Who is responsible for your data
This website is operated by an individual, not a company. Under data protection law the person deciding why and how personal data is processed is the “data controller”, and on this site that person is Joseph Gitau Chege, trading as Mfalme·0.
Because there is a single decision-maker and no outsourced support team, the practical difference is that your data goes to me and to the specific processors named in section 5, and to nobody else. There is no advertising network, no data broker, and no third party that buys, rents or appends records about you.
| Detail | Value |
|---|---|
| Controller | Joseph Gitau Chege |
| Trading as | Mfalme·0 |
| joseph.gitau.c@gmail.com | |
| Telephone | +254 755 917 099 |
| Location of processing | Nairobi, Kenya, Republic of Kenya |
| Regulator | Office of the Data Protection Commissioner (ODPC), Nairobi, Kenya |
What this policy covers
This policy covers the website at mfalme.runs-on.dev, including the guides, the two interactive tools, the case studies and the home lab pages. It does not cover external websites you arrive at from a link here — WhatsApp, LinkedIn, GitHub and similar services run under their own policies, and clicking a link transfers you out of my control entirely.
It is written to satisfy two overlapping regimes at once: the Data Protection Act, 2019 of Kenya, which applies to me as a controller operating from Nairobi, and the EU General Data Protection Regulation and UK GDPR, which apply where a visitor lives in the EEA, the UK or Switzerland. Where the two are stricter, the stricter one is followed.
What is actually collected
There are only three real sources of personal data here. Nothing is collected in the background beyond a page view, and nothing is collected at all if you never fill in a form.
| Data | Where it comes from | When |
|---|---|---|
| Name, email address, phone or WhatsApp number, company, budget and project details | The contact form on /contact and the two interactive tools | Only when you submit a form yourself |
| Rough device, browser, language, approximate region and referring page | Google Analytics 4 and Vercel Analytics | Only after you accept analytics cookies |
| Your cookie choices | This site's own preference storage | When you accept, reject or change the banner |
Why it is collected, and on what legal basis
Each processing activity has a stated purpose and a lawful basis. The purposes are specific rather than open-ended, which is the whole point of having to declare them.
| Purpose | Data | Legal basis |
|---|---|---|
| Answering your enquiry, quoting for work, and delivering services you have asked for | Contact details and project details | Performance of a contract or steps taken at your request prior to one (GDPR Art. 6(1)(b); Kenya DPA 2019 s.34 consent) |
| Keeping a record of conversations and work performed, and meeting accounting and legal obligations | Contact details, engagement history, invoices | Compliance with a legal obligation (GDPR Art. 6(1)(c)) |
| Measuring which pages are useful so the site and the work can be improved | Device, browser, language, approximate region, page path | Consent, withdrawn at any time (GDPR Art. 6(1)(a)) |
| Replying to you and defending legal claims | Correspondence | Legitimate interests in operating and defending the business (GDPR Art. 6(1)(f)) |
| Detecting and preventing abuse of the forms and site | Technical request data | Legitimate interests in keeping the service available (GDPR Art. 6(1)(f)) |
Where consent is the basis, it is specific, informed, freely given and as easy to withdraw as to give. Refusing non-essential cookies is a single click and leaves the rest of the site fully usable.
Cookies and analytics
Analytics code is not downloaded until you consent to it. If you decline, the Google Analytics and Vercel Analytics scripts are never fetched, so no analytics cookie is set and no request reaches either provider. There is no default-on tracking and no bundled tag manager that fires before consent.
Where analytics is allowed, IP anonymisation is on, Google Signals are disabled, and personalised advertising features are explicitly switched off, so no advertising profile is built from your visit. Full technical detail sits in the cookie policy, which lists every cookie by name, provider, purpose and duration.
- Your browser may also send a Global Privacy Control or Do Not Track signal. Where that signal is present, non-essential cookies start switched off.
- If your browser blocks cookies or JavaScript entirely, the site still renders, but your choice cannot be remembered between visits and the banner reappears.
Who else receives your data
The following organisations process data on my behalf, strictly for the purpose listed. Each is an independent controller for its own service and is subject to its own privacy commitments.
| Recipient | Data | Why |
|---|---|---|
| Formspree | Everything you type into a contact form or tool summary | Delivers the enquiry to my inbox. Submissions are handled on infrastructure located in the United States. |
| Google LLC (Analytics 4) | Device, browser, language, approximate region, page path, events | Aggregate page performance. Only if you consent. Google acts as an independent controller for this processing. |
| Vercel Inc. | Request metadata for hosting, plus page views if consented | Hosting the site and, if you consent, cookieless page analytics. |
| WhatsApp (Meta Platforms) | Your phone number and any message you send | Opens in WhatsApp when you choose to contact me that way. Governed by WhatsApp's own policy once you leave this site. |
| Email provider | Your email address and correspondence | Delivering replies. Addresses are consumer webmail accounts, not a marketing list. |
| Payment providers | Payment references and amounts | Only if we do business together, at which point your details go to the provider named on the invoice — not through this site. |
I do not sell personal data, rent mailing lists, or share it for anyone else’s independent purposes. I will not add a new recipient without updating this policy first.
