Privacy Policy

How we collect, use, and protect your personal data — in line with the Constitution of Kenya (2010) and the Data Protection Act, 2019.

Last updated: 8 September 2026

This Privacy Policy explains how The Kenya Software & AI Summit (“the Summit”, “we”, “us”) collects, uses, shares, and safeguards your personal data when you register for, apply to, or take part in the Summit through this website and the Summit mobile app. It is issued in compliance with Article 31 of the Constitution of Kenya (2010) and the Data Protection Act, 2019 and its Regulations, as administered by the Office of the Data Protection Commissioner (ODPC).

1. Who we are (Data Controller)

The Summit is convened by the Ministry of Information, Communications & The Digital Economy, which is the data controller responsible for your personal data. You can reach our team, including on data-protection matters, at:

  • Email: softwaresummit@ict.go.ke
  • Address: GPO Telposta Towers, Koinange Street, Nairobi
  • Postal address: P.O. Box 30025–00100, Nairobi, Kenya
  • Attention: Software Summit Team / Data Protection Officer
2. Personal data we collect

We collect only what we need to register you, run the event, and operate the features you choose to use. Depending on how you interact with the Summit, this includes:

a. Delegate registration

  • Title, first name, and other names
  • Email address and phone number
  • Organization category and institution/organization name (and the free-text description if you select “Other”)
  • Job title or role, and registration category (e.g. Delegate, Exhibitor, Speaker, Student)
  • Areas of professional or personal interest (including any “Other” interest you specify)
  • National ID or Passport number, and a scanned copy of your National ID or Passport
  • Passport-style photograph
  • Accessibility or dietary needs, if you provide them
  • Days you intend to attend, and your communication preferences (opt-in for future updates)
  • Your confirmation of consent to this Privacy Policy

b. Exhibitor applications

  • Contact person details, organization name and type, and exhibition category
  • Business type (local/international), KRA PIN, and country of registration
  • Business registration and international-business documents
  • Beneficial ownership details — full name, nationality, identification type and number, and ownership percentage of individuals who own or control a significant share of the business, where applicable

c. Partner / sponsor applications

  • Organization name, sector/industry, business registration number or PIN, website, and logo
  • Contact person’s name, designation, email, and phone
  • Areas of sponsorship interest and proposed contribution
  • Supporting documents such as a company profile, proposal file, and tax compliance certificate

d. Your profile and engagement activity (web portal and mobile app)

  • Profile details you choose to add — photo, company, role, bio, interests, location — and your visibility and “open to networking” settings
  • Connections and connection requests, and direct messages you send to other delegates
  • Community feed posts, comments and reactions; session questions (Q&A), poll responses, and feedback; and discussion-room messages
  • Meeting requests you send or receive, and sessions you save
  • Attendance check-ins (which sessions/days you check in to, with date and time)
  • Points, badges, and achievements earned through gamification features

e. Technical and device data (collected automatically)

  • IP address, browser type, and device information, used for security, fraud-prevention, and rate-limiting
  • Authentication and session tokens that keep you signed in
  • Mobile push-notification tokens, so we can deliver notifications you’ve enabled
  • App-permission data you grant — e.g. camera access (used only to scan session/badge QR codes) and notification permission

f. Media captured at the event

Photography, videography, and live streaming take place during the Summit. By attending, you acknowledge that you may appear in official event photos, videos, or streams used for documentation, publicity, and promotional purposes.

3. Sensitive personal data

Some information we collect is treated as sensitive personal data under the Data Protection Act, 2019 — in particular your National ID/Passport number and scan (identity data) and any accessibility or dietary needs (which may reveal health information). We collect these only where necessary, with your consent, and apply additional care to how they are stored and accessed.

