Legal

Privacy Policy

Last updated 13 August 2026

This explains what we collect, why, and what you can tell us to do about it. It is written to meet the Data Protection Act, 2019, and in plain language on purpose.

1. Who is responsible for your data

Digital Moran Academy is operated by Digital Moran, of Nairobi, Kenya. For the purposes of the Data Protection Act, 2019, we are the data controller for the personal data described here — we decide what is collected and why.

Questions, requests or complaints about your data go to info@digitalmoran.africa.

2. What we collect

Only what the service needs to work:

  • Your account. Name, email address, and a password stored only as a one-way cryptographic hash — we never hold your actual password and cannot recover it for you.
  • Your profile, if you fill it in. Photo, headline, short bio, phone number, location and website. All optional.
  • Your learning. Courses you enrol on, lessons completed, quiz attempts and scores, assignment submissions and the marks and feedback on them, and certificates issued.
  • Support messages. Tickets you open, our replies, and any screenshots you choose to attach.
  • If you sign in with Google. Your name, verified email address and profile photo. Nothing else, and we never receive your Google password.

We do not use advertising trackers, and we do not build behavioural profiles of you.

3. Why we are allowed to hold it

Section 30 of the Act requires a lawful basis for every use. Ours are:

  • Performance of a contract. Running your account, giving you the courses you enrolled on, marking your work and issuing your certificate.
  • Legitimate interests. Keeping the platform secure and working, and preventing fraud — balanced against your rights, which is why we collect as little as we do.
  • Consent. Marketing email, and listing your certificates in the public register. Both can be withdrawn at any time without affecting anything else.

4. Email, and how to stop it

When you create an account we subscribe you to academy updates. Every such email carries a working unsubscribe link, and one click removes you — you do not need to sign in or ask us.

You can also choose exactly which emails you receive under Settings → General: course updates, assignment feedback, event reminders and new-course announcements are each separate switches.

Some emails are not marketing and are always sent, because they are about your account or something you earned: password resets, your certificate, and replies to your support tickets.

5. Who else sees it

We do not sell your data. We never have and we will not. It is shared only with the processors that make the service run:

  • Google Firebase (Firestore) — stores the database.
  • Vercel — hosts the site and stores uploaded files.
  • Resend — delivers our email.
  • Google — only if you choose to sign in with Google.

We may also disclose data where the law requires it, and to professional advisers where necessary.

6. Data leaving Kenya

Our processors operate servers outside Kenya, so your data is transferred abroad. Sections 48 and 49 of the Act permit this where appropriate safeguards exist. Each of the providers above is bound by its own data-processing terms and operates under recognised protection frameworks. We choose established providers for exactly this reason.

7. How long we keep it

  • Your account and learning records — for as long as the account exists, and then deleted on request.
  • Certificates — kept indefinitely, so a certificate stays verifiable years later. That is the point of it.
  • Support tickets — two years after they close.

8. Your rights

Under section 26 of the Act you have the right to:

  • Be told how your data is used — this document.
  • Access a copy of it. You do not have to ask: Settings → Security → Download my data gives you everything we hold, as a file, immediately.
  • Correct anything inaccurate — your profile is editable at any time.
  • Delete your data. Email us and we will action it, other than records we are legally required to keep.
  • Object to a use, or ask us to restrict it.
  • Portability — the download is machine-readable JSON for exactly this reason.

We respond within seven days. If you are not satisfied, you may complain to the Office of the Data Protection Commissioner at odpc.go.ke.

9. Keeping it safe

  • Everything travels over HTTPS.
  • Passwords are stored as salted scrypt hashes, never in a readable form.
  • Session cookies are HTTP-only and signed, so they cannot be read or forged by scripts in your browser.
  • Access to the dashboards is checked on the server for every request, not merely hidden in the interface.
  • We take no payments at all, so there are no card or mobile-money details anywhere in this system to leak.

No system is perfectly secure. If a breach occurs that is likely to harm you, we will notify the Data Protection Commissioner within 72 hours and tell you without undue delay, as section 43 requires.

10. Children

Digital Moran Academy is for adults. We do not knowingly collect data from anyone under 18. If you believe a child has given us their data, tell us and we will delete it.

11. Cookies

We use one cookie: the session cookie that keeps you signed in. It is strictly necessary for the service to function, so it does not require consent. We set no advertising or analytics cookies. Your theme choice is stored in your own browser and never sent to us.

12. Changes

If we change this policy we will update the date at the top, and tell you by email if the change materially affects your rights.