PRIVACY
Privacy Policy
This notice explains what personal data may be processed when you use pryntor.store, with particular attention to Kenya’s Data Protection Act, 2019 and related regulations.
Last updated: 6 October 2026.
1. Scope and identity
This Privacy Policy applies to pryntor.store. No legal company name, registration number or tax identifier was provided for publication. The published contact point is [email protected], with the address and telephone number stated on the Contact page. This notice does not invent an entity that has not been supplied.
2. Kenyan data-protection framework
The site is designed with the Kenya Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021 in mind. Those rules emphasise lawful, fair and transparent processing; purpose limitation; data minimisation; accuracy; storage limitation; security; and data-subject rights. Whether a particular statutory obligation applies in a specific operational situation can depend on facts outside this website build, such as who ultimately operates the hosting, email and analytics services.
3. Data you may provide directly
If you use the contact form, you may provide your name, email address, subject and message. The form is intended for website enquiries. Because health status is sensitive personal data under Kenya’s framework, the form specifically asks users not to send unnecessary medical details, identity numbers, laboratory reports or other sensitive records.
4. Technical data
Like most web servers, hosting infrastructure may generate operational logs containing IP address, requested URL, timestamp, user-agent string, response status and security events. The exact hosting provider and retention period were not supplied, so this policy does not claim a specific provider or fixed retention schedule.
5. Purpose and lawful basis
Contact data is used to receive, review and respond to enquiries, maintain site security, prevent spam and troubleshoot technical problems. Where consent is the applicable basis for a specific processing operation, it should be requested in a clear and specific manner. Other lawful grounds may apply depending on the operator’s actual circumstances and legal obligations.
6. Sensitive health data
Pryntor does not operate a patient portal and does not ask users to create medical profiles. A free-text contact message could nevertheless contain health information if a user chooses to type it. Users are asked not to do so unless genuinely necessary. Any operational deployment should apply additional safeguards appropriate to sensitive data.
7. Cookies and local storage
The current build uses local storage to remember the user’s cookie preference. GA4, GTM, Cookiebot and reCAPTCHA identifiers were not provided and are not active. If analytics or advertising technologies are added later, this policy and the Cookie Policy must be updated before or at the time they are activated.
8. Recipients and processors
Contact messages are intended to be delivered to [email protected] using the server’s mail capability. Hosting, email and security providers may process limited data as technical service providers, but their identities were not supplied for this build. We therefore do not name vendors that may not actually be used.
9. International transfers
Kenyan data-protection rules place conditions on transfers of personal data outside Kenya. If the deployed hosting, email or analytics infrastructure transfers personal data internationally, the operator should assess the destination, safeguards and applicable transfer mechanism. This build does not falsely state that all data stays in Kenya.
10. Retention
Personal data should be kept only as long as necessary for the purpose for which it was collected and for legitimate legal, security or dispute-resolution needs. Because the production email and hosting retention settings were not provided, this policy does not promise a fabricated number of days or months.
11. Your rights
Depending on the circumstances and applicable law, a data subject in Kenya may have rights to be informed, access personal data, object to processing, seek correction of false or misleading data, and seek deletion of false or misleading data. Requests can be sent to [email protected]. Identity verification may be required where appropriate before disclosing or changing personal data.
12. Security
The site uses server-side input validation, a honeypot field and minimal data collection in the contact form. Security also depends on the deployed server, TLS configuration, email service, software updates and access controls. No website can guarantee absolute security.
13. Children
This resource is intended for adults. It is not designed to solicit health information from children. If the operator becomes aware that personal data from a child has been collected in circumstances requiring parental or guardian authority, the appropriate legal and technical steps should be taken.
14. Complaints and regulator
Individuals may contact the Office of the Data Protection Commissioner (ODPC) regarding data-protection concerns where applicable. This site does not insert an external regulator link in the navigation; users can locate the ODPC through official Kenyan government channels.
15. Changes
This notice should be reviewed whenever forms, analytics, advertising, affiliate tracking, captcha, maps, hosting or email flows change. A materially different data flow should not be hidden behind an outdated policy.