Legal

Privacy Policy

How Orygin Core Africa collects, uses, stores, and protects personal information.

DRAFT — FOR LEGAL REVIEW. This policy is a working draft prepared to satisfy the disclosure requirements of the Kenya Data Protection Act (2019). It has not yet been reviewed by counsel and should not be treated as the final published policy.

Last updated: 27 July 2026

1. Who we are

Orygin Core Africa ("we", "us", "our") is a Kenyan counselling and consultancy firm based in Nairobi. For the purposes of the Kenya Data Protection Act (2019) ("DPA"), we act as the data controller of the personal information described in this policy.

2. Personal data we collect

Through this website and the Thrive Covenant Diagnostic we collect:

  • Identity and contact data — your preferred name, email address and, optionally, your phone number.
  • Relationship context — the stage you selected (dating, engaged, married, separated), the mode (solo or couple), and your faith-framing preference.
  • Assessment responses — your answers to the Thrive Covenant Diagnostic, including the safety-screen and wellness items.
  • Payment metadata — the M-Pesa reference code, amount, and timestamp you submit to unlock your report. We do not receive or store your M-Pesa PIN or bank credentials.
  • Technical data — basic logs (IP address, browser, timestamps) needed to operate and secure the service.

3. Sensitive personal data

Under section 44 of the DPA, information about your health, wellbeing, family life, sexual life and religious belief is sensitive personal data. Your Thrive Covenant Diagnostic responses fall into this category. We process this data only with your explicit consent (given at the start of the assessment), only for the purposes described below, and with additional access restrictions inside our team.

4. How we use your data

  • To generate your private assessment report and reconnection plan.
  • To email you a resume link if you switch devices or clear your browser.
  • To send you the transactional emails you request (booking confirmations, unlock notifications).
  • To meet safety and safeguarding obligations — for example, showing support resources if a safety-screen response suggests you may be at risk.
  • To operate, secure and improve the service.

5. Legal basis

We rely on your consent for the Thrive Covenant Diagnostic and any marketing emails, and on legitimate interest and legal obligation for security logging, fraud prevention and record-keeping.

6. Who can see your responses

Your individual responses to the Thrive Covenant Diagnostic are never disclosed to your partner, to any third party, or to anyone outside a small internal clinical team on a need-to-know basis. When both partners in a couple complete their side, the merged couple report describes patterns without exposing either partner's private wording.

7. Storage and retention

Personal data is stored on managed database and file-storage infrastructure operated for us by our hosting and backend providers. Data may be processed in Kenya, the European Union, the United States or the United Kingdom, depending on the provider. Where data leaves Kenya, we rely on the provider's contractual safeguards and standard data-transfer terms.

We retain assessment responses for up to 24 months from the date of completion so you can request your report again, after which they are deleted or irreversibly anonymised. Contact records tied to bookings and payments are retained for up to 7 years to satisfy Kenyan tax and record-keeping requirements.

8. Your rights

Under the DPA you have the right to:

  • Access the personal data we hold about you.
  • Ask us to correct data that is inaccurate or incomplete.
  • Ask us to erase your data ("right to be forgotten"), subject to legal retention obligations.
  • Withdraw consent at any time, including for the Thrive Covenant Diagnostic.
  • Object to, or ask us to restrict, certain uses of your data.
  • Lodge a complaint with the Office of the Data Protection Commissioner (odpc.go.ke).

9. Security

We use industry-standard technical and organisational measures — encryption in transit, access controls, audit logging and least-privilege access to sensitive tables — to protect your information. No system is completely secure; if we become aware of a personal-data breach that is likely to result in risk to you, we will notify you and the Office of the Data Protection Commissioner in line with the DPA.

10. Cookies and analytics

We use only the cookies strictly necessary to run the site and remember your session. We do not sell or share your data with advertising networks.

11. Changes to this policy

We may update this policy from time to time. Material changes will be announced on this page and, where appropriate, by email.

12. Contact — data protection

For any question or request relating to your personal data, contact our data protection representative at hello@orygincoreafrica.co.ke. Orygin Core Africa, Nairobi, Kenya.