Data Privacy & Security Framework

Privacy Policy

LJK Marketing Agency · Nairobi, Kenya · Compliant with the Kenya Data Protection Act 2019 · Last Updated: August 31, 2026

1. Introduction & Overview

LJK Marketing Agency (“LJK”, “Company”, “We”, “Us”, or “Our”), located in Nairobi, Kenya, operates an enterprise telecommunications and marketing automation platform accessible via https://www.ljkmarketingagency.co.ke.

We are committed to protecting the privacy, confidentiality, and security of personal data entrusted to us in strict accordance with the Kenya Data Protection Act 2019, the regulations promulgated by the Office of the Data Protection Commissioner (ODPC), and international best practices.

2. Roles: Data Controller vs. Data Processor

To ensure full legal clarity under the Kenya Data Protection Act 2019:

  • LJK as a Data Controller: LJK acts as a Data Controller with respect to the personal data of our registered business users (e.g. your account name, business email, phone number, M-PESA transaction codes, and login credentials).
  • LJK as a Data Processor: When you upload customer databases, phone numbers, or recipient contact lists via CSV/Excel to send SMS or Email campaigns, You (the Client) remain the sole Data Controller, and LJK acts strictly as a Data Processor executing dispatches upon your instructions.

3. Absolute Confidentiality of Client Contact Databases (Zero Data Selling)

We maintain an absolute, ironclad commitment regarding your uploaded contact databases:

  • Zero Commercial Monetization: We NEVER sell, rent, lease, share, trade, or monetize your contact lists, recipient phone numbers, or subscriber databases to any third party or advertiser under any circumstance.
  • No Cross-Account Aggregation: Your contacts remain strictly isolated within your private workspace and are never merged or matched with other clients' databases.
  • Purpose-Bound Processing: Contact lists are processed exclusively for the mechanical transmission of your authorized SMS and Email campaigns, delivery receipt (DLR) tracking, and opt-out suppression.

4. Categories of Data Collected

  • Account Registration Data: Full Name, business name, work email address, telephone number, password hash, and optional tax PIN / business registration documents.
  • Financial & Transaction Telemetry: M-PESA transaction references, billing history, and credit allocation ledger records (we do not store raw banking passwords or PINs).
  • Campaign & Transmission Data: SMS message body, recipient telephone numbers, email headers, delivery timestamps, carrier delivery receipts (DLR), bounce codes, and link click statistics.
  • Technical & Device Data: IP address, browser type, operating system, and access timestamps for system security, fraud prevention, and session management.

5. Third-Party Telecom & Cloud Sub-Processors

To deliver SMS and Email messages across Kenyan and global networks, we route payloads through licensed infrastructure partners, authorized gateway aggregators, and mobile network operators:

  • Licensed Mobile Network Operators & Gateway Providers: Safaricom PLC, Airtel Kenya, and authorized Tier-1 telecom SMS gateway providers and routing aggregators for carrier SMS termination and real-time delivery receipt (DLR) tracking.
  • Cloud Email Delivery Infrastructure: Authenticated SMTP relays and cloud email delivery sub-processors (including AWS SES and Resend) for transactional and marketing email transmission.
  • Payment Gateways: Safaricom Daraja M-PESA API and licensed payment service providers for real-time wallet top-ups.

All sub-processors and telecom routing partners are bound by strict data confidentiality agreements, statutory telecom secrecy regulations, and the Kenya Data Protection Act 2019.

6. Data Security & Storage Safeguards

We implement robust technical and organizational security measures:

  • TLS 1.3 encryption in transit for all web dashboard, API, and webhook traffic.
  • AES-256 encryption at rest for database records and contact tables.
  • Strict role-based access control (RBAC) ensuring only authorized administrators can access system infrastructure.
  • Automated threat monitoring and vulnerability scrubbing.

7. Your Rights Under the Kenya Data Protection Act 2019

Data subjects hold the following rights under Kenyan law:

  • Right to be Informed: To know how your personal data is collected and processed.
  • Right of Access: To request a copy of the personal data we hold about you.
  • Right to Rectification: To update or correct inaccurate or incomplete data.
  • Right to Erasure: To request the permanent deletion of your account and uploaded contact lists.
  • Right to Object & Opt-Out: To opt out of commercial communications at any time.

8. Contact the Data Protection Officer (DPO)

If you have questions regarding this Privacy Policy, wish to exercise your data subject rights, or require a data processing addendum (DPA), please contact our Data Protection Officer:

LJK Marketing Agency
Attn: Data Protection Officer (DPO) · Nairobi, Kenya
Physical Office: Nairobi, Kenya