Privacy Policy

NORTHGATE POLICY AND RESEARCH CENTER — Data Protection Notice

Effective: 1 January 2026  ·  Last updated: 10 June 2026

Contents

  1. Who we are and how to contact us
  2. What personal data we collect
  3. Why we collect it — lawful bases
  4. How we use your data
  5. Who we share your data with
  6. International transfers
  7. How long we keep your data
  8. How we protect your data
  9. Your rights under the Data Protection Act 2019
  10. Cookies
  11. Changes to this policy
  12. Contact and complaints

1. Who We Are and How to Contact Us

NORTHGATE POLICY AND RESEARCH CENTER ("Northgate Research", "we", "us", "our") is an independent research consultancy established in 2026 and based in Ruiru, Kiambu County, Kenya.

We are registered with the Office of the Data Protection Commissioner (ODPC) of Kenya as both a Data Controller and a Data Processor under the Data Protection Act 2019 (Cap. 411C).

Our Designated Data Protection Officer (DPO) is:

Data Protection Officer

Dr. David Mutabari
Director, Northgate Research & Policy Center

Email: davidmutabari42@gmail.com

Phone: +254 742 300 002

Post: Executive Apartment, Ruiru, Kiambu County, Kenya. P.O. Box 1598 – 00232.

2. What Personal Data We Collect

We collect personal data only where necessary to deliver our services or comply with legal obligations. The categories of data we may collect include:

2.1 Data you give us directly

2.2 Data we collect automatically

2.3 Data from research engagements (Service 04 / 05)

Where we conduct research on behalf of clients, we may process personal data about research participants. This data is governed by a separate Data Processing Agreement between Northgate and the commissioning organisation (the Data Controller). We process this data only on documented instructions from the client.

Note: We do not collect sensitive personal data (health, biometric, financial, or criminal records) about website visitors or service enquirers. Research participant data is handled under separate contractual arrangements.

3. Why We Collect It — Lawful Bases

Under the Data Protection Act 2019, we rely on the following lawful bases for processing:

PurposeLawful basis
Delivering a service you have booked and paid forPerformance of a contract
Responding to an enquiry or consultation requestLegitimate interests
Sending the Insights newsletter (where subscribed)Consent
Verifying M-Pesa paymentPerformance of a contract
Maintaining financial and tax recordsLegal obligation (KRA, Kenya Revenue Authority)
Protecting Northgate's legal rightsLegitimate interests
Processing research participant data on client instructionsData Processing Agreement / client's lawful basis

4. How We Use Your Data

We do not sell, rent, or trade your personal data. We do not use your data for automated decision-making or profiling that produces legal effects about you.

5. Who We Share Your Data With

We share personal data only where necessary and on a need-to-know basis:

5.1 Within Northgate

Only team members and associates who need access to deliver your engagement see your data. Every associate and enumerator signs a confidentiality agreement (NDA) before accessing client material.

5.2 Third-party service providers

Each provider is bound by their own privacy and data protection terms. We do not grant them access to data beyond what is technically necessary for the service.

5.3 Legal and regulatory

We may disclose data to ODPC, KRA, or law enforcement where required by Kenyan law, a court order, or a legitimate legal obligation.

6. International Transfers

Our primary operations are Kenya-based. Some of our service providers (Google Workspace, Meta/WhatsApp) may process data outside Kenya. Where this occurs, we rely on the safeguards established in those providers' standard contractual terms and, where applicable, adequacy decisions or other appropriate transfer mechanisms under the Data Protection Act 2019.

Where a research engagement involves international data transfer (e.g., data shared with a foreign institution), this is governed by a separate Data Processing Agreement with the commissioning organisation.

7. How Long We Keep Your Data

Data typeRetention period
Service enquiry (no engagement proceeds)6 months from last contact
Completed service engagement records5 years from engagement completion
Financial and payment records7 years (KRA legal obligation)
Newsletter subscriber dataUntil unsubscribed + 30 days
Website analytics (aggregated)12 months rolling
Research participant data (processed on client instructions)Per Data Processing Agreement with client

After the applicable retention period, we securely delete or anonymise personal data. You may request earlier deletion — see Section 9.

8. How We Protect Your Data

9. Your Rights Under the Data Protection Act 2019

As a data subject under Kenyan law, you have the following rights:

RightWhat it means
AccessRequest a copy of the personal data we hold about you
RectificationAsk us to correct inaccurate or incomplete data
ErasureAsk us to delete your data (subject to legal retention obligations)
RestrictionAsk us to limit how we use your data while a dispute is resolved
ObjectionObject to processing based on legitimate interests
PortabilityReceive your data in a machine-readable format
Withdraw consentWithdraw consent at any time where consent is the lawful basis (e.g. newsletter)

To exercise any right, email our DPO at davidmutabari42@gmail.com with subject line "Data Subject Request". We will respond within 21 days as required by the Data Protection Act 2019.

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at www.odpc.go.ke.

10. Cookies

Our website uses the following categories of cookies:

CategoryPurposeCan you opt out?
Strictly necessarySession management, form submission, securityNo — required for the site to function
AnalyticsAggregate page visit statistics (no personal identification)Yes — see below

We do not use advertising, tracking, or third-party social media cookies. Analytics cookies collect only aggregated, anonymised data about page visits. No individual user is identified.

To opt out of analytics cookies, you can use your browser's built-in cookie controls: Settings → Privacy → Cookies → Block third-party cookies. You can also use a browser extension such as uBlock Origin.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. The "Last updated" date at the top of this page will always show when the most recent change was made.

For material changes — those that significantly affect your rights or how we use your data — we will notify active clients by email at least 14 days before the change takes effect.

12. Contact and Complaints

For any privacy-related question, request, or complaint:

Contact our DPO

Email: davidmutabari42@gmail.com

WhatsApp: +254 742 300 002

Post: Dr. David Mutabari, Data Protection Officer
Northgate Research & Policy Center
P.O. Box 1598 – 00232, Ruiru, Kiambu County, Kenya

If you are not satisfied with our response, you may contact the ODPC:
www.odpc.go.ke  ·  P.O. Box 41270 – 00100, Nairobi