1. Who is responsible
Kaizen is operated by Brian Bichage in Nairobi, Kenya. Contact brianbichage81@gmail.com about this policy, support, your information or a concern about another person’s information.
2. Information we handle
Account information includes your name, email address, optional phone number, settings, verification status and the time and versions of the Privacy Policy and Terms accepted at registration. Passwords are stored as hashes. Google sign-in provides your Google identifier, name and email for authentication.
Activity information includes group memberships, roles and invitations; projects, milestones and daily commitments; check-ins, evidence files, links and file metadata; comments, reviews, notifications and fine-ledger records. You and other members decide what information to include in this activity.
We also handle authentication cookies, session information, request and device-related technical information, and security information used to prevent misuse. Support messages and any guardian-consent records include the information supplied for those purposes. Age declarations collected under an earlier signup flow may remain in existing account records; the current signup form does not ask for an age group. Please do not send passwords, verification codes or unnecessary sensitive information.
3. Why we use information
We use information to operate and secure accounts, provide groups and activity history, store and show evidence to authorised people, deliver service messages, calculate progress, maintain optional fine records, prevent abuse, respond to requests and meet applicable obligations.
Depending on the purpose and applicable law, processing supports the service you request, legitimate interests in operating and protecting it, legal obligations, or consent where required. We do not use a privacy-policy acknowledgement as blanket consent to unrelated processing.
4. Visibility and sharing
Active group members can see the member directory, including names, emails and roles, and information shared inside their group, subject to feature permissions. Private milestones and their evidence are visible only to their creator through the app. Guardians do not automatically receive access to that private activity.
We use providers for hosting, private file storage, authentication and service email. We may disclose information when required by law, to protect people or the service, or at your direction. Evidence links may open third-party websites with their own privacy practices. Do not share other people’s private information without permission.
5. Providers and international processing
Kaizen uses Google Cloud for application infrastructure, a PostgreSQL database and private evidence storage; Google for optional sign-in; and Gmail for service and support email. Google Cloud deployments include South Africa and Belgium. The primary database and private-evidence bucket are configured in South Africa.
Provider operations, email, authentication, backups and technical support may involve processing in other countries. Their applicable service terms and privacy commitments govern their processing alongside our arrangements. Contact us for information about international processing and the applicable safeguards; this policy does not mean information remains in Kenya.
6. Cookies and analytics
Kaizen uses necessary authentication cookies and limited browser storage for sign-in recovery and invitation handling. Private workspace data is not deliberately persisted in browser storage. Progress analytics inside Kaizen are calculated from accountability activity.
This version of the service does not include Google Analytics or advertising tracking. If we introduce optional tracking, we will update the policy and provide any notice or consent choices required before it operates.
7. Retention and deletion
We retain account and activity information while needed to provide the service and accountability history, respond to requests, protect the service or meet applicable obligations. We assess deletion requests individually and explain any information that must be retained and why. Shared records may need to be minimised or de-identified while preserving other members’ information.
Deletion from active use does not necessarily remove every recoverable copy immediately. The current database configuration retains seven automated backups by count and three days of transaction logs. Private-file storage uses versioning and seven-day soft deletion; removing an uploaded file requires considering its stored versions. Infrastructure log retention varies by category, including 30-day operational and 400-day required audit-log buckets.
These settings describe recovery and logging arrangements, not a promise that every copy is erased by a fixed deadline after a request. Restricted copies are used for recovery, security or applicable obligations. Contact us about the treatment of your specific records.
8. Children and guardian consent
If you are under 18, involve your parent or legal guardian before creating an account or sharing personal information. Kenyan data-protection requirements call for parental or guardian consent and appropriate verification when children’s personal data is processed. A parent or guardian should contact brianbichage81@gmail.com to discuss consent and the child’s use of Kaizen. Do not send identity documents in an initial email.
The signup checkbox records agreement to the Privacy Policy and Terms; it does not verify age, parental authority or parental consent. We do not treat a child’s agreement to these documents as the parent’s consent or as a waiver of the child’s rights.
Young users should join only groups their parent or guardian has reviewed, avoid sharing sensitive evidence, and discuss optional fine arrangements with that adult before joining. Group membership can expose names, email addresses and shared activity to other active members. A guardian does not automatically receive access to private milestones.
A parent or guardian can contact brianbichage81@gmail.com about a child’s information, to exercise applicable rights, or to withdraw consent. We verify the request as appropriate, may restrict access and revoke sessions, and assess deletion or other action with regard to the child’s interests and applicable law.
9. Your choices and rights
You can update available profile details and contact brianbichage81@gmail.com to request information about processing, access, correction or deletion, or to ask about objection, restriction, portability and consent withdrawal where applicable. We verify identity as appropriate and consider other people’s rights and applicable retention duties before acting.
You may also raise a concern with Kenya’s Office of the Data Protection Commissioner at www.odpc.go.ke. We will explain the outcome of your request and any reasons for a limitation.
10. Fines and security
Fines are an optional group feature. Kaizen records amounts, proposals and decisions; it does not collect, transfer or enforce fine payments. Turning a group’s fines off stops new fines but does not remove its existing history.
We use authentication, access controls and short-lived access to private uploaded files. No online service can guarantee absolute security. Please use care with account access and the evidence you share.
11. Policy changes
We will maintain the current policy at kaizen.co.ke/privacy and identify its version and date. When a material change affects how we use information, we will provide appropriate notice and obtain any newly required consent before applying it.