Website privacy notice

Home → Our Story → CFAO Mobility data privacy


1         Introduction

Your privacy is important to CFAO Mobility. Accordingly, we have developed this Privacy Notice (also referred to as “Notice”) to explain the following:

  • Who we are
  • The personal information we collect, use, store, share, or otherwise process, about customers and other individuals
  • Why we collect it
  • How you can exercise your privacy rights.

CFAO Mobility referred to as (‘‘we’’, ‘‘us’’ or ‘‘our’’) in this Privacy Notice is the Data Controller (registration number 751-6174-0BDF) responsible for your personal data.

By providing your personal data to us (whether via our website, by email, in person or over the phone), you agree to the processing set out in this Privacy Notice.

2         Contact Us

If you have any questions about:

  • This Privacy Notice
  • The use of your personal data
  • Or wish to request to exercise any of your rights

Please contact us using the following details:

By email:  LST-KE-3655-RISK-DEPARTMENT-GROUP@cfao.com

By post: CFAO Mobility Kenya Limited

Uhuru Highway, opposite Nyayo stadium

P.O Box 3391 – 00506

Nairobi

3         Personal Data We Collect from You

We shall collect your personal data with your knowledge and consent when you do any of the following:

  • Sales administration – purchase of a product or service, including but not limited to purchase of vehicles and parts, service of vehicles, service contract subscriptions and leasing of motor vehicles;
  • Subscribe to our newsletters or other marketing communications
  • Complete an online contact form;
  • Visit our website;
  • Attend our activations during marketing events;
  • Contact CFAO Mobility with a query or complaint;
  • Respond to or participate in a survey, marketing promotion, prize competition or special offer;
  • You apply for a job with us for recruitment purposes – either directly to us and/or sometimes from an employment agency or background check provider. We may sometimes collect additional information from third parties including former employers, credit reference agencies and/or other background credit agencies;
  • We may collect your information when you interact with us as a supplier, agent, merchant or dealer;
  • We also collect information when you visit any of our premises;
  • Call us or interact with us through social media, our email (we may record your conversations for quality assurance purposes);
  • We do not collect data for minors (any person under 18 years of age) except where you additionally consent and/or register on their behalf as their parent and/ or legal guardian. We shall have appropriate mechanisms in place for age verification and consent in order to process personal data of a child.
  • Provide us feedback.

Your access and/or use of any of the above constitutes your consent to collection and processing of your data and acceptance of the terms and conditions in this Notice.

4         What Information is Collected?

The information we collect and store about you may include but is not limited to the following:

  • Identity data – your name, title, date of birth, photograph, identity document type and number.
  • Contact data – email address, telephone number(s), location.
  • Demographic data – address, preferences or interests.
  • Vehicle registration details – number plate, chassis no., model
  • Financial data – your credit or debit-card information – information about your bank account numbers and SWIFT codes or other banking information for billing purposes.
  • Images, quotes and/or videos from which you may be identified – during marketing events or interviews
  • Identification and other background verification data such as a copy of passports or utility bills or evidence of beneficial ownership or the source of funds to comply with client due diligence/‘‘know your client”/anti-money laundering laws and collected as part of our client acceptance and ongoing monitoring procedures.
  • Recruitment related data such as your curriculum vitae, your education and employment history, details of professional memberships and other information relevant to potential recruitment with us.
  • Engagement data – which includes your views during and after the marketing activations & events, posts on social media and any feedback or comments submitted to us.
  • Technical data – includes Internet Protocol (IP) address, the date and time of your website visit, which pages you browsed and whether the pages have been delivered successfully, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
  • Profile Data – this includes feedback and survey responses.
  • Any personal data about you included in free text boxes when you complete our web
    forms; including in relation to enquiries or comments submitted to us.
  • If you visit our premises, for security reasons we might also record your data through video or other electronic, digital or wireless surveillance system or device (e.g. CCTV).

It is important the personal data we hold about you is accurate and up-to date. Please keep us informed of any changes to your personal data.

