- Version 2026-07-19.1. Controller/operator details: [FelbaCare operating legal entity, registration number, registered address, Tax PIN, ODPC registration status, support contact, and legal contact to be inserted after advocate review].
- Publication-ready use requires review and approval by a qualified Kenyan advocate. These policies are a compliance-engineering draft and do not replace a formal legal opinion.
- FelbaCare may act as an independent controller for platform accounts, security, subscriptions, billing, support, analytics, abuse prevention, and legal compliance; as a processor or service provider for group records entered under administrator instructions; and, in some workflows, as a joint participant in determining safety, fraud, audit, or compliance processing. Final role allocation requires Kenyan advocate review and customer-contract approval.
- Personal data categories include identity, contact, profile, authentication, group membership, officer role, contribution, payment reference, payer phone, alternate payer, claim, beneficiary, uploaded evidence, document metadata, message, announcement, vote, meeting, device, IP address, session, security log, cookie, analytics, marketing preference, support, subscription, billing, audit, fraud indicator, API log, AI prompt/output, and data-export data.
- Sensitive or higher-risk data may include beneficiary details, claim evidence, health or welfare-event details, identity documents if introduced, child data if a guardian-supported flow is introduced, financial hardship information, payment references, encrypted phone references, and fraud or security flags.
- Sources include the user, group administrators, officers, other members, inviters, payment providers, bank or statement imports, third-party payers, devices, browsers, support channels, automated security systems, and regulators or law-enforcement bodies where applicable.
- Processing purposes include account creation, authentication, group administration, contribution tracking, payment declaration and verification, reconciliation, claims review, payout administration, billing, subscription collection, member statements, audit integrity, fraud prevention, security, customer support, legal compliance, data exports, notices, and product improvement.
- Lawful bases must be mapped purpose by purpose. Contract is generally used for core account and group services, legitimate interests for security and fraud prevention where balanced, legal obligation for statutory retention and lawful requests, consent for optional marketing and non-essential cookies, and explicit or appropriate consent or another lawful basis for sensitive personal data where required.
- Marketing consent must be optional, granular by channel, unticked by default, recorded, and withdrawable. Transactional, security, group operational, and legal notices are separate from marketing consent.
- Group-provided data requires the submitting administrator, officer, member, claimant, or inviter to have authority and a lawful basis. FelbaCare should provide indirect notice where practical when data is received about a person who has not yet registered.
- Within a group, visibility must be limited by role and purpose. Members may see relevant group records, their own statements, applicable rules, and approved summaries; officers may see records needed for their duties; sensitive claim, beneficiary, billing, and security details require stricter role-based access.
- Recipients may include authorized group users, payment providers, banks, hosting providers, database providers, communication providers, analytics providers, security vendors, professional advisers, regulators, law enforcement, and corporate transaction recipients. The live subprocessor register must identify actual vendors before publication.
- FelbaCare must not claim all data stays in Kenya without infrastructure proof. Cross-border transfer assessments, contracts, safeguards, and notices are required where hosting, support, payment, AI, analytics, or communications providers process data outside Kenya.
- Retention must distinguish active records, archived records, backups, legal holds, anonymization, and deletion. Finance, audit, claim, tax, and dispute records may need longer retention than ordinary profile or marketing data.
- Data subjects may request access, correction, deletion where lawful, objection handling, restriction, portability where applicable, consent withdrawal, human review of significant automated decisions, and complaint escalation including ODPC complaint routes.
- Fraud scoring, payment matching, contribution recommendations, claim risk signals, AI assistant responses, and automated summaries must be disclosed as decision support with human review and contest routes. Private user data must not be used to train third-party AI models unless a lawful basis, contract, and clear disclosure are approved.
- Security controls include encryption where configured, role-based access control, audit logs, same-origin checks, session controls, provider secret references, immutable evidence practices, backups, monitoring, secure development, incident response, and vendor assessment. FelbaCare does not promise perfect security.
- Breach procedures must cover detection, containment, assessment, user communication, regulator notification where required, evidence preservation, and post-incident remediation.
- Children must not use FelbaCare unless a lawful guardian-approved or legally authorized flow exists. Child-data collection, school or family groups, identity checks, and financial participation by minors require legal and privacy review before activation.
Loading FelbaCare