Privacy Policy
Internal use only. These applications are provided to authorised Vibrant Village Foundation staff, volunteers, contractors and partners for programme work. They are not a public service, and access is granted and withdrawn by the Foundation. The rules everyone with an account agrees to are the Terms of Service.
Who we are and what this policy covers
Vibrant Village Foundation (the Foundation) runs internal applications that support its programmes: education, agriculture, and savings and loans. This policy explains what information those applications hold, why the Foundation holds it, who can see it, how long it is kept, and the rights of the people it is about. It covers everyone with an account and everyone the programmes keep records about, and it applies to every application published under vvfkenya.org.
Information we hold
- Account and identity data: name, work email address, phone number, role and permissions, cluster or school assignment, sign-in identifiers, profile photograph, and whether the account is active.
- Programme data: the records users enter or upload: volunteer and learner details, attendance, assessments, trainings, savings and agriculture records, payments, documents, and the notes attached to them.
- Messages: SMS and email the applications send on the Foundation's behalf, their delivery status, and replies received.
- Usage, device and security data: sign-in times and outcomes, IP address, browser and device type, pages and features used, and the audit trail of changes made, including who made each one.
- Location data: where a feature depends on it, such as the GPS position recorded with an attendance check-in.
Information reaches the applications three ways: entered by users doing programme work, generated by the systems themselves (logs, delivery reports, the audit trail), or received from Google when someone chooses to sign in with a Google account, as the next clause sets out.
Signing in with Google
Where an application offers Continue with Google, using it gives that application three things about you from your Google account: your name, your email address and your profile picture. These come from the standard sign-in scopes (openid, email and profile), and they are the whole of what is asked for. No application here requests, receives or stores access to Gmail, Drive, Calendar, Contacts or anything else in your Google account, and nothing is read from it after the sign-in itself.
How it is used. What comes back is used to sign you in and nothing else: the email address is matched against the account an administrator has already created, and the name and picture become your profile inside the application. Signing in with Google does not create an account, and only vvf-kenya.org Workspace accounts are accepted.
How it is stored, protected and shared. The name, email address and picture received from Google are stored with the rest of your account data in the application's own database. They are transmitted only over encrypted connections (HTTPS), held on access-controlled infrastructure, reachable inside the application only by role, and covered by the same safeguards as the security clause below. They are shared with no one outside the Foundation beyond the service providers named in the sharing clause, who host and operate the applications on the Foundation's instructions and may not use the information for their own purposes.
How long it is kept, and how to remove it. This information is retained for as long as the account exists and is deleted, anonymised or archived on the same terms as the rest of your account data, set out in the retention clause below. You can withdraw the application's access at any time, and you can ask the Foundation to delete what it received from Google, under the rights clause below.
Limited use. Information received from Google is never sold or transferred to data brokers or information resellers, never used for targeted, personalised, retargeted or interest-based advertising, never used to determine creditworthiness or for lending purposes, and never used to develop, improve or train generalised artificial-intelligence or machine-learning models. The Foundation's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can withdraw an application's access to your Google account at any time from your Google account's security settings; password sign-in continues to work afterwards. You can also ask the Foundation to delete the name, email address and picture received from Google by making a request under the rights clause below, subject to the retention obligations that clause describes.
Why we hold it
To run the Foundation's programmes and the applications that support them: authenticating users and controlling access; recording programme activity; calculating and paying volunteer stipends; monitoring, reporting and evaluation; communicating with users and participants; keeping the systems secure and investigating misuse; and meeting the Foundation's legal, audit and donor obligations. Processing rests on the Foundation's legitimate interest in running its programmes, on the performance of each person's engagement with the Foundation, on legal obligation, and on consent where the law requires it. Aggregated and de-identified figures are used for reporting. Personal information held in these applications is never sold, and is not used for advertising or marketing.
Records about programme participants, including children
These applications hold records about people who are not users, including children enrolled in Foundation programmes: enrolment details, attendance, and assessment results. That information is collected from and through the programmes for delivery, monitoring and reporting under the Foundation's safeguarding and data-protection policies, and is handled with particular care: users may view it only where their role requires it, must not copy or share it outside approved workflows, and must never remove it from Foundation systems onto personal devices or accounts. The applications themselves are not directed at children and children are not given accounts.
Who can see it, and who it is shared with
Access within an application is limited by role and permissions, so users see the records their work requires rather than everything the system holds. Outside the Foundation, information is shared only with:
- Service providers that process it on the Foundation's behalf under confidentiality and security obligations: hosting and infrastructure, email delivery, and SMS delivery. They act on the Foundation's instructions and may not use the information for their own purposes.
- Programme partners and donors, where reporting requires it, and in aggregated or de-identified form wherever that serves the purpose.
- Authorities, where the law requires disclosure, or where disclosure is necessary to protect people, rights or safety.
Personal information is never sold, never rented, and never given to anyone for advertising.
Audit trail
Changes made in these applications are recorded: what changed, who changed it and when. This is deliberate and cannot be switched off by users: it is how errors are traced, how disputes about records are settled, and how misuse is detected. Assume your actions in the system are attributable to you.
Cookies
The applications set only the cookies they need to work: a session cookie that keeps you signed in, and the tokens that protect forms against forgery. There are no advertising cookies, no third-party trackers and no analytics cookies, and nothing follows you to other sites. Blocking cookies entirely will prevent signing in, because the session cannot exist without one.
How long we keep it, and deletion
Information is retained for as long as it is needed for the purposes above, including operational, audit, donor-reporting and legal requirements, after which it is deleted, anonymised or archived. Retention varies by record type: an access log is not kept as long as a payment record, and a payment record carries statutory retention of its own. When an account is closed it is deactivated rather than erased, because the audit trail and the programme records it signed must remain attributable; personal details no longer needed are removed on request under the rights clause below. Backups are retained on a fixed cycle and deleted data leaves them as that cycle turns over.
Security
The Foundation uses administrative, technical and organisational safeguards to protect this information: connections are encrypted in transit, access is limited by role, accounts are protected by two-factor authentication, sign-in activity is monitored, and changes are audit-trailed. No system is completely secure. Users must protect their own credentials, must not share accounts, and must report a suspected compromise or an accidental disclosure immediately. If a breach puts people's rights at real risk, the Foundation notifies the affected people and the regulator as the law requires.
Where it is processed
These applications and their backups are hosted with cloud providers whose infrastructure may sit outside the country the information was collected in. Where a cross-border transfer requires safeguards, the Foundation applies them, including contractual protections with the providers concerned.
Your rights
Subject to applicable law, including Kenya's Data Protection Act, 2019 where it applies, you may ask for: access to the personal information held about you; correction of what is inaccurate; deletion; a copy in a usable form; restriction of certain processing; or to object to processing that rests on legitimate interest. Requests go to the contact below. The Foundation may need to verify your identity, will answer within the time the law allows, and will say plainly if some information must be kept because a legal, audit or safeguarding obligation applies. If you are not satisfied with the answer, you may complain to the Office of the Data Protection Commissioner in Kenya, or to the authority where you are.
Changes to this policy
This policy is updated as the applications, the law or the Foundation's operations change; the revised version is published here with a new effective date, and a change that matters to how your information is handled is communicated rather than left to be discovered.
Contact
Privacy questions and requests, including about information received from Google, go to your Vibrant Village Foundation system administrator.