Back to Home
Legal

Data Protection Policy

Effective: July 2026 · Apptuned Limited

How Apptuned Limited governs personal data in compliance with Kenya’s Data Protection Act 2019, the EU General Data Protection Regulation (GDPR), and international best practices.

Data Protection Principles

Apptuned processes personal data in accordance with the following principles:

  1. Lawfulness, fairness, and transparency — We always have a lawful basis for processing and are transparent about how we use data.
  2. Purpose limitation — Data is collected for specified, explicit, and legitimate purposes and not processed beyond those purposes.
  3. Data minimisation — We collect only the data we genuinely need.
  4. Accuracy — We keep data accurate and up to date.
  5. Storage limitation — Data is not kept longer than necessary (see retention schedule).
  6. Integrity and confidentiality — We protect data against unauthorised access, loss, and destruction using appropriate technical and organisational measures.
  7. Accountability — We are responsible for demonstrating compliance and maintain records of processing activities (ROPA).

Data Controller

The data controller for personal data processed through apptuned.app is:

Apptuned Limited

Upperhill Business Park, Nairobi, Kenya

Registration: Companies Act (Cap. 486)

DPO contact: dpo@apptuned.app

Lawful Bases for Processing

Under Kenya DPA 2019 Section 30 and GDPR Article 6, we rely on:

  • Consent — for newsletter subscriptions and cognitive assessment data. You may withdraw consent at any time without affecting prior processing.
  • Contract performance — for processing necessary to deliver services you have purchased or requested.
  • Legitimate interests — for responding to enquiries, improving our services, and fraud prevention. We conduct Legitimate Interests Assessments (LIAs) and they are available on request.
  • Legal obligation — for retaining records as required by Kenyan tax and corporate law.

For special category / sensitive data (neurodiversity assessment results), we rely exclusively on explicit consent under DPA Section 44 and GDPR Article 9(2)(a).

Technical & Organisational Security Measures

Encryption

  • TLS 1.3 in transit
  • AES-256 at rest
  • Encrypted backups

Access control

  • Role-based access control
  • MFA for all admin access
  • Least-privilege principle

Monitoring

  • Audit logs for data access
  • Automated anomaly detection
  • Regular penetration testing

Procedures

  • 72-hour breach notification
  • Annual staff training
  • Supplier DPA review

Data Breach Response

In the event of a personal data breach, Apptuned will:

  1. Contain and assess the breach within 24 hours of discovery.
  2. Notify the Office of the Data Protection Commissioner (ODPC) within 72 hours if the breach poses a risk to individuals’ rights.
  3. Notify affected individuals without undue delay if the breach is likely to result in high risk.
  4. Document all breaches, including those not reportable, in our breach register.

Individual Rights

Under Kenya DPA 2019 Part IV, individuals have the right to:

Access

Request a copy of your personal data (Subject Access Request).

Correction

Request correction of inaccurate or incomplete data.

Deletion

Request erasure of your data where there is no legitimate reason to retain it.

Restriction

Request that we limit processing while a dispute is resolved.

Portability

Receive your data in a structured, machine-readable format.

Objection

Object to processing based on legitimate interests or for direct marketing.

Submit requests to: dpo@apptuned.app. We will respond within 30 days.

Cross-Border Transfers

When personal data is transferred outside Kenya (e.g. to Vercel’s global servers or OpenAI in the US), we ensure transfers comply with DPA Section 48 by using appropriate safeguards: Standard Contractual Clauses, adequacy decisions, or binding corporate rules where applicable.