Skip to content

Privacy Notice

Effective date: 26 July 2026. Version: 1.0.

This notice explains what personal data Creativ Razor collects through this website, why we collect it, what we do with it, and the rights you have over it. It is written to meet the duty to notify under section 29 of the Kenya Data Protection Act, 2019 and, for visitors in the European Economic Area and the United Kingdom, Articles 13 and 14 of the UK/EU General Data Protection Regulation.

We have written it in plain language on purpose. If anything here is unclear, ask us and we will explain it.

1. Who we are, and who is responsible

Creativ Razor is a brand and marketing studio in Nairobi, Kenya, operating as part of Brandflix BSI Limited. For the purposes of the Data Protection Act, 2019, Brandflix BSI Limited trading as Creativ Razor is the data controller for the personal data described in this notice. That means we decide what is collected and why, and we are accountable for it.

Data controller Brandflix BSI Limited, trading as Creativ Razor
Postal and physical address Westlands, Nairobi, Kenya
Email hello@creativrazor.com
Website creativrazor.com

2. Our data protection contact

We do not currently operate at a scale that requires us to appoint a designated Data Protection Officer under section 24 of the Act. All data protection matters are handled directly by the studio.

Send any question, request or complaint about your personal data to hello@creativrazor.com, with “Data protection” in the subject line. A named person will handle it and reply.

We only collect what we need. Under section 30 of the Act, and Article 6 GDPR, every use of your data needs a lawful basis. Here is each one, stated separately.

What we collect When Why Lawful basis
Your name, email address, company name, the description of your project, the budget band you select, and how you heard about us When you submit the brief or enquiry form To read your enquiry, reply to it, ask follow-up questions and discuss whether we can do the work Consent (s.30(1)(a) Act / Art. 6(1)(a)) for making the enquiry, and necessary for the performance of a contract or steps leading to one (s.30(1)(b)(i) / Art. 6(1)(b)) once we are in discussion
Your email address When you subscribe to the journal To send you the journal, and nothing else Consent (s.30(1)(a) / Art. 6(1)(a)). You may withdraw it at any time
Your IP address, browser type and version, device type, operating system, the pages you request, timestamps, and the referring page Automatically, whenever you visit To keep the site running, diagnose faults, protect against attack and abuse, and understand which pages are read so we can improve them Legitimate interests (s.30(1)(b)(vii) / Art. 6(1)(f)) in operating and securing our own website. For analytics specifically, see section 10 on cookies

Is providing your data mandatory? No. Every form on this site is optional. If you choose not to complete one, you simply will not receive a reply or the journal. There is no other consequence, and you can still read everything on the site.

We do not collect sensitive personal data. We do not ask for, and you should not send us, information about your health, religion, ethnicity, political views, sexual orientation, biometric or genetic data, or your children’s information. Section 2 of the Act treats these as sensitive, and we have no reason to process them.

We do not take payment through this website. Any invoicing happens separately, under a signed engagement, and is covered by that agreement rather than by this notice.

4. What we never do

Stated plainly, because these are the questions people actually have:

  • We do not sell your personal data. Not to anyone, at any price.
  • We do not share it with advertisers or data brokers.
  • We do not add you to a mailing list because you sent us an enquiry. Those are separate choices, and asking about a project is not consent to be marketed to.
  • We do not use your project brief as a case study, an example or promotional material without asking you first, in writing.

5. Who else sees your data

We use a small number of service providers who process data on our behalf, as data processors under section 42 of the Act. Each is bound by contract to act only on our instructions.

These are given as categories of recipient, which is what section 29 of the Act and Article 13(1)(e) GDPR require. If you want the specific identity of a provider handling your data, ask us at hello@creativrazor.com and we will tell you.

Provider What they do Where they process it
Our web hosting provider Hosts the website and stores its server access logs Within the European Union
Google LLC Provides Google Analytics, which tells us in aggregate which pages are read United States
Our email provider Delivers and stores the email you send us Within the European Union or the United States

We may also disclose personal data where we are legally required to: to a court, to the Office of the Data Protection Commissioner, or to a law enforcement or regulatory body acting under lawful authority. We will not do so voluntarily or without checking that the request is valid.

If our business is ever sold or restructured, personal data may transfer to the acquiring entity. We would notify you before that happened and you would keep every right described in section 8.

6. Sending data outside Kenya

Part VI of the Act (sections 48 to 51) restricts transferring personal data out of Kenya. Two of our processing activities involve such a transfer, and we want to be specific rather than vague about it.

  • Website hosting. Our hosting provider processes data within the European Union, whose data protection law provides safeguards the Act would recognise as appropriate.
  • Google Analytics. Data is transferred to the United States and processed by Google LLC. This is the transfer most worth your attention, because United States law permits certain government access to data held by US providers. We rely on Google’s contractual commitments, including the European Commission’s Standard Contractual Clauses, as the safeguard. If you would rather this did not happen, section 10 explains how to prevent it, and doing so does not affect your use of the site.

We do not otherwise transfer personal data out of Kenya.

7. How long we keep things

We keep personal data only as long as it is doing the job it was collected for.

