Privacy Policy
1. Who we are
Bailey Training Solutions (“Bailey Training”, “we”, “us”, “our”) is the online learning and professional-training arm of Bailey Consulting Group, operating the learning platform at https://training.baileycgroup.com , through which we deliver online courses, live and recorded training, assessments, certificates and related educational services.
For the purposes of the Data Protection Act, No. 24 of 2019 (Laws of Kenya) (the “Act”) and the Data Protection (General) Regulations, 2021, we are the data controller responsible for the personal data we collect and process about you.
| Detail | Information |
| Legal / trading name | Bailey Consulting Group |
| Physical address | MSCC Centre, UpperHill, Nairobi, Kenya |
| General email | training@baileycgroup.com |
| Data Protection Officer | Samuel Wachira – dpo@baileycgroup.com |
If you have any questions about this policy or how we handle your personal data, contact our Data Protection Officer using the details above.
2. Scope and legal framework
This policy explains how we collect, use, share, retain and protect your personal data when you visit our website, create an account, enrol in or take a course, make a payment, sit an assessment, contact us, or otherwise interact with us. We process personal data in accordance with:
- the Data Protection Act, No. 24 of 2019 and the Data Protection (General) Regulations, 2021 of Kenya, which give effect to Article 31 of the Constitution of Kenya on the right to privacy;
- guidance and codes of practice issued by the Office of the Data Protection Commissioner (ODPC); and
- the EU / UK GDPR where we offer courses to, or monitor learners located in, the European Union / EEA or the United Kingdom.
Where we act as a data processor on behalf of an organisation that sponsors its staff on our courses (for example a corporate or government client), we process learner data on that organisation’s documented instructions under a separate data-processing agreement, and that organisation is the controller for its own learners’ data.
3. The personal data we collect
Account and registration data — full name, username, email address, password (stored hashed), telephone number, country / city, organisation or employer, job title, and profile photo where provided.
Course and learning data — courses you enrol in, progress and completion status, quiz and assessment responses and scores, assignments and submissions, attendance in live sessions, certificates issued, and feedback or reviews you post.
Payment and billing data — billing name, billing address, transaction records and invoices. We do not store full card numbers or mobile-money PINs; card and mobile-money details are handled directly by our payment providers (see Section 8).
Comments and user-generated content — when you leave a comment we collect the content, your IP address and browser user-agent string to help with spam detection. An anonymised hash of your email address may be shared with the Gravatar service to check for a profile picture (privacy policy at https://automattic.com/privacy/). After approval, your profile picture is visible to the public alongside your comment.
Media you upload — images, documents and files (e.g. assignment attachments or a profile picture). Please avoid uploading images containing embedded location data (EXIF GPS), as anyone able to view the file may extract it.
Communications — emails, support tickets, chat messages and other correspondence between you and us, including our responses.
Technical and usage data — IP address, device and browser type, operating system, referring pages, pages viewed, and time and date of access, collected automatically through cookies and server logs (see Section 7).
We generally do not seek sensitive personal data (as defined in the Act — including data revealing race, health, ethnic or social origin, conscience, belief, genetic or biometric data, marital or family details, sex or sexual orientation). Where a course requires it (for example an accessibility accommodation), we process it only with your explicit consent or another lawful basis, and only to the extent necessary.
4. How we collect your data
- Directly from you — when you register, enrol, pay, submit assignments, post comments, complete your profile, or contact us;
- Automatically — through cookies, server logs and analytics as you use the platform; and
- From third parties — such as an employer or sponsoring organisation that enrols you, or a payment provider confirming a transaction.
5. Why we use your data, and our lawful basis
We process your personal data only where the Act (and, where applicable, the GDPR) permits. The main purposes and lawful bases are:
| Purpose | Lawful basis under the Act / GDPR |
| Creating and managing your account | Performance of a contract with you |
| Delivering courses, tracking progress, running assessments and issuing certificates | Performance of a contract with you |
| Processing payments and issuing invoices / receipts | Contract; compliance with a legal (tax / accounting) obligation |
| Providing support and responding to enquiries | Contract; our legitimate interest in assisting learners |
| Sending service messages (enrolment, updates, security notices) | Contract; our legitimate interest in operating the platform |
| Sending marketing about new courses and offers | Your consent (withdrawable at any time) |
| Displaying approved comments and reviews | Your consent; our legitimate interest in a learning community |
| Preventing fraud, spam and abuse; securing the platform | Our legitimate interest in security; legal obligation |
| Improving our courses and platform (analytics) | Consent (non-essential cookies); our legitimate interest |
| Meeting legal, regulatory, audit and record-keeping duties | Compliance with a legal obligation |
Where we rely on consent, you may withdraw it at any time without affecting processing carried out beforehand. Where we rely on legitimate interest, we have balanced that interest against your rights and freedoms.
6. Marketing communications
We send marketing emails about new courses, promotions or events only where you have opted in or the law otherwise permits. Every marketing email contains an unsubscribe link, and you can opt out at any time. Opting out does not stop essential service messages about courses you are enrolled in.
7. Cookies
Cookies are small files stored on your device that help the platform function and remember your preferences.
- Comment cookies — if you opt in, your name, email address and website are saved so you need not re-enter them; these last one year.
- Login and session cookies — a temporary cookie checks whether your browser accepts cookies (discarded on close). Login cookies last two days and display-option cookies one year; “Remember Me” persists for two weeks; logging out removes them.