5         Use of Personal Information

The Data Protection law permits us to process personal information only if we have a valid legal basis to do so. We must have one of the following reasons:

  • Contract performance – where your information is necessary to enter into or perform our contract with you.
  • Legal obligation – where we need to use your information to comply with our legal obligations.
  • Legitimate interests – where we use your information to achieve a legitimate interest and our reasons for using it outweigh any prejudice to your data protection rights.
  • Consent – where you have consented to our use of your information (you will have been presented with a consent form or facility in relation to any such use and may withdraw your consent through an unsubscribe or similar facility).
  • Legal claims: where your information is necessary for us to defend, prosecute or make a claim against you, us or a third party.

In general, and subject to applicable law, including consent (as required), we may use your personal information for the following purposes as appropriate:

Purpose/Activity Type of Data Lawful basis of processing
Registration and delivery of products and services that you have bought from CFAO Mobility or from third parties such as dealers and service centers • Identity

• Contact

• Vehicle registration details

• Demographic

Contract performance
Billing – to recover any payments due to us and where necessary to enforce such recovery through the engagement of debt collection agencies or taking other legal action (including the commencement and carrying out of legal and court proceedings); • Identity

• Contact

• Financial

Contract performance

Legal claims

Legitimate interest

Respond to any of your queries or concerns • Identity

• Contact

• Demographic

Legitimate interests

To enter into a contract

Keep you informed generally about new products and services, events and contacting you with offers or promotions based on how you use our or third-party products and services. We will provide an option to unsubscribe or opt-out of further communication on any electronic marketing communication sent to you or you may opt out by contacting us. • Identity

• Contact

• Engagement

Legitimate interests

Consent

To comply with any legal, governmental or regulatory requirement or for use by our lawyers in connection with any legal proceedings • Identity

• Contact

 

Legal obligation
In business practices including quality control, training and ensuring effective systems operations • Identity

• Contact

• Technical

Legitimate interests
To use data analytics and to improve our website, services, marketing and customer experience • Contact

• Technical

Legitimate interests
For recruitment purposes – to enable us to process applications for employment submitted via the Careers section of our website and to assess your suitability for any position for which you may apply at CFAO Mobility • Identity

• Contact

Contract performance

Legitimate interests

Surveillance recordings • Identity Legitimate interests
To re-organize or make changes to our business -In the event that we undergo a re-organization (e.g. if we merge, combine or divest a part of our business), we may need to transfer some or all of your personal data to the relevant third party (or its advisors) as part of any due diligence process or transfer to that re-organized entity or third party your personal data for the same purposes as set out in this Privacy Notice or for the purpose of analyzing any proposed re-organization • Identity

• Contact

• Demographic

Legitimate interests

 

Where we are processing your personal data for our legitimate interests, you may object to the processing of your personal data.

 

6         Disclosure/Sharing of Your Personal Information

When necessary, we may share your personal data with:

  • Our dealers and authorized service centers who are involved in delivering CFAO Mobility products and services you order or use;
  • Tax, Government, and any relevant regulatory authorities if CFAO Mobility becomes aware of a violation of law or regulation;
  • Prosecuting authorities and courts, and/or other relevant third parties connected with legal proceedings or claims to which CFAO Mobility is a party;
  • Law-enforcement agencies with notification to you where possible;
  • Fraud prevention and Anti money laundering agencies, credit reference agencies;
  • Publicly available and/or restricted government databases to verify your identity information in order to comply with regulatory requirements;
  • Debt collection agencies or other debt-recovery organizations;
  • Survey agencies that conduct surveys on behalf of CFAO Mobility;
  • Some of your data may be passed on to third parties that host our mobile money payment platforms;
  • Any other person that we deem legitimately necessary to share the data with.

7         International Data Transfers

From time to time we may need to transfer your personal information outside the Republic of Kenya to our trusted manufacturers.

Where we send your information outside Kenya, we will make sure that the necessary safeguards are in place prior to transfer of such data and your data is properly protected in accordance with the applicable Data Protection Laws.

8         Retention of Personal Information

We will only retain your personal information for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

9         Safeguarding and Protection of Information

CFAO Motors has put in place technical and operational measures to ensure integrity, confidentiality and to protect your data from unauthorized access, accidental loss or destruction.

