Privacy

Privacy and cookie policy

How Tumeiva Marketing collects, uses and protects personal data, in line with Kenya’s Data Protection Act, 2019 and, where it applies, the EU General Data Protection Regulation (GDPR).

Last updated: October 2026

1. Who we are

Tumeiva Marketing (“Tumeiva”, “we”) is a digital marketing agency based in Nairobi, Kenya. For personal data collected through this website and in running our business, we are the data controller.

Contact: privacy@tumeiva.com · P.O. Box 23075–00505, Nairobi, Kenya.

2. What we collect

  • Enquiry form: name, email, phone number, company, services of interest, budget range and your message.
  • Free marketing plan form: name, email, optional WhatsApp number, and the business details you enter (industry, what you sell, customers, markets, goals, budget range, current marketing and challenges).
  • Communications: emails, WhatsApp messages and call notes when you contact us.
  • Website analytics (only with your consent): pages visited, device and browser type, approximate location and how you arrived, collected through Google Analytics.
  • Client and campaign data: covered separately in section 9.

We do not knowingly collect sensitive personal data through this website, and the site is not directed at children under 18.

3. Why we use it, and our lawful basis

  • To respond to enquiries and prepare proposals: steps you ask us to take before entering a contract.
  • To prepare and send your free marketing plan: your consent, given on the form.
  • To deliver services to clients: performance of our contract.
  • To send marketing emails or messages: only with your separate, opt-in consent. You can unsubscribe at any time, free of charge.
  • To understand how the website is used: your consent to analytics cookies.
  • To keep financial and tax records and meet legal duties: legal obligation.
  • To keep our website and systems secure: our legitimate interests.

4. How the free marketing plan is prepared

The details you enter in the plan form are sent to an AI service provided by Anthropic, which drafts a starter plan using our planning framework. The plan is advisory only: no decision with legal or similarly significant effect is made about you automatically. You can ask us to review or discuss any plan with a person.

5. Who we share data with

We do not sell personal data. We share it only with service providers that help us run the website and our business, under contracts that require them to protect it:

  • Truehost (Kenya): website hosting and business email.
  • Google (USA): website analytics, only with your consent.
  • Anthropic (USA): AI processing for the free marketing plan.
  • Make (EU): workflow automation that routes form submissions.
  • HubSpot (EU data centre): customer relationship management.
  • Meta / WhatsApp (USA): when you message us on WhatsApp.

We may also disclose data where the law requires it.

6. International transfers

Some providers process data outside Kenya. Where this happens, we rely on appropriate safeguards, such as the provider’s data processing terms and standard contractual protections, as required by the Data Protection Act.

7. How long we keep data

  • Enquiries and plan requests that don’t become clients: up to 24 months, then deleted.
  • Client records: for the duration of the engagement, plus financial records for as long as Kenyan tax law requires.
  • Marketing consent: until you unsubscribe or ask us to stop.
  • Analytics data: retained in Google Analytics for up to 14 months.

8. Your rights

Under the Data Protection Act you have the right to be informed about how your data is used, to access it, to object to its processing, to have inaccurate data corrected, to have false or misleading data deleted, and to data portability. Where GDPR applies, you also have rights to erasure, restriction and to withdraw consent at any time.

To exercise any right, email privacy@tumeiva.com. We will respond within the time required by law. If you’re unhappy with our response, you can complain to the Office of the Data Protection Commissioner (odpc.go.ke) or, in the EU, your local supervisory authority.

9. Client and campaign data

When we run marketing for clients, we often handle their customers’ data, for example leads, CRM records, audience lists and ad-platform data. For that data the client is the data controller and Tumeiva acts as a data processor. We:

  • process it only on the client’s documented instructions and for the agreed campaign purposes;
  • keep it confidential and limit access to people who need it to deliver the work;
  • work in client-owned ad, analytics and CRM accounts wherever possible, so clients keep control of their data;
  • use secure tools, strong passwords and two-factor authentication on the accounts we manage;
  • never use one client’s data for another client or for our own marketing;
  • return or delete client data at the end of an engagement, unless the law requires us to keep it;
  • notify the client without delay if we become aware of a personal data breach affecting their data.

10. Cookies

We use a small number of cookies and similar technologies:

  • Essential: remembering your cookie choice (stored in your browser). These don’t require consent.
  • Analytics (optional): Google Analytics cookies such as _ga, used to measure how the site is used. These are only set if you click “Accept”. Until then, Google Analytics runs in a restricted mode that sets no analytics cookies.

You can change your choice at any time using Cookie settings, or by clearing your browser’s cookies and site data.

11. Security

We use HTTPS across the website, access controls and two-factor authentication on our systems, and choose providers with recognised security practices. No system is completely secure, and if a breach is likely to put your rights at risk we will notify the Data Protection Commissioner and affected people as the law requires.

12. Changes to this policy

We may update this policy as our services or the law change. The date at the top shows the latest version.

Chat with us