Privacy Policy

Privacy Policy

6. Marketing communications

We send marketing emails about new courses, promotions or events only where you have opted in or the law otherwise permits. Every marketing email contains an unsubscribe link, and you can opt out at any time. Opting out does not stop essential service messages about courses you are enrolled in.

7. Cookies

Cookies are small files stored on your device that help the platform function and remember your preferences.

  • Comment cookies — if you opt in, your name, email address and website are saved so you need not re-enter them; these last one year.
  • Login and session cookies — a temporary cookie checks whether your browser accepts cookies (discarded on close). Login cookies last two days and display-option cookies one year; “Remember Me” persists for two weeks; logging out removes them.
  • Content-editing cookies — if you edit or publish content, a cookie stores the item ID and expires after one day; it holds no personal data.
  • Analytics and performance cookies — where enabled, these help us improve the platform, and are set only with your consent via our cookie banner.

You can manage or disable cookies through your browser and our cookie-consent tool, though disabling essential cookies may affect how the platform works.

8. Who we share your data with

We do not sell your personal data. We share it only as necessary with:

  • Payment processors —  e.g. M-Pesa / Safaricom, Stripe, JamboPay etc to process fees and confirm transactions.
  • Hosting and platform providers — our website host, learning-management system and cloud storage.
  • Email and communication tools — providers that deliver transactional and (where consented) marketing emails.
  • Spam-detection service — visitor comments may be checked through an automated spam-detection service.
  • Analytics providers — where enabled and consented to, to help us understand and improve usage.
  • Sponsoring organisations — where your employer or another body enrolled and paid for you, we may share enrolment, attendance, progress and completion status.
  • Professional advisers and authorities — accountants, auditors, lawyers, regulators, or law-enforcement and courts, where legally required or permitted.

All service providers acting as our data processors are bound by written agreements requiring them to protect your data, process it only on our instructions, and comply with applicable law.

9. Password resets

If you request a password reset, your IP address will be included in the reset email for security and verification purposes.

10. Embedded content from other websites

Course pages may include embedded content (videos, images, documents) from other websites, which behaves as though you had visited the other site. Those sites may collect data about you, set cookies, embed third-party tracking, and monitor your interaction — including where you are logged in to them. We do not control their practices; please review their privacy policies.

11. International transfers of your data

Some service providers (hosting, email or payment) may store or process personal data outside Kenya. Where we transfer data outside Kenya we do so in accordance with Part VI of the Act and the Data Protection (General) Regulations, 2021, and only where:

  • the destination country provides an adequate level of data protection;
  • appropriate safeguards (such as contractual data-protection clauses) are in place;
  • the transfer is necessary to perform our contract with you; or
  • you have given your explicit consent.

For learners in the EU / EEA or UK, transfers outside those regions are made under a recognised mechanism such as an adequacy decision or Standard Contractual Clause

12. How long we keep your data

We retain personal data only as long as necessary for the purposes in this policy or as required by law:

  • Account and learning records — while your account is active and thereafter for 7 years to support certificate re-issue, alumni verification and legitimate business needs.
  • Certificates and assessment records — retained long-term so we can verify qualifications we have awarded.
  • Financial and transaction records — retained for at least 7 years to meet tax, accounting and audit obligations.
  • Comments and their metadata — retained indefinitely so follow-up comments can be recognised and approved automatically, unless you ask us to delete them.
  • Marketing data — until you unsubscribe or withdraw consent.
  • Support communications and logs — for 5 years for service and security purposes.

When data is no longer needed, we securely delete or anonymise it.

13. How we protect your data

We apply appropriate technical and organisational measures against loss, misuse, unauthorised access, disclosure or alteration — including encryption in transit (HTTPS), hashed passwords, access controls, need-to-know staff access, and regular review of our security practices. No system is completely secure, but we work to protect your data and respond promptly to any incident.

Data-breach notification. If a personal-data breach occurs that poses a real risk of harm, we will notify the ODPC within 72 hours of becoming aware of it, in line with the Act, and will notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

14. Your rights as a data subject

Under the Act (and, where applicable, the GDPR), you have the right to:

  • be informed of how your personal data is used (through this policy);
  • access the personal data we hold about you and obtain a copy;
  • rectify inaccurate or incomplete data;
  • erase / delete your data where there is no lawful reason to keep it (“right to be forgotten”);
  • restrict or object to processing in certain circumstances, including objecting to direct marketing;
  • data portability — receive your data in a structured, commonly used, machine-readable format and have it transferred to another controller where feasible;
  • withdraw consent at any time where processing is based on consent; and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, save as permitted by law.

If you have an account or have left comments, you can request an exported file of your personal data and request that we erase it. This does not extend to data we must keep for administrative, legal, security or accounting purposes. Registered users can view, edit or delete most profile information at any time (usernames cannot be changed); administrators can also see and edit that information.

15. How to exercise your rights, and how to complain

To exercise any right, contact our Data Protection Officer at [insert dpo@baileycgroup.com]. We will respond within the timeframe required by law and without undue delay, and may ask you to verify your identity first.

If you are dissatisfied with how we have handled your personal data, you may complain to the Office of the Data Protection Commissioner (ODPC):

  • Website — https://www.odpc.go.ke/
  • Complaints portal — via the ODPC website

Learners in the other countries may also complain to their local supervisory authority.

16. Children and minors

Our courses are intended for adults and learners aged 18 and above. Where a course is open to minors, we require verifiable consent from a parent or guardian before processing a minor’s data, in line with the Act. We do not knowingly collect data from children without such consent; if you believe a minor has provided us data without consent, contact us and we will delete it.

17. Automated decision-making

Our platform may automatically grade certain quizzes and mark course completion. These routine assessment functions do not produce legal or similarly significant effects within the meaning of the Act. We do not use your data for automated profiling that produces such effects without a lawful basis and appropriate safeguards.

18. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or the law. We will post the updated version on this page with a revised “Last updated” date, and where changes are significant we will take reasonable steps to notify you.

19. Contact us

For any privacy question or request, contact:

Bailey Training Solutions — Data Protection Officer

Samuel Wachira

MSCC Centre, Upperhill, Nairobi, Kenya

Email: dpo@baileycgroup.com

Website: https://training.baileycgroup.com