1.Who we are and what this policy covers
Donjo is a video-first, proof-of-work hiring platform for Kenya and East Africa. This Privacy Policy explains how personal data is handled when you visit our website (https://donjoafrica.com) or use the Donjo application (https://hr.donjoafrica.com), together called the Service.
The controller of your personal data is [to be confirmed], of [to be confirmed] (company registration number [to be confirmed]). In this policy, "Donjo", "we", "us" and "our" mean that controller.
We handle personal data in line with the Kenya Data Protection Act, 2019 and its Regulations. Where the law of the European Economic Area or the United Kingdom applies to you, we also respect the GDPR and UK GDPR rights described below.
2.Definitions
- Personal data
- Any information that identifies you or can reasonably be linked to you.
- Processing
- Anything done with personal data, such as collecting, storing, using, sharing or deleting it.
- Controller
- The party that decides why and how personal data is processed. For the Service, that is Donjo.
- Processor
- A party that processes personal data on our behalf and on our instructions, such as a hosting provider.
- Applicant
- A person who creates a profile, records proof clips or applies to jobs, challenges or programmes.
- Employer
- An organisation or person who posts jobs or challenges and reviews applicants.
- Founder
- A person who submits a venture application to a programme.
- Admin or Reviewer
- A Donjo-authorised person who reviews applications and manages the Service.
- Proof content
- Videos, audio, images, pitch decks, documents and text you submit to the Service.
- ODPC
- The Office of the Data Protection Commissioner of Kenya.
3.Personal data we collect
What we collect depends on how you use the Service. We collect it from you directly, from your use of the Service, and (where you choose to use them) from sign-in providers.
| Category | Examples | Source |
|---|---|---|
| Account and profile | Name, username, email, password (stored hashed), account role, bio, skills, avatar, links | You |
| Proof content | Video and audio clips, thumbnails, titles and descriptions, pitch decks, privacy settings | You |
| Venture and application data | Venture name, stage, industry, problem and solution, traction, team role, job or challenge applications, cover messages | You |
| Employer and company data | Company name, size, industry, logo, website, job postings, challenges, shortlists and notes | You |
| Messages and notifications | Messages between employers and applicants, in-app notifications | You and other users |
| Location | County or country you choose to provide; approximate country derived from your time zone | You and your device |
| Usage and analytics | Pages viewed, referrer, campaign tags, device class, approximate country, interaction events | Your device (see Analytics) |
| Device and technical | Browser and operating-system family, language, screen size class, security logs, error reports | Your device |
| Passkey credentials | WebAuthn credential ID and public key, signature counter | Your device (public data only) |
| Contact and partnership requests | Name, organisation, email, phone, message you send through website forms | You |
| Enquiries by WhatsApp or email | Content of messages you send us | You |
We do not knowingly collect special categories of personal data (such as health, religion or ethnicity). Please do not include them in your proof content or messages unless you choose to. We do not collect payment card numbers on the website.
4.Passkeys and biometric data
Donjo supports passkeys (WebAuthn) as a way to sign in. When you use a passkey, your device (or password manager or security key) checks your fingerprint, face, PIN or pattern locally. That biometric information never leaves your device and is never sent to, or stored by, Donjo.
Donjo stores only the public part of the credential: a credential identifier, a public key and a signature counter. These cannot be used to reconstruct your biometrics. You can remove a passkey at any time in your account settings.
Passkey sign-in is being rolled out. Until it is available in your account, sign-in uses the methods shown on the sign-in page.
5.How and why we use personal data
We use personal data only for specified purposes and only where we have a lawful basis. The table below shows each purpose, the data involved, our lawful basis, how long we keep the data, and who it is shared with.
| Purpose | Data | Lawful basis | Retention | Shared with |
|---|---|---|---|---|
| Create and run your account | Account and profile, passkey credentials | Contract | While your account is active, then up to 30 days to complete deletion | Processors (hosting, storage) |
| Host and display your proof content | Proof content, profile | Contract; consent for public visibility | Until you delete it or your account | Employers, reviewers and the public, as you choose |
| Process applications, challenges and venture reviews | Application and venture data, proof content | Contract; legitimate interests | Until you delete your account or ask us to delete it | The employer or programme you applied to; Admins |
| Enable messaging and notifications | Messages, notifications | Contract | While your account is active | The other participants in the conversation |
| Generate applicant dossiers and reports | Names, roles, portfolio links | Legitimate interests; contract | Generated on demand; not retained by us | Authorised employers and Admins |
| Respond to enquiries and partnership requests | Contact and partnership requests | Legitimate interests; steps at your request | Until we delete it or you ask us to | Our team and hosting processors |
| Keep the Service secure and prevent abuse | Device and technical, security logs | Legitimate interests; legal obligation | Kept while needed for security and accountability | Processors; authorities where required by law |
| Understand and improve the Service (first-party analytics) | Usage and analytics (no IP address stored) | Legitimate interests; consent where required | A limited period set by administrators (90 days by default), then deleted | Not shared outside Donjo and its processors |
| Comply with the law and protect legal rights | Any data needed | Legal obligation; legitimate interests | As long as the law requires | Regulators, courts, advisers |
Where we rely on consent (for example to make a video public), you can withdraw it at any time. Withdrawal does not affect processing that happened before you withdrew.
Where we rely on legitimate interests, we weigh them against your rights and freedoms. You can object to this processing (see Your rights).
6.Your videos and who can see them
Video is at the heart of Donjo, so we give you control over it:
- Public videos appear on your profile and can be seen by anyone who can visit it, including employers.
