Who this policy covers
This policy explains how Afreeket handles personal data when you visit our websites, use our apps, buy or receive a ticket, create or manage an event, scan attendees, request support, join a promotion or otherwise interact with us.
For core platform activity, Afreeket determines why and how personal data is processed. An organiser may separately control attendee data for its own event communications, access, safety and legal obligations. The organiser’s own privacy notice may therefore also apply.
Information we collect
Information you provide
- Identity and contact details such as name, email address, phone number, country and account profile.
- Order and attendee details such as event, ticket type, quantity, attendee name, accessibility request and transaction reference.
- Organiser and business details such as organisation name, contacts, team roles, verification documents, tax or payout information and event content.
- Support, survey, review and communication content, including files or evidence you choose to send.
Information collected automatically
- Device, browser, IP address, language, approximate location, session identifiers and diagnostic information.
- Platform activity such as pages viewed, searches, clicks, referrals, order progress, login events and feature usage.
- Ticket validation data such as scan time, event, gate, result and authorised scanner account.
- Cookie and similar-technology data, subject to the choices available through our cookie controls.
Information from others
- Payment status and transaction references from mobile-money, bank and card-processing partners. Afreeket should not receive or store full card credentials.
- Information from organisers, ticket purchasers, transfer senders, service providers, identity-verification partners and fraud-prevention sources.
- Publicly available or authorised business information needed to verify an organiser or investigate misuse.
Why we use personal data
- Create and secure accounts; authenticate users; manage roles and preferences.
- Process orders and payments; issue, deliver, transfer, download and validate tickets.
- Publish events; support organiser operations, analytics, payouts, refunds and attendee communications.
- Provide customer support, investigate complaints and preserve transaction evidence.
- Detect fraud, duplicate tickets, abuse, security incidents and prohibited transactions.
- Operate, measure, troubleshoot, personalise and improve Afreeket and develop new features.
- Send service messages and, where permitted, relevant marketing that you can opt out of.
- Meet accounting, tax, regulatory, law-enforcement and other legal obligations and establish or defend legal claims.
Legal grounds for processing
Depending on the context and applicable law, we rely on one or more lawful grounds: performing a contract with you; taking steps you request before a contract; complying with a legal obligation; your consent; protecting vital interests; and our or another party’s legitimate interests where those interests are not overridden by your rights.
- Contract: account administration, orders, ticket delivery, event tools, refunds and payouts.
- Legal obligation: transaction records, tax, lawful requests, consumer protection and data-security duties.
- Legitimate interests: platform security, fraud prevention, service improvement and proportionate business analytics.
- Consent: optional marketing, non-essential cookies and another activity where consent is the appropriate basis. You may withdraw consent prospectively.
International data transfers
Afreeket serves events across Africa and may use providers located in other countries. When personal data moves across borders, we use safeguards required by applicable law, which may include adequacy decisions, contractual protections, consent where appropriate, or another recognised transfer mechanism. We also limit access to what is needed for the stated purpose.
How long we keep data
We retain personal data only as long as reasonably needed for the purposes described, including providing tickets and event records, resolving disputes, preventing fraud, meeting tax and accounting duties, and enforcing agreements. Retention varies by record type and legal requirement.
- Account data is generally kept while the account is active and for a limited period afterward.
- Transaction, payout, refund and dispute records may be kept for the period required by financial, tax, consumer and limitation laws.
- Security logs are kept for a proportionate period based on risk and operational need.
- Data may be retained longer when a complaint, investigation, legal hold or outstanding balance requires it, then deleted or de-identified when no longer needed.
Security
We use administrative, technical and physical measures designed to protect personal data, including access controls, secure transmission, logging, staff and vendor controls, backups and incident response. No method is completely secure, so use a unique password, protect your device and report suspicious activity promptly.
If a personal-data breach creates a notification duty, we will notify the appropriate authority and affected people in the manner and timeframe required by applicable law.
Your privacy rights
Subject to applicable law and appropriate identity checks, you may have the right to:
Send a request to support@afreeket.com with enough detail for us to identify the relevant account or transaction. We may ask for proportionate proof of identity and may retain data that we must keep by law or for compelling lawful reasons.
- Be informed about how your personal data is used and request access to it.
- Ask us to correct inaccurate or misleading data.
- Object to or request restriction of certain processing.
- Request deletion of data in circumstances recognised by law.
- Receive portable data where the right applies.
- Withdraw consent without affecting processing already carried out lawfully.
- Object to direct marketing and raise concerns about qualifying automated decisions.
- Complain to the Office of the Data Protection Commissioner in Kenya or another competent supervisory authority.
Children and sensitive information
Afreeket is not designed for children to create independent accounts where they cannot legally consent. A parent, guardian or authorised adult should make purchases and supervise participation. Organisers are responsible for clearly stating age restrictions and obtaining any event-specific permissions.
Please do not send sensitive personal data unless it is necessary for a clearly explained purpose, such as an accessibility accommodation, identity verification or legal requirement. We apply additional care where sensitive data is processed.
Updates, contact and complaints
We may update this policy as our services, providers or legal obligations change. The revised version will be posted here with a new update date, and material changes may also be communicated directly.
For questions or to exercise a privacy right, contact support@afreeket.com or write to Afreeket, Nairobi, Kenya. If we do not resolve a concern, you may contact the Office of the Data Protection Commissioner at odpc.go.ke.
Still have a question?
Our support team can help you understand how these terms apply.