Privacy Policy
📜 Oak Nation Privacy Policy
Effective Date: 10/01/2018
Last Updated: 01/10/2025
Oak Nation (“we,” “our,” “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our CRM web application, websites, and related services.
1. Information We Collect
We may collect the following types of personal data:
-
Identity Information: name, title, organization, role.
-
Contact Information: email address, phone number, billing/shipping address.
-
Account Information: username, login credentials, CRM activity logs.
-
Financial Information: invoices, payment history, bank/payment details (only where necessary).
-
Staff & Volunteer Data: HR records, contractual documents, compliance data.
-
Technical Data: IP address, browser type, device identifiers, CRM usage data.
2. How We Use Your Data
We process your personal data lawfully, fairly, and transparently for the following purposes:
-
To deliver and manage CRM services.
-
To maintain accurate customer, staff, and partner records.
-
To communicate important updates, responses, and support.
-
To comply with legal, tax, and audit requirements.
-
To improve system security, functionality, and user experience.
-
To send newsletters, campaigns, and outreach materials (only if you have opted in).
3. Legal Basis for Processing
We process personal data under the following legal bases:
-
Consent – where you have explicitly agreed (e.g., marketing emails).
-
Contractual necessity – to fulfill services or agreements.
-
Legal obligation – to comply with laws and regulations.
-
Legitimate interest – to operate and improve our services in ways that do not override your rights.
4. Data Sharing and Disclosure
We do not sell your personal data. We may share your data only with:
-
Trusted third-party service providers (hosting, email, payment, security).
-
Legal or regulatory authorities if required by law.
-
Internal teams (staff, volunteers) for legitimate organizational needs.
All third parties are bound by confidentiality and data protection agreements.
5. Data Retention
We retain your personal data only as long as necessary for the purposes outlined above, and in line with legal or regulatory obligations. Inactive accounts and unnecessary data will be securely deleted.
6. Your Rights
Under GDPR, you have the right to:
-
Access your data.
-
Request corrections or updates.
-
Request deletion (“right to be forgotten”).
-
Restrict or object to processing.
-
Request data portability.
-
Withdraw consent at any time.
Requests may be submitted via [email protected]. We respond within a week.
7. Security
We use appropriate technical and organizational measures to safeguard your data against unauthorized access, alteration, loss, or disclosure.
8. Cookies & Tracking
Our CRM and website may use cookies or similar technologies for functionality, analytics, and security. You may disable cookies in your browser, but this may affect functionality.
9. International Transfers
If we transfer your data outside the EEA or Kenya, we ensure appropriate safeguards are in place (e.g., data protection agreements, secure servers).
10. Contact Us
For questions, requests, or complaints about this Privacy Policy or your data rights, contact our Data Protection Officer (DPO):
Email: [email protected]
Imprint: Oak Nation, Uhuru Business Complex, Kisumu, Nyanza, Kenya