Privacy Notice
Effective date: 26 July 2026. Version: 1.0.
This notice explains what personal data Creativ Razor collects through this website, why we collect it, what we do with it, and the rights you have over it. It is written to meet the duty to notify under section 29 of the Kenya Data Protection Act, 2019 and, for visitors in the European Economic Area and the United Kingdom, Articles 13 and 14 of the UK/EU General Data Protection Regulation.
We have written it in plain language on purpose. If anything here is unclear, ask us and we will explain it.
1. Who we are, and who is responsible
Creativ Razor is a brand and marketing studio in Nairobi, Kenya, operating as part of Brandflix BSI Limited. For the purposes of the Data Protection Act, 2019, Brandflix BSI Limited trading as Creativ Razor is the data controller for the personal data described in this notice. That means we decide what is collected and why, and we are accountable for it.
| Data controller | Brandflix BSI Limited, trading as Creativ Razor |
| Postal and physical address | Westlands, Nairobi, Kenya |
| hello@creativrazor.com | |
| Website | creativrazor.com |
2. Our data protection contact
We do not currently operate at a scale that requires us to appoint a designated Data Protection Officer under section 24 of the Act. All data protection matters are handled directly by the studio.
Send any question, request or complaint about your personal data to hello@creativrazor.com, with “Data protection” in the subject line. A named person will handle it and reply.
3. What we collect, why, and on what legal basis
We only collect what we need. Under section 30 of the Act, and Article 6 GDPR, every use of your data needs a lawful basis. Here is each one, stated separately.
| What we collect | When | Why | Lawful basis |
|---|---|---|---|
| Your name, email address, company name, the description of your project, the budget band you select, and how you heard about us | When you submit the brief or enquiry form | To read your enquiry, reply to it, ask follow-up questions and discuss whether we can do the work | Consent (s.30(1)(a) Act / Art. 6(1)(a)) for making the enquiry, and necessary for the performance of a contract or steps leading to one (s.30(1)(b)(i) / Art. 6(1)(b)) once we are in discussion |
| Your email address | When you subscribe to the journal | To send you the journal, and nothing else | Consent (s.30(1)(a) / Art. 6(1)(a)). You may withdraw it at any time |
| Your IP address, browser type and version, device type, operating system, the pages you request, timestamps, and the referring page | Automatically, whenever you visit | To keep the site running, diagnose faults, protect against attack and abuse, and understand which pages are read so we can improve them | Legitimate interests (s.30(1)(b)(vii) / Art. 6(1)(f)) in operating and securing our own website. For analytics specifically, see section 10 on cookies |
Is providing your data mandatory? No. Every form on this site is optional. If you choose not to complete one, you simply will not receive a reply or the journal. There is no other consequence, and you can still read everything on the site.
We do not collect sensitive personal data. We do not ask for, and you should not send us, information about your health, religion, ethnicity, political views, sexual orientation, biometric or genetic data, or your children’s information. Section 2 of the Act treats these as sensitive, and we have no reason to process them.
We do not take payment through this website. Any invoicing happens separately, under a signed engagement, and is covered by that agreement rather than by this notice.
4. What we never do
Stated plainly, because these are the questions people actually have:
- We do not sell your personal data. Not to anyone, at any price.
- We do not share it with advertisers or data brokers.
- We do not add you to a mailing list because you sent us an enquiry. Those are separate choices, and asking about a project is not consent to be marketed to.
- We do not use your project brief as a case study, an example or promotional material without asking you first, in writing.
5. Who else sees your data
We use a small number of service providers who process data on our behalf, as data processors under section 42 of the Act. Each is bound by contract to act only on our instructions.
These are given as categories of recipient, which is what section 29 of the Act and Article 13(1)(e) GDPR require. If you want the specific identity of a provider handling your data, ask us at hello@creativrazor.com and we will tell you.
| Provider | What they do | Where they process it |
|---|---|---|
| Our web hosting provider | Hosts the website and stores its server access logs | Within the European Union |
| Google LLC | Provides Google Analytics, which tells us in aggregate which pages are read | United States |
| Our email provider | Delivers and stores the email you send us | Within the European Union or the United States |
We may also disclose personal data where we are legally required to: to a court, to the Office of the Data Protection Commissioner, or to a law enforcement or regulatory body acting under lawful authority. We will not do so voluntarily or without checking that the request is valid.
If our business is ever sold or restructured, personal data may transfer to the acquiring entity. We would notify you before that happened and you would keep every right described in section 8.
6. Sending data outside Kenya
Part VI of the Act (sections 48 to 51) restricts transferring personal data out of Kenya. Two of our processing activities involve such a transfer, and we want to be specific rather than vague about it.
- Website hosting. Our hosting provider processes data within the European Union, whose data protection law provides safeguards the Act would recognise as appropriate.
- Google Analytics. Data is transferred to the United States and processed by Google LLC. This is the transfer most worth your attention, because United States law permits certain government access to data held by US providers. We rely on Google’s contractual commitments, including the European Commission’s Standard Contractual Clauses, as the safeguard. If you would rather this did not happen, section 10 explains how to prevent it, and doing so does not affect your use of the site.
We do not otherwise transfer personal data out of Kenya.
