Legal

Privacy Policy

Version 1.0Published 20 Jul 2026

Effective Date: April 21, 2026

1. Introduction SyncD Group Africa Limited T/A Brandefy Creative Studio ("Brandefy") respects your privacy. This Privacy Policy explains how we collect, use, process, and protect your Personal Data when you use our services or website, in compliance with the Kenya Data Protection Act, 2019 (KDPA) and the EU General Data Protection Regulation (GDPR).

2. Data Controller SyncD Group Africa Limited is the Data Controller for the Personal Data collected under this policy. Our registered address is P. O. Box 13242 - 00100, Nairobi, Kenya. You can contact our Data Protection Officer at [Insert DPO Email].

3. The Data We Collect We may collect, use, store, and transfer different kinds of Personal Data, including:

  • Identity Data: First name, last name, username.

  • Contact Data: Billing address, email address, telephone numbers.

  • Financial Data: Bank account and payment card details.

  • Transaction Data: Details about payments to and from you and details of services you have purchased from us.

  • Technical Data: IP address, browser type and version, time zone setting and location, browser plug-in types, and operating system.

4. How We Use Your Data (Legal Basis) We will only use your Personal Data when the law allows us to. Most commonly, we use it:

  • Contractual Necessity: To register you as a new client, process quotes, and deliver services.

  • Legitimate Interests: To manage our relationship with you, improve our website and services, and secure our systems.

  • Legal Obligation: To comply with tax and regulatory requirements in Kenya.

  • Consent: To send direct marketing communications (you have the right to withdraw consent at any time).

5. Data Sharing and Transfers We may share your data with trusted third parties, including payment processors, cloud hosting providers, and legal authorities.

  • Cross-Border Transfers: As an agency serving global clients, your data may be transferred outside Kenya or the European Economic Area (EEA). We ensure a similar degree of protection is afforded to it by utilizing safeguards such as KDPA/GDPR-compliant Standard Contractual Clauses.

6. Data Security and Retention We have implemented appropriate security measures to prevent your Personal Data from being accidentally lost, used, accessed in an unauthorized way, altered, or disclosed. We will only retain your Personal Data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.

7. Your Legal Rights Under the KDPA and GDPR, you have the right to:

  • Request access to your Personal Data.

  • Request correction of the Personal Data we hold about you.

  • Request erasure of your Personal Data (Right to be Forgotten).

  • Object to processing of your Personal Data.

  • Request restriction of processing of your Personal Data.

  • Request the transfer of your Personal Data to you or a third party (Data Portability).

  • Withdraw consent at any time.

To exercise these rights, please email [Insert DPO Email]. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) in Kenya or your local supervisory authority.