Privacy Policy
Last updated: March 2026
Table of Contents
1. Introduction
Silicon Savannah Talent ("SST", "we", "us", or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information in compliance with the Data Protection Act, 2019 of Kenya (DPA) and the regulations issued by the Office of the Data Protection Commissioner (ODPC).
By using our platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our services.
2. Data Controller
The data controller responsible for your personal data is:
3. Data We Collect
We collect the following categories of personal data:
- Identity data: Full name, email address, phone number
- Professional data: Resume, skills, work experience, education, certifications
- Preference data: Job preferences, project interests, desired salary range, location preferences
- Usage data: Platform interactions, search queries, application history, chat transcripts
- Device data: Browser type, IP address, device identifiers, operating system
- Payment data: M-Pesa phone number, transaction references (we do not store full payment credentials)
4. Purpose of Processing
- Match candidates with job opportunities and project roles using AI-powered semantic matching
- Facilitate recruitment workflows between candidates and employers
- Provide AI-powered career tools including resume building, skill assessments, and career guidance
- Process payments and milestone-based escrow disbursements via M-Pesa and Pesapal
- Improve platform features and user experience through aggregated analytics
- Communicate service updates, matching notifications, and platform announcements
5. Legal Basis for Processing
We process your personal data on the following legal bases under the DPA:
Consent
You provide consent when you register an account and submit your personal data to the platform.
Legitimate Interest
AI-powered matching and platform improvements serve the legitimate interests of connecting talent with opportunities.
Contract Performance
Processing is necessary to deliver the recruitment and project management services you have requested.
6. Data Sharing
We may share your personal data with the following categories of recipients:
- Employers: Candidate profiles are shared with employers only for roles where a match has been identified. Employers cannot browse all candidate data freely.
- Payment processors: Pesapal processes payment transactions on our behalf. Only transaction-relevant data is shared.
- AI services: Google Gemini is used for natural language processing. Data sent to AI services is anonymized and stripped of direct identifiers.
- Vector database: Pinecone stores anonymized semantic embeddings for matching purposes. No personally identifiable information is stored in vector form.
We do not sell your personal data to third parties.
7. Cross-Border Transfers
Your data may be processed by service providers located outside Kenya, including Google Cloud (United States) and Pinecone (United States). In accordance with Section 48 of the DPA, we ensure that adequate safeguards are in place, including contractual clauses requiring recipients to maintain data protection standards equivalent to those under Kenyan law.
8. Data Retention
Active accounts
Data is retained for as long as your account remains active.
Inactive accounts
Accounts inactive for 24 months are scheduled for deletion. You will receive a notification before deletion occurs.
Draft content
Unsaved drafts (resumes, job posts, project briefs) are automatically deleted after 30 days.
Chat sessions
AI chat transcripts are retained for 90 days to improve service quality, then permanently deleted.
9. Your Rights
Under Section 26 of the Data Protection Act 2019, you have the following rights regarding your personal data:
- Right to access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data. You can use the "Delete My Account" option in your account Settings.
- Right to data portability: Request your data in a structured, machine-readable format.
- Right to object: Object to processing of your data for specific purposes, including AI-based profiling.
- Right to withdraw consent: Withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact us at privacy@siliconsavannahtalent.com. We will respond within 30 days.
10. Data Security
We implement appropriate technical and organizational measures to protect your data:
- All data transmitted between your browser and our servers is encrypted using TLS
- Passwords are hashed using Argon2, an industry-leading algorithm
- Refresh tokens are stored as httpOnly, secure cookies to prevent XSS attacks
- Rate limiting is applied to all API endpoints to prevent abuse
- Role-based access control ensures users can only access data relevant to their role
12. Children
Our services are not directed at persons under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a person under 18, we will take steps to delete that data promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will notify you via email or a prominent notice on the platform. The date of the most recent revision is indicated at the top of this page.
14. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Email: privacy@siliconsavannahtalent.com
Address: Silicon Savannah Talent, Nairobi, Kenya