Article 1: Data Controller
The data controller responsible for the processing of personal data collected through the Website and associated digital platforms is the Brand, People & Culture Desk of:
for Africa's Sovereign Development Trust®
Head Office: UN Crescent, Gigiri, P.O. Box 43112-00100, Nairobi, Kenya
Trust Domicile: 1st Floor, Eden Plaza, Eden Island, Victoria, The Seychelles
U.K. Mailing Address: 116 Pall Mall, St. James's, London, SW1Y 5ED, United Kingdom
Primary Contact: hello@thendegegroup.com | +254 799 504 111
Legal Enquiries: legal@thendegegroup.com
Article 2: Categories of Personal Data Collected
We may collect and process the following categories of personal data when you interact with The Trust's digital properties:
2.1 Identity and Contact InformationThis encompasses data such as your full name, professional title, organisational affiliation, email address, telephone number, postal address, and any other identifying information you provide when completing contact forms, subscribing to communications, submitting enquiries via the Website, or engaging through direct messages on social media platforms.
2.2 Technical and Usage DataInformation concerning your interaction with and navigation of the Website, including but not limited to: Internet Protocol (IP) address, browser type and version, device identifiers, operating system, time zone settings, referring and exit pages, clickstream data, pages viewed, time spent on pages, search queries, and other diagnostic data. This category also includes aggregated, non-personally identifiable data from your interactions with The Trust's social media channels as provided by social media platforms in accordance with their analytics services. This data is collected through automated technologies including cookies, web beacons, server logs, and third-party analytics tools such as Google Analytics.
2.3 Communications and Correspondence DataDetails from emails, letters, telephone conversations, chat interactions, and any other communications you send to us or exchange with us, including information shared via direct messages on social media platforms. This includes the content of your messages, metadata associated with communications, and any attachments you provide.
2.4 Voluntarily Submitted InformationAny additional information you elect to provide, including but not limited to: feedback on The Trust's initiatives, survey responses, details related to project enquiries or collaboration interests, research participation data, event registration information, curriculum vitae or professional credentials submitted for partnership opportunities, and any other data you choose to share whether via the Website, social media platforms, or direct communication channels.
2.5 Special Categories of DataWe do not routinely collect special categories of personal data (also referred to as sensitive personal data), which include data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a data subject's sex life or sexual orientation. Should circumstances arise requiring the processing of such data, we shall seek your explicit, informed, and freely given consent and implement enhanced protective safeguards as required by applicable data protection legislation.
2.6 Children's DataWe do not knowingly collect, process, or solicit personal data from individuals under the age of 16 without verifiable parental or guardian consent. The Trust's services are not directed towards children. If you believe that we may have inadvertently collected personal data from a child under the age of 16 without appropriate consent, please contact us immediately at legal@thendegegroup.com so that we may take prompt action to investigate and, where necessary, delete such data in accordance with The Trust's legal obligations.
Article 3: Methods of Data Collection
3.1 Direct Interactions and Voluntary ProvisionYou provide data directly when you: complete forms on The Trust's Website (including contact forms, newsletter subscriptions, enquiry forms, and registration forms); communicate with us via email, telephone, postal mail, or direct messaging on social media platforms; participate in surveys, feedback mechanisms, or research initiatives; register for events, webinars, or institutional programmes; or submit applications for partnerships, collaborations, or professional opportunities.
3.2 Automated Collection TechnologiesAs you navigate and interact with The Trust's Website, we automatically collect Technical and Usage Data through: cookies (small text files stored on your device); web beacons and pixel tags (transparent graphic images placed on web pages or in emails); server logs (records of server activity); analytics platforms such as Google Analytics, which provide aggregated usage statistics; and session replay tools that may record anonymised browsing sessions for the purpose of improving user experience. For detailed information on The Trust's use of cookies and similar technologies, please refer to The Trust's Cookie Policy below.
3.3 Social Media Platform DataWe collect aggregated usage and engagement data from social media platforms regarding interactions with The Trust's official social media channels. This data is provided by the platforms in accordance with their terms of service and is subject to the privacy settings and policies of those platforms. The extent of data we receive is determined by your privacy settings on each respective platform and the permissions you have granted.
3.4 Third-Party Sources and Public InformationWe may receive personal data about you from various third-party sources and publicly available channels, including but not limited to: analytics providers; advertising networks; publicly accessible databases, registries, and directories; social media platforms where you have made information publicly available or granted permission for data sharing; professional networking platforms; business partners, affiliates, or sub-contractors who provide services on The Trust's behalf; and publicly available sources such as institutional websites, published research, media articles, and government registries.
