Skip to content
42×42 Youth's Corner
Home About Programmes Services Events Field Notes Get Involved
Get Involved

Legal / 2026-09-01.1

Privacy Policy

What personal data Youth's Corner collects, why we collect it, who else sees it, how long we keep it and what you can require us to do about it.

Version
2026-09-01.1
Last updated
1 September 2026
Applies to
This website

On this page

  1. Who is responsible
  2. What we collect, and why
  3. Our legal basis
  4. Who else handles it
  5. Data leaving Kenya
  6. How long we keep it
  7. Your rights
  8. How to exercise them
  9. How we protect it
  10. Young people
  11. Changes to this policy
  12. How to complain

This policy is written in plain English on purpose. Where a term has a specific legal meaning we have said so rather than hiding it.

1. Who is responsible

Youth's Corner is the data controller for the personal data described in this policy. That means we decide what is collected and what happens to it, and we are the ones accountable for it.

Organisation
Youth's Corner
Location
Langata, Nairobi, Kenya
Privacy contact
legal@youthscorner.org
General contact
info@youthscorner.org

2. What we collect, and why

We collect as little as we can get away with. Every field on every form exists because we need it to do the thing you asked for.

Personal data collected, its source and its purpose
WhatWhere fromWhy
Name and contact details (phone or email) Enquiry forms on the Services and Get Involved pages To reply to you, and to match a service enquiry to the right member
Name, contact details and any comments you add Event registration forms To register you, plan numbers and equipment, and contact you about that event
Organisation name (optional) Partner and donor forms To understand who we are talking to
Email address Newsletter sign-up To tell you when an event is happening
Cookie choice, the time you made it, your truncated IP address and the policy version The cookie banner To prove we asked and you answered, as the law requires us to be able to do
Pseudonymous usage data Analytics cookies — only if you turn them on To see which pages are useful so we can improve them
Name, email, role and password hash Staff and volunteer accounts in our content management system To run the site. Passwords are hashed and are never stored or readable in plain text

We do not collect special category data — health, ethnicity, religion, political opinion, biometrics — through this website. Please do not put it in a free-text box.

3. Our legal basis

Under the GDPR (Article 6) and the Data Protection Act 2019 (section 30), we need a lawful reason to process your data. Ours are:

  • Consent — for analytics and marketing cookies, for the newsletter, and for every enquiry and registration form, each of which carries its own tick box. You can withdraw consent at any time and that is as easy as giving it.
  • Legitimate interests — for keeping the site secure and working: session cookies, CSRF protection, rate limiting and our error logs. We have weighed this against your interests and consider it proportionate, because none of it identifies you and the site cannot function safely without it.
  • Legal obligation — for keeping records of consent, which both regimes require us to be able to produce on request.

4. Who else handles it

We do not sell your data, and we do not share it for anyone else's marketing. These are the only third parties that process personal data on our behalf, and each does so under a contract that limits them to our instructions.

Brevo (Sendinblue)

Role
Transactional email delivery
Data involved
Name and email address of recipients
Where
European Union
Safeguard
Data processing agreement; EU adequacy

Google Analytics

Role
Website analytics
Data involved
Pseudonymous usage data, truncated IP address
Where
United States
Safeguard
Consent; EU Standard Contractual Clauses

Brevo is named explicitly because it sends every email this site generates — your enquiry confirmation, an event confirmation, a password reset. Your name and email address pass through Brevo for that purpose and no other.

We may also disclose data where the law requires it, for example in response to a valid order from a court or a regulator.

5. Data leaving Kenya

Section 48 of the Data Protection Act 2019 restricts transferring personal data out of Kenya. Two of our processors are outside the country:

  • Brevo processes email in the European Union, which maintains data protection standards at least equivalent to Kenya's.
  • Google Analytics, if and only if you consent to analytics cookies, processes data in the United States under Standard Contractual Clauses. IP addresses are truncated before storage.

