Data Privacy and Governance Policy

Effective Date: 08 May 2026. Policy Version: 1.0.

1. Introduction

Tetherlink Consulting Data Privacy and Governance Policy is committed to protecting the privacy, confidentiality, integrity, and security of all information entrusted to the Company. As a multidisciplinary consultancy operating across agriculture, livestock production, entrepreneurship, information and communication technology (ICT), market systems, circular economy, research, and capacity development, Tetherlink Consulting recognizes that information is one of its most valuable strategic assets. Responsible information governance is fundamental to stakeholder trust, regulatory compliance, and sustainable growth.

This Policy establishes the framework through which Tetherlink Consulting collects, creates, receives, records, processes, stores, uses, shares, transfers, retains, archives, and securely disposes of personal data and other information assets throughout their lifecycle. It integrates privacy, data protection, cybersecurity, records management, and the responsible use of Artificial Intelligence into a single governance framework aligned with Kenyan law and internationally recognized best practices.

Tetherlink Consulting acknowledges that privacy is a fundamental human right and that effective governance extends beyond legal compliance. Strong leadership, clear accountability, sound risk management, secure systems, and continuous improvement all contribute to the responsible stewardship of information. Every person who handles information on behalf of the Company shares responsibility for upholding the standards described in this Policy.

2. Purpose

The purpose of this Data Privacy and Governance Policy is to establish consistent, enforceable standards for the management and protection of information across all operations of Tetherlink Consulting. It defines the principles, responsibilities, and controls that guide lawful, ethical, and secure information handling from collection through disposal.

Specifically, the Policy seeks to safeguard the privacy and rights of individuals whose personal data is processed. It protects confidential business information, intellectual property, research outputs, and project records against unauthorized access, disclosure, alteration, or destruction. It supports compliance with applicable legal, regulatory, and contractual obligations affecting the Company’s work.

The Policy also strengthens cybersecurity resilience across websites, cloud services, and internal systems. It promotes the ethical and accountable use of AI and emerging technologies. Finally, it fosters a culture of privacy, security, accountability, and continuous improvement throughout the organization and among the partners who work with Tetherlink Consulting.

3. Scope

This Policy applies to all information collected, generated, received, processed, stored, transmitted, or otherwise handled by or on behalf of Tetherlink Consulting, regardless of format, source, storage location, or method of processing. It covers electronic, digital, cloud-based, physical, and hybrid records maintained in any environment operated by or for the Company.

Covered records include databases, websites, email systems, collaboration platforms, mobile devices, portable media, printed documents, photographs, audio and video recordings, contracts, financial records, research data, agricultural and livestock datasets, and consultancy deliverables. The Policy also extends to any future technologies, systems, or platforms adopted by Tetherlink Consulting.

The Policy binds all directors, employees, consultants, contractors, interns, volunteers, and project personnel. It equally binds any third party authorized to process information on behalf of Tetherlink Consulting, including cloud service providers, software vendors, subcontractors, professional advisers, and strategic partners.

It further applies to information relating to clients, prospective clients, suppliers, government agencies, development partners, donors, project beneficiaries, farmers, entrepreneurs, trainees, workshop participants, job applicants, website visitors, and any other identifiable individual whose information the Company processes. Where contractual or legal obligations impose stricter requirements than this Policy, the stricter standard shall prevail to the extent permitted by law.

4. Guiding Principles

Tetherlink Consulting manages information according to internationally recognized principles of responsible data governance. Lawfulness requires that information is processed only where a valid legal basis exists. Fairness requires that processing respects the dignity, rights, and reasonable expectations of individuals. Transparency requires that individuals receive clear, accessible information about how their data is collected, used, shared, and protected.

Purpose limitation means information is collected only for specified, explicit, and legitimate purposes and is not reused in incompatible ways unless the law permits. Data minimization means only information reasonably necessary for legitimate business purposes is collected. Accuracy requires reasonable steps to keep information complete, correct, and up to date, with corrections made without undue delay.

Storage limitation means information is retained no longer than necessary and is then securely archived or destroyed. Integrity and confidentiality require appropriate administrative, technical, physical, and organizational safeguards against unauthorized access, loss, alteration, or misuse. Accountability places responsibility for compliance on every person processing information on behalf of Tetherlink Consulting.

Privacy by design and security by design require that privacy and security controls are embedded into systems, projects, procurement, and business processes from the earliest planning stages. Ethical innovation requires that AI, automation, and analytics are deployed transparently and responsibly, under appropriate human oversight, and in a manner consistent with applicable legal and professional standards.

5. Applicable Laws and Regulatory Framework

Tetherlink Consulting is committed to complying with all applicable privacy, data protection, and cybersecurity legislation in every jurisdiction in which it operates. This Policy is designed to support compliance with the Constitution of Kenya, 2010, including the right to privacy under Article 31, and the Data Protection Act, No. 24 of 2019.

The Policy also reflects the Data Protection (General) Regulations, 2021; the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021; and the Data Protection (Complaints Handling and Enforcement Procedures) Regulations, 2021. It further supports compliance with the Computer Misuse and Cybercrimes Act, 2018, and the Kenya Information and Communications Act where applicable.

Relevant employment, taxation, procurement, and financial reporting legislation also shapes how records are created and retained. Binding contractual obligations with clients, donors, and partners, together with internationally recognized privacy and governance principles applicable to cross-border operations, cloud services, and donor-funded programmes, complete the framework. Where legal requirements differ across jurisdictions, Tetherlink Consulting shall apply the higher standard where reasonably practicable.

6. Definitions

Personal Data means any information relating to an identified or identifiable natural person, including names, contact details, identification numbers, online identifiers, and location data. Sensitive Personal Data means personal information requiring enhanced legal protection, including health, biometric, genetic, financial, and government-issued identification data. Data Subject means the individual to whom personal data relates.

Processing means any operation performed on information, whether automated or manual, including collection, recording, organization, storage, retrieval, use, disclosure, transmission, restriction, archiving, deletion, or destruction. Data Controller means a person or organization that determines the purposes and means of processing personal data. Data Processor means a person or organization that processes personal data on a controller’s behalf.

Consent means a freely given, specific, informed, and unambiguous indication of agreement to processing. Data Breach means any unauthorized or unlawful access, disclosure, alteration, loss, or destruction of personal data or confidential information. Confidential Information means non-public information with commercial, legal, financial, operational, strategic, or reputational value that requires protection from unauthorized disclosure.

Artificial Intelligence means computational systems performing tasks associated with human intelligence, including prediction, pattern recognition, content generation, automation, analytics, and decision support. Anonymization means irreversibly removing identifying information so an individual can no longer be identified. Pseudonymization means processing data so it cannot be attributed to an individual without separately safeguarded additional information. Information Asset means any information of value to Tetherlink Consulting regardless of format or storage medium.

7. Roles and Responsibilities

Senior management of Tetherlink Consulting provides strategic direction, approves governance frameworks, allocates appropriate resources, oversees compliance with this Policy, and promotes a culture of accountability, privacy, and ethical information management across the organization.

Employees, consultants, contractors, interns, and project personnel must comply with this Policy, access information only where authorized, and protect confidential information during and after their engagement. They must report suspected incidents or privacy concerns without delay and complete any security or privacy awareness training required by the Company.

Information owners ensure that records under their authority are properly classified, protected, maintained, and retained in line with legal, contractual, and operational requirements. Technology administrators and custodians implement the technical and organizational safeguards that preserve the confidentiality, integrity, availability, and resilience of Company systems.

Third-party service providers, vendors, and subcontractors must implement appropriate security measures and comply with their contractual, legal, and confidentiality obligations. Every person granted access to information or systems operated by Tetherlink Consulting shares responsibility for the lawful, ethical, and secure management of that information at all times.

8. Data Collection and Categories of Information

Tetherlink Consulting collects information directly from individuals, through business relationships, through its websites and digital platforms, and from lawful third-party and publicly available sources. Collection is limited to what is adequate, relevant, and necessary for the purposes identified at the time of collection or otherwise permitted by law.

Categories of information processed may include identity and contact details; employment and professional information; financial and billing information; project, research, and training records; and agricultural and livestock production data gathered through consultancy and field activities. Technical data such as IP addresses, device identifiers, browser types, and usage logs may be collected through Company websites.

Communications, correspondence, and photographs or recordings captured during projects, workshops, or field activities may also be processed, with appropriate notice given to participants. Sensitive personal data is collected only where strictly necessary, supported by a valid legal basis, and protected by enhanced safeguards proportionate to the risks involved.

Tetherlink Consulting processes personal data only where one or more lawful bases apply under the Data Protection Act, 2019. These include the consent of the data subject and the performance of a contract, including steps taken at the data subject’s request before entering a contract.

Processing may also rest on compliance with a legal obligation, the protection of vital interests, or the performance of a task carried out in the public interest. The Company may additionally rely on its legitimate interests or those of a third party, provided such interests are not overridden by the rights and freedoms of the data subject.

Where consent is the applicable basis, it shall be obtained through a clear affirmative action and recorded appropriately. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal, and withdrawal shall be made as simple as giving consent.

10. Use of Information

Information is used to deliver consultancy, research, training, and advisory services; manage client, supplier, and partner relationships; and administer contracts, billing, and payments. It also supports the operation and improvement of websites and digital platforms operated by Tetherlink Consulting.

