Siasa Digital
Privacy Policy
- Last updated:
- 12 March 2026
- Effective date:
- 12 March 2026
This Privacy Policy explains how [Siasa Digital] (“we”, “us”, “our”) collects, uses, stores, shares, and protects information when you use:
- the Siasa Digital web platform (including candidate/campaign dashboards);
- the Siasa Digital Agent mobile application; and
- related APIs, SMS/email notifications, and support services
(collectively, the “System” or “Services”).
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Services.
1. Who we are
This Privacy Policy is issued by [Siasa Digital] (“we”, “us”, “our”), the operator of Siasa Digital.
For privacy requests and questions, contact us at:
- Email: [Insert Privacy Contact Email]
- Address: [Insert Physical / Registered Address]
2. Scope of this Policy
This Policy applies to:
- Campaign owners / candidates and authorised dashboard users;
- Field agents using the Siasa Digital Agent mobile app;
- Any person whose information is processed through the Services in connection with campaign operations, voter engagement, field reporting, or election monitoring activities.
This Policy does not cover third-party websites, apps, or services that we do not control, even if linked from the Services.
3. Information we collect
Depending on your role and how you use the Services, we may collect the following categories of information.
3.1 Account and identity information
- Name
- Phone number
- Email address
- Role / access level (e.g. candidate/admin user, field agent, tier such as Polling Station Agent)
- Login credentials (passwords are stored in hashed form; we do not store plain-text passwords)
- Organisation / campaign association
3.2 Campaign and operational information
- Campaign details (candidate name, contested seat, geography, manifesto content, plans, and related campaign records)
- Agent assignments (county, constituency, ward, polling station)
- Daily tasks / plans, completion status, notes, and evidence links
- Agent notifications sent by a candidate/campaign to agents
- Broadcast / messaging configuration and campaign communication records, where enabled
- Wallet / finance-related transaction metadata, where the finance modules are used
3.3 Field reporting and election-monitoring information
- Tally submissions and related form data (including photograph/scanned form images where submitted)
- Incident reports, including:
- incident type;
- custom “other” incident type text where selected;
- severity level;
- description;
- optional photo evidence;
- status and any action taken by campaign operators
- Location-related information associated with reporting (where provided by the device or form context)
3.4 Device, technical, and session information
- Device type / operating system
- App or browser information
- IP address and approximate connection metadata
- Authentication tokens and session state
- Logs needed for security, troubleshooting, and abuse prevention
3.5 Authentication and security data
- One-time passcodes (OTP) delivered by SMS and/or email for login verification
- Biometric unlock preference on the agent mobile device (e.g. fingerprint / Face ID enabled or disabled)
Important note on biometrics: Siasa Digital does not collect or store your fingerprint, face template, or other biometric identifiers on our servers. Where biometric unlock is enabled on the mobile app, the device’s operating system performs local biometric authentication to unlock an already authenticated session stored securely on the device. Biometrics are used as a device unlock gate, not as a replacement for server login.
3.6 Communications
- Support requests, feedback, or correspondence you send us
- System notifications and operational messages
4. How we collect information
We collect information:
- directly from you when you register, log in, create records, submit reports, or communicate with us;
- from authorised campaign users who create or manage agent accounts and send tasks/notifications;
- automatically through the app, website, and server logs when you use the Services;
- from service providers that help us deliver SMS, email, hosting, storage, or payments (where enabled).
5. Why we use your information (purposes)
We process information for the following purposes:
- To provide the Services — Create and manage accounts; authenticate users; enable campaign operations; support agent field workflows.
- To support election-monitoring and field operations — Collect and manage tallies, incident reports, agent tasks, coverage, and campaign updates.
- To communicate with you — Send OTP codes, operational alerts, agent notifications, and service-related messages.
- To secure the System — Detect and prevent fraud, abuse, unauthorised access, and security incidents; maintain audit trails.
- To improve and maintain the platform — Diagnose errors, monitor performance, and develop product improvements.
