Privacy Notice
How Datapoint handles personal data.
This notice explains what personal data Datapoint Analytics collects, why it is used, how it is protected and the choices available to individuals.
This notice applies when you visit the Datapoint website, submit an enquiry or verification request, communicate with the team, receive a service, or are the subject of a verification assignment.
Datapoint may act as a data controller where it determines the purpose and means of processing, or as a data processor where it handles personal data on documented instructions from a client. The applicable role depends on the activity and the terms of the assignment.
Personal data may be obtained directly from you, from a client instructing Datapoint, from authorised representatives, referees, employers, institutions, public records, professional bodies, official registries, service providers or field sources relevant to the assignment.
Datapoint seeks to use sources that are appropriate to the check being performed and records the source or method used where this is necessary for the report and audit trail.
Processing is based on the lawful basis that applies to the activity, including consent where required, performance of a contract, compliance with a legal obligation, protection of legitimate interests, or another basis recognised by law.
- To respond to enquiries and determine the appropriate verification route.
- To scope, perform, review and report on authorised verification assignments.
- To provide dashboards, analytics, field confirmation and related client support.
- To manage contracts, accounts, billing, security, quality assurance and service improvement.
- To meet legal, regulatory, audit, complaint-handling and dispute-resolution obligations.
- To prevent misuse, fraud, unauthorised access and threats to the service.
Datapoint limits each assignment to the checks relevant to the stated decision. Sensitive personal data is handled only where the assignment, applicable law and lawful basis permit it, and with additional controls appropriate to the risk.
Where a client initiates the assignment, the client is responsible for having authority to request the checks and for providing any notices, permissions or supporting instructions required from the verification subject.
Personal data may be shared with authorised client users, approved source organisations, professional advisers, technology and hosting providers, payment or communications providers, field partners and public authorities where disclosure is lawful and necessary.
Access is limited to the information required for the relevant role. Service providers are expected to apply confidentiality, security and data-handling controls appropriate to the services they provide.
Where personal data is transferred or accessed outside Kenya, Datapoint applies the safeguards required by applicable law. These may include an adequacy basis, contractual protections, consent where appropriate, or another permitted transfer mechanism.
Personal data is retained only for as long as necessary for the purpose for which it was collected, the assignment and contractual requirements, legal or regulatory obligations, complaint and dispute periods, security, audit and legitimate record-keeping needs.
When the applicable retention period ends, records are deleted, anonymised or securely archived in accordance with the relevant retention and disposal controls.
Datapoint uses technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, disclosure or misuse. Controls may include access restrictions, authentication, encryption, secure transfer, logging, confidentiality duties, backups, incident response and periodic review.
No system can guarantee absolute security. Datapoint reviews risks and updates safeguards where changes in technology, processing or identified threats require it.
Subject to applicable law and any lawful limitation, an individual may request information about the use of their personal data, access data held about them, object to processing, and request correction or deletion of false or misleading data.
Datapoint may need to verify the identity and authority of the person making the request. A request may also be referred to the relevant client where that client controls the data or the underlying decision.
The website and standard verification services are not directed to children. Where an assignment lawfully involves a child or vulnerable person, Datapoint applies the additional authorisation, necessity, proportionality and safeguarding measures required by the circumstances and applicable law.
Privacy questions and rights requests may be submitted through the Datapoint Contact page. Complaints may also be made to the Office of the Data Protection Commissioner where the individual considers that personal data has been processed contrary to applicable law.
This notice may be updated to reflect changes in services, technology, law or operational practice. The current version and effective date will be published on this page.
