Your privacy is important to us. It is Patatix Technologies Ltd's policy to respect your privacy and comply with the Kenya Data Protection Act (DPA), 2019, as well as any other applicable laws and regulations regarding any personal information we may collect about you. This policy applies across our website, https://patatix.com, and any other sites or services we own and operate.
Personal information is any information about you which can be used to identify you. This includes information about you as a person (such as name, address, and date of birth), your devices, payment details, and even information about how you use a website or online service.
In the event our site contains links to third‑party sites and services, please be aware that those sites and services have their own privacy policies. After following a link to any third‑party content, you should read their posted privacy policy about how they collect and use personal information. This Privacy Policy does not apply to any of your activities after you leave our site.
Data Controller
Patatix Technologies Ltd
Physical Address: Nairobi, Kenya
ODPC Registration Number: Contact our Data Protection Officer for our current ODPC registration number.
Data Protection Officer: dpo@patatix.com
This policy is effective as of March 27, 2026.
Last updated: March 27, 2026
Information we collect
Information we collect falls into two categories: "voluntarily provided" information and "automatically collected" information.
"Voluntarily provided" information refers to any information you knowingly and actively provide us when using or participating in any of our services and promotions.
"Automatically collected" information refers to any information automatically sent by your devices in the course of accessing our products and services.
Log data
When you visit our website, our servers may automatically log the standard data provided by your web browser. It may include your device's Internet Protocol (IP) address, your browser type and version, the pages you visit, the time and date of your visit, the time spent on each page, and other details about your visit.
Additionally, if you encounter certain errors while using the site, we may automatically collect data about the error and the circumstances surrounding its occurrence. This data may include technical details about your device, what you were trying to do when the error happened, and other technical information relating to the problem. You may or may not receive notice of such errors, even in the moment they occur, that they have occurred, or what the nature of the error is.
Please be aware that while this information may not be personally identifying by itself, it may be possible to combine it with other data to personally identify individual persons.
Device data
When you visit our website or interact with our services, we may automatically collect data about your device, such as:
- Device Type
- Operating system
- Unique device identifiers
- Device settings
Data we collect can depend on the individual settings of your device and software. We recommend checking the policies of your device manufacturer or software provider to learn what information they make available to us.
Personal information
We may ask for personal information – for example, when you submit content to us, when you subscribe to our newsletter, when you register an account, or when you contact us – which may include one or more of the following:
- Name
- Social media profiles
- Phone/mobile number
- Home/mailing address
Financial information
We use Stripe to process payments. When you make a payment (or receive a payout), specific financial information is shared with Stripe to process the transaction. We do not store full credit card numbers on our servers. The collection and use of this information are governed by the Stripe Privacy Policy. Patatix is PCI‑DSS compliant (or utilises PCI‑compliant partners) to ensure the security of your payment data.
User‑generated content
We consider "user‑generated content" to be materials (text, image and/or video content) voluntarily supplied to us by our users for the purpose of publication on our website or re‑publishing on our social media channels. All user‑generated content is associated with the account or email address used to submit the materials.
Please be aware that any content you submit for the purpose of publication will be public after posting (and subsequent review or vetting process). Once published, it may be accessible to third parties not covered under this privacy policy.
Information shared with event organizers
When you register for an event or purchase a ticket on Patatix, we share the personal information you provide (such as your name, email, and ticket details) with the specific event organizer for that event. This is necessary for them to manage the event, check you in, and communicate updates to you.
Please note that the event organizer is a separate entity from Patatix Technologies Ltd. Their use of your data is governed by their own privacy practices. We are not responsible for the privacy practices of event organizers, and we encourage you to review their policies if you have concerns.
Legitimate reasons for processing your personal information
We only collect and use your personal information when we have a legitimate reason for doing so, as set out in the Kenya Data Protection Act, 2019. In such cases, we only collect personal information that is reasonably necessary to provide our services to you. Our lawful bases include:
- Consent from you – where you give us consent to collect and use your personal information for a specific purpose. You may withdraw your consent at any time using the facilities we provide; however, this will not affect any use of your information that has already taken place.
- Performance of a contract or transaction – where you have entered into a contract or transaction with us, or in order to take preparatory steps prior to our entering into a contract or transaction with you.
- Our legitimate interests – where we assess it is necessary for our legitimate interests, such as to provide, operate, improve and communicate our services.
- Compliance with the law – where we have a legal obligation to use or keep your personal information, such as for tax, accounting, or regulatory reporting purposes.
Collection and use of information
We may collect personal information from you when you do any of the following on our website:
- Register for an account
- Purchase a ticket or register for an event
- Sign up to receive updates from us via email or social media channels
- Post a comment or review or otherwise participate in our online community
- Use a mobile device or web browser to access our content
- Contact us via email, social media, or on any similar technologies
- When you mention us on social media
We may collect, hold, use, and disclose information for the following purposes, and personal information will not be further processed in a manner that is incompatible with these purposes:
- To provide you with our platform's core features and services
- To facilitate ticket purchases and event registrations
- To enable you to customize or personalize your experience of our website
- To deliver products and/or services to you
- To contact and communicate with you
- For analytics, market research, and business development, including to operate and improve our website, associated applications, and associated social media platforms
- To send you marketing and promotional communications. To opt out of these communications, please see "Your rights and controlling your personal information" below
- To enable you to access and use our website, associated applications, and associated social media platforms
- For internal record keeping and administrative purposes
- To comply with our legal obligations and resolve any disputes that we may have
- To attribute any content (e.g. posts and comments) you submit that we publish on our website
- For security and fraud prevention, and to ensure that our sites and apps are safe, secure, and used in line with our terms of use
- For technical assessment, including to operate and improve our app, associated applications, and associated social media platforms
We may combine voluntarily provided and automatically collected personal information with general information or research data we receive from other trusted sources. For example, our marketing and market research activities may uncover data and insights, which we may combine with information about how visitors use our site to improve our site and your experience on it.