How long your data is kept
Data is kept only for as long as the stated purpose requires, then deleted or anonymised.
- Enquiries that do not become projects: deleted within 12 months of last contact.
- Client records and correspondence: kept for the duration of the engagement plus 6 years, which is the period Kenyan tax and company record-keeping expectations assume.
- Analytics data: held by Google for up to 14 months at user level and 25 months at event level, then aggregated. Deleting cookies shortens this to whatever the provider retains for an anonymous identifier, which is typically a few months.
- Abuse and security logs: retained 6 months, then deleted.
International transfers
This site is hosted on infrastructure outside Kenya, and two of the processors named above operate outside Kenya. Where personal data leaves Kenya or the EEA, it is done on the lawful basis described in section 4, with the standard contractual protections that apply: processor agreements where the recipient is acting for me, and an adequacy decision or equivalent safeguards where the recipient is an independent controller.
Transfers to the United States rely on the mechanisms available under the applicable regime, including the EU-US Data Privacy Framework where a recipient is certified. If you want to know the current certification status of a specific recipient, ask and I will confirm it rather than guess.
How your data is protected
Reasonable technical and organisational measures, no more than a solo practice can honestly deploy:
- Traffic served over HTTPS only, with HSTS enabled.
- Modern password hashing, MFA on the hosting account and the email account, and a hardware-backed key where the service supports it.
- No production database on this site at all. Form submissions pass through Formspree and land in email, which keeps the store of personal data small and easy to audit.
- Analytics disabled at the source until consent, so an unauthorised tag cannot quietly accumulate a profile of visitors.
- Access limited to one person. There is no team, so there is no insider risk beyond the obvious.
No system is perfectly secure. If a breach affects your data and is likely to cause you harm, the law requires me to notify you without undue delay and to notify the relevant supervisory authority where the threshold is met.
Your rights
You keep control of your data. These rights apply whether you are in Kenya, the EEA or anywhere else, and there is no charge for making any of them.
| Right | What it means in practice |
|---|---|
| Access | I confirm what personal data I hold about you, where it came from, why it is held, who it is shared with, and how long it is kept. |
| Rectification | I correct anything inaccurate, incomplete or out of date. |
| Erasure | I delete your data where there is no overriding legal reason to keep it. |
| Restriction | I stop processing while a dispute about accuracy or legitimate interests is resolved. |
| Objection | I stop legitimate-interest processing, such as defensive retention of correspondence, on request. |
| Portability | I provide your data in a structured, machine-readable format. |
| Withdraw consent | I remove analytics and any other optional processing immediately, via the cookie settings. |
| Complain | You can complain to a supervisory authority without going to me first. |
To exercise any of these, email joseph.gitau.c@gmail.comwith the subject line “Data request”. I respond within seven days. I may ask for enough information to confirm the request is genuinely from you; I will not ask for ID unless there is a concrete reason, and I will say why.
Kenya: complaints may be lodged with the Office of the Data Protection Commissioner (ODPC), Nairobi, Kenya. If you are in the EU or UK, you may also complain to Any supervisory authority in the visitor's country of residence, or the Irish Data Protection Commission as the lead authority where one-stop-shop applies or the Information Commissioner's Office (ICO), Wilmslow, United Kingdom. The UK position is set out in the Information Commissioner’s register of international transfers.
Children
This site is a professional portfolio and is not directed at anyone under 16. I do not knowingly collect personal data from children. If you believe a child has submitted information through a form on this site, email joseph.gitau.c@gmail.com and it will be deleted immediately and without question.
Automated decisions and profiling
No decision with legal or similarly significant effect about you is made by automated means. The free tools apply a fixed scoring formula to the answers you give so they can produce a summary for you — they do not build a profile, and they do not know who you are. The output is informational and is not professional advice.
Changes to this policy
If this policy changes materially — a new processor, a new category of data, or a change to the lawful basis — the “last updated” date at the top changes and the revision is noted below. Minor wording and formatting corrections do not trigger a new date.
| Date | Change |
|---|---|
| 27 September 2026 | First published version. |
Contact and complaint
Questions, requests and complaints all go to the same person, which is the point. Write to joseph.gitau.c@gmail.com or call +254 755 917 099 between 09:00 and 18:00 EAT, Monday to Saturday. Postal correspondence is accepted at Nairobi, Kenya, Republic of Kenya.
If you are not satisfied with how I have handled a request, you have every right to escalate to a regulator. That is a legitimate step, not a betrayal.