Obwatoto bwabasefwe

Privacy Policy

Version 1.0 Effective 10 August 2026 Data Protection Act, 2019 (Kenya)

The short version. We never store your National ID number — only a one-way digest of it that cannot be turned back into the number. Your name and phone are encrypted on disk. Every separate use of your data was consented to separately and can be withdrawn separately. You can make us erase you, and we will tell you the one record that survives it and why.

1. Who is responsible for your data

Two different answers, depending on which data:

Your campaign is the data controller for your membership.
The campaign you joined decides what to collect about its members and why, and it answers to you and to the ODPC for that. We hold and process it on the campaign’s instructions as its processor, under the Data Processing Agreement, which the campaign can read in its console.
We are the controller for the platform itself.
Your sign-in records, identity verification, payments to us, security logs and support correspondence are ours to answer for. So is a campaign applicant’s own data, before there is a campaign to hand it to.

We are African Wood Inc (registration CF/2010/34975), trading as VEDDA, registered with the Office of the Data Protection Commissioner as a Data Controller under identification 604-5622-D9D7 — certificate serial 23048, valid to 9 June 2028. The CellTree software is licensed to us by Dhamana Technologies Limited, which is why its name appears on the copyright line; it does not decide anything about your data.

2. What we hold, and why

Data Why How it is stored
Your name So your cell-mates and your campaign know who you are Encrypted (AES-256-GCM). You may choose to show only your initials to cell-mates.
Your phone number Sign-in codes and campaign messages. It is your account. Encrypted, plus a keyed one-way digest used only to look you up at sign-in
Your National ID number To confirm you are a real, single person and to place you correctly Not stored. Only a keyed one-way digest (HMAC-SHA256). There is no decryption path in the code because there is nothing to decrypt.
Identity verification result Proof the check was done The verdict and a reference. Not the document, not the image.
Your photo, if you add one So cell-mates can recognise you Encrypted reference
Ward and cell The whole point of the platform: where you organise Plain — it is not identifying on its own
Whether you say you are registered to vote Only if you tell us. See section 3. Plain, behind its own consent
Payments Entry fees, upkeep, and receipts Amounts, M-Pesa receipt numbers, and dates. We never see your M-Pesa PIN.
What you post on cell boards Discussion with your cell Plain, readable by your cell and your campaign
Sign-in and device records Security: knowing which device signed in, and stopping a stolen number Device identifier, times, and the IP address recorded at consent
Consent records Proof that each use of your data was agreed to Append-only. See section 4.

3. Sensitive data

Membership of a political campaign reveals a political opinion, which is sensitive personal data under section 44 of the Data Protection Act. So does saying you are registered to vote in a particular ward. We treat both accordingly:

5. The lawful bases we rely on

Your consent
For everything in section 4. This is the main basis and the one you control.
Performance of a contract
Running your account, taking a payment you initiated, and delivering what a campaign bought.
Legal obligation
Keeping financial records, and responding to a lawful order.
Legitimate interests
Security: detecting a stolen number, blocking abuse, keeping audit logs. We have balanced this against your interests and it is limited to what security actually needs.

6. How it is protected

7. Who else sees it

We do not sell personal data, and we never will. It goes to these people and no others:

Who What they get Where they hold it
Your campaign Your membership record — it is the controller Kenya / South Africa
Twilio Inc. Your phone number, to deliver a sign-in code or a notification United States
Smile Identity What identity verification requires, at the moment you are verified Outside Kenya — see section 8
Safaricom PLC (M-Pesa / Daraja) Your phone number and the amount, to take a payment Kenya
Pesapal Payment details, where a campaign uses it to collect Kenya
Amazon Web Services Hosting — the encrypted database sits on their infrastructure Cape Town, South Africa (af-south-1)
A court, the ODPC, or a lawful order Only what the order requires Kenya

We hold written processor agreements with Twilio and with Smile Identity. Each is bound to use what we send only to do the job we send it for.

8. Data that leaves Kenya

Sections 48–50 of the Data Protection Act restrict sending personal data out of Kenya. Two transfers are unavoidable in how this platform works, and we would rather name them than have you find them:

Your phone number goes to Twilio, in the United States.
That is what delivering a sign-in code means. There is no version of a code sent to your phone in which your number does not reach the network that carries it. It is covered by a written processor agreement, and Twilio may use it only to deliver the message.
Identity verification goes to Smile Identity.
Only at the moment you are verified, and only what the check needs. What comes back and is stored is a verdict and a digest — not your ID number, not your document, not your photograph. Covered by a written processor agreement.

Everything else — your record, your cell, your payments, your posts — stays on African infrastructure. The service checks every outbound processor address against an approved list when it starts, and refuses to run if one of them has been changed to somewhere nobody assessed.

9. How long we keep it

WhatKept forWhy
Your membership record While you are a member, then 24 months So a return, or a dispute, does not start from nothing
Financial records 5 years from the transaction Required by the Tax Procedures Act
Consent records Indefinitely, in tombstoned form after erasure They are the proof that processing was lawful. See section 11.
Sign-in and security logs 12 months Investigating a compromised account after the fact
Cell board posts While the campaign exists The campaign is the controller and decides
A campaign application we refused 12 months So a refusal can be explained and reviewed

10. Your rights

Under the Data Protection Act you may:

Ask your campaign first for anything about your membership — it is the controller and it holds the decision. Ask us at support@veddaonline.com for anything about the platform, or if a campaign does not answer you. We respond within 30 days. There is no charge.

11. Erasure, exactly

When you ask to be erased, in one transaction:

The ID digest goes because leaving it would let a campaign match you against an external register later and work out who the erased row had been. An erasure that leaves a handle behind is not an erasure.

One thing survives, and you should know why. The consent records stay. They say that on a given date somebody consented to a given purpose, and they are the only evidence that what we did with your data before you asked us to stop was lawful. Destroying them would destroy your protection along with your data — an organisation that erases its consent trail cannot be held to account for anything it did. They no longer connect to a name, a number, or an ID, because those are gone.

Your seat in the cell also stays open as a vacancy, with no name attached, so the cell’s own history stays intact and someone else can take the place.

Financial records are kept for the 5 years the law requires, and are not erased on request — we are not permitted to.

12. If something goes wrong

If personal data is breached, we notify the ODPC within 72 hours of becoming aware, as section 43 requires, and we tell the people affected without undue delay where there is a real risk to them. Where the data was a campaign’s, we tell the campaign immediately so it can meet its own obligations as controller.

We will tell you what happened, what it means for you, and what we have done. We will not minimise it.

13. Children

CellTree is for adults. We do not knowingly hold data about anyone under 18, and if we find that we do, we erase it. Tell us at support@veddaonline.com if you believe a child’s data is on the platform.

14. Changes

We will post any change here with a new version and date. Where a change materially affects your rights, or introduces a new purpose, we will tell you — and where the new purpose needs consent, we will ask for it rather than assume it.

15. Contact and complaints

Data protection
support@veddaonline.com — mark it for the attention of the Data Protection Officer.
Office of the Data Protection Commissioner
odpc.go.ke — you may complain to them directly at any time.