compliance & privacy // framework-aligned

Privacy & Data Protection

Baraka Digital Hub is committed to protecting your data and operating with transparency. This page summarises our security, retention and data subject rights, following ISO frameworks and applicable Kenyan and international data protection standards.

ISO 27001ISO 9001GDPR principlesKenya DPA 2019
ISO 27001Information security practices are structured around international risk-management principles.
ISO 9001Quality procedures are documented, measurable, and continuously improved.
Rights-basedClients can request access, correction, deletion, portability, restriction, and objection.
01 — ISO 27001

ISO 27001

Our information security practices are structured around ISO 27001 principles — the international standard for managing information security risks.

  • All staff sign NDAs before accessing client data
  • Locked workstations during client work sessions
  • No personal devices permitted in project areas
  • Managed company email accounts for all contractors
  • Role-based access controls — only assigned personnel access project data
  • Client data deleted upon project completion
02 — ISO 9001

ISO 9001

Our quality procedures follow ISO 9001 principles — ensuring consistent, measurable, and continuously improving service delivery.

  • Documented procedures for every service type
  • Minimum 95% certification pass before any live project
  • 100% QA review after first pass — not spot-checking
  • Error logging with root-cause categorisation
  • Weekly accuracy and performance reports to clients
  • Continuous improvement through targeted retraining
03 — What we collect

What we collect

Client-provided data

Project files and task materials shared for annotation, transcription, or processing; contact information for communication and invoicing; platform credentials if operating within your environment.

Website visitor data

Name and email submitted via contact forms; general analytics (page visits, device type) with no personal identifiers; no advertising cookies or tracking pixels.

04 — Retention & deletion

Retention & deletion

Project data

Deleted at completion: All client files and task materials are securely deleted upon project sign-off.

Contact records

Up to 24 months: Business contact details retained for relationship management; erasable on request.

Invoicing & billing

7 years: Financial records retained in compliance with Kenyan tax regulations.

NDAs & agreements

Duration + 5 years: Contractual documents retained for legal compliance and audit purposes.

05 — Your rights

Your rights

In alignment with GDPR principles and the Kenya Data Protection Act 2019, you have the following rights over any personal data we hold:

  • Access — Request a copy of any personal data we hold about you
  • Rectification — Ask us to correct inaccurate or incomplete data
  • Erasure — Request deletion of your personal data at any time
  • Portability — Receive your data in a structured, machine-readable format
  • Restriction — Ask us to limit how we process your data
  • Objection — Object to processing where legitimate interest applies
06 — Regulatory basis & frameworks

Regulatory basis & frameworks

  • Kenya Data Protection Act 2019 — Our primary regulatory obligation; we are committed to registration with the ODPC as we formalise operations.
  • GDPR Principles (EU) — Applied voluntarily to all international client engagements.
  • ISO 27001 — Our information security controls are structured in alignment with this framework; we are working toward formal third-party certification.
  • ISO 9001 — Our quality management follows ISO 9001 with documented procedures, QA checkpoints, and continuous improvement cycles.
07 — Questions or requests?

Questions or requests?

For a detailed Data Processing Agreement (DPA), privacy impact assessment, or to exercise your rights, contact our Data Protection Officer at projects@barakadigitalhub.com.