & similar technologies

We use cookies and similar technologies for:

  • Essential functions (security, session/CSRF)

  • Preferences (remembering certain choices)

  • Analytics (understanding usage to improve the site)

You can control cookies via your browser settings. Disabling essential cookies may affect site functionality.


5) Sharing your data

We do not sell personal data. We may share data with:

  • Service providers (secure hosting, site maintenance, email/SMS/OTP delivery, analytics) under contract and confidentiality

  • Regulators and lawful authorities where required by law

  • Professional advisers (auditors, legal counsel) under confidentiality

  • Internal party organs on a need-to-know basis for legitimate administration

If processing occurs outside Kenya (e.g., cloud hosting), we apply safeguards consistent with KDPA.


6) How long we keep your data (retention)

We retain data only as long as necessary for the purposes above, legal/regulatory requirements, and legitimate interests:

  • Active members: for the duration of membership

  • Resigned members: core records kept up to 7 years after resignation (or longer if legally required)

  • System logs: typically 6–24 months depending on security/backup needs

  • Analytics data: typically 12–24 months, aggregated or pseudonymised where possible

We periodically review retention and securely delete or anonymise when no longer needed.


7) Security

We use technical and organisational measures to protect data, including:

  • Encryption in transit (HTTPS)

  • Access controls and role-based permissions

  • Audit logging and backups

  • Vendor due diligence for service providers

While no system is 100% secure, we continuously assess and improve our safeguards.


8) Your rights (KDPA)

Subject to legal limits, you may:

  • Access your data

  • Correct/rectify inaccuracies

  • Object to certain processing or withdraw consent where processing is based on consent

  • Request deletion/erasure

  • Request restriction of processing

  • Request portability (where applicable)

To exercise these rights, contact info@ikopoa.co.ke or 0724237237. We may need to verify your identity (e.g., ID/Passport + OTP). You may also lodge a complaint with the Office of the Data Protection Commissioner (ODPC).


9) Children

Membership is restricted to persons aged 18 and above. We do not knowingly process children’s data for membership.


10) Automated decision-making

We do not use automated decision-making that produces legal or similarly significant effects without human review. Limited automated checks (e.g., duplicate detection, age validation) support manual decisions.


11) Changes to this policy

We may update this notice from time to time. The latest version will always be available on this page, with the Effective date at the top.


12) Contact

POA Party
Email: info@ikopoa.co.ke
Phone: 0724237237

 

Party Of Action
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.