Data Retention period
Project enquiries that did not become work 24 months from your last message, then deleted. Briefs often go quiet and return, which is why it is not shorter
Project enquiries that became a signed engagement For the duration of the engagement and 7 years afterwards, to meet Kenyan tax and company record-keeping obligations
Journal subscription (your email address) Until you unsubscribe, then deleted within 30 days
Server access logs Up to 12 months, on our host’s rotation schedule
Google Analytics data 14 months, the retention period we have configured

When a period ends we delete the data or irreversibly anonymise it.

8. Your rights

Under section 26 of the Act, and Articles 15 to 22 GDPR, you have the following rights. They are free to use.

Right What it means
The right to be informed To know how your data is being used. That is what this notice is for
The right of access To get a copy of the personal data we hold about you, and to be told how and why we are using it. Sometimes called a subject access request
The right to rectification (correction) To have inaccurate or incomplete data about you corrected
The right to erasure (deletion, sometimes called the right to be forgotten) To have your personal data deleted where we no longer have a good reason to keep it
The right to object To object to processing based on our legitimate interests, including analytics. If you object to analytics we will stop, and section 10 lets you enforce that yourself immediately
The right to restriction of processing To ask us to pause processing while a dispute about accuracy or lawfulness is resolved
The right to data portability To receive your data in a structured, commonly used, machine-readable format, or have it sent to another controller
The right to withdraw consent To withdraw consent at any time, where consent is the basis. See section 9
The right not to be subject to automated decisions See section 11. We make none

How to exercise them. Email hello@creativrazor.com. We will acknowledge within 7 days and respond substantively within 30 days, which is the period set by the Data Protection (Complaints Handling and Enforcement) Regulations. If a request is genuinely complex we will tell you before that deadline and explain the delay.

We may ask you to confirm your identity before we act, but only enough to be sure we are not disclosing your data to somebody else.

Where we rely on your consent you can withdraw it at any time, and it must be as easy to withdraw as it was to give.

  • Journal: click the unsubscribe link in the footer of any issue, or email us. It takes effect immediately.
  • Enquiry: email us and ask us to delete your enquiry. We will, unless we are required to keep records of a signed engagement, in which case we will tell you exactly what we must retain and why.
  • Analytics cookies: see section 10.

Withdrawing consent does not make our earlier processing unlawful, and it will never affect the quality of service you receive from us.

10. Cookies and tracking

A cookie is a small file a website stores in your browser. This site uses them for two purposes only.

Cookie type Purpose Set by Consent needed
Strictly necessary Page caching so the site loads quickly, and security Our own domain No. The site cannot function without these
Analytics Counting page views and understanding which content is read, in aggregate Google Analytics Yes

We do not use advertising cookies, retargeting pixels, social media trackers or cross-site tracking of any kind.

How to refuse analytics. You can:

  1. Decline analytics cookies in the cookie banner, where one is presented.
  2. Install Google’s official browser opt-out add-on.
  3. Block or delete cookies in your browser settings. Every major browser allows this, usually under Privacy.
  4. Send a Global Privacy Control or Do Not Track signal, which we honour where our providers support it.

Blocking analytics cookies does not break the site. Everything remains readable.

11. Automated decision-making and profiling

We do not make any decision about you by automated means alone, and we do not profile you. No algorithm decides whether we take your project, what we quote, or how we respond to you. Every one of those is a decision made by a person.

Section 35 of the Act gives you the right not to be subject to a solely automated decision with significant effect. We have nothing of that kind to disclose.

12. Security, and what happens if it goes wrong

We protect personal data with measures appropriate to the risk: HTTPS encryption across the whole site, access limited to the people who need it, multi-factor authentication on the accounts that hold data, and a maintained host and platform.

No system is perfectly secure and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will:

  • notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it, as section 43 of the Act requires; and
  • notify you without undue delay, telling you what happened, what data was involved, what we are doing about it, and what you should do.

13. Children

This site is aimed at businesses and is not intended for children. We do not knowingly collect personal data from anyone under 18. Section 33 of the Act requires a parent or guardian’s consent to process a child’s data. If you believe a child has sent us information, email us and we will delete it.

14. Complaining

If you are unhappy with how we have handled your personal data, please tell us first at hello@creativrazor.com, because most issues can be fixed quickly and directly.

You do not have to come to us first, and you have the right to complain to the regulator at any time.

Office of the Data Protection Commissioner (Kenya) Britam Towers, 12th Floor, Hospital Road, Upperhill, Nairobi P.O. Box 30920-00100, Nairobi, Kenya Complaints: complaint@odpc.go.ke · General: info@odpc.go.ke Website and online complaint form: www.odpc.go.ke

If you are in the EEA or the UK, you may instead complain to your own national supervisory authority, or in the UK to the Information Commissioner’s Office at ico.org.uk.

You also retain the right to seek a judicial remedy in the Kenyan courts.

15. Changes to this notice

If we change how we handle personal data we will update this page, change the version number and effective date at the top, and describe the change below. For any material change we will give notice on the site before it takes effect, and where we hold your email address and the change affects you, we will tell you directly.

Version Date Change
1.0 26 July 2026 First full notice, replacing placeholder text