Legal
Privacy Policy
Last updated: June 2026 · Compliant with the Kenya Data Protection Act, 2019
Hekima AI Limited(“Hekima AI”, “we”, “our”) operates the learning platform at hekima-ai.org and the Hekima AI mobile app. We are committed to protecting the personal data of every learner, job seeker and visitor who uses our services.
This policy explains what personal data we collect, why we collect it, how we use and share it, and what rights you have under the Kenya Data Protection Act, 2019 (the “Act”).
1. Who We Are (Data Controller)
Hekima AI Limited is the data controller responsible for your personal data. We are registered in Kenya and are subject to the Kenya Data Protection Act, 2019.
2. Information We Collect
Account information
- Email address and name
- Password (stored as a secure one-way hash, so we never see your actual password)
- Google account details, if you sign in with Google (website only)
Learning activity
- Courses enrolled in, lessons completed, quiz attempts and scores
- Capstone project submissions
- Certificates issued (verified via hekima-ai.org/verify)
- Course feedback and ratings you submit voluntarily
AI tutor (Rafiki) conversations
Messages you send to Rafiki, our AI tutor, are processed in real time by trusted third-party AI service providers so we can generate a reply. We do not permanently store the full text of your Rafiki conversations on our servers. These providers process your messages under their own data protection terms.
Payment information
We record your subscription plan, the amount paid (in KES) and a transaction reference number. We never receive or store your M-Pesa PIN, card number or bank details. Those are handled entirely by our licensed third-party payment processor.
Device and technical information (app users)
- Device type, operating system version and app version
- Push notification token (for study reminders, if you grant permission)
Usage and analytics data
- Pages and features you visit or use, and when
- IP address and approximate location (country/region level)
- Last active date (used to send optional re-engagement nudges)
Sensitive personal data
We do not ask for, or intentionally collect, sensitive personal data, such as information about your health, ethnicity, religious or political beliefs, or genetic or biometric data, as defined by the Kenya Data Protection Act, 2019. Please do not include such information in your Rafiki messages, capstone projects or feedback.
3. How We Use Your Information
| Purpose | Legal basis (Kenya DPA 2019) |
|---|---|
| Create and manage your account | Performance of contract |
| Deliver course content, track your progress and issue certificates | Performance of contract |
| Power the Rafiki AI tutor | Performance of contract |
| Process payments and maintain financial records | Performance of contract; legal obligation |
| Send transactional emails (payment receipts, password resets, welcome messages) | Performance of contract |
| Send optional learning nudge emails (max 4 per year, easy opt-out) | Legitimate interest; consent |
| Improve our courses, platform and AI tutor | Legitimate interest |
| Detect fraud and ensure security | Legitimate interest; legal obligation |
Automated decisions
Some of our processing is automated: Rafiki generates replies using AI, your quiz answers are scored automatically, and certificates are issued automatically once you meet a course's requirements. These automated steps do not produce legal effects concerning you. You can always contact us at support@hekima-ai.org to ask a member of our team to review any outcome that affects you.
4. Sharing Your Data
We do not sell your personal data, and we never share it for anyone else's advertising. We share it only with the service providers we need to run Hekima AI, giving each one only the data necessary to do its job. These providers act on our instructions and are required to keep your data confidential and use it solely for the purposes we set.
Categories of service providers we use
- AI service providers: to generate the Rafiki tutor's replies to your questions
- Payment processors: to handle M-Pesa and card payments securely
- Cloud hosting and database providers: to run the platform and store your account and progress data
- Email delivery providers: to send receipts, password resets and optional learning reminders
- Analytics providers: to understand how the platform is used, using pseudonymous identifiers
- Mobile app distribution providers: to deliver the app and its updates
Some of these providers operate outside Kenya. See Section 5 on international transfers. We may also disclose your data where required by Kenyan law, a court order or a lawful request by a public authority, or where necessary to protect our rights, our users or the public.
5. International Data Transfers
Several of our service providers are based outside Kenya (primarily in the USA and EU). Under the Kenya Data Protection Act 2019, we are required to ensure that any transfer of personal data outside Kenya is to a country that provides an adequate level of protection, or that appropriate safeguards are in place. We rely on the data processing agreements and standard contractual terms we have in place with our service providers to meet this requirement.
6. Your Rights Under the Kenya Data Protection Act 2019
As a data subject under Kenyan law, you have the following rights:
- Right to be informed: to know what data we hold about you and how we use it (this policy fulfils that right).
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to ask us to correct inaccurate or incomplete data.
- Right to erasure: to ask us to delete your personal data (subject to legal and contractual obligations).
- Right to restrict processing: to ask us to limit how we use your data in certain circumstances.
- Right to data portability: to receive your data in a structured, machine-readable format.
- Right to object: to object to processing based on legitimate interest, including direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email us at support@hekima-ai.org. We will respond within the timelines set by the Data Protection (General) Regulations, 2021: within 7 days for an access request, and within 14 days for a correction or deletion request.
7. Data Retention
| Data type | Retention period |
|---|---|
| Account data (email, name, password hash) | Duration of account + 90 days after deletion request |
| Learning progress and certificates | Duration of account + 90 days |
| Payment records | 7 years (Kenya tax and financial record-keeping requirements) |
| Analytics and usage data | 13 months rolling |
| Email unsubscribe preferences | Indefinitely (to honour your opt-out) |
8. Security
We apply appropriate technical and organisational measures to protect your personal data, including:
- HTTPS encryption for all data in transit
- Passwords stored as irreversible cryptographic hashes (bcrypt)
- Access controls limiting who within our team can access personal data
- Payment details handled exclusively by our PCI-DSS-compliant payment processor. We never see your card or M-Pesa PIN
If a personal data breach occurs that poses a real risk of harm to you, we will notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it, and we will inform you without undue delay, as required by Section 43 of the Kenya Data Protection Act, 2019.
No system is completely secure. If you discover a security vulnerability, please report it responsibly to support@hekima-ai.org.
9. Children and Young People
Hekima AI is intended for adult learners aged 18 and above. Under the Kenya Data Protection Act, 2019, a child is any person under the age of 18. We do not knowingly collect the personal data of children under 18 without the verifiable consent of a parent or guardian. If you believe a child under 18 has provided us with personal data without such consent, please contact us at support@hekima-ai.org and we will delete it promptly.
10. Cookies and Analytics
We use essential cookies to keep you logged in and to protect against CSRF attacks. We also use a third-party analytics tool to understand how the platform is used. This analytics data is pseudonymised (linked to a hashed identifier, not directly to your name or email). You can opt out of analytics tracking by contacting us.
11. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will notify you by email and by posting a notice on the platform at least 14 days before the changes take effect. Your continued use of Hekima AI after that date means you accept the updated policy.
12. Contact Us and How to Complain
For any privacy-related questions, to exercise your rights or to raise a concern, contact us:
If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya:
© 2026 Hekima AI Limited. This policy is governed by the laws of Kenya.