ATE AFRICA TECH EVENTS
  • Browse Events
  • Speakers
  • How It Works
  • Browse Events
  • Speakers
  • How It Works
Legal

Privacy Policy

Effective Date: [To be announced]  ·  Version 1.0

Contents
  1. Introduction
  2. Who Controls Your Data
  3. Personal Data We Collect
  4. Purposes & Lawful Bases
  5. How We Share Data
  6. International Transfers
  7. Data Retention
  8. Your Rights
  9. Security
  10. Cookies
  11. Children
  12. Organizer Obligations
  13. Third-Party Links
  14. Changes to This Policy
  15. Contact Us

1. Introduction

Africa Tech Events ("the Platform", "we", "us", "our") is a multi-tenant event ticketing and management platform operated from Nairobi, Kenya, enabling event organizers ("Organizers") to create events, sell tickets and merchandise, issue corporate invoices, manage attendees, and communicate with their audiences across Africa.

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use the Platform, whether as an event attendee or ticket buyer ("Attendee"), an Organizer, a member of an Organizer's team ("Team Member"), a speaker listed in our speaker directory ("Speaker"), or a visitor to our websites (collectively, "Users", "you").

We are committed to complying with:

  • The Data Protection Act, 2019 (Kenya) ("DPA") and guidance issued by the Office of the Data Protection Commissioner (ODPC);
  • The EU General Data Protection Regulation (GDPR) and UK GDPR, where they apply to data subjects in the EEA or UK;
  • Other applicable data protection laws in jurisdictions where we operate, including Tanzania, Uganda, Rwanda, Nigeria, South Africa (POPIA), and Ghana.

If you do not agree with this Privacy Policy, please do not use the Platform.

2. Who Controls Your Data (Controller vs. Processor)

Because the Platform is multi-tenant, responsibility for your personal data depends on the context:

ContextData ControllerOur Role
Your account on the Platform (Organizer/Team Member accounts, platform-level analytics, billing, fraud prevention, security logs)Africa Tech EventsController
Attendee/buyer data collected when you purchase a ticket or merchandise for a specific event, including responses to custom registration fields defined by the OrganizerThe Organizer of that eventProcessor
Speaker directory profiles submitted for public listingAfrica Tech EventsController
Payment transactionsThe relevant payment provider (e.g., Safaricom M-Pesa, Paystack, DPO)Processor / facilitator
Important: Where an Organizer collects data through custom registration fields, the Organizer — not Africa Tech Events — determines what is collected and why. Attendees should direct questions about event-specific data collection to the relevant Organizer.

3. Personal Data We Collect

3.1 Attendees and Ticket Buyers

  • Identity and contact data: buyer name, ticket holder name(s), email address(es), phone number(s);
  • Custom registration responses: answers to event-specific fields defined by the Organizer. Organizers are prohibited from collecting sensitive personal data through custom fields without a lawful basis and our prior written approval;
  • Ticket and attendance data: ticket type, QR codes, check-in timestamps and the identity of the staff member who checked you in;
  • Merchandise orders: items ordered, sizes/variations, delivery address;
  • Payment-related data: phone number used for M-Pesa, M-Pesa receipt numbers, payment references, amounts and currency, payment status history. We do not store full card numbers, CVVs, or card PINs — card payments are processed directly by PCI-DSS compliant providers.

3.2 Corporate Buyers

Company name, company email and address, contact person name and phone, company logo, tax registration details (e.g., KRA PIN), invoice line items, and banking references used for settlement.

3.3 Organizers and Team Members

  • Account credentials (passwords stored hashed), names, email addresses, phone numbers, roles and permissions (Owner, Admin, Agent, Support);
  • Organization details: name, logo, banner, website, contact information, custom domain details;
  • Settlement and banking details: bank name, account name and number, till/paybill numbers;
  • Payment integration credentials (API keys/secrets), stored encrypted and used solely to process payments on the Organizer's behalf;
  • Notification preferences and custom sender identities (email sender names/addresses, SMS sender IDs).

3.4 Speakers

Name, biography, photograph, country/city, topics, contact email, and social/professional links, where submitted for directory listing.

3.5 Support Requesters

Name, email, phone number, ticket contents, escalation notes, and resolution records.

3.6 Automatically Collected Data

  • Device and log data: IP address, browser type, pages visited, timestamps, referral URLs;
  • Webhook and API logs relating to payment confirmations (retained for reconciliation, dispute resolution, and fraud prevention);
  • Notification dispatch records; cookies and similar technologies (see Section 10).

3.7 Data from Third Parties

Payment confirmations and metadata from M-Pesa (Safaricom Daraja), Paystack, DPO, and other payment providers; lead/callback request details submitted through our sales forms.

4. Purposes and Lawful Bases of Processing

PurposeLawful Basis (DPA / GDPR)
Creating and administering accounts; issuing tickets; processing orders and merchandise sales; delivering QR codes; managing check-inPerformance of a contract
Processing payments, issuing invoices and receipts, settlement to OrganizersPerformance of a contract; legal obligation
Transactional communications (order confirmations, ticket delivery, event reminders, post-event follow-ups)Performance of a contract; legitimate interests
Marketing communications from the PlatformConsent (withdrawable at any time)
Marketing communications from OrganizersThe Organizer's responsibility as controller
Fraud prevention, duplicate-payment detection, webhook verification, security monitoringLegitimate interests; legal obligation
Analytics and reporting for Organizers (aggregate sales, revenue, check-in statistics)Legitimate interests; contract with the Organizer
Public speaker directoryConsent
Compliance with law, court orders, and lawful requests from regulatorsLegal obligation
Establishing, exercising, or defending legal claimsLegitimate interests

5. How We Share Personal Data

We do not sell personal data. We share it only as follows:

