Privacy Policy
The short version. We never store your National ID number — only a one-way digest of it that cannot be turned back into the number. Your name and phone are encrypted on disk. Every separate use of your data was consented to separately and can be withdrawn separately. You can make us erase you, and we will tell you the one record that survives it and why.
1. Who is responsible for your data
Two different answers, depending on which data:
- Your campaign is the data controller for your membership.
- The campaign you joined decides what to collect about its members and why, and it answers to you and to the ODPC for that. We hold and process it on the campaign’s instructions as its processor, under the Data Processing Agreement, which the campaign can read in its console.
- We are the controller for the platform itself.
- Your sign-in records, identity verification, payments to us, security logs and support correspondence are ours to answer for. So is a campaign applicant’s own data, before there is a campaign to hand it to.
We are African Wood Inc (registration CF/2010/34975), trading as VEDDA, registered with the Office of the Data Protection Commissioner as a Data Controller under identification 604-5622-D9D7 — certificate serial 23048, valid to 9 June 2028. The CellTree software is licensed to us by Dhamana Technologies Limited, which is why its name appears on the copyright line; it does not decide anything about your data.
2. What we hold, and why
| Data | Why | How it is stored |
|---|---|---|
| Your name | So your cell-mates and your campaign know who you are | Encrypted (AES-256-GCM). You may choose to show only your initials to cell-mates. |
| Your phone number | Sign-in codes and campaign messages. It is your account. | Encrypted, plus a keyed one-way digest used only to look you up at sign-in |
| Your National ID number | To confirm you are a real, single person and to place you correctly | Not stored. Only a keyed one-way digest (HMAC-SHA256). There is no decryption path in the code because there is nothing to decrypt. |
| Identity verification result | Proof the check was done | The verdict and a reference. Not the document, not the image. |
| Your photo, if you add one | So cell-mates can recognise you | Encrypted reference |
| Ward and cell | The whole point of the platform: where you organise | Plain — it is not identifying on its own |
| Whether you say you are registered to vote | Only if you tell us. See section 3. | Plain, behind its own consent |
| Payments | Entry fees, upkeep, and receipts | Amounts, M-Pesa receipt numbers, and dates. We never see your M-Pesa PIN. |
| What you post on cell boards | Discussion with your cell | Plain, readable by your cell and your campaign |
| Sign-in and device records | Security: knowing which device signed in, and stopping a stolen number | Device identifier, times, and the IP address recorded at consent |
| Consent records | Proof that each use of your data was agreed to | Append-only. See section 4. |
3. Sensitive data
Membership of a political campaign reveals a political opinion, which is sensitive personal data under section 44 of the Data Protection Act. So does saying you are registered to vote in a particular ward. We treat both accordingly:
- Your voter-registration status is recorded only if you state it, and only behind a consent asked for that purpose alone. Agreeing to join a campaign did not license it.
- Checking your ID digest against a register the campaign bought is a separate question again, asked as its own un-ticked box. You can state your status and still refuse the cross-check.
- Analysis of what you write on cell boards is a third separate consent, and refusing it does not remove you from the campaign.
4. Consent, asked one purpose at a time
There is no single “I agree” that covers everything. Each of the following is asked separately, as a box that starts empty, and each can be withdrawn on its own:
- Registration — joining a campaign, and processing your ID to do it
- Placement into a cell within a ward
- Payment processing through M-Pesa
- Analysis of cell discussion
- Minting your permanent identity anchor
- Re-pointing that anchor at a new phone number
- Recording your own statement of voter-registration status
- Checking your ID digest against a certified register
- Erasure, when you ask for it
Every one of these writes a record of who consented, to what, when, from which device and IP address. The system is built so that your record cannot be changed at all without a matching consent record being written in the same breath — the database refuses the write otherwise. That is enforced in the database itself, not left to whoever wrote the last feature to remember.
Withdrawing consent is not retrospective: it stops the processing, it does not undo what was lawfully done before. Withdrawing consent for something essential to membership — your registration itself — means leaving the campaign.
5. The lawful bases we rely on
- Your consent
- For everything in section 4. This is the main basis and the one you control.
- Performance of a contract
- Running your account, taking a payment you initiated, and delivering what a campaign bought.
- Legal obligation
- Keeping financial records, and responding to a lawful order.
- Legitimate interests
- Security: detecting a stolen number, blocking abuse, keeping audit logs. We have balanced this against your interests and it is limited to what security actually needs.
6. How it is protected
- Your National ID cannot leak, because it is not there. What is stored is a keyed HMAC-SHA256 digest. Someone with the entire database still cannot recover an ID number from it.
