Privacy and Data Protection Policy
Effective date: 30 July 2026
Last updated: 31 July 2026
1. Introduction
iD7 is a brand and business division of Creative Edge Ltd ("Creative Edge", "we", "us" or "our"). iD7 is not a separate legal entity.
Creative Edge respects your privacy and is committed to protecting your personal data.
This Privacy and Data Protection Policy explains how we collect, use, store, disclose and protect personal data when you:
- Visit or use the iD7 website at https://id7.co.ke/;
- Contact us or submit an enquiry;
- Complete a brief, request a proposal or ask about our services;
- Subscribe to marketing communications;
- Complete a publication self-audit, request a discovery call or download a podcast;
- Engage us as a client, supplier, partner or service provider; or
- Otherwise interact with us.
This policy is intended to support compliance with the Kenya Data Protection Act, 2019, the Data Protection (General) Regulations, 2021, and, where applicable, the EU General Data Protection Regulation (GDPR) and the UK GDPR.
2. Who We Are
For the purposes of applicable data-protection law, the data controller responsible for personal data collected through the iD7 website and services is Creative Edge:
Company: Creative Edge Ltd
3. Personal Data We Collect
Depending on how you interact with us, we may collect the following categories of personal data.
3.1 Identity and contact information
- Full name;
- Job title and organisation;
- Email address;
- Telephone number;
- Postal or physical address; and
- Other information you choose to include in an enquiry or brief.
3.2 Business and project information
- The services in which you are interested;
- Project objectives, requirements, scope, budget and timelines;
- Information about your organisation, systems, customers or operations;
- Communications, meeting notes and correspondence; and
- Proposal, contract, billing and relationship-management information.
Please avoid submitting confidential personal data about other people unless you are authorised to do so and the information is necessary for your enquiry.
3.3 Technical and usage information
- Internet Protocol (IP) address;
- Browser type and version;
- Device type and operating system;
- Time zone, language and approximate location;
- Pages visited, buttons selected and website interactions;
- Referral source, campaign information and advertising identifiers; and
- Cookie or similar-technology identifiers.
3.4 Marketing and communication preferences
- Your consent and subscription status;
- Preferred communication channels;
- Records of marketing messages sent to you; and
- Your responses to or interactions with those messages.
3.5 Publication interactions
- Your answers to publication self-audit questions when you choose to submit a call request;
- Your requested discovery-call date and time, which are preferences and not a confirmed appointment;
- Your WhatsApp number when you request a downloadable podcast;
- Your consent record and the podcast edition requested; and
- A pseudonymous identifier used to prevent repeated reader reactions and basic automated misuse.
3.6 Transaction and financial information
Where relevant to a commercial relationship, we may process:
- Billing details;
- Payment status and transaction references;
- Tax information; and
- Bank or payment information needed to make or receive payments.
We do not intentionally collect sensitive personal data through the website unless it is necessary, lawful and accompanied by appropriate safeguards.
4. How We Collect Personal Data
We may collect personal data:
- Directly from you, including through contact forms, progressive brief forms, email, telephone calls, meetings, contracts or events;
- Automatically, through cookies, analytics technologies, server logs and similar tools when you use our website;
- From your organisation, colleagues or authorised representatives;
- From public sources, including company websites, professional directories and professional social networks;
- From referral partners or service providers, where they are authorised to provide the information; and
- From advertising and analytics platforms, subject to your choices and applicable law.
5. How We Use Personal Data
We may use personal data to:
- Receive, review and respond to enquiries;
- Understand your needs and recommend relevant services;
- Prepare assessments, briefs, proposals, estimates and contracts;
- Deliver requested publications and respond to publication call requests;
- Record genuine reader reactions while limiting duplicate or automated submissions;
- Provide, administer and improve our services;
- Manage client, supplier and partner relationships;
- Communicate about projects, services and support;
- Process invoices, payments and business records;
- Operate, secure, maintain and improve our website;
- Measure website performance and understand how visitors use it;
- Attribute enquiries and conversions to relevant marketing activity;
- Send marketing communications where permitted;
- Detect, investigate and prevent fraud, misuse or security incidents;
- Exercise or defend legal rights;
- Meet legal, tax, regulatory and reporting obligations; and
- Carry out other purposes disclosed when the information is collected.
We will not use personal data for a materially incompatible purpose without providing appropriate notice or obtaining consent where required.
6. Lawful Bases for Processing
Depending on the circumstances and applicable law, we rely on one or more of the following lawful bases:
- Consent: You have freely given clear permission for a specific use of your personal data.
- Contract: Processing is necessary to take steps at your request before entering a contract or to perform a contract with you.
- Legal obligation: Processing is necessary to comply with an applicable legal or regulatory requirement.
- Legitimate interests: Processing is necessary for our legitimate business interests or those of a third party, provided those interests are not overridden by your rights and freedoms.
- Vital interests: Processing is necessary to protect a person's life or physical safety.
- Public interest: Processing is necessary for a task carried out in the public interest or under official authority, where applicable.
Our legitimate interests may include operating and improving our business, responding to enquiries, protecting our systems, managing commercial relationships, understanding service performance and marketing relevant business services.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
7. Cookies and Website Measurement
The iD7 website uses cookies and similar technologies for essential website functions and may use them for analytics, performance measurement and marketing attribution.
Creative Edge may use tag-management, analytics and advertising services to operate and measure the website. These may include services provided by Google or other approved providers.
