Data Security

Data Protection & Security Statement

Protecting personal data through responsible governance, security, accountability, and privacy

Effective Date: January 31, 2026
Applies to: Spice Without Borders & Spicy Awards programs, websites, digital platforms, events, and related services
Effective Date: January 31, 2026 Applies to: Spice Without Borders & Spicy Awards programs, websites, digital platforms, events, and related services

Spice Without Borders (SWOB) and the Spicy Awards (“we,” “our,” or “us”) are committed to maintaining strong standards of data protection and information security for individuals whose personal data we collect, use, store, or otherwise process.

This Data Protection & Security Statement explains the organizational and technical measures we use to protect personal data and support responsible data processing in accordance with applicable laws and recognized international data protection practices.

Our approach is guided by:

  • Kenya Data Protection Act, 2019
  • EU General Data Protection Regulation (GDPR), where applicable
  • Other applicable data protection and privacy laws
  • Recognized international data protection and information security practices

01 | Our Data Protection Principles
We apply the following principles when collecting and processing personal information:
  • Lawfulness, fairness & transparency — personal data is processed lawfully, fairly, and transparently.
  • Purpose limitation — personal data is collected and processed only for specified, explicit, and legitimate purposes.
  • Data minimization — we seek to collect only the personal data that is reasonably necessary for the relevant purpose.
  • Accuracy — we take reasonable steps to keep personal information accurate and up to date where necessary.
  • Storage limitation — personal data is retained only for as long as reasonably necessary for the purpose for which it was collected, subject to legal, contractual, archival, or operational requirements.
  • Integrity & confidentiality — personal data is protected through appropriate technical and organizational security measures.
  • Accountability — we take responsibility for our data processing activities and seek to demonstrate compliance with applicable data protection requirements.
02 | Organizational Measures
Data protection is supported through organizational policies, procedures, responsibilities, and controls designed to reduce the risk of unauthorized access, disclosure, alteration, loss, or misuse of personal data. Our organizational measures may include:
  • Staff, volunteers, and relevant personnel training on data protection.
  • Confidentiality obligations and agreements for staff, partners, and processors.
  • Data Protection Impact Assessments (DPIAs) where required or appropriate.
  • Role-based access controls based on responsibilities and legitimate need.
  • Internal data protection, privacy, and information security procedures.
  • Documented data retention and disposal practices.
  • Processes for identifying and managing data protection risks.
Access to personal data is limited to individuals and service providers who have a legitimate need to access such information for authorized purposes.
03 | Technical Security Measures
We use reasonable technