Privacy Policy

Your Privacy Matters

We are committed to protecting your personal information and privacy rights. This policy explains how we collect, use, and safeguard your data in compliance with the Kenya Data Protection Act 2019.

Last Updated: October 11, 2025

1. Introduction

Blink Star Consultants Limited ("we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (www.blinkstarconsultants.co.ke) or use our financial consultancy services.

We are registered with the Office of the Data Protection Commissioner (ODPC) in Kenya and comply with the Kenya Data Protection Act, 2019 (DPA). This policy also incorporates principles from the General Data Protection Regulation (GDPR) for our international clients.

By using our services or website, you consent to the data practices described in this policy. If you do not agree with this policy, please do not access or use our services.

2. Information We Collect

Personal Information You Provide

We collect information that you voluntarily provide when you:

  • Register for our services or create an account
  • Request information about our financial consulting services
  • Subscribe to our newsletter or blog updates
  • Contact us through forms, email, or phone
  • Engage us for accounting, tax, or advisory services
  • Participate in surveys or feedback requests

This information may include:

  • Personal identifiers: Name, email address, phone number, physical address
  • Business information: Company name, business registration number, KRA PIN, industry sector
  • Financial information: Bank account details, financial statements, tax records, payroll data
  • Identification documents: National ID, passport, business permits
  • Professional information: Job title, professional qualifications, business relationships

Automatically Collected Information

When you access our website, we automatically collect certain information through cookies and similar technologies:

  • Device information: IP address, browser type, operating system
  • Usage data: Pages visited, time spent on pages, click patterns, referring URLs
  • Location data: General geographic location based on IP address
  • Analytics data: Website performance metrics, user behavior patterns

Information from Third Parties

We may receive information about you from third parties such as business partners, service providers, public databases, and social media platforms when you interact with us through those channels.

3. How We Use Your Information

We use your personal information for legitimate business purposes, including:

Service Delivery

  • Providing accounting, bookkeeping, and financial advisory services
  • Processing tax returns and compliance filings
  • Conducting financial analysis and business intelligence
  • Managing payroll and benefits administration
  • Preparing audit documentation and support

Communication & Support

  • Responding to your inquiries and support requests
  • Sending service updates, appointment reminders, and important notices
  • Providing technical support and troubleshooting
  • Delivering newsletters and educational content (with your consent)

Business Operations

  • Processing payments and managing billing
  • Maintaining accurate client records and documentation
  • Improving our services and developing new offerings
  • Conducting internal research and analytics
  • Managing risk and preventing fraud

Legal Compliance

  • Complying with legal obligations under Kenya law
  • Meeting ICPAK, KRA, and other regulatory requirements
  • Responding to legal process and government requests
  • Enforcing our terms and conditions and protecting our rights

Marketing (With Consent)

  • Sending promotional materials about our services
  • Inviting you to events and webinars
  • Conducting surveys to improve client satisfaction

You may opt out of marketing communications at any time by clicking "unsubscribe" in emails or contacting us directly.

4. Legal Basis for Processing

Under the Kenya Data Protection Act 2019, we process your personal data based on the following lawful grounds:

  • Consent: You have given clear consent for us to process your personal data for specific purposes (e.g., newsletter subscriptions, marketing)
  • Contract Performance: Processing is necessary to fulfill our contractual obligations for services you have engaged us to provide
  • Legal Obligation: Processing is required to comply with legal obligations under Kenya law, including tax regulations, financial reporting standards, and anti-money laundering requirements
  • Legitimate Interests: Processing is necessary for our legitimate business interests, such as fraud prevention, network security, and improving our services, provided these interests do not override your rights

5. Data Sharing & Disclosure

We do not sell, rent, or trade your personal information. We may share your data only in the following circumstances:

Service Providers

We engage trusted third-party service providers who assist us in delivering our services, including:

  • Cloud hosting and data storage providers
  • Accounting and financial software platforms
  • Payment processors and banking partners
  • Email and communication service providers
  • Website analytics tools (e.g., Google Analytics)

These providers are contractually obligated to protect your data and use it only for the purposes we specify.

Regulatory & Legal Authorities

We may disclose your information to:

  • Kenya Revenue Authority (KRA) for tax compliance
  • Institute of Certified Public Accountants of Kenya (ICPAK) for professional oversight
  • Courts, law enforcement, or government agencies when legally required
  • Regulatory bodies investigating compliance matters

Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal information may be transferred to the acquiring entity, subject to the same privacy protections outlined in this policy.

Professional Advisors

We may share information with lawyers, auditors, insurers, and other professional advisors as necessary for business operations and legal compliance.

