Legal

Privacy
Policy

At Artworld Branding & Design, your privacy matters. This policy explains what personal data we collect, why we collect it, how we protect it, and the rights you have over it.

Last updated: 1 September 2026 · Governed by the Kenya Data Protection Act, 2019

01 /

Information We Collect

We collect information you provide when booking, using our portal, or contacting us:

  • Identity — full name, business/brand name.
  • Contact — email, phone (including WhatsApp), and physical address for delivery or site surveys.
  • Project data — creative briefs, reference materials, brand guidelines, and design files you share with us.
  • Financial — invoice records and payment references. We do not store card numbers or banking credentials.
  • Usage — standard server logs (IP, browser, pages visited, timestamps) when you use our website or portal.

We do not purchase marketing lists or collect data from third parties.

02 /

How We Use Your Information

We use your data to:

  • Deliver your project — coordinate design, production, delivery, and task management.
  • Communicate — send confirmations, project updates, delivery notifications, and follow-ups via email, WhatsApp, and SMS.
  • Invoice and payment — generate quotes, invoices, and track payments.
  • Improve our services — understand how our website and portal are used.
  • Legal obligations — maintain records required under Kenyan law and KRA requirements.

We never sell, rent, or trade your personal information to third parties for their own marketing purposes.

03 /

Messaging & Communications

When you book or engage us, you will receive automated communications via:

  • Email — confirmations, project updates, invoices, and delivery notifications.
  • WhatsApp — booking confirmations and delivery updates via the CallMeBot service.
  • SMS — short confirmations and reminders via our local SMS gateway on a Kenyan SIM network.

By providing your contact details, you consent to project-related communications. You may opt out of non-essential messages at any time by contacting us.

04 /

Data Storage & Security

Your data is stored on Cloudflare's infrastructure (SOC 2 Type II, ISO 27001 certified):

  • Database — project records and client data in Cloudflare D1.
  • Files — design files in Cloudflare R2 with server-side encryption at rest.
  • Sessions — HMAC-SHA256 signed cookies with 8-hour expiry.
  • Passwords — we store none. Staff authentication is Google OAuth 2.0 only.

All data in transit is protected by TLS 1.3. In the event of a breach affecting your rights, we will notify you within 72 hours.

05 /

Data Retention

  • Active project data — retained for the project duration plus 3 years.
  • Financial records — 7 years as required by Kenyan tax law.
  • Design files — 1 year after project completion, then deleted unless you have an archiving agreement.
  • Website logs — 90 days.

You may request early deletion of your data, subject to legal retention obligations.

06 /

Your Rights

Under Kenya's Data Protection Act (2019) you have the right to:

  • Access a copy of your personal data.
  • Rectify inaccurate or incomplete data.
  • Erasure of your data, subject to legal obligations.
  • Object to processing for marketing purposes at any time.
  • Data portability — receive your data in a machine-readable format.
  • Withdraw consent at any time without affecting prior lawful processing.

Contact us to exercise any right. We will respond within 30 days.

07 /

Third-Party Services

We use a small number of carefully selected services:

  • Google OAuth — staff authentication only.
  • Cloudflare — infrastructure, DNS, and DDoS protection.
  • CallMeBot — WhatsApp delivery. Your phone and message content are transmitted to their API.
  • TextBee — SMS via a local Android gateway. Your number and message are processed for delivery.
  • SMTP provider — email delivery.

We do not use advertising networks, cross-site analytics, or social media tracking pixels.

08 /

Cookies

Our public website uses no third-party tracking cookies. Our staff portal uses one strictly necessary cookie:

  • aw_session — a secure, httpOnly, SameSite=Strict cookie that keeps you logged in. Expires after 8 hours. Cannot be disabled as it is required for the portal to function.
09 /

Changes to This Policy

We may update this policy from time to time. The "Last updated" date above will reflect any changes. Active clients will be notified by email of significant updates. Continued use of our services constitutes acceptance.

Questions about this policy?

Our data contact is David Tuarari, Founding Director.