1. Scope and controller
This Policy explains how [INSERT LEGAL COMPANY NAME AND DATA-CONTROLLER DETAILS] collects and uses personal data through Aurevia. It should be aligned to the Operator’s actual registration and obligations under the Kenya Data Protection Act, 2019 where applicable, together with the law of every territory in which the programme operates.
2. Information collected
We may collect account details (name, mobile number, email, country and authentication records); nomination and professional information (biography, role, organisation, achievements, evidence, references, images and social links); voting and integrity data (hashed network and device identifiers, timestamps, approximate country, account and payment references, risk signals); transaction and event details; communications, consents and support records; and technical logs needed for security and performance.
Nomination information may be supplied by the nominee, an authorised representative or a third-party nominator. Public professional information may be checked solely for verification. Do not submit sensitive or private material unless specifically requested through the secure channel and lawful to provide.
3. Purposes and lawful bases
We process data to create and secure accounts; deliver OTP and service messages; receive and verify nominations; publish approved profiles; administer voting, judging, finalists and winners; take payments; issue QR-verifiable certificates; operate events; answer enquiries; investigate fraud; maintain audit records; meet tax, legal and regulatory duties; improve the service; and send marketing only where consent or another lawful basis permits. Depending on jurisdiction, processing may rely on contract, consent, legal obligation, legitimate interests, protection of vital interests or another lawful basis recorded by the Operator.
4. Public information
Approved nominee profiles, categories, verification status, finalist or winner status, approved images and selected professional information may be public and indexed by search engines. Voting totals appear only when configured. A third-party nominee will be contacted or otherwise given an appropriate opportunity to confirm participation before full publication, subject to the published rules and applicable law.
5. Sharing
Data may be shared on a need-to-know basis with contracted hosting, SMS, payment, analytics, security, verification, event and professional advisers; assigned judges under confidentiality; programme partners where clearly disclosed; competent authorities where legally required; or a successor in a lawful corporate transaction. We do not sell personal data. Service providers must be bound by suitable confidentiality, security and processing terms.
6. International transfers
Because Aurevia may operate across Africa, data may be processed outside your country. Before launch, the Operator must document hosting locations and implement the safeguards, adequacy findings, contractual terms or specific consent required by applicable law, including restrictions on transfers outside Kenya where the Kenya framework applies.
7. Retention
Account and active nomination records are kept while needed for the service. Winner, certificate and official award-history records may be retained as a legitimate permanent archive. Voting, payment and audit evidence is retained for [INSERT PERIOD BASED ON LEGAL AND DISPUTE REQUIREMENTS]. Failed OTPs and high-volume technical logs should be kept for the shortest operational period. A documented retention and secure-disposal schedule must be approved before launch.
8. Security
Controls include PIN hashing, short-lived OTPs, encrypted transport, role-based access, least privilege, validation, rate limits, upload controls, backups, audit logs and monitoring. No system is risk-free. The Operator will operate an incident-response process and make legally required notifications.
9. Your choices and rights
Subject to applicable law, you may ask to be informed about use, access your data, correct inaccurate data, object to or restrict certain processing, withdraw consent, request deletion where retention is no longer lawful, receive portable data where available, or complain to the relevant regulator. Identity verification may be required. Some records must be retained for fraud prevention, legal claims, certificate validity or statutory duties. Marketing can be stopped without blocking service messages.
10. Children, cookies and automated signals
Youth-category data requires an age-appropriate notice and guardian process where required. Cookies and similar technology are covered by the Cookie Policy. Fraud scoring helps flag activity for review; final enforcement decisions with significant effects should include authorised human oversight unless applicable law permits otherwise.
11. Contact
Privacy requests: [INSERT PRIVACY EMAIL, DATA PROTECTION OFFICER DETAILS AND POSTAL ADDRESS]. Complaints may also be made to the competent data-protection authority in your jurisdiction.
Document ID 2 · Version draft-1.0. Acceptance records, where required, are linked to this exact version.