Privacy Policy
Effective Date: 10th October 2025
RefHub (“we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal data when you visit our website refhub.co.ke (the “Site”) and use our services (e.g. browsing, purchasing, contacting us, subscribing).
1. Interpretation & Definitions
Data Subject
A natural person who can be identified, directly or indirectly, by reference to data such as name, email address, phone number, etc.
Personal Data
Any information that relates to an identified or identifiable individual. Examples include name, email address, telephone number, IP address, etc.
Processing
Any operation performed on personal data — collection, recording, storing, use, disclosure, deletion, etc.
Controller / Data Controller
RefHub, as the entity determining how and why personal data is processed.
Processor / Data Processor
Any third party that processes personal data on our behalf (e.g. email service provider, hosting provider).
Website / Site
The online platform at https://refhub.co.ke/ and its associated subpages.
2. Legal Basis for Processing
Under Kenya’s Data Protection Act, 2019 (DPA) and other applicable laws, we rely on one or more of the following legal bases to process personal data:
Consent: You give us permission (e.g. when you fill a contact form or subscribe).
Contractual necessity: Processing is required to fulfill a contract (e.g. ordering, delivery).
Legal obligation: Complying with a law or regulation.
Legitimate interests: We have legitimate business interests (e.g. security, improving our Site), provided these do not override your rights.
3. What Data We Collect
We may collect the following categories of personal data:
a) Information You Provide Directly
Name
Email address
Phone number
Postal address
Payment or billing information
Other optional fields you supply (e.g. company name, message)
b) Automatically Collected Data
IP address
Device information (browser type, operating system)
Usage data (pages visited, time spent)
Cookies, tracking technologies, analytics data
c) Third-Party Data
Data from payment processors (e.g. via WooCommerce)
Data from analytics/advertising providers (if used)
4. How We Use Your Data
We use your data for the following purposes:
To provide, operate, and maintain the Site
To process and fulfill orders, payments, and invoices
To respond to your inquiries, requests, or support issues
To send transactional emails (order confirmations, shipping notices)
To send promotional or marketing communications (if you opt in)
To improve our Site, products, and services
To detect, prevent, and address technical or security issues
To comply with legal or regulatory obligations
5. Cookies & Tracking Technologies
We use cookies and similar technologies to enhance user experience, analyze usage, and deliver targeted content. By using our Site, you consent to the use of cookies unless disabled in your browser.
You may refuse or disable cookies via your browser settings. However, some features of the Site may not function properly if cookies are disabled.
We also comply with Kenya’s Data Protection Act guidelines that using cookies or similar technologies requires explicit, informed, and freely given consent.
6. Disclosure of Your Data
We may share your data with:
Service providers / processors (e.g. hosting, email, payment gateways)
Business partners (for joint offerings, only with consent)
Legal & regulatory authorities (if required by law)
Successors or assignees (if the business is sold or merged)
We require that third parties protect data securely and only use it for our agreed purposes.
7. Data Retention
We keep your personal data only as long as necessary for the purposes for which it was collected (e.g. to fulfill orders, maintain accounts, comply with legal obligations). When no longer needed, data will be securely deleted or anonymized.
8. Security Measures
We adopt appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or destruction. These may include encryption, secure servers, access controls, regular audits, and staff training.
While we strive to protect your data, no transmission over the internet or storage is 100% secure. We cannot guarantee absolute security.
9. Your Rights as a Data Subject
Under the DPA (and relevant principles), you have rights including:
Right to be informed — about how we collect and use data
Right of access — to see what personal data we hold
Right to rectification — to correct inaccurate or incomplete data
Right to erasure — to request deletion under certain conditions
Right to restrict processing — in certain cases
Right to object — to processing based on legitimate interests or direct marketing
Right to data portability — to obtain your data in a machine-readable format
Right to withdraw consent — where processing is based on consent
To exercise these rights, please contact us via the contact information below.
10. Children’s Data
Our Site is not intended for children under 18. If you believe we have collected data from a minor without parental consent, please contact us and we will delete it.
11. International Transfers
If your data is transferred outside Kenya (e.g. to servers in other countries), we ensure that such transfers are done in compliance with applicable law (using standard contractual clauses or adequate safeguards) or with your consent.
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically. The “Effective Date” at the top will reflect the last revision. We encourage you to review this page to stay informed about how we process your data.
13. How to Contact Us
If you have questions, requests, or complaints regarding this Privacy Policy or how we process personal data, you may contact:
RefHub
Email: info@refhub.co.ke
You also have the right to lodge a complaint with Kenya’s Office of the Data Protection Commissioner (ODPC).