Skip to main content

Impact Hub Nairobi

Privacy Policy

Last updated: 4 September 2026

This Privacy Policy explains how Impact Hub Nairobi (“IHN”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal data when you use the community platform at www.impacthubnairobi.com, related web applications, and any official mobile application (together, the “Platform”).

We designed this notice to meet a global standard of transparency, including the Kenya Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021, and — where they apply to you — principles aligned with the EU/UK GDPR, and US state privacy laws such as the California Consumer Privacy Act (as amended). Some rights apply only if the relevant law covers you.

Related documents: Terms of Service.

1. Who we are (data controller)

Impact Hub Nairobi is the data controller for personal data processed to operate the Platform, membership, events, and workspace operations described here.

Address: Impact Hub Nairobi, Muthangari Rd, Nairobi, Kenya
Privacy / general contact: nairobi@impacthub.net
Phone: +254 708 298 856

We are part of the global Impact Hub network. Other Impact Hub locations are typically independent organisations. We do not share your member profile with other hubs by default. Sharing with a network programme or partner happens only as described in this Policy (for example if you apply to that programme).

2. Scope

This Policy applies to:

  • members, invited users, and organisational contacts who create a Platform account;
  • people who book workspace, register for events, or submit applications or forms;
  • newsletter subscribers and people who email or call us;
  • visitors you host, where you provide their details for front-desk operations;
  • public website visitors (limited technical data such as logs and essential cookies).

It does not apply to third-party websites, payment-provider hosted checkout pages, or other organisations' processing after you leave the Platform, except for processors acting on our instructions.

3. Personal data we collect

Depending on how you use the Platform, we may process the following categories:

  • Identity and contact: name, email address, phone number, organisation, role, location, profile photo.
  • Account: hashed password, email verification status, session tokens, Terms acceptance timestamp, last active time.
  • Profile and community: member type, sector, skills, interests, availability, short intro, LinkedIn URL, project and venture information, connections and follows.
  • Membership and billing: plan or tier, invoices, payment status, payment provider references, and limited payment-method metadata (for example card brand and last four digits). We do not store full card PAN or CVV.
  • Workspace operations: bookings, check-ins, desk assignments, visitor records you submit (visitor name and optional email, phone, company, purpose, time).
  • Events and programmes: registrations, attendance, application answers, and related communications.
  • Communications: notification preferences, emails we send and related delivery events, support correspondence.
  • Technical: IP address, device/browser type, approximate location derived from IP, app version, crash or error logs, and security logs (for example rate-limit events).
  • Optional investor metadata if you choose to provide it (ticket size, sector focus, thesis). Treat this as sensitive commercial information; share only what you are comfortable making available to authorised community use.

We do not seek to collect special-category data (for example health, religion, or biometric templates) as a core Platform feature. If you include such data in a free-text field, we will process it only as needed to host that content and respond to your request.

4. How we obtain data

  • Directly from you — registration, onboarding, profile edits, bookings, payments, event sign-up, applications, and support.
  • From staff or an organisation — if you are invited as a member or named on an organisational account.
  • Automatically — cookies, sessions, server logs, and (in the mobile app) basic device information needed to run the app.
  • From payment providers — confirmation that a payment succeeded or failed, and limited card/M-Pesa metadata.
  • From you about others — visitor or teammate details you submit. You must have a lawful basis to provide another person's data (typically their knowledge and a legitimate operational need).

5. Why we use personal data

We use personal data to:

  • create and secure your account, verify email, and authenticate sessions;
  • complete onboarding and show you in the member directory as you configured;
  • process bookings, check-ins, visitors, memberships, invoices, and payments;
  • register you for events and programmes and send related operational updates;
  • enable connections, follows, project pages, and community features;
  • notify hub staff of operational events (for example new members, booking payments, programme applications) so they can deliver services;
  • send service emails and, where permitted, newsletters or community news;
  • improve safety, prevent fraud and abuse, and debug the Platform;
  • comply with legal, tax, accounting, and regulatory duties;
  • establish, exercise, or defend legal claims.

We do not sell your personal data.

7. Community directory and visibility

Authenticated members can typically see directory information such as your name, photo, organisation, role, sector, skills, interests, bio, and LinkedIn profile. Your mobile number is collected for hub staff operations and is not shown on the public or member directory.

Do not post contact details you are unwilling to share with other members. You can edit or remove most profile fields in Profile settings. Some operational records (bookings, invoices) remain visible to you and to authorised staff.

8. Sharing, processors and disclosures

We share personal data only as needed:

  • Other members — directory and content you choose to make visible; connection requests you send or accept.
  • IHN staff — community, programmes, space, and finance teams with role-based access.
  • Service providers (processors) acting on our instructions, including cloud hosting and content delivery (for example Vercel), database hosting (for example Neon), email delivery, image storage, error/security tooling, and payment processing (for example Paystack for card and M-Pesa). They may process data in Kenya or other countries where they operate.
  • Programme or event partners — only data you submit for that application or event, or that is necessary to deliver it.
  • Professional advisers and authorities — where required by law, court order, or to protect rights, safety, and security.
  • Business transfers — if we reorganise, transfer operations, or similar, data may transfer to the successor under equivalent protections.

