Segmetrix Research
Legal

Privacy Policy

Last updated: July 21, 2026

This Privacy Policy explains how Segmetrix Research collects, uses, stores, shares, and protects personal data through the Segmetrix Research Panel. It is intended to reflect the Kenya Data Protection Act, the applicable Data Protection Regulations, and guidance issued by the Office of the Data Protection Commissioner.

1. Who We Are

Segmetrix Research operates the Segmetrix Research Panel for field research operations, surveyor onboarding, client project administration, verification, quality review, and summary reporting.

For panel account, surveyor, staff, and operational records, Segmetrix Research generally acts as a data controller because it determines why and how that personal data is processed. Where Segmetrix processes personal data strictly on behalf of a client under a research engagement, Segmetrix may act as a data processor for that client.

2. Personal Data We May Collect

Depending on your role and interaction with the panel, we may collect:

Some information, including gender, date of birth, and research responses, may require additional care depending on context. We do not intentionally collect sensitive personal data unless it is necessary for a lawful research purpose and appropriate safeguards are in place.

3. How We Collect Personal Data

We collect personal data directly from users during registration, login, profile updates, client setup, project administration, verification, support requests, and research activity. We may also receive information from authorized clients, managers, administrators, or research partners where this is lawful, necessary, and connected to an approved project.

4. Why We Use Personal Data

We process personal data for explicit, specified, and legitimate purposes, including to:

5. Lawful Bases for Processing

Depending on the activity, Segmetrix Research may rely on one or more lawful bases recognized under Kenyan data protection law, including consent, performance of a contract or pre-contract steps, compliance with legal obligations, legitimate interests that do not override the rights and freedoms of data subjects, public interest where applicable, and research or statistical purposes with appropriate safeguards.

Where processing depends on consent, you may withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal or processing that we must continue for another lawful reason.

6. Privacy Notice and Choice

Before collecting personal data, we aim to tell data subjects what data is being collected, why it is needed, whether it is mandatory or voluntary, who may receive it, the safeguards used, the relevant contact point, and the possible consequences of not providing required data.

7. Respondent and Research Data

Research data must be collected fairly, transparently, and only for approved study purposes. Surveyors must follow the study script, obtain required respondent consent, collect only necessary data, and protect respondent confidentiality.

Client access is intended to be summary-level. Raw respondent-level data should remain restricted to authorized internal users unless a separate lawful instruction, consent basis, and access control decision allows otherwise.

8. Children and Minors

Surveyor accounts are intended for adults. Where a research project involves children or minors, personal data may only be processed with appropriate parent or guardian consent, age-appropriate safeguards, and measures that protect the best interests of the child.

9. Sharing Personal Data

We may share personal data only where necessary and lawful, including with authorized Segmetrix staff, approved managers, client users with permitted summary access, service providers who support hosting, email, security, storage or technical operations, professional advisers, regulators, law enforcement, courts, or other authorities where required by law.

We do not sell personal data. Service providers that process personal data for us are expected to act under appropriate instructions and confidentiality, security, and data protection obligations.

10. Transfers Outside Kenya

If personal data is transferred or accessed outside Kenya, Segmetrix Research will take steps required by Kenyan data protection law, which may include assessing safeguards, using appropriate contractual protections, relying on recognized lawful grounds, or obtaining consent where required.

11. Data Security

We use reasonable technical and organizational measures to protect personal data, including role-based access, password hashing, email verification, audit logs, access restrictions, secure configuration, and operational review controls. No system can be guaranteed to be completely secure, but we work to reduce unauthorized access, loss, misuse, alteration, or disclosure.

12. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, unless a longer period is required or allowed by law, contract, audit needs, dispute resolution, legitimate operational purposes, or research and statistical purposes with safeguards. When personal data is no longer needed, we will delete, erase, anonymize, or pseudonymize it where appropriate.

13. Data Subject Rights

Subject to applicable law, you may have the right to be informed about how your personal data is used, access your personal data, object to processing, request correction of false or misleading data, request deletion where data is no longer lawfully retained, request restriction of processing, request data portability where applicable, withdraw consent, and challenge decisions based solely on automated processing where such decisions significantly affect you.

To exercise these rights, contact us using the details below. We may need to verify your identity before acting on a request. You may also contact or complain to the Office of the Data Protection Commissioner if you believe your data protection rights have been infringed.

14. Data Breaches

If a personal data breach creates a real risk of harm, Segmetrix Research will take steps to contain and assess the breach, notify the Office of the Data Protection Commissioner within the required timelines where applicable, and communicate with affected data subjects where required and reasonably practicable.

15. Legal Framework

This policy is guided by the Data Protection Act, Cap. 411C, the ODPC regulatory framework, and ODPC guidance on data subject rights, registration, consent, research processing, breach reporting, and data protection impact assessment.

16. Contact

Questions, privacy requests, or complaints can be sent to contact@segmetrix-research.com.

You may also contact the Office of the Data Protection Commissioner through its official website if you need regulatory guidance or wish to lodge a complaint.

17. Updates

We may update this Privacy Policy as the panel grows, the law changes, or our processing activities change. The latest version will be posted on this page.