Article 4: Purposes and Legal Basis for Processing
We process your personal data for specific, explicit, and legitimate purposes, relying on appropriate legal bases under the Data Protection Act, 2019 of Kenya:
4.1 Service Provision and CommunicationPurpose: To fulfil your requests, respond to enquiries, provide information about The Trust's initiatives and projects, deliver services you have requested, manage The Trust's relationship with you, and facilitate communications initiated via any channel including social media.
Legal Basis: Performance of a contract with you, or taking steps at your request prior to entering into a contract (Section 32(a) of the Data Protection Act, 2019); or The Trust's legitimate interests in communicating effectively with stakeholders (Section 32(f)).
Purpose: To analyse usage patterns, identify and resolve technical issues, conduct user experience research, enhance functionality, improve content relevance and quality, and refine The Trust's digital engagement strategies across all platforms.
Legal Basis: The Trust's legitimate interests in understanding how The Trust's digital properties are utilised in order to continuously improve The Trust's services (Section 32(f)).
Purpose: To send newsletters, institutional updates, promotional materials, event invitations, research publications, policy briefs, and other information about The Trust's activities, services, programmes, and initiatives, where you have consented to receive such communications or where we have a legitimate interest in doing so.
Legal Basis: Your explicit consent (Section 32(b)); or The Trust's legitimate interests in promoting The Trust's activities and maintaining stakeholder relationships (Section 32(f)). You retain the absolute right to withdraw consent or object to processing at any time.
Purpose: To meet The Trust's regulatory, statutory, and legal obligations under Kenyan, Seychellois, and United Kingdom law, including but not limited to tax reporting, anti-money laundering requirements, counter-terrorism financing obligations, data protection compliance, financial reporting, and audit requirements.
Legal Basis: Compliance with legal obligations to which we are subject (Section 32(c)).
Purpose: To prevent, detect, and investigate fraud, unauthorised access, security breaches, and other unlawful activities; enforce The Trust's Terms of Use and other legal agreements; protect and defend The Trust's intellectual property rights; and maintain the security and integrity of The Trust's systems.
Legal Basis: The Trust's legitimate interests in protecting our business, institutional reputation, rights, assets, and the security of The Trust's users and stakeholders (Section 32(f)); compliance with legal obligations (Section 32(c)).
Purpose: To conduct research into developmental frameworks, policy effectiveness, and institutional impact; develop new methodologies and services; and advance the objectives of Africa's Sovereign Development Trust®.
Legal Basis: The Trust's legitimate interests in advancing The Trust's institutional mission and contributing to academic and policy discourse (Section 32(f)).
Purpose: To administer and improve The Trust's internal operations, conduct data analysis and testing, maintain records, perform financial and accounting functions, engage in strategic planning, assess institutional performance, and ensure business continuity.
Legal Basis: The Trust's legitimate interests in operating efficiently and effectively as an organisation (Section 32(f)).
Article 5: Data Sharing, Disclosure, and International Transfers
5.1 Categories of RecipientsWe may share your personal data with the following categories of recipients, subject to appropriate safeguards and contractual obligations: trusted third-party service providers (including website hosting, cloud storage, data analytics, email delivery, CRM systems, social media management tools, IT support, and professional advisors); legal and regulatory authorities when required by law, court order, or governmental request; and business transfer recipients in the event of a merger, acquisition, or corporate restructuring, subject to equivalent or stronger data protection standards.
All service providers are contractually obligated to process your data only as instructed by us, maintain strict confidentiality, implement appropriate security measures, and comply with applicable data protection laws.
5.2 International Data TransfersGiven that Africa's Sovereign Development Trust® maintains operational presence across multiple jurisdictions and utilises global service providers, some data processing activities may involve transfers to countries outside Kenya. When transferring your personal data internationally, we implement appropriate safeguards which may include: adequacy decisions recognised by the Office of the Data Protection Commissioner (ODPC); Standard Contractual Clauses approved by the ODPC or recognised international data protection authorities; Binding Corporate Rules approved by competent data protection authorities; or, in certain circumstances, your explicit informed consent for the specific transfer. Transfers to entities in the United Kingdom are conducted in compliance with the UK GDPR; transfers to The Seychelles comply with the Seychelles Data Protection Act, 2021.
5.3 No Sale of Personal DataWe do not sell, rent, lease, or trade your personal data to third parties for their own marketing or commercial purposes. Any sharing of data is conducted solely for the purposes outlined in this Privacy Policy and under strict contractual, legal, and institutional safeguards.