- To meet legal and compliance obligations — Comply with applicable laws, respond to lawful requests, and enforce our terms and policies.
- To process payments / wallet activity (if you use finance features) — Process top-ups, tips, or ledger entries related to campaign finance tooling.
6. Legal bases for processing
Where required by applicable law (including Kenya’s Data Protection Act, 2019, where applicable), we rely on one or more of the following bases:
- performance of a contract / provision of the requested Services;
- your consent (for example, where expressly required);
- our legitimate interests in operating, securing, and improving the System, balanced against your rights;
- compliance with a legal obligation.
Where processing is based on consent, you may withdraw consent at any time, without affecting processing already carried out lawfully before withdrawal.
8. International transfers
Your information may be processed on servers or by providers located outside your country of residence. Where such transfers occur, we take reasonable steps to ensure appropriate safeguards are in place, consistent with applicable data-protection law.
9. Data retention
We retain information only for as long as reasonably necessary for the purposes described in this Policy, including:
- while your account/campaign remains active;
- for the duration of an election cycle or operational engagement, plus a reasonable archival period;
- as needed for security, dispute resolution, audit, and legal compliance;
- in accordance with any contractual retention requirements agreed with the campaign/organisation.
When information is no longer needed, we will delete it or irreversibly anonymise it, subject to technical and legal limitations (for example, backup systems).
10. Security measures
We use administrative, technical, and organisational measures designed to protect information, which may include:
- encrypted transport (HTTPS/TLS) where supported;
- hashed password storage;
- token-based authentication;
- role-based access controls;
- secure on-device storage for mobile session data;
- optional biometric unlock on the mobile device for session access;
- OTP verification for agent login;
- server and application logging for abuse detection and troubleshooting.
No method of transmission or storage is 100% secure. You are responsible for safeguarding your devices, passwords, OTP channels, and access credentials.
11. Your rights
Subject to applicable law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of your data;
- object to or request restriction of certain processing;
- withdraw consent where processing is based on consent;
- request data portability where applicable;
- lodge a complaint with the relevant data-protection authority.
To exercise these rights, contact us using the details in Section 1. We may need to verify your identity before fulfilling a request. To request deletion of your account and associated data, use our account deletion request page.
Note: Some operational records (for example, submitted tallies, incident reports, or audit logs) may need to be retained for accountability, campaign integrity, or legal reasons even if a deletion request is received.
12. Children’s privacy
The Services are intended for authorised adult users involved in campaign and election-monitoring operations. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can take appropriate action.
Our published standards against child sexual abuse and exploitation (CSAE), including how to report concerns, are available on our Child safety standards page.
14. Mobile permissions
Depending on features used, the Siasa Digital Agent app may request access to:
- Camera / photos — to capture form images and incident evidence;
- Location — to associate reports with field context, where enabled;
- Biometrics / device authentication — to unlock a saved session locally;
- Network access — to communicate with Siasa Digital servers;
- Notifications (if later enabled) — for operational alerts.
You can manage permissions in your device settings. Some features may not work if required permissions are denied.
15. Third-party messaging and communications
Where SMS, email, WhatsApp, voice, or similar channels are used, message delivery depends on third-party providers and network availability. Those providers process routing data necessary to deliver messages. Content sent through those channels should be limited to what is operationally necessary.
16. Your responsibilities
You agree to:
- provide accurate information;
- use the Services only for lawful campaign and election-monitoring purposes;
- avoid uploading unlawful, false, defamatory, or unauthorised personal data;
- protect agent and campaign credentials;
- obtain any consents or authorisations required for information you submit about other people;
- comply with applicable electoral, communications, and data-protection laws.
Campaign organisations remain responsible for ensuring their use of Siasa Digital (including agent management, voter outreach, and evidence handling) is lawful in their jurisdiction.
17. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date and, where appropriate, provide additional notice through the Services. Continued use of the Services after an update constitutes acceptance of the revised Policy, except where applicable law requires otherwise.