Where consent is required, non-essential analytics or advertising technologies will not be activated until the appropriate choice has been made. You may change or withdraw your choices through the Cookie Settings control available on the website.
Full details—including the technologies used, their providers, purposes, categories and durations—are provided in the separate iD7 Cookie Policy, available through the website footer.
8. Direct Marketing
We may send you information about our services, events, insights or related business updates when:
- You have consented;
- Applicable law otherwise permits us to do so; or
- We have a relevant existing business relationship and a lawful basis for the communication.
You can unsubscribe at any time by:
- Selecting the unsubscribe link in a marketing email;
- Using the contact or preference mechanism provided with the communication; or
- Changing your communication preferences where that option is available.
We may retain limited information on a suppression list so that we can respect an unsubscribe request.
9. Sharing Personal Data
We may share personal data only where reasonably necessary and lawful, including with:
- Employees, contractors and authorised members of our group or wider business network;
- Hosting, cloud-storage, website, analytics, communication and cybersecurity providers;
- Customer relationship management, project management and productivity-platform providers;
- Professional advisers, including lawyers, accountants, auditors and insurers;
- Payment, banking and financial-service providers;
- Marketing and advertising providers, subject to applicable consent requirements;
- Prospective purchasers, investors or advisers in connection with a business transaction;
- Courts, regulators, law-enforcement agencies or other public authorities when required by law; and
- Other parties where you instruct us or provide consent.
Service providers that process personal data on our behalf are expected to use it only for authorised purposes, protect it appropriately and comply with applicable data-protection obligations.
We do not sell personal data.
10. International Transfers
Some service providers or systems may store or process personal data outside Kenya or outside the country in which you are located.
When personal data is transferred internationally, we will take reasonable steps to ensure the transfer is lawful and that appropriate safeguards are in place. Depending on the circumstances, these safeguards may include:
- An adequacy decision or approved country mechanism;
- Standard contractual clauses;
- Binding corporate rules;
- A legally permitted contractual or consent-based transfer mechanism; or
- Other safeguards recognised under applicable data-protection law.
You may contact us for more information about the safeguards used for relevant transfers.
11. Data Retention
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected and to meet legal, accounting, tax, contractual, security or reporting requirements. The appropriate retention period depends on the nature of the information, the reason it was collected, the applicable legal requirements and whether it is needed to establish, exercise or defend legal rights.
When personal data is no longer required, we will delete, anonymise or securely dispose of it, unless continued retention is legally permitted or required.
12. Data Security
We use reasonable administrative, organisational and technical safeguards designed to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These safeguards may include:
- Access controls and least-privilege permissions;
- Authentication and account-security measures;
- Encryption where appropriate;
- Secure hosting and transmission practices;
- Backups, monitoring and vulnerability management;
- Staff and contractor confidentiality obligations;
- Supplier due diligence and contractual safeguards; and
- Incident-response and breach-management procedures.
No internet transmission or storage system can be guaranteed to be completely secure. If we become aware of a qualifying personal-data breach, we will assess it and notify the relevant regulator and affected individuals where required by law.
13. Your Data-Protection Rights
Subject to applicable law and any lawful limitations, you may have the right to:
- Be informed about how your personal data is used;
- Request access to personal data held about you;
- Request correction of inaccurate or incomplete information;
- Object to certain processing;
- Request restriction of processing;
- Request deletion or erasure of personal data;
- Receive certain personal data in a structured, commonly used and machine-readable format;
- Request transfer of eligible information to another controller;
- Withdraw consent at any time where processing relies on consent;
- Object to direct marketing;
- Not be subject to a decision based solely on automated processing where it produces legal or similarly significant effects; and
- Lodge a complaint with a competent data-protection authority.
To exercise a right, submit a request through the contact facility on the iD7 website. We may ask for information needed to confirm your identity and understand your request. We will respond within the period required by applicable law.
We will not ordinarily charge a fee for a valid request. However, a reasonable fee may be charged, or a request may be refused, where permitted by law—for example, if it is manifestly unfounded, excessive or repetitive.
14. Automated Decision-Making
We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects on website visitors or prospective clients.
If this changes, we will provide appropriate information about the logic involved, the significance and likely consequences, and any rights available to you.
15. Children's Privacy
The iD7 website and services are intended primarily for organisations and adults. Creative Edge does not knowingly collect personal data from children through the website.
If you believe a child has provided personal data to us without appropriate authorisation, notify us through the contact facility on the iD7 website so that we can investigate and take suitable action.
16. External Links
Our website may contain links to third-party websites, platforms or services. We do not control their privacy practices and are not responsible for their content or handling of personal data.
We encourage you to review the privacy information of any third-party service you use.
17. Complaints
Questions or complaints concerning this policy or the processing of personal data may be directed to the Office of the Data Protection Commissioner of Kenya (ODPC):
Website: https://www.odpc.go.ke/
If the GDPR or another privacy law applies to your circumstances, you may also have the right to complain to the competent supervisory authority in your country of residence, place of work or the location of the alleged infringement.
18. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices, services, technology or legal obligations.
The latest version will be published on this page with an updated "Last updated" date. Where a change is significant, we may provide an additional notice where appropriate.
19. Company and Policy Enquiries
Company: Creative Edge Ltd
For questions regarding this data policy, please contact the Office of the Data Protection Commissioner of Kenya through the ODPC website.