- Private videos are visible only to you, unless you submit them to a specific job, challenge, venture application or programme, in which case the receiving employer, programme and authorised Admins can view them.
- Submitting proof to an employer or programme is your choice. You should only submit what you are comfortable sharing with them.
- Employers can shortlist applicants and add private notes. Those notes are visible to the employer and authorised Donjo staff, not to the applicant.
- Other viewers may like, comment on, or save public videos. Comments are visible with your username.
If you record other people, you must have their permission (see our Terms of Use). Tell us if content about you was posted without your permission and we will review it promptly.
7.Analytics
We aim to understand how the Service is used without tracking individuals. Where we run analytics, they are first-party (operated by us, not an advertising network), do not use cookies, and do not store your IP address. They record events such as pages viewed, the referring website, campaign tags, device class, approximate country (from your time zone) and interactions such as clicking a call-to-action.
- We respect the Do Not Track signal: if your browser sends it, we do not run analytics for you.
- An anonymous random identifier may be held in your browser's local storage so we can count repeat visits. It contains no personal data and you can clear it at any time.
- We filter obvious bots and do not build advertising profiles.
See the Cookie and Local-Storage Notice for details.
10.International transfers
Our providers may process data outside Kenya. Where we transfer personal data out of Kenya, we do so as the Kenya Data Protection Act, 2019 and its Regulations allow: to countries or providers with adequate safeguards, under contracts that require them to protect the data, or with your consent where required. For EEA and UK users, we use appropriate safeguards such as standard contractual clauses where needed.
The hosting region depends on how our providers are configured. Ask us for the current regions and safeguards.
11.How long we keep personal data
We keep personal data only as long as needed for the purposes above, then delete or anonymise it. Typical periods are shown in the table in the purposes section. In addition:
- When you delete your account, we delete or anonymise your profile and proof content within 30 days, except what we must keep by law or to resolve disputes.
- Backups are overwritten on a rolling basis and deleted data drops out of backups on that cycle.
- Content you submitted to an employer or programme may remain with them, under their own responsibilities as a controller, unless you ask them to delete it.
- Security and audit logs are kept for up to 12 months unless needed longer to investigate an incident.
12.How we protect personal data
We use technical and organisational measures appropriate to the risk, including:
- Encryption in transit (HTTPS/TLS) for the Service.
- Role-based access control: talent, employer, founder, investor, judge and admin accounts see only what their role requires.
- Server-side authorisation checks on admin actions, and audit logging of sensitive administrative activity.
- Passkey (WebAuthn) support to reduce reliance on passwords, and hashed storage for any passwords.
- Rate limiting and abuse controls on public forms.
- Security headers and hardening on the website and edge protection through our hosting provider.
- Limiting staff access to personal data to those who need it, under confidentiality duties.
No system is perfectly secure. Please use a strong, unique password or a passkey, and tell us straight away if you suspect unauthorised access.
13.Your rights
Under the Kenya Data Protection Act, 2019 (and, where applicable, the GDPR and UK GDPR) you have the right to:
- be informed about how your personal data is used (this policy);
- access the personal data we hold about you and receive a copy;
- ask us to correct inaccurate or incomplete data (rectification);
- ask us to delete your data (erasure) where there is no good reason for us to keep it;
- ask us to restrict processing in certain circumstances;
- receive your data in a commonly used, machine-readable format and have it transmitted to another provider where technically feasible (portability);
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent at any time, where processing is based on consent;
- not be subject to a decision based solely on automated processing that significantly affects you.
These rights are not absolute and some have exceptions, for example where we must keep data by law. We will explain if we cannot fully act on a request.
14.How to exercise your rights
Email [email protected] (or [to be confirmed] once a dedicated mailbox is in place), or message us on WhatsApp at +254 113 881 734. Tell us who you are and what you would like us to do. We may ask you to verify your identity to protect your data.
- We aim to respond within 30 days, and sooner where the law requires a shorter period.
- There is normally no charge. If a request is manifestly unfounded or excessive we may charge a reasonable fee or decline, and we will tell you why.
- You can also correct much of your data yourself in your account settings, and delete your videos and account there.
15.Automated decision-making
Donjo does not make hiring, shortlisting or selection decisions solely by automated means. People (employers, reviewers and Admins) watch proof content and make the decisions. Analytics and charts, such as cohort skill views, are informational aids based on tags that applicants provide, not automated ratings of a person.
16.Children
The Service is intended for people aged 18 and over. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
17.Personal data breaches
If a personal data breach occurs that is likely to result in a real risk of harm to your rights and freedoms, we will notify the ODPC within 72 hours of becoming aware of it where the law requires, and we will notify affected individuals without unreasonable delay, describing what happened and what you can do.
18.Complaints
We would like the chance to fix any concern first, so please contact us. You also have the right to complain to the Office of the Data Protection Commissioner (Kenya), at odpc.go.ke. If you are in the EEA or UK you may complain to your local supervisory authority.
19.Contact and data protection officer
- Controller: [to be confirmed]
- Address: [to be confirmed]
- Registration number: [to be confirmed]
- ODPC registration number: [to be confirmed]
- Privacy contact: [email protected] (dedicated DPO mailbox: [to be confirmed])
- WhatsApp: +254 113 881 734
20.Changes to this policy
We may update this policy as the Service or the law changes. The "Last updated" date at the top shows the current version. If we make material changes, we will give reasonable notice, by a notice in the app or on the website, before they take effect.