- Content-editing cookies — if you edit or publish content, a cookie stores the item ID and expires after one day; it holds no personal data.
- Analytics and performance cookies — where enabled, these help us improve the platform, and are set only with your consent via our cookie banner.
You can manage or disable cookies through your browser and our cookie-consent tool, though disabling essential cookies may affect how the platform works.
8. Who we share your data with
We do not sell your personal data. We share it only as necessary with:
- Payment processors — e.g. M-Pesa / Safaricom, Stripe, JamboPay etc to process fees and confirm transactions.
- Hosting and platform providers — our website host, learning-management system and cloud storage.
- Email and communication tools — providers that deliver transactional and (where consented) marketing emails.
- Spam-detection service — visitor comments may be checked through an automated spam-detection service.
- Analytics providers — where enabled and consented to, to help us understand and improve usage.
- Sponsoring organisations — where your employer or another body enrolled and paid for you, we may share enrolment, attendance, progress and completion status.
- Professional advisers and authorities — accountants, auditors, lawyers, regulators, or law-enforcement and courts, where legally required or permitted.
All service providers acting as our data processors are bound by written agreements requiring them to protect your data, process it only on our instructions, and comply with applicable law.
9. Password resets
If you request a password reset, your IP address will be included in the reset email for security and verification purposes.
10. Embedded content from other websites
Course pages may include embedded content (videos, images, documents) from other websites, which behaves as though you had visited the other site. Those sites may collect data about you, set cookies, embed third-party tracking, and monitor your interaction — including where you are logged in to them. We do not control their practices; please review their privacy policies.
11. International transfers of your data
Some service providers (hosting, email or payment) may store or process personal data outside Kenya. Where we transfer data outside Kenya we do so in accordance with Part VI of the Act and the Data Protection (General) Regulations, 2021, and only where:
- the destination country provides an adequate level of data protection;
- appropriate safeguards (such as contractual data-protection clauses) are in place;
- the transfer is necessary to perform our contract with you; or
- you have given your explicit consent.
For learners in the EU / EEA or UK, transfers outside those regions are made under a recognised mechanism such as an adequacy decision or Standard Contractual Clause
12. How long we keep your data
We retain personal data only as long as necessary for the purposes in this policy or as required by law:
- Account and learning records — while your account is active and thereafter for 7 years to support certificate re-issue, alumni verification and legitimate business needs.
- Certificates and assessment records — retained long-term so we can verify qualifications we have awarded.
- Financial and transaction records — retained for at least 7 years to meet tax, accounting and audit obligations.
- Comments and their metadata — retained indefinitely so follow-up comments can be recognised and approved automatically, unless you ask us to delete them.
- Marketing data — until you unsubscribe or withdraw consent.
- Support communications and logs — for 5 years for service and security purposes.
When data is no longer needed, we securely delete or anonymise it.
13. How we protect your data
We apply appropriate technical and organisational measures against loss, misuse, unauthorised access, disclosure or alteration — including encryption in transit (HTTPS), hashed passwords, access controls, need-to-know staff access, and regular review of our security practices. No system is completely secure, but we work to protect your data and respond promptly to any incident.
Data-breach notification. If a personal-data breach occurs that poses a real risk of harm, we will notify the ODPC within 72 hours of becoming aware of it, in line with the Act, and will notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
14. Your rights as a data subject
Under the Act (and, where applicable, the GDPR), you have the right to:
- be informed of how your personal data is used (through this policy);
- access the personal data we hold about you and obtain a copy;
- rectify inaccurate or incomplete data;
- erase / delete your data where there is no lawful reason to keep it (“right to be forgotten”);
- restrict or object to processing in certain circumstances, including objecting to direct marketing;
- data portability — receive your data in a structured, commonly used, machine-readable format and have it transferred to another controller where feasible;
- withdraw consent at any time where processing is based on consent; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, save as permitted by law.
If you have an account or have left comments, you can request an exported file of your personal data and request that we erase it. This does not extend to data we must keep for administrative, legal, security or accounting purposes. Registered users can view, edit or delete most profile information at any time (usernames cannot be changed); administrators can also see and edit that information.
15. How to exercise your rights, and how to complain
To exercise any right, contact our Data Protection Officer at [insert dpo@baileycgroup.com]. We will respond within the timeframe required by law and without undue delay, and may ask you to verify your identity first.
If you are dissatisfied with how we have handled your personal data, you may complain to the Office of the Data Protection Commissioner (ODPC):
- Website — https://www.odpc.go.ke/
- Complaints portal — via the ODPC website
Learners in the other countries may also complain to their local supervisory authority.
16. Children and minors
Our courses are intended for adults and learners aged 18 and above. Where a course is open to minors, we require verifiable consent from a parent or guardian before processing a minor’s data, in line with the Act. We do not knowingly collect data from children without such consent; if you believe a minor has provided us data without consent, contact us and we will delete it.
17. Automated decision-making
Our platform may automatically grade certain quizzes and mark course completion. These routine assessment functions do not produce legal or similarly significant effects within the meaning of the Act. We do not use your data for automated profiling that produces such effects without a lawful basis and appropriate safeguards.
18. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or the law. We will post the updated version on this page with a revised “Last updated” date, and where changes are significant we will take reasonable steps to notify you.
19. Contact us
For any privacy question or request, contact:
Bailey Training Solutions — Data Protection Officer
Samuel Wachira
MSCC Centre, Upperhill, Nairobi, Kenya
Email: dpo@baileycgroup.com
Website: https://training.baileycgroup.com