Additional purposes include conducting market and agricultural research; meeting legal, tax, audit, and regulatory obligations; communicating with stakeholders; recruiting and managing personnel; and protecting the security of Company systems, records, and premises. Aggregated or anonymized information may be used for analysis, reporting, and service improvement.

Tetherlink Consulting does not sell personal data. The Company does not use personal data for automated decision-making that produces legal or similarly significant effects on individuals without appropriate safeguards, meaningful human oversight, and compliance with applicable law.

11. Cookies and Website Technologies

Websites operated by Tetherlink Consulting may use cookies and similar technologies to enable core functionality, remember user preferences, analyze traffic, improve performance, and support security. These technologies help the Company understand how visitors interact with its content and services.

Where required by law, non-essential cookies are deployed only with user consent. Visitors may manage or disable cookies through their browser settings, although some site features may not function correctly as a result. Analytics data is used in aggregated form wherever practicable, and the Company avoids intrusive tracking that is not justified by a legitimate purpose.

12. Disclosure to Third Parties

Tetherlink Consulting discloses information to third parties only where necessary for legitimate business purposes, required by law, or authorized by the data subject. Disclosures are limited to the minimum information necessary to achieve the relevant purpose.

Recipients may include service providers and subcontractors acting under contract; professional advisers such as auditors, accountants, and lawyers; financial institutions processing payments; and government or regulatory authorities where disclosure is legally required. Information may also be shared with clients or partners in connection with agreed deliverables.

All third parties processing personal data on the Company’s behalf are bound by confidentiality and data protection obligations. Tetherlink Consulting takes reasonable steps to ensure that recipients handle information securely and only for the purposes for which it was disclosed.

13. Data Classification

Information assets are classified according to their sensitivity and the potential business impact of unauthorized disclosure. Classification determines the handling, storage, transmission, and disposal controls applied to each asset throughout its lifecycle.

Public information may be disclosed without restriction. Internal information is intended for use within Tetherlink Consulting and its authorized partners. Confidential information includes client records, commercial terms, and unpublished research, and requires controlled access on a need-to-know basis.

Restricted information includes sensitive personal data, credentials, and security configurations. It requires the strongest available safeguards, including encryption, strict access limitation, and enhanced monitoring. Personnel are expected to handle each asset according to its classification and to seek guidance where the correct classification is unclear.

14. Records Management and Retention

Records are created accurately, stored securely, and maintained in a manner that preserves their integrity, authenticity, and availability. Tetherlink Consulting retains records only as long as necessary to satisfy operational, legal, contractual, regulatory, audit, or research requirements.

Retention periods are guided by applicable Kenyan legislation, including tax and employment law, and by contractual commitments to clients and funding partners. Records subject to ongoing legal proceedings, audits, or investigations are preserved until the matter concludes.

When retention periods expire, records are securely destroyed or irreversibly anonymized. Paper records are shredded, and electronic records are deleted using methods that prevent recovery. Archived records remain subject to the same confidentiality and security obligations as active records.

15. International Data Transfers

Where information is transferred, stored, or accessed outside Kenya, including through cloud services and international partnerships, Tetherlink Consulting shall ensure the transfer complies with the Data Protection Act, 2019 and its regulations.

Transfers occur only where appropriate safeguards exist. These may include adequate data protection standards in the destination jurisdiction, binding contractual protections, the informed consent of the data subject, or another lawful basis for transfer recognized under applicable law.

The Company assesses the privacy and security practices of foreign-hosted platforms and services before entrusting them with personal or confidential information. Cross-border arrangements are reviewed periodically to confirm that safeguards remain effective as services, laws, and risks evolve.

16. Vendor and Third-Party Management

Before engaging vendors, cloud providers, subcontractors, or technology partners that will process Company information, Tetherlink Consulting assesses their security posture, reliability, and compliance capability. The depth of assessment is proportionate to the sensitivity and volume of the information involved.

Engagements involving personal data include contractual terms addressing confidentiality, required security measures, breach notification, sub-processing restrictions, data return or deletion at termination, and compliance with applicable law. Vendors are expected to notify the Company promptly of any incident affecting its information.

Vendor performance and compliance are reviewed periodically throughout the relationship. Access to Company systems and information is revoked promptly when an engagement ends, and the return or verified destruction of Company information is confirmed at offboarding.

17. Information Security and Cybersecurity

Tetherlink Consulting implements administrative, technical, physical, and organizational safeguards proportionate to the risks facing its information assets. Access to systems and records is granted on the principle of least privilege, supported by strong authentication and multi-factor authentication where available.

Sensitive data is encrypted in transit and, where practicable, at rest. Software, plugins, and operating systems are updated and patched regularly. Malware protection, secure configuration of websites and hosting environments, and hardening of cloud services reduce exposure to common attack methods.

Routine backups are maintained and tested for recoverability. Physical security measures protect premises, devices, and paper records, and equipment and media are disposed of securely at end of life. Systems are monitored for signs of unauthorized activity, and anomalies are investigated promptly.

Personnel receive security awareness guidance covering phishing, password hygiene, safe use of email and mobile devices, remote working practices, and incident reporting. Security controls are reviewed periodically and strengthened as threats, technologies, and business operations evolve.

18. Artificial Intelligence Governance

Tetherlink Consulting uses AI, automation, and analytics to enhance service delivery, content production, research, and operational efficiency, and is committed to doing so responsibly. AI systems operate under human oversight, and material outputs affecting clients or individuals are reviewed by qualified personnel before reliance or publication.

Personal or confidential information is not entered into AI tools unless the tool and its data handling practices meet the Company’s security and confidentiality standards. Contractual and technical controls are applied where AI services process Company information.

The Company avoids AI uses that are deceptive, discriminatory, or inconsistent with applicable law. AI outputs are monitored for accuracy, bias, and unintended effects, and corrective action is taken where problems are identified. Tetherlink Consulting remains fully accountable for decisions and deliverables regardless of the tools used to produce them.

19. Incident and Data Breach Response

Any person who suspects a security incident or data breach involving Company information must report it immediately through internal channels. Early reporting enables faster containment and reduces potential harm to individuals and the Company.

Upon notification, Tetherlink Consulting shall promptly assess and contain the incident, mitigate harm, preserve evidence, and determine the scope and categories of information affected. Response actions are documented to support investigation, accountability, and any required notifications.

Where a breach involving personal data is likely to result in a real risk of harm to data subjects, the Company shall notify the Office of the Data Protection Commissioner within the timelines prescribed by the Data Protection Act, 2019. Affected data subjects shall be informed where required, with clear guidance on protective steps they can take.

Post-incident reviews are conducted to identify root causes, evaluate the effectiveness of the response, and implement corrective measures that reduce the likelihood of recurrence.

20. Business Continuity

Tetherlink Consulting maintains proportionate measures to preserve the availability of critical information and systems during disruptions. These include regular backups, redundant storage for essential records, documented recovery procedures, and periodic verification that backups can be restored successfully.

Continuity arrangements are designed to enable the timely resumption of client services and statutory obligations following an incident, disaster, or system failure. Lessons learned from disruptions and tests are used to improve resilience over time.

21. Data Subject Rights

Subject to applicable law, individuals whose personal data is processed by Tetherlink Consulting have the right to be informed about the collection and use of their data and the right to access their personal data held by the Company.

Individuals may request correction of inaccurate or incomplete data and deletion of data where continued retention is no longer justified. They may object to or request restriction of certain processing, exercise data portability where applicable, and withdraw consent where processing is based on consent.

Requests may be submitted through the contact channels published by Tetherlink Consulting and shall be handled within the timelines prescribed by the Data Protection Act, 2019. The Company may take reasonable steps to verify the identity of the requester before acting, and will explain any lawful grounds on which a request cannot be fulfilled.

22. Complaints and Dispute Resolution

Individuals with concerns about the handling of their personal data are encouraged to contact Tetherlink Consulting directly so the matter can be investigated and resolved promptly and fairly. Complaints are acknowledged, reviewed objectively, and answered within a reasonable timeframe.

Where a complainant remains dissatisfied with the Company’s response, they retain the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya or to pursue any other remedy available under applicable law. Nothing in this Policy limits any statutory right of a data subject.

23. Liability

While Tetherlink Consulting takes reasonable and appropriate measures to protect information, no system can guarantee absolute security. Risks evolve continuously, and even well-defended environments can be affected by sophisticated attacks.

To the extent permitted by law, the Company shall not be liable for loss arising from circumstances beyond its reasonable control, including sophisticated cyberattacks that circumvent reasonable safeguards, provided the Company has complied with its legal obligations and the standards set out in this Policy. This section does not exclude or limit any liability that cannot be excluded under applicable law.

24. Policy Review

This Policy shall be reviewed at least annually, and additionally whenever significant changes occur in applicable law, business operations, technology, or the threat environment. Reviews consider regulatory guidance, incident lessons, audit findings, and stakeholder feedback.

Amendments are approved by senior management, and the current version is made available to all personnel and, where relevant, published on the websites operated by Tetherlink Consulting. Continued engagement with the Company following publication of an updated Policy constitutes notice of the revised terms.

25. Contact Information

Questions, requests, or complaints relating to this Policy or to the handling of personal data may be directed to Tetherlink Consulting through the official contact details published on the Company’s website. The Company welcomes feedback that helps strengthen its privacy, security, and governance practices, and is committed to responding to genuine inquiries promptly and professionally.

Scroll to Top