  1. With Organizers: Attendee data for events you register for is made available to the relevant Organizer and its authorized Team Members. Organizers are independently responsible for their use of this data.
  2. With payment providers: Safaricom (M-Pesa/Daraja), Paystack, DPO, and banks, to the extent needed to process transactions, refunds, and chargebacks.
  3. With communication providers: email delivery services and SMS gateways, solely to deliver messages on our or the Organizer's behalf.
  4. With service providers/sub-processors: hosting, infrastructure, storage, and analytics vendors bound by data processing agreements.
  5. For legal reasons: where required by law, regulation, court order, or to protect the rights, property, or safety of the Platform, our Users, or the public.
  6. Business transfers: in connection with a merger, acquisition, or asset sale, subject to this Policy's protections.
  7. Public directory: Speaker profiles are published publicly with the Speaker's consent.

6. International Data Transfers

Our operations are primarily based in Kenya. Where personal data is transferred outside Kenya, we ensure the transfer complies with Sections 48–49 of the DPA and, where GDPR applies, Chapter V of the GDPR, using appropriate safeguards such as transfers to adequate jurisdictions, standard contractual clauses, or your explicit consent where required.

7. Data Retention

Data CategoryIndicative Retention
Order, ticket, and payment records7 years after the transaction (tax and accounting obligations)
Corporate invoices and settlement records7 years
Attendee custom registration responsesEvent lifecycle plus 12 months, or as instructed by the Organizer
Check-in logs24 months after the event
Account data (Organizers/Team Members)Duration of the account plus 12 months after closure
Support tickets36 months after resolution
Security, webhook, and payment API logsUp to 24 months
Marketing consents and suppression listsUntil withdrawal, plus a record of the withdrawal

When retention periods expire, data is securely deleted or irreversibly anonymized.

8. Your Rights

Under the DPA (and, where applicable, GDPR) you have the right to:

  • Access the personal data we hold about you;
  • Rectification of inaccurate or incomplete data;
  • Erasure ("right to be forgotten"), subject to legal retention obligations;
  • Restriction of processing;
  • Object to processing based on legitimate interests, and to direct marketing at any time;
  • Data portability in a structured, commonly used, machine-readable format;
  • Withdraw consent at any time, without affecting prior lawful processing;
  • Not be subject to solely automated decision-making producing legal or similarly significant effects;
  • Lodge a complaint with the ODPC (Kenya) or your local supervisory authority.

To exercise these rights, contact us using the details in Section 15. We will respond within the timelines required by law (generally 30 days). Where your request concerns data controlled by an Organizer, we will forward it to the Organizer and assist as processor.

9. Security

  • Encryption of data in transit (TLS) and encryption of stored payment integration credentials;
  • Password hashing; role-based access control limiting who can view attendee data;
  • Webhook signature verification and duplicate-event (replay) protection on payment callbacks;
  • Audit logging of payment status transitions and notification dispatches;
  • Tenant isolation so that one Organizer cannot access another Organizer's data;
  • Regular review of access rights and security practices.

In the event of a personal data breach likely to result in a risk to your rights, we will notify the ODPC within 72 hours as required by Section 43 of the DPA, and affected data subjects without undue delay where legally required.

10. Cookies and Similar Technologies

We use cookies that are strictly necessary for the Platform to function (session management, security, CSRF protection) and, with your consent, analytics cookies to understand usage. You can manage cookies through your browser settings; disabling essential cookies may impair Platform functionality.

11. Children

The Platform is not directed at children under 18. Attendee tickets for minors must be purchased and managed by a parent or guardian. Organizers hosting events for minors are responsible for obtaining verifiable parental consent as required by Section 33 of the DPA.

12. Organizer Obligations

Organizers who use the Platform to collect attendee data are data controllers for that data and must:

  • Register with the ODPC as data controllers/processors where required by Kenyan law;
  • Collect only data that is necessary and lawful for their events, and provide their own privacy notices to attendees;
  • Not use custom registration fields to collect sensitive personal data without a lawful basis;
  • Use attendee data only for the event(s) concerned and lawful, disclosed purposes;
  • Honor data subject rights requests relating to their events;
  • Notify us without undue delay of any suspected breach involving Platform data.
Africa Tech Events is not responsible or liable for an Organizer's independent misuse of attendee data. Misuse of attendee data by Organizers or their Team Members is a material breach of our Terms and Conditions and may result in suspension, termination, and referral to the ODPC or law enforcement.

13. Third-Party Links and Services

Event pages may contain links to Organizer websites, online event platforms, and social media. Payment flows redirect to or invoke third-party providers. We are not responsible for the privacy practices of third parties; review their policies before providing data.

14. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified via the Platform or email at least 14 days before taking effect. Continued use after the effective date constitutes acceptance.

15. Contact Us / Data Protection Officer

Africa Tech Events — Data Protection Officer
Email: info@africatechevents.org
Phone: +254 745149280
Nairobi, Kenya

Supervisory Authority: Office of the Data Protection Commissioner (ODPC), P.O. Box 30920-00100, Nairobi, Kenya — www.odpc.go.ke

ATE AFRICA TECH EVENTS

Africa’s end-to-end events platform. Plan your event, promote it, sell tickets, collect M-Pesa, and manage your day — all from one dashboard.

Platform
  • Browse Events
  • Speaker Directory
  • How It Works
  • Start Selling
Organizers
  • Dashboard Login
  • Create Event
  • Check-In Tool
Legal
  • Privacy Policy
  • Terms & Conditions
Contact
Nairobi, Kenya

info@africatechevents.org
+254 745149280

© 2026 Africa Tech Events. All rights reserved.  ·  Privacy  ·  Terms

Nairobi, Kenya