International Data Transfers

Some of our service providers (e.g., cloud hosting platforms) may process data outside Kenya. When transferring data internationally, we ensure adequate safeguards are in place, including:

  • Standard contractual clauses approved by data protection authorities
  • Ensuring recipients are located in countries with adequate data protection laws
  • Implementing technical and organizational security measures

6. Data Security

We implement robust security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction:

Technical Safeguards

  • 256-bit SSL/TLS encryption for data transmission
  • AES-256 encryption for data at rest on secure servers
  • Multi-factor authentication for system access
  • Regular security audits and penetration testing
  • Firewall protection and intrusion detection
  • Secure cloud infrastructure with redundant backups

Organizational Safeguards

  • Access controls limiting data access to authorized personnel only
  • Confidentiality agreements for all employees and contractors
  • Regular staff training on data protection and security best practices
  • Incident response plan for data breaches
  • Annual compliance audits and security assessments

Data Breach Notification

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Office of the Data Protection Commissioner within 72 hours as required by the Kenya Data Protection Act 2019.

While we implement industry-standard security measures, no system is completely secure. You are responsible for maintaining the confidentiality of your account credentials and should notify us immediately of any unauthorized access.

7. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this policy and comply with legal obligations:

  • Client Records: Financial records, tax documents, and client files are retained for a minimum of 7 years as required by Kenya tax law and ICPAK professional standards
  • Contract Documents: Engagement agreements and related correspondence are retained for the duration of the relationship plus 7 years
  • Marketing Data: Newsletter subscriptions and marketing preferences are retained until you opt out or request deletion
  • Website Analytics: Anonymized usage data is retained for 26 months
  • Inquiries: Contact form submissions and general inquiries are deleted after 2 years if no service relationship is established

After the retention period expires, we securely delete or anonymize your personal data in accordance with our data retention and disposal policy.

8. Your Privacy Rights

Under the Kenya Data Protection Act 2019, you have the following rights regarding your personal information:

1. Right to Access

You can request a copy of the personal data we hold about you, free of charge. We will provide this information in a commonly used electronic format within 30 days.

2. Right to Rectification

You can request correction of inaccurate or incomplete personal data. We will update your information promptly upon verification.

3. Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data, subject to legal and regulatory retention requirements. We will delete data that is no longer necessary for the purposes it was collected.

4. Right to Restriction of Processing

You can request that we limit how we use your personal data in certain circumstances, such as while we verify the accuracy of disputed information.

5. Right to Data Portability

You can request your personal data in a structured, commonly used, machine-readable format for transfer to another service provider.

6. Right to Object

You can object to processing of your personal data for direct marketing purposes or when processing is based on legitimate interests.

7. Right to Withdraw Consent

Where processing is based on your consent, you can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

8. Right to Lodge a Complaint

You have the right to file a complaint with the Office of the Data Protection Commissioner (ODPC) if you believe your data protection rights have been violated.

ODPC Contact: Office of the Data Protection Commissioner, Nairobi, Kenya | Website: www.odpc.go.ke | Email: info@odpc.go.ke

To Exercise Your Rights:

Contact our Data Protection Officer at: dpo@blinkstarconsultants.co.ke or +254 724 129 280. We will respond to your request within 30 days and may require verification of your identity before processing.

9. Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience and analyze website traffic.

Types of Cookies We Use

  • Essential Cookies: Required for website functionality, security, and session management
  • Performance Cookies: Collect anonymous data about how visitors use our site (e.g., Google Analytics)
  • Functional Cookies: Remember your preferences and settings
  • Marketing Cookies: Track your activity across websites for advertising purposes (only with your consent)

Managing Cookies

You can control cookies through your browser settings. Most browsers allow you to refuse cookies or delete existing cookies. Note that disabling cookies may affect website functionality.

Third-Party Analytics

We use Google Analytics to understand how visitors interact with our website. Google Analytics uses cookies to collect anonymous information such as page views, session duration, and traffic sources. You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on.

10. Children's Privacy

Our services are designed for businesses and adults. We do not knowingly collect personal information from individuals under the age of 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately, and we will delete the information from our systems.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you via email if you are an active client
  • Post a prominent notice on our website for 30 days
  • Request your consent if required by law for material changes

We encourage you to review this Privacy Policy periodically. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.

12. Contact Information

For questions, concerns, or requests related to this Privacy Policy or your personal data, please contact:

Data Protection Officer

Blink Star Consultants Limited

Trio Complex, Old EABL Building, Off Exit 7 Thika Road

Nairobi, Kenya

Email: dpo@blinkstarconsultants.co.ke

Phone: +254 724 129 280 | +254 726 911 912

Business Hours: Monday - Friday, 8:00 AM - 5:00 PM EAT

Regulatory Authority

If you are not satisfied with our response to your privacy concerns, you may contact:

Office of the Data Protection Commissioner

Nairobi, Kenya

Website: www.odpc.go.ke

Email: info@odpc.go.ke

Ready to transform your finances?

Let's build your financial
success story

Schedule a free consultation with our experts to discover how we can optimize your financial operations and accelerate your growth.

Or reach us directly

Trusted by

500+ businesses

4.9/5 average client rating

Empowering businesses with intelligent financial solutions and strategic insights.

Company

About Us

Services

Blog

Contact

Get in Touch

support@blinkstarconsultants.co.ke

Blinkstar Consultants. Nairobi, Kenya

Trio Complex, Old EABL Building,Off Exit 7 Thika Road.

© 2025 Blinkstar Consultants. All rights reserved.

PrivacyTermsLegal