10      Your Data Privacy Rights and How to Exercise Them

Subject to legal and contractual exceptions, you have rights under data protection laws in relation to your personal data and we encourage you to exercise them as listed below:

  • Right to be informed: We are obliged to provide clear and transparent information about our processing activities of your personal data;
  • Right to access to your personal data: You have the right to understand what personal data we hold about you and why;
  • Right to request rectification of your personal data: If you believe that we hold inaccurate or incomplete personal data, you have the right to request us to rectify your personal data.
  • Right to request that we erase your personal data: You may ask us to delete or remove personal data
    where there is no good reason for us to continue to process it. Please note however that we may continue to retain it if obligated by the law or entitled to do so;
  • Right to request restriction of processing of your personal data: You may ask us to stop processing your personal data. We will still hold the data, but we will not process it any further. You may exercise the right to restrict processing when one of the following conditions applies:
  • The accuracy of the personal data is contested
  • Processing of the personal data is unlawful
  • We no longer need the personal data for processing, but the personal data is required as part of a legal process
  • The right to object has been exercised and processing is restricted pending a decision on the status of the processing
  • Right to data portability: You may request to receive your personal data or transfer to another data controller or processor, provided the data is in a structured, commonly used and machine-readable format.
  • Right to withdraw your consent: You may withdraw your consent at any time. However, your withdrawal won’t affect any processing already carried out before you withdraw your consent or processing under other grounds that mandate us by law to process your data.
  • Right to object: You have the right to object to our processing of your personal data where:
  • Processing is based on legitimate interest, unless the data controller or data processor demonstrates compelling legitimate interest for the processing which overrides the data subject’s interests
  • Processing is for the purpose of direct marketing

We may request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within reasonable time. Occasionally it could take us longer if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

11      Direct Marketing

You may be required to opt in or give any other form of explicit consent before receiving marketing messages from us. You can ask us to stop sending you marketing messages at any time by writing to us or logging onto our website, www.cfaomotors.co.ke and checking or unchecking relevant boxes to adjust your marketing preferences or by following the opt out links on any marketing message sent to you or by attending to us or contacting us at any time through the provided contacts.

Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of [a product, service already taken up, warranty registration, product or service experience or other transactions].

12      The Use of Cookies

We may store some information (using “cookies”) on your computer when you visit our websites to help you personalize your online experience. This enables us to recognize you during subsequent visits. The type of information gathered is non-personal (such as: The Internet Protocol (IP) address of your computer, the date and time of your visit, which pages you browsed and whether the pages have been delivered successfully).

We may also use this data in aggregate form to develop customized services – tailored to your individual interests and needs. Should you choose to do so, it is possible (depending on the browser you are using), to be prompted before accepting any cookies, or to prevent your browser from accepting any cookies at all. This will however cause certain interactive features of the website not to be accessible.

13      The Use of Hyperlinks

Our website may provide hyperlinks to other locations or websites on the internet. These hyperlinks lead to websites published or operated by third parties who are not affiliated with or in any way related to us and may have been included in our website to enhance your user experience and are presented for information purposes only.

We do not endorse, recommend, approve or guarantee any third-party products and services by providing hyperlinks to an external website or webpage and do not have any co-operation with such third parties unless otherwise disclosed. We are not in any way responsible for the content of any externally linked website or webpage.

By clicking on the hyperlink, you will leave the CFAO Mobility webpage and accordingly you shall be subject to the terms of use, privacy and cookie policies of the other website that you choose to visit.

14      Right to Lodge a Complaint

If you have any concerns about the use of your personal data or the way we handle your requests relating to your rights, you can raise a complaint directly with us by using the contact details provided in this notice.

If not satisfied with the way we handle your complaint, you are entitled to lodge a complaint directly with the Data Commissioner’s Office via the details provided on their website: www.odpc.go.ke

15      Applicable & Governing Law

Your data will be controlled and processed as per this Notice within the Republic of KENYA and therefore KENYAN law governs the operation and enforceability of this Notice.

16      Amendments to this Notice

CFAO Mobility reserves the right to amend or modify this Privacy Notice at any time to reflect changes in the law, our company, our Services, our data processing practices, customer/user feedback or advances in technology.

Notice Effective Date – 20 April 2023