- Names and phone numbers are encrypted at rest with AES-256-GCM, using a key held outside the database. A stolen backup is not a stolen member list.
- Searching does not require decrypting. Lookups run against keyed digests, so signing you in never needs the plaintext of anything.
- Campaigns are isolated from each other. No campaign can read another’s members, rolls, payments, or boards.
- Consent records are append-only. The database refuses to alter or delete them, which is what makes them evidence rather than a claim.
- Hosting is in Africa. The service runs in AWS Cape Town (af-south-1), and it refuses to start in production anywhere outside the permitted African regions.
8. Data that leaves Kenya
Sections 48–50 of the Data Protection Act restrict sending personal data out of Kenya. Two transfers are unavoidable in how this platform works, and we would rather name them than have you find them:
- Your phone number goes to Twilio, in the United States.
- That is what delivering a sign-in code means. There is no version of a code sent to your phone in which your number does not reach the network that carries it. It is covered by a written processor agreement, and Twilio may use it only to deliver the message.
- Identity verification goes to Smile Identity.
- Only at the moment you are verified, and only what the check needs. What comes back and is stored is a verdict and a digest — not your ID number, not your document, not your photograph. Covered by a written processor agreement.
Everything else — your record, your cell, your payments, your posts — stays on African infrastructure. The service checks every outbound processor address against an approved list when it starts, and refuses to run if one of them has been changed to somewhere nobody assessed.
9. How long we keep it
| What | Kept for | Why |
|---|---|---|
| Your membership record | While you are a member, then 24 months | So a return, or a dispute, does not start from nothing |
| Financial records | 5 years from the transaction | Required by the Tax Procedures Act |
| Consent records | Indefinitely, in tombstoned form after erasure | They are the proof that processing was lawful. See section 11. |
| Sign-in and security logs | 12 months | Investigating a compromised account after the fact |
| Cell board posts | While the campaign exists | The campaign is the controller and decides |
| A campaign application we refused | 12 months | So a refusal can be explained and reviewed |
10. Your rights
Under the Data Protection Act you may:
- Be told what we hold about you and why — that is this document.
- Get a copy of your data.
- Correct anything wrong.
- Have it erased — see the next section for exactly what that destroys.
- Object to processing, and withdraw any consent, one purpose at a time.
- Ask for it in a portable form you can take elsewhere.
- Complain to the ODPC.
Ask your campaign first for anything about your membership — it is the controller and it holds the decision. Ask us at support@veddaonline.com for anything about the platform, or if a campaign does not answer you. We respond within 30 days. There is no charge.
11. Erasure, exactly
When you ask to be erased, in one transaction:
- Your name and phone number are overwritten with a tombstone. Not blanked — replaced, so nothing can be recovered from them.
- The digest of your National ID is destroyed and replaced with a value derived from nothing but your record’s own identifier.
- The digest of your phone number is deleted.
- Your ward is cleared.
The ID digest goes because leaving it would let a campaign match you against an external register later and work out who the erased row had been. An erasure that leaves a handle behind is not an erasure.
One thing survives, and you should know why. The consent records stay. They say that on a given date somebody consented to a given purpose, and they are the only evidence that what we did with your data before you asked us to stop was lawful. Destroying them would destroy your protection along with your data — an organisation that erases its consent trail cannot be held to account for anything it did. They no longer connect to a name, a number, or an ID, because those are gone.
Your seat in the cell also stays open as a vacancy, with no name attached, so the cell’s own history stays intact and someone else can take the place.
Financial records are kept for the 5 years the law requires, and are not erased on request — we are not permitted to.
12. If something goes wrong
If personal data is breached, we notify the ODPC within 72 hours of becoming aware, as section 43 requires, and we tell the people affected without undue delay where there is a real risk to them. Where the data was a campaign’s, we tell the campaign immediately so it can meet its own obligations as controller.
We will tell you what happened, what it means for you, and what we have done. We will not minimise it.
13. Children
CellTree is for adults. We do not knowingly hold data about anyone under 18, and if we find that we do, we erase it. Tell us at support@veddaonline.com if you believe a child’s data is on the platform.
14. Changes
We will post any change here with a new version and date. Where a change materially affects your rights, or introduces a new purpose, we will tell you — and where the new purpose needs consent, we will ask for it rather than assume it.
15. Contact and complaints
- Data protection
- support@veddaonline.com — mark it for the attention of the Data Protection Officer.
- Office of the Data Protection Commissioner
- odpc.go.ke — you may complain to them directly at any time.