Privacy & Safeguarding Policy

We collect, use, and protect personal data with dignity, transparency, and full compliance with the Kenya Data Protection Act 2019.

Home › Privacy & Safeguarding  |  Effective: May 2025  |  Version 1.0

1. Introduction

Home of Light & Love Foundation (“we”, “us”, “our”) is committed to protecting the personal data of all individuals we interact with — including children in our care, donors, volunteers, staff, and community partners. This Privacy Policy sets out how we collect, use, store, and protect personal information in line with the Kenya Data Protection Act 2019 and international safeguarding best practices.

Privacy and safeguarding are not just policies here — they are fundamental expressions of our respect for every person’s dignity and autonomy.

Section 2

Data Controller Details

Home of Light & Love Foundation is the Data Controller responsible for the collection and use of personal data in accordance with applicable data protection laws.

Organisation Name Home of Light & Love Foundation
Location Baringo, Kenya
General Email info@lightlovefoundation.org
Privacy / DPO Email privacy@lightlovefoundation.org
Data Protection Officer Responsible Officer (appointed internally)

This same contact information appears on our contact page, footer, and all field consent forms.

Section 3

Data We Collect

We collect the following categories of personal data:

  • Children in care: Names or initials, age, gender, health status, guardian details, school enrolment.
  • Donors: Full name, email address, phone number, payment details (processed securely).
  • Volunteers & Staff: National ID, contact details, qualifications, emergency contacts.
  • Website visitors: IP address, browser type, pages visited (via cookies — see Section 15).
  • Medical camp participants: Name, age, presenting health concern, treatment provided.

Section 4

Sensitive Data (Medical & Health)

Some of our programmes — particularly medical camps — require us to collect special category data including health conditions, treatment records, and disability status. This data is:

  • Collected only with explicit written or verbal consent from the individual or their guardian.
  • Stored separately from general personal data with restricted access.
  • Used exclusively for delivering medical or care services — never shared commercially.
  • Retained only as long as necessary for the care programme (see Section 9).

Section 5

How We Collect Data

  • Online: Donation forms, contact forms, newsletter sign-ups, and website enquiries.
  • Field operations: Paper consent forms at medical camps, outreach visits, and community events.
  • Photography & media: Only with signed or witnessed consent (see Section 12).
  • Third parties: Partner NGOs or referral agencies who share data only with your knowledge.

Section 7

How We Use Your Data

We use collected data to:

  • Deliver programmes, medical care, and support services to those in need.
  • Process donations securely and issue acknowledgement receipts.
  • Communicate with donors and volunteers about our work and impact.
  • Report to regulatory bodies and grant-making partners (using anonymised data where possible).
  • Improve our website and digital communications.
  • Safeguard children and vulnerable individuals in our care.

Section 8

Data Sharing

We never sell, rent, or trade personal data. We may share data only in the following limited circumstances:

  • Service providers: Secure payment processors and email platforms, under strict data agreements.
  • Government authorities: When legally required (e.g. child protection referrals).
  • Partner organisations: Only with your knowledge and consent, for coordinated care.
  • Auditors / Funders: Anonymised or aggregated data only, for reporting purposes.

Section 9

Data Retention

We retain personal data only as long as necessary:

Data Category Retention Period
Donor records 7 years (financial and tax obligations)
Children's case files Until the child turns 25, or 7 years after last contact
Medical camp records 5 years after the camp event
Staff and volunteer records 3 years after end of engagement
Website analytics 12 months

After the applicable retention period, data is securely deleted or fully anonymised.

Section 10

Your Rights

Under the Kenya Data Protection Act 2019, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete information.
  • Erase your data (right to be forgotten) where applicable.
  • Restrict or object to certain types of processing.
  • Data portability — receive your data in a readable format.
  • Withdraw consent at any time without affecting past processing.

To exercise any of these rights, contact us at: privacy@lightlovefoundation.org

Section 11

Children's Data

We recognise that children require enhanced privacy protection. Our policy is:

  • We never display the full identity (name + face) of a child without guardian consent.
  • Photos and videos of children are blurred or use initials only when full consent is not obtained.
  • Children's data is processed only under vital interests or explicit guardian consent.
  • All staff and volunteers working with children receive child safeguarding training.

Section 12

Media & Photography Consent

Before any photo, video, or personal story is shared publicly, we:

  • Obtain a signed or witnessed consent form from the individual or their guardian.
  • Clearly explain how and where the media will be used.
  • Give individuals the right to withdraw consent and have content removed at any time.
  • Never use images for any purpose beyond what was originally agreed.

Section 13

Security Measures

We implement the following technical and organisational safeguards:

  • SSL/TLS encryption on all web forms and donation pages.
  • Restricted access to personal data — only authorised staff can view sensitive records.
  • Password-protected and encrypted file storage for all digital records.
  • Locked physical storage for all paper-based consent and medical forms.
  • Regular staff training on data protection and safeguarding best practices.

Section 14

Data Breach Handling

In the event of a personal data breach, we will:

  • Investigate and contain the breach within 24 hours of discovery.
  • Notify the Office of the Data Protection Commissioner (ODPC) within 72 hours if required by law.
  • Inform affected individuals promptly where there is a high risk to their rights and freedoms.
  • Document all breaches in our internal breach register, regardless of severity.

Section 15

Cookies & Website Tracking

Our website uses cookies to improve your experience. These include:

  • Essential cookies: Required for the website to function (cannot be disabled).
  • Analytics cookies: Help us understand how visitors use the site (e.g. Google Analytics). These are optional.

You can control or disable analytics cookies through your browser settings. This will not affect your ability to use the site.

Section 16

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be published on our website with an updated effective date. Significant changes will be communicated directly to registered donors and partners.

We encourage you to review this page periodically to stay informed about how we protect your data.

Section 17

Contact Information

For any privacy-related queries, data subject requests, or safeguarding concerns — please reach out:

We aim to respond to all data requests within 30 days in line with the Kenya Data Protection Act 2019.

Our Commitment

At Home of Light & Love Foundation, privacy and safeguarding are not just policies — they are fundamental expressions of our respect for human dignity. We are committed to maintaining the highest standards of protection for every person involved in our work.

Regular Training

Our team receives ongoing training in safeguarding and data protection best practices.

Open Communication

We maintain transparent communication about our privacy practices with all stakeholders.

Community Trust

We build lasting trust through consistent protection of every community member we serve.

Need a Copy?

Download our official documents for your records, community use, or field operations.

Privacy Concerns or Questions?

If you have any questions about our privacy practices, wish to exercise your data rights, or need to report a safeguarding concern — please contact us immediately.