4. Lawful basis for processing

In line with sections 30–32 of the Data Protection Act, 2019, we process your data on one or more of these bases:

  • Your consent — e.g. creating a networking profile, or opting in to future-event updates
  • Performance of a contract — processing your registration or application and providing the event and its services
  • Compliance with a legal obligation — identity and business verification, and record-keeping required by law
  • A task carried out in the public interest / official authority — as a government-convened national event
  • Our legitimate interests — securing the platform, preventing fraud, and improving the event, balanced against your rights
5. How we use your data
  • To register, verify, and confirm your participation, and communicate with you about it
  • To verify identity and eligibility for exhibitor and sponsor applications
  • To produce delegate/exhibitor badges and manage venue access and session check-in
  • To operate the engagement features you use — directory, networking, messaging, discussion rooms, Q&A, polls, feed, meetings, and gamification
  • To personalize your experience, including suggesting people and sessions that match your interests
  • To send you event updates and, only where you have opted in, information about future summits and related events
  • To document and promote the Summit through photography, videography, and media coverage
  • To produce aggregate, non-identifying statistics for organizers and government stakeholders, and to keep the platform secure
6. Sharing and disclosure

We do not sell, rent, or lease your personal data. We share it only in these limited circumstances:

  • With your consent — for example, showing your professional details in the delegate directory or networking features you enable
  • With authorized service providers / data processors — such as hosting, email/SMS, and push-notification providers, acting on our instructions under confidentiality and data-protection agreements
  • For legal or regulatory compliance — where required by law, court order, or a lawful government directive

Identity-verification and business documents are visible only to authorized organizing staff reviewing your registration or application — they are never published. What other delegates can see about you is controlled by your own profile visibility settings.

7. Data security

We apply reasonable technical and organizational safeguards, including:

  • Encryption of data in transit (SSL/TLS)
  • Access controls that limit personal data to authorized personnel only
  • Authentication safeguards, and optional two-factor authentication on accounts
  • Periodic reviews, monitoring, and audits of our data-handling practices
8. Data retention

We keep your personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Retention periods vary with statutory obligations, record-keeping needs, and any consent you give for future communications. When the retention period expires, data is securely deleted, destroyed, or anonymized.

9. International transfers

Where any processing (for example, cloud hosting or notification delivery) involves transferring data outside Kenya, we do so only where the Data Protection Act, 2019 permits it — for instance where there is adequate protection, appropriate safeguards, or your consent.

10. Your rights

Under the Constitution of Kenya (2010) and the Data Protection Act, 2019, you have the right to:

  • Access — obtain a copy of the data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request deletion of your data where appropriate
  • Restriction — ask us to limit how we process your data
  • Object — object to certain processing, including direct marketing
  • Data portability — receive your data in a structured, commonly used format
  • Withdraw consent — at any time, without affecting processing already carried out
  • Lodge a complaint — with the Office of the Data Protection Commissioner (ODPC) if you believe your rights have been violated

To exercise any of these rights, contact us using the details in section 1. You can also manage much of this yourself — update your profile and visibility settings, change your communication preferences, or turn networking off — from the web portal or the mobile app.

11. Cookies and analytics

We use strictly necessary cookies and similar technologies to keep you signed in, secure the site, and remember your preferences. Any analytics we use are aggregate and non-identifying, to help us understand attendance and improve the event.

12. Children

The Summit and its platform are intended for adults (18 and over) and for delegates registering in a professional or academic capacity. We do not knowingly collect data from children without the consent of a parent or guardian as required by the Data Protection Act, 2019. If you believe a child has provided us data, contact us and we will address it.

13. Mobile app permissions

The Summit mobile app may ask for certain device permissions, each used only for its stated purpose: camera (to scan session and badge QR codes), notifications (to deliver reminders and announcements you’ve enabled), and photo/file access (only when you choose to upload a photo or document). You can change these in your device settings at any time.

14. Changes to this policy

We may update this policy to reflect legal, operational, or service changes. Updates are posted on this page with a revised “Last updated” date. Continued use of the platform or participation in the Summit after changes constitutes acknowledgment of the updated policy.

15. Governing law and contact

This policy is governed by the laws of Kenya, including Article 31 of the Constitution (2010) and the Data Protection Act, 2019. For any questions, data-access requests, or concerns, contact the Ministry of Information, Communications & The Digital Economy at softwaresummit@ict.go.ke (see section 1). You may also contact the Office of the Data Protection Commissioner via www.odpc.go.ke.