1. Scope
This Privacy Policy applies to personal data processed through larexod.top. The site publishes educational content about diabetes and everyday health habits. It is not a clinic, does not provide individual medical treatment and should not be used to transmit medical records or emergency requests.
Kenya's Data Protection Act, 2019 establishes rules for processing personal data and rights of data subjects. The Data Protection (General) Regulations, 2021 provide additional detail on matters including consent, notices, rights requests and transfers. This policy is written to reflect the website's actual current implementation rather than describing services that are not enabled.
2. Controller identity and transparency
No legal company name, registration number or tax identifier was supplied for this website. We therefore do not invent or imply a corporate identity. The responsible website contact can be reached at [email protected], +254 722 485 556, and Kolloh Road, Nairobi, Kenya.
If the legal operator changes or formal company information becomes available, this policy should be updated before that information is represented as fact.
3. Categories of data we process
Information you choose to send
The contact form requests your name, email address, subject and message. You may also contact the website directly by email or phone. Please do not include health records, national identification numbers, payment-card data or other sensitive information unless there is a clear and lawful reason to do so.
Technical and security data
Web hosting normally requires servers to receive technical request information such as IP address, date and time, requested URL, referrer where sent by the browser, user-agent string, response status and security-event information. The website code does not create a marketing profile from this data, but hosting and security infrastructure may retain ordinary logs for operational security, abuse prevention and troubleshooting.
4. Purposes and lawful handling
Contact data is used to read, route and respond to your enquiry, protect the form from abuse, maintain an appropriate record of correspondence where necessary, and comply with legal obligations. We do not ask for contact-form consent to send unrelated marketing. If processing practices change, the notice and consent mechanism should be updated before the new purpose begins.
Kenyan data-protection principles include lawful, fair and transparent processing; purpose limitation; data minimisation; accuracy; storage limitation; and appropriate safeguards. The site is designed around those principles by collecting only the fields needed for ordinary correspondence.
5. Contact-form processing
When you submit the contact form, the server validates the name, email, subject and message, checks a hidden anti-spam field and a basic timing field, and then attempts to send the content by email to [email protected]. The current implementation does not send the enquiry to an affiliate partner, CRM or advertising platform.
The form contains a required privacy acknowledgement. The acknowledgement is not intended to convert every processing activity into consent-based processing; it confirms that you were shown this notice before sending your information.
6. Server logs and security
Access logs can be necessary to keep a website available and secure, investigate abuse, diagnose errors and understand whether systems are operating correctly. The exact log retention period depends on the hosting environment because hosting-provider configuration is not supplied in this project. The operator should review host settings and keep data no longer than necessary for the relevant operational purpose.
7. Cookies, localStorage and similar technologies
The current production code does not intentionally set advertising, analytics or personalisation cookies. It does not use localStorage to preserve the habit checklist or resource filters. The interactive checklist operates only in page memory and resets when the page is reloaded. The contact form does not require a PHP session cookie.
A hosting provider or network security layer may still use strictly necessary technical mechanisms outside this codebase. If non-essential cookies or storage technologies are introduced later, the Cookie Policy and consent controls must be updated before they are enabled.
8. Analytics, tag management, reCAPTCHA and maps
Google Analytics 4, Google Tag Manager, Cookiebot, Google reCAPTCHA and Google Maps are not active because no valid identifiers or configuration were provided. Empty integration hooks exist so real identifiers can be added later without redesigning the site. Their presence in configuration files does not mean those services are processing data now.
If any of these services are later enabled, the operator should reassess lawful basis, consent requirements, disclosures, international transfer safeguards and the information shown in this policy.
9. Recipients and processors
Contact messages may be processed by the website's hosting and email infrastructure because those services are necessary to transmit and store the message. No affiliate network or partner has been supplied and the current contact form does not send data to an affiliate partner. Personal data should not be sold or disclosed to unrelated third parties merely because they are commercial partners.
Service providers that process personal data on behalf of the operator should be selected and managed with appropriate contractual and security protections consistent with applicable law.
10. International transfers
The physical location of the hosting and email systems has not been provided. If personal data is transferred outside Kenya, the operator should ensure that the transfer meets the requirements of the Data Protection Act and applicable regulations, including appropriate safeguards or another valid transfer basis where required. The site does not claim that an adequacy decision or specific safeguard exists unless it has actually been established.
11. Retention
Contact correspondence should be retained only for as long as necessary to respond, manage follow-up, resolve a dispute, maintain security or meet an applicable legal obligation. Because the operator's email-retention system is not specified, this policy does not invent a fixed retention period. A practical retention schedule should be documented by the operator and reviewed periodically.
12. Security
The site uses server-side input validation, a honeypot field and a minimum form-completion time to reduce automated abuse. HTTPS should be enabled on the production host. No website can guarantee absolute security; the operator should maintain supported PHP/server software, restrict administrative access, use strong credentials and backups, and respond appropriately to security incidents.
13. Data-subject rights
Kenya's data-protection framework gives data subjects rights that include being informed about the use of personal data, accessing personal data held by a controller or processor, objecting to certain processing, requesting correction of false or misleading data, and requesting deletion in applicable circumstances. Additional rights and procedures may apply depending on the processing situation.
To make a privacy request about data held through this website, email [email protected] with enough information to identify the relevant correspondence. The operator may need to verify identity before disclosing or deleting data so that another person's information is not released improperly.
14. Children
The site is written for a general audience and is not designed to solicit personal information from children. If a child or guardian believes personal data was submitted inappropriately, contact the website so the situation can be reviewed.
15. Changes to this policy
This policy should change when the site's actual data flows change. Examples include enabling analytics, introducing an affiliate network, adding a CRM, changing hosting, adding user accounts, accepting health records or changing the contact process. Material changes should not be hidden behind an unchanged effective date.
16. Contact and complaints
Privacy questions can be sent to [email protected] or raised using the contact details above. Kenya's Office of the Data Protection Commissioner (ODPC) is the national authority responsible for the Data Protection Act framework and provides complaint and data-subject guidance. This website does not provide legal advice about whether a particular complaint will be accepted.