Security of your personal information
When we collect and process personal information, and while we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use or modification.
Although we will do our best to protect the personal information you provide to us, we advise that no method of electronic transmission or storage is 100% secure and no one can guarantee absolute data security.
You are responsible for selecting any password and its overall security strength, ensuring the security of your own information within the bounds of our services. For example, ensuring any passwords associated with accessing your personal information and accounts are secure and confidential.
Notification of data breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, Patatix will notify the Office of the Data Protection Commissioner (ODPC) within 48 hours of detection, as required by Kenyan law. We will also notify affected users without undue delay where required.
How long we keep your personal information
We keep your personal information only for as long as we need to, in accordance with the purposes set out in this policy and in compliance with Kenyan law. For example:
- Account information: retained for the duration your account exists on our system plus a period of 12 months for backup and recovery purposes.
- Transaction data: retained for 7 years to comply with tax and accounting obligations under Kenyan law (e.g., Kenya Revenue Authority requirements).
- Marketing data: retained until you unsubscribe or withdraw your consent.
When your personal information is no longer required for these purposes, we will delete it or make it anonymous by removing all details that identify you. If necessary, we may retain your personal information for our compliance with a legal, accounting, or reporting obligation or for archiving purposes in the public interest, scientific, or historical research purposes or statistical purposes.
Children's privacy
We do not aim any of our products or services directly at children under the age of 18, and we do not knowingly collect personal information about children under 18. If we become aware that we have collected personal information from a child under 18 without parental or guardian consent, we will take steps to delete that information as soon as possible.
Disclosure of personal information to third parties
We may disclose personal information to:
- A parent, subsidiary or affiliate of our company
- Third‑party service providers for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, hosting and server providers, analytics, error loggers, debt collectors, maintenance or problem‑solving providers, professional advisors, and payment systems operators
- Our employees, contractors, and/or related entities
- Our existing or potential agents or business partners
- Credit reporting agencies, courts, tribunals, and regulatory authorities, in the event you fail to pay for goods or services we have provided to you
- Courts, tribunals, regulatory authorities, and law enforcement officers, as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise, or defend our legal rights
- Third parties, including agents or sub‑contractors who assist us in providing information, products, services, or direct marketing to you
- An entity that buys, or to which we transfer all or substantially all of our assets and business
Third parties we currently use include:
- Fathom Analytics – website analytics
- Stripe – payment processing
- Amazon Web Services – email delivery and cloud hosting
We ensure that all third parties who handle personal information on our behalf have appropriate data protection safeguards in place and are contractually bound to process data only in accordance with our instructions.
Your rights and controlling your personal information
Under the Kenya Data Protection Act, 2019, you have the following rights regarding your personal information:
- Right to be informed – you have the right to be informed of the collection and use of your personal information.
- Right of access – you may request details of the personal information that we hold about you.
- Right to rectification – if you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, you may request correction.
- Right to erasure – you may request that we delete your personal information, subject to legal exceptions.
- Right to restriction of processing – you may ask us to limit the processing of your personal information in certain circumstances.
- Right to data portability – you may request a copy of your personal information in a structured, commonly used, and machine‑readable format (e.g., CSV).
- Right to object – you may object to processing based on our legitimate interests or for direct marketing purposes.
- Right not to be subject to automated decision‑making – you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you.
How to exercise your rights
Please contact us using the details at the end of this policy. We will respond to your request within 30 days, as required by Kenyan law.
Marketing permission
If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by using the "unsubscribe" link in any marketing email or by contacting us.
Non‑discrimination
We will not discriminate against you for exercising any of your rights over your personal information. Unless your personal information is required to provide you with a particular service or offer (for example providing user support), we will not deny you goods or services and/or charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties, or provide you with a different level or quality of goods or services.
Complaints
If you believe that we have breached the Kenya Data Protection Act and wish to make a complaint, please contact us using the details below. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at any time.
Business transfers
If we or our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, we would include data, including your personal information, among the assets transferred to any parties who acquire us. You acknowledge that such transfers may occur, and that any parties who acquire us may, to the extent permitted by applicable law, continue to use your personal information according to this policy, which they will be required to assume as it is the basis for any ownership or use rights we have over such information.
Cross‑border data transfers
Patatix may transfer your personal information to servers located outside Kenya (for example, to cloud service providers in other jurisdictions). Any such transfer will be carried out in compliance with Section 48 of the Kenya Data Protection Act, 2019. We will ensure that appropriate safeguards are in place, such as:
- Adequate protection under the laws of the recipient country;
- Standard data protection clauses approved by the ODPC; or
- Your explicit consent to the transfer after being informed of the possible risks.
By using our services, you acknowledge that your personal information may be transferred to and processed in countries other than Kenya.
Limits of our policy
Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices.
Changes to this policy
At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here at the same link by which you are accessing this privacy policy.
If the changes are significant, or if required by applicable law, we will contact you (based on your selected preferences for communications from us) and all our registered users with the new details and links to the updated or changed policy.
If required by law, we will get your permission or give you the opportunity to opt in to or opt out of, as applicable, any new uses of your personal information.
Contact us
For any questions or concerns regarding your privacy, or to exercise any of your rights under the Kenya Data Protection Act, you may contact us using the following details:
Patatix Technologies Ltd
Data Protection Officer: dpo@patatix.com
Physical Address: Nairobi, Kenya
Email: privacy@patatix.com