7. How long we keep things
We keep personal data only as long as it is doing the job it was collected for.
| Data | Retention period |
|---|---|
| Project enquiries that did not become work | 24 months from your last message, then deleted. Briefs often go quiet and return, which is why it is not shorter |
| Project enquiries that became a signed engagement | For the duration of the engagement and 7 years afterwards, to meet Kenyan tax and company record-keeping obligations |
| Journal subscription (your email address) | Until you unsubscribe, then deleted within 30 days |
| Server access logs | Up to 12 months, on our host’s rotation schedule |
| Google Analytics data | 14 months, the retention period we have configured |
When a period ends we delete the data or irreversibly anonymise it.
8. Your rights
Under section 26 of the Act, and Articles 15 to 22 GDPR, you have the following rights. They are free to use.
| Right | What it means |
|---|---|
| The right to be informed | To know how your data is being used. That is what this notice is for |
| The right of access | To get a copy of the personal data we hold about you, and to be told how and why we are using it. Sometimes called a subject access request |
| The right to rectification (correction) | To have inaccurate or incomplete data about you corrected |
| The right to erasure (deletion, sometimes called the right to be forgotten) | To have your personal data deleted where we no longer have a good reason to keep it |
| The right to object | To object to processing based on our legitimate interests, including analytics. If you object to analytics we will stop, and section 10 lets you enforce that yourself immediately |
| The right to restriction of processing | To ask us to pause processing while a dispute about accuracy or lawfulness is resolved |
| The right to data portability | To receive your data in a structured, commonly used, machine-readable format, or have it sent to another controller |
| The right to withdraw consent | To withdraw consent at any time, where consent is the basis. See section 9 |
| The right not to be subject to automated decisions | See section 11. We make none |
How to exercise them. Email hello@creativrazor.com. We will acknowledge within 7 days and respond substantively within 30 days, which is the period set by the Data Protection (Complaints Handling and Enforcement) Regulations. If a request is genuinely complex we will tell you before that deadline and explain the delay.
We may ask you to confirm your identity before we act, but only enough to be sure we are not disclosing your data to somebody else.
9. Withdrawing consent
Where we rely on your consent you can withdraw it at any time, and it must be as easy to withdraw as it was to give.
- Journal: click the unsubscribe link in the footer of any issue, or email us. It takes effect immediately.
- Enquiry: email us and ask us to delete your enquiry. We will, unless we are required to keep records of a signed engagement, in which case we will tell you exactly what we must retain and why.
- Analytics cookies: see section 10.
Withdrawing consent does not make our earlier processing unlawful, and it will never affect the quality of service you receive from us.
10. Cookies and tracking
A cookie is a small file a website stores in your browser. This site uses them for two purposes only.
| Cookie type | Purpose | Set by | Consent needed |
|---|---|---|---|
| Strictly necessary | Page caching so the site loads quickly, and security | Our own domain | No. The site cannot function without these |
| Analytics | Counting page views and understanding which content is read, in aggregate | Google Analytics | Yes |
We do not use advertising cookies, retargeting pixels, social media trackers or cross-site tracking of any kind.
How to refuse analytics. You can:
- Decline analytics cookies in the cookie banner, where one is presented.
- Install Google’s official browser opt-out add-on.
- Block or delete cookies in your browser settings. Every major browser allows this, usually under Privacy.
- Send a Global Privacy Control or Do Not Track signal, which we honour where our providers support it.
Blocking analytics cookies does not break the site. Everything remains readable.
11. Automated decision-making and profiling
We do not make any decision about you by automated means alone, and we do not profile you. No algorithm decides whether we take your project, what we quote, or how we respond to you. Every one of those is a decision made by a person.
Section 35 of the Act gives you the right not to be subject to a solely automated decision with significant effect. We have nothing of that kind to disclose.
12. Security, and what happens if it goes wrong
We protect personal data with measures appropriate to the risk: HTTPS encryption across the whole site, access limited to the people who need it, multi-factor authentication on the accounts that hold data, and a maintained host and platform.
No system is perfectly secure and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will:
- notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it, as section 43 of the Act requires; and
- notify you without undue delay, telling you what happened, what data was involved, what we are doing about it, and what you should do.
13. Children
This site is aimed at businesses and is not intended for children. We do not knowingly collect personal data from anyone under 18. Section 33 of the Act requires a parent or guardian’s consent to process a child’s data. If you believe a child has sent us information, email us and we will delete it.
14. Complaining
If you are unhappy with how we have handled your personal data, please tell us first at hello@creativrazor.com, because most issues can be fixed quickly and directly.
You do not have to come to us first, and you have the right to complain to the regulator at any time.
Office of the Data Protection Commissioner (Kenya) Britam Towers, 12th Floor, Hospital Road, Upperhill, Nairobi P.O. Box 30920-00100, Nairobi, Kenya Complaints: complaint@odpc.go.ke · General: info@odpc.go.ke Website and online complaint form: www.odpc.go.ke
If you are in the EEA or the UK, you may instead complain to your own national supervisory authority, or in the UK to the Information Commissioner’s Office at ico.org.uk.
You also retain the right to seek a judicial remedy in the Kenyan courts.
15. Changes to this notice
If we change how we handle personal data we will update this page, change the version number and effective date at the top, and describe the change below. For any material change we will give notice on the site before it takes effect, and where we hold your email address and the change affects you, we will tell you directly.
| Version | Date | Change |
|---|---|---|
| 1.0 | 26 July 2026 | First full notice, replacing placeholder text |