Privacy Policy

Our website privacy policies and conditions of use are as stipulated below.

Last Updated: 18 August 2026

1. Who We Are

This Privacy Policy explains how FINSTOCK EVARSITY LIMITED collects, uses, stores, shares, protects, and retains personal data in line with applicable Kenyan law, including the Data Protection Act, 2019.

Controller details: FINSTOCK EVARSITY LIMITED, Jogoo Road Plaza, 1st Floor Suite T01, Along Jogoo Road, Next to United Petrol Station, Nairobi, Kenya. Contact: +254703313722 | info@finstockevarsity.com.

2. Scope of This Policy

This policy applies to data processed through our website, LMS/portal, internal and public APIs, support channels, communications tools (email/SMS/WhatsApp/chatbot), payment processing workflows, CRM activities, and related systems.

3. Personal Data We Collect

Depending on your relationship with us, we may collect:

  • Identity and contact data (name, phone, email, address, account identifiers).
  • Account and profile data (login details, preferences, cohort/program details).
  • Learning and academic records (enrollment, course progress, assessments, certification data).
  • Payment and billing records (invoices, transaction references, reconciliation records).
  • Communication records (support interactions, chatbot/WhatsApp/SMS/email metadata and logs).
  • Technical and security data (IP address, device/browser info, audit logs, API request logs).
  • Usage and analytics data (page events, feature usage, traffic and performance metrics).

4. How We Collect Data

  • Directly from you during registration, inquiry, enrollment, support requests, and account use.
  • Automatically via cookies, analytics tools, server logs, and security monitoring.
  • From integrations and service partners such as payment gateways and communication providers.

5. Why We Process Personal Data

We process personal data for lawful purposes, including:

  • Providing and managing education, certification, and support services.
  • Account authentication, fraud prevention, system administration, and security.
  • Billing, reconciliation, financial reporting, and compliance obligations.
  • Communicating service alerts, updates, reminders, and customer support responses.
  • Running analytics to improve platform quality, reliability, and user experience.
  • Managing API operations, abuse prevention, and operational troubleshooting.
  • Marketing and outreach in accordance with your preferences and applicable law.

6. Cookies and Similar Technologies

We use cookies and similar tools for session management, functionality, analytics, and operational performance.

Our current model enables cookies by default, with opt-out mechanisms where available. If you disable cookies, some features may not function correctly.

7. Analytics and Advertising Technologies

We may use analytics and related tools to measure usage, diagnose issues, and improve service delivery. These tools may process identifiers, cookie IDs, and event-level interaction data.

Where advertising technologies are used, we seek to align data usage with lawful and transparent practices under applicable law.

8. Communications, Internal API, and Cloud API Processing

To deliver communications and operational features, we may process personal data and metadata through integrated communication and cloud services (including WhatsApp Cloud API, email, SMS, chatbot, and API infrastructure).

We maintain operational logs for reliability, abuse prevention, security investigations, reconciliation, and compliance support.

9. Data Sharing and Recipients

We may share data with vetted service providers where necessary to operate our services, such as API providers, analytics tools, payment gateways, communication providers, cloud infrastructure services, and CRM tools.

We may also disclose data where required by law, legal process, court order, or regulatory obligation.

10. Data Retention

We retain user, learning, and payment records until a data subject submits a written deletion request, subject to legal/regulatory obligations and the need to verify academic credentials, including QR-based certificate verification.

We may retain chats, system logs, analytics records, and marketing data for up to 10 years where reasonably required for service integrity, audit, legal compliance, and dispute handling.

Where data is no longer required, we delete, anonymize, or securely archive it in line with our retention and security controls.

11. Data Security

We implement appropriate safeguards to protect personal data, including encryption of data in transit, access controls, and audit logging.

Although we apply reasonable measures, no transmission or storage system can be guaranteed 100% secure.

12. Your Rights Under Kenyan Data Protection Law

Subject to legal limitations and verification requirements, you may request to:

  • Be informed about processing of your personal data.
  • Access personal data we hold about you.
  • Correct inaccurate or incomplete personal data.
  • Object to certain processing activities.
  • Request deletion or restriction where legally applicable.

To exercise these rights, contact info@finstockevarsity.com. We respond in line with Kenyan practice and applicable legal timelines, typically within 30 days unless extension is lawfully required.

13. Children

Our services are intended for adults and are not directed to children under 18.

14. External Links

Our website may link to third-party sites and services. We are not responsible for external privacy practices, content, or data handling.

15. Policy Updates

We may revise this Privacy Policy from time to time. Updated versions will be published on this page with immediate effect unless stated otherwise.

16. Complaints and Regulatory Contact

If you have privacy concerns, contact us first at info@finstockevarsity.com so we can address them promptly. You may also escalate unresolved matters to the Office of the Data Protection Commissioner (Kenya), where applicable.

Hi,

WhatsApp Agent 1

WhatsApp Agent 1

WhatsApp us now!