Privacy policy.
What data we collect, why we collect it, where it lives, who has access, and how to exercise your rights. Plain language. No dark patterns.
Last updated: [PLACEHOLDER — DATE]
1. Who we are
[PLACEHOLDER — JH legal review required] Jesus Helpers Children's Home is a registered Community-Based Organisation in Kenya, registration number [PLACEHOLDER — REG. NO.], with operational addresses at our three homes in Nyandarua, Uthiru, and Nakuru. We are the data controller for any personal data collected through this website.
2. What data we collect
We collect:
- Inquiry data: name, email, country, message body — when you submit the contact, partnership, or volunteer forms.
- Donation data: name, email, billing address, gift amount, currency, payment method reference (we do not see your card number — Stripe holds it).
- Sponsorship data: the same as donation data, plus the child name you choose to sponsor.
- Newsletter data: email address and (optional) first name.
- Operational data: IP address, user agent, request timestamps — automatically logged by our hosting and used for security.
3. Why we collect it
[PLACEHOLDER — JH legal review required] We use your data to: respond to your inquiry; process your donation or sponsorship; send you receipts and the welcome / quarterly / annual emails associated with your gift; send you the monthly newsletter you subscribed to; protect the website from abuse.
We do not sell, rent, or share your data with anyone outside the third-party processors listed below.
4. Lawful basis
[PLACEHOLDER — GDPR review required] We process your data on the following bases:
- Contract: processing donations and sponsorships you have asked us to process.
- Legitimate interests: sending donor stewardship emails, fraud detection, security logging.
- Consent: newsletter subscription, optional cookies (analytics).
- Legal obligation: retaining donation records for accounting and audit.
5. Third-party processors
We use the following processors:
- Stripe — payment processing. stripe.com/privacy
- Brevo (Sendinblue) — email delivery (receipts, newsletter, journey emails). brevo.com/privacy
- Cloudflare — content delivery, DDoS protection. cloudflare.com/privacy
- Google Analytics 4 — anonymised website analytics (only after consent).
- Safaricom Daraja — M-Pesa payments for Kenyan donors.
[PLACEHOLDER — confirm none additional] We do not use Facebook Pixel, LinkedIn Insight Tag, or other marketing pixels.
6. Retention
[PLACEHOLDER — JH legal review required] We retain donor records for the period required by Kenyan tax and accounting law (currently seven years from the last transaction). Newsletter subscribers are retained until they unsubscribe; on unsubscribe we keep only an irreversible hash of the email so we don't accidentally re-add them.
7. Your rights
You have the right to:
- Request a copy of the personal data we hold about you
- Correct any data that is inaccurate
- Have your data erased, subject to our legal retention obligations
- Object to specific processing, including marketing emails
- Lodge a complaint with the Kenyan Office of the Data Protection Commissioner
Email privacy@jesushelpers.org to exercise any of these rights. We respond within 30 days.
8. Cookies & analytics
[PLACEHOLDER — JH legal review required] We use a session cookie for security (CSRF protection on form submissions). It is essential and runs without consent. Analytics cookies (Google Analytics 4) only fire after you give consent through the cookie banner. You can withdraw consent at any time.
9. Children's data
[PLACEHOLDER — JH legal review required] Children's data is governed by our child safeguarding policy, which is stricter than this privacy policy. Public-facing pages display first name and year of birth only; full names and exact birth dates remain in internal records accessible only to authorised JH staff.
10. How to contact us
For privacy questions or to exercise your rights, email privacy@jesushelpers.org or write to: [PLACEHOLDER — postal address].