In both cases the transfer is covered by appropriate safeguards and, for analytics, by your consent — which you can withdraw at any time on the Cookie Policy page.

6. How long we keep it

We delete data when it has served its purpose. These are the periods we actually operate to, not aspirations:

Retention periods by record type
RecordKept for
Enquiries and leads 24 months
Event registrations 12 months
Cookie consent records 24 months
Administrator audit log 24 months
Support tickets 24 months
Deactivated CMS accounts 24 months

If you ask us to delete something sooner, we will — see below. The only exception is where we are legally required to keep a record, and we will tell you plainly if that applies.

7. Your rights

These rights are yours under both the GDPR (Articles 15–22) and the Data Protection Act 2019 (Part IV). They are free to use.

  • 01

    Access

    Ask what personal data we hold about you and get a copy of it.

  • 02

    Rectification

    Have anything inaccurate corrected, or anything incomplete completed.

  • 03

    Erasure

    Have your data deleted, where we have no overriding reason to keep it.

  • 04

    Portability

    Receive the data you gave us in a structured, machine-readable file you can take elsewhere.

  • 05

    Objection

    Object to processing we do on the basis of legitimate interests, including any profiling.

  • 06

    Restriction

    Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.

  • 07

    Withdraw consent

    Withdraw consent at any time, without affecting anything done before you withdrew it.

8. How to exercise them

Email legal@youthscorner.org and say what you want. You do not need to cite a law or use particular wording — "please delete my details" is enough.

  1. We acknowledge within 5 working days.
  2. We may verify who you are, but only as far as necessary — we will not demand ID we do not need.
  3. We respond in full within 30 days. If a request is genuinely complex we may extend that, and we will tell you why before the 30 days is up.

Our administrators can export everything we hold on you as a file, and can delete it, directly from our content management system — so these are routine operations here, not special projects.

9. How we protect it

  • The whole site is served over HTTPS and refuses unencrypted connections.
  • Passwords are hashed with Argon2id. Nobody at Youth's Corner can read your password, and neither can we.
  • Access inside our system is limited by role — staff see only what their job needs.
  • Administrator actions are written to an audit log.
  • Uploaded files are stored outside the web root and cannot be executed.
  • Our logs deliberately redact passwords, tokens and keys before anything is written to disk.

No system is perfect. If we ever suffer a breach that is likely to put your rights at risk, we will notify the Office of the Data Protection Commissioner within 72 hours and tell you directly without undue delay.

10. Young people

We are a youth-led organisation and young people are welcome at our events. Where someone under 18 registers, we collect only their name, a contact detail and anything they choose to tell us. For under-13s we ask that a parent or guardian registers on their behalf, and we will act on a parent or guardian's request to see or delete that data.

11. Changes to this policy

When we change this policy materially we increase its version number. The current version is 2026-09-01.1. Because your cookie choice is recorded against the version it was made under, a new version means the cookie banner asks you again rather than assuming your old answer still applies to new terms.

12. How to complain

Come to us first if you can — legal@youthscorner.org — and we will try to put it right.

You do not have to. You have the right to complain directly to the Office of the Data Protection Commissioner (ODPC) in Kenya at any time. If you are in the UK or the EU, you may instead complain to your own national supervisory authority.

34 Youth's Corner

Building a better world, one idea at a time. A youth-led NGO in Langata, Nairobi, Kenya.

Explore

About Us Programmes Services Events Field Notes

Take Part

Volunteer Partner With Us Donate Book A Member

Contact

  • Langata, Nairobi, Kenya
  • +254 708 018108
  • info@youthscorner.org
© 2026 Youth's Corner. All rights reserved.
Privacy Policy Cookie Policy Terms of Use Design by Yutie

Your choice about cookies

Only strictly necessary cookies run by default. Analytics and marketing stay off until you turn them on, and you can change your mind at any time — see our Cookie Policy.