We require processors to implement appropriate confidentiality and security measures. We do not allow them to use your data for their own unrelated marketing.

9. International data transfers

The Platform is operated from Kenya. Hosting, email, and payment providers may store or access data in other countries (including the European Economic Area, the United Kingdom, and the United States).

Where we transfer personal data out of Kenya, we do so in line with the Data Protection Act, 2019 (including adequacy, appropriate safeguards, or another lawful transfer mechanism). Where GDPR applies, we use appropriate safeguards such as standard contractual clauses with processors where required.

10. Cookies and similar technologies

We use essential cookies and similar storage to keep you signed in, protect against abuse (for example rate limiting), and remember session state. These are necessary for the Platform to function.

We do not use third-party advertising cookies or sell browsing data to ad networks. Embedded third-party content (for example maps or payment checkout) may set their own cookies under their policies.

You can block cookies in your browser; essential cookies cannot be disabled without breaking sign-in. The mobile app uses local storage and secure session tokens rather than browser cookies.

11. Payments

When you pay for membership, bookings, or other fees, you are redirected to or processed by a regulated payment provider (currently including Paystack). Card data is entered on the provider's systems. We receive payment status, amount, currency, and limited method metadata.

The provider is an independent controller or a processor depending on the transaction. Read their privacy notice before paying. M-Pesa transactions are also subject to the mobile-money operator's terms.

12. Retention

We keep personal data only as long as needed for the purposes above, including:

  • Account and profile — for the life of the account, then deleted or irreversibly anonymised after a short winding-up period unless law requires longer.
  • Bookings, invoices, and payments — typically for the statutory accounting and tax period in Kenya (often up to seven years).
  • Security and server logs — for a limited period to investigate incidents and abuse.
  • Newsletter data — until you unsubscribe, plus a minimal suppression record so we do not email you again.

When you delete your account from Profile (or we delete it on request), we remove or anonymise profile, community, and login data that is not required for legal, security, or financial records.

13. Security

We use technical and organisational measures appropriate to the risk, including HTTPS, hashed passwords, role-based staff access, and rate limiting. No method of transmission or storage is 100% secure. Please use a unique password and tell us promptly of suspected unauthorised access.

In the event of a personal-data breach that meets the legal threshold, we will notify the Office of the Data Protection Commissioner and affected individuals as required by Kenyan law, and other authorities where applicable.

14. Children

The Platform is for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.

15. Your rights

Subject to the Kenya Data Protection Act and any other law that applies to you, you may have the right to:

  • be informed about how we process your data (this Policy);
  • access a copy of personal data we hold about you;
  • rectify inaccurate or incomplete data (you can edit much of this in Profile);
  • erase data in the circumstances the law allows (including account deletion);
  • restrict or object to certain processing;
  • data portability, where technically feasible and legally required;
  • withdraw consent where processing is based on consent;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except as the law allows;
  • lodge a complaint with a supervisory authority (see section 20).

To exercise rights, email nairobi@impacthub.net from your account email, or use in-product tools (Profile edit, notification settings, account deletion, newsletter unsubscribe). We may need to verify your identity. We will respond within the time required by applicable law (under the Kenya DPA, generally without undue delay and within statutory limits).

We may refuse or charge a reasonable fee for requests that are manifestly unfounded, excessive, or repetitive, as the law permits.

16. Automated processing

We may use limited automated logic to assign membership tiers from plan payments, send reminders, or recommend community content. These processes do not produce legal effects comparable to credit scoring or automated refusal of a fundamental right. Staff remain involved in programme admissions, partnership decisions, and enforcement actions.

17. Marketing and newsletters

Transactional and service messages (verification, bookings, payments, security) are sent because they are necessary to perform the contract.

Community members are subscribed to the Impact Hub Nairobi newsletter when they create or activate an account (lawful bases: contract and consent given at registration). Newsletter emails include an unsubscribe link. Unsubscribing from the newsletter does not stop service messages while your account remains open.

Other marketing emails are sent only with a lawful basis (typically additional consent) and include an unsubscribe mechanism.

18. Third-party sites and SDKs

Links, maps, calendars, and payment pages are operated by third parties with their own privacy notices. The mobile app may use platform services provided by Apple or Google (for example push delivery). Those providers process data under their terms.

19. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date will change. For material changes, we will take reasonable steps to notify you (email or in-product notice). Continued use after the effective date means you acknowledge the updated Policy.

20. Complaints and supervisory authorities

Please contact us first so we can try to resolve your concern. You also have the right to complain to:

  • Kenya: Office of the Data Protection Commissioner (ODPC) — www.odpc.go.ke
  • EEA/UK: your local data protection authority, if GDPR/UK GDPR applies to the processing.

21. Contact

Data controller: Impact Hub Nairobi
Impact Hub Nairobi, Muthangari Rd, Nairobi, Kenya
nairobi@impacthub.net · +254 708 298 856
Website: nairobi.impacthub.net

See also our Terms of Service.