Privacy notice
Draft pending legal review, 1 October 2026.
Our advocate has not yet reviewed this notice. Details in square brackets are still to be supplied. We will publish the reviewed notice here, with a new date.
Who we are
Mdzini ([legal entity name]) runs this website and a rent-support programme for college and university students. Mdzini decides why and how the personal data described here is used.
- Address: [physical address]
- Privacy contact: [data protection officer or contact person], [contact email]
- Registration with the Office of the Data Protection Commissioner (ODPC): [registration number or status]
What we collect now
- When you create a student account: your full name, email address, mobile number and a password. We never store your password; we keep only a one-way bcrypt hash of it. Your mobile number is stored encrypted.
- When you create an account: which version of this notice you confirmed you had read, and when.
- When you sign in: a session record kept on our server (your browser holds only a random session cookie), the country and city our hosting provider reports for your connection, and your chosen language. We do not store your IP address with your session.
- A random device identifier kept in a cookie on your device. We store only a keyed hash of it, with the dates it was first and last used, so that staff are told when their account is used from a new device.
- To protect accounts and the site: counts of attempts, stored under a keyed hash of your IP address or email address (never the address itself), and an audit record of account actions that holds a keyed hash of the IP address instead of the address.
- For each email we send you: its type, when it was sent and whether it was delivered, with your email address replaced by a keyed hash.
- Your language and colour-theme choices, kept in cookies on your device.
Vercel BotID checks that requests come from a real browser. It keeps its own values in your browser; they do not identify you.
What the application form collects
The application asks: whether you are enrolled, whether you rent off-campus and whether another programme covers your accommodation; your name, email address and mobile number; the type and name of your institution and your registration number; your year of study and HELB band; your household monthly income and number of dependants; your monthly rent and type of accommodation; your landlord’s name and phone number and the county you live in; the semester and academic year; your referee’s name, phone number, email address (optional), how you know them and where they work; other financial pressures (optional); and how rent affects your studies.
Your answers are saved on our server as you go, encrypted, under a random identifier kept in a cookie on your device. They are deleted when you submit, when you choose "Clear my answers", or 14 days after your last change. After you submit, phone numbers, email addresses, your other financial pressures and your statement are stored encrypted.
Your landlord’s and referee’s details are personal data about them. We use them only to check your application.
What we do not collect
We do not collect health information, national ID numbers, documents or photos, or payment details, and we do not take donations through this website. We use no advertising or tracking cookies, and we do not sell personal data. If any of this changes, we will update this notice first.
Why we use it
- To create your account and let you sign in.
- To email you about your account, such as confirming your email address or resetting your password, and about your application.
- To review applications for rent support. If your application goes forward, a field assessor visits your home to verify your situation. If it is approved, rent is paid directly to your landlord.
- To keep the service secure: limits on repeated attempts, checks for automated traffic, audit records and alerts about unusual sign-ins.
- To meet our legal obligations.
Our lawful basis
We use your data to provide the account and the application you ask for, and to keep the service secure. [Our advocate is confirming the lawful basis for each use under the Data Protection Act, 2019, as part of reviewing this notice.]
Who processes your data for us, and where
- Vercel Inc. (United States) hosts this website. Our server code runs in its Dublin, Ireland region. Its BotID service checks for automated traffic, its Speed Insights service measures how fast our pages load (the page address, the kind of device and browser, and timings, without cookies), and its storage will hold our encrypted backups.
- Turso keeps our database in Amazon Web Services’ Ireland region (eu-west-1).
- Brevo sends our emails.
Your personal data is therefore stored and processed outside Kenya: in Ireland, in the European Union, and by these providers where they operate. [The safeguards for these transfers are being confirmed in our advocate’s review.] Mdzini staff see personal data only as far as their role needs.
We do not yet use Tally (for contact forms) or Pay Hero (for donations). We will update this notice before we do.
How long we keep it
- Application answers saved as you go: deleted 14 days after your last change, or earlier as described above.
- Email-confirmation links expire after 24 hours and password-reset links after 1 hour.
- A signed-in session ends after 30 days without activity.
[How long we keep account records, applications, email records and security records is being set with our advocate.] Until those periods are stated here, we keep this data while your account exists, and you can ask us to delete it at any time.
Your rights
Under the Data Protection Act, 2019, you have the right to be told how your personal data is used, to see the personal data we hold about you and receive a copy, to object to its use, to have false or misleading data corrected, and to have it deleted.
To use these rights, email [contact email] from the address you used with us, saying what you are asking for. We will reply within [the time to be confirmed in the legal review].
When we delete your data at your request, we remove your name, your contact details and every encrypted field, and close your account. We keep only what records of applications and payments need to stay complete: identifiers, references, statuses, amounts and dates, without your personal details.
You can also complain to the Office of the Data Protection Commissioner (ODPC) at www.odpc.go.ke.
How we protect it
- Every page and request uses HTTPS.
- Passwords are stored only as bcrypt hashes. Phone numbers and, in applications, email addresses and written answers are encrypted before they reach the database.
- Staff sign in with a passkey, and each staff role sees only the records its work needs. Changes are recorded in an audit log that shows if it has been altered.
- Repeated attempts are limited, and automated traffic is checked.
No system is perfectly secure. If a breach of personal data puts people at risk, we will tell the ODPC within 72 hours of becoming aware of it and tell the people affected.
Changes to this notice
We will publish any change here with a new date and version.
Version: draft-2026-10-01b