Article 6: Data Security and Protection Measures
We have implemented a comprehensive framework of technical and organisational measures designed to protect your personal data from accidental loss, unauthorised or unlawful access, use, alteration, disclosure, or destruction. The Trust's security architecture adheres to the principles of security by design and by default as required by the Data Protection Act, 2019 of Kenya.
Technical measures include, without limitation: encryption of data in transit using industry-standard TLS/SSL protocols; encryption of sensitive data at rest; pseudonymisation and anonymisation techniques where appropriate; secure multi-factor authentication mechanisms; regular security patching and system updates; intrusion detection and prevention systems; firewalls and network segmentation; secure backup and disaster recovery systems; and regular vulnerability assessments and penetration testing conducted by qualified third-party specialists.
Organisational measures include: strict access controls based on the principle of least privilege; role-based access management enforced through formal authorisation procedures; confidentiality obligations and mandatory training for all personnel with access to personal data; data protection impact assessments for high-risk processing activities; documented incident response and breach notification procedures; regular security awareness training programmes; and periodic third-party security audits and compliance assessments.
Article 7: Data Retention and Deletion
We retain your personal data only for so long as is reasonably necessary to fulfil the purposes for which it was collected, satisfy legal, accounting, or reporting requirements, establish or defend legal claims, or pursue legitimate business interests. The Trust's retention practices are guided by the principles of data minimisation and storage limitation as enshrined in applicable data protection legislation.
Contact and enquiry data is retained for the duration necessary to resolve your enquiry or fulfil your request, plus a reasonable administrative period of 12 to 24 months, or until you opt out of communications. Usage and analytics data is typically retained for a maximum of 24 months. Marketing communications data is retained until you unsubscribe or withdraw consent, plus a reasonable period to process your opt-out request and maintain suppression records. Legal and compliance data is retained for periods mandated by applicable law, including typically 6 to 7 years for tax and audit purposes. Security and fraud prevention data is retained for as long as necessary to protect against identified threats and maintain system integrity.
Once personal data is no longer required for any lawful purpose and all retention obligations have expired, it is securely and permanently deleted or anonymised in a manner that prevents its reconstruction or re-identification, utilising secure erasure protocols, data shredding methodologies, or cryptographic deletion of encryption keys as appropriate to the medium.
Article 8: Your Data Protection Rights
Under the Data Protection Act, 2019 of Kenya, you possess comprehensive rights concerning your personal data. We are committed to facilitating the exercise of these rights promptly, transparently, and without undue impediment:
8.1 Right to be InformedYou have the right to receive clear, transparent, and easily understandable information about how we collect, use, share, and protect your personal data, and about the rights available to you. This Privacy Policy serves to fulfil this obligation.
8.2 Right of Access (Subject Access Right)You have the right to obtain confirmation as to whether or not your personal data is being processed by us, and where that is the case, to access the personal data together with information about the purposes of processing, the categories of personal data concerned, the recipients or categories of recipients to whom the data has been or will be disclosed, the envisaged retention period, and the existence of any automated decision-making. The first copy of your personal data will be provided free of charge; additional copies may be subject to a reasonable administrative fee.
8.3 Right to RectificationYou have the right to request the correction of inaccurate personal data concerning you without undue delay, and to have incomplete personal data completed, including by means of providing a supplementary statement.
8.4 Right to Erasure (Right to be Forgotten)You have the right to request the deletion or removal of your personal data where: the data is no longer necessary for the purposes for which it was collected; you withdraw consent on which processing is based and there is no other legal ground for processing; you object to processing and there are no overriding legitimate grounds; the data has been unlawfully processed; or the data must be erased for compliance with a legal obligation. This right is not absolute and is subject to applicable legal exceptions, including where processing is necessary for establishment, exercise, or defence of legal claims.
8.5 Right to Restriction of ProcessingYou have the right to request that we restrict the manner in which we use your personal data in specified circumstances, including where you contest the accuracy of the personal data, where the processing is unlawful but you oppose erasure, or where you have objected to processing pending verification of The Trust's legitimate grounds.
8.6 Right to Data PortabilityYou have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance, where processing is based on consent or on the performance of a contract and is carried out by automated means. You also have the right to have your personal data transmitted directly to another controller where technically feasible.
8.7 Right to ObjectYou have the right to object, on grounds relating to your particular situation, to processing of your personal data based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defence of legal claims. You have the absolute right to object to processing of your personal data for direct marketing purposes at any time, without condition or qualification.
8.8 Right to Withdraw ConsentWhere we rely on your consent as the legal basis for processing your personal data, you have the right to withdraw that consent at any time by contacting us at legal@thendegegroup.com or by using the unsubscribe mechanism provided in marketing communications. Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
8.9 Right to Lodge a ComplaintYou have the right to lodge a complaint with a supervisory authority if you believe that The Trust's processing of your personal data contravenes applicable data protection law. The relevant supervisory authorities are:
The Seychelles: Data Protection Commissioner
United Kingdom: Information Commissioner's Office (ICO) — www.ico.org.uk
To exercise any of these rights, please contact The Trust's Legal Desk at legal@thendegegroup.com. We will respond without undue delay and in any event within one calendar month of receipt. This period may be extended by a further two months where necessary, taking into account the complexity and volume of requests, in which case we will notify you of such extension and the reasons therefor. We will not charge a fee for processing your request unless it is manifestly unfounded, excessive, or repetitive.
Article 9: Automated Decision-Making and Profiling
We do not currently engage in automated decision-making or profiling that produces legal effects concerning you or that similarly significantly affects you within the meaning of applicable data protection legislation. Any analytics or profiling we conduct is for aggregate analysis purposes only and does not result in automated decisions affecting your legal rights. Should our practices change, we shall update this Privacy Policy accordingly and, where required by law, obtain your explicit consent or provide you with the right to object prior to implementing any such change.
Article 10: Third-Party Websites and Services
The Trust's Website and social media channels may contain links to third-party websites, applications, plug-ins, or services not owned, controlled, or operated by The Ndege Group®. These links are provided solely for your convenience and information. We do not control and are not responsible for the privacy statements, content, or data processing practices of these third-party websites and services. When you click on such links or enable such connections, those third parties may collect or share data about you according to their own privacy policies, over which we have no control or supervisory authority.
We strongly encourage you to read the privacy policy and terms of use of every third-party website or service you visit or use. Your interactions on social media platforms are governed by the terms of service, privacy policies, and data practices of those specific platforms.
Article 11: Updates and Amendments to This Privacy Policy
We reserve the right to update, modify, or replace this Privacy Policy periodically to reflect changes in The Trust's data processing practices, organisational structure, legal obligations, regulatory requirements, technological developments, or best practices in data protection. Any revisions shall be effective immediately upon posting the updated Privacy Policy on the Website. The "Last Updated" date at the commencement of this Policy shall be revised to reflect the date of the most recent changes.
For material changes that significantly affect your rights or The Trust's processing practices, we shall provide more prominent notice, which may include email notification to the address you have provided, a notice on The Trust's Website homepage, or other appropriate communication methods. Your continued use of the Website or engagement with The Trust's digital platforms following the posting of any changes constitutes your acknowledgement and acceptance of the revised Privacy Policy. We encourage you to review this Privacy Policy regularly to remain informed of how we protect your information and your rights.
Article 12: Children's Privacy
The Trust's services are not intended for, marketed to, or designed to attract individuals under the age of 18 years. We do not knowingly collect, process, or solicit personal data from children under 18 years of age without verifiable parental or legal guardian consent. If you are a parent or legal guardian and become aware that your child has provided us with personal data without your consent, please contact us immediately at legal@thendegegroup.com. We shall take prompt action to investigate and, if confirmed, delete such data from The Trust's systems unless we have a legal obligation to retain it. If we learn that we have collected personal data from a child under 18 without appropriate parental consent, we shall take immediate steps to delete that information and terminate the child's account or access, if applicable.
Article 13: Contact Information and Data Protection Enquiries
For any questions, comments, concerns, or requests regarding this Privacy Policy, The Trust's data processing practices, or to exercise your data protection rights, please contact:
The Ndege Group Nominees Limited for Africa's Sovereign Development Trust®
Head Office: UN Crescent, Gigiri, P.O. Box 43112-00100, Nairobi, Kenya
Trust Domicile: 1st Floor, Eden Plaza, Eden Island, Victoria, The Seychelles
U.K. Mailing Address: 116 Pall Mall, St. James's, London, SW1Y 5ED, United Kingdom
Email: legal@thendegegroup.com
Telephone: +254 799 504 111
General Enquiries: hello@thendegegroup.com
We are committed to addressing your enquiries and requests promptly and thoroughly. We shall acknowledge receipt of your communication and provide a substantive response within the timeframes required by applicable data protection law.
© 2026 David Okiki Amayo Jr. and The Ndege Group®. All rights reserved.
Africa's Sovereign Development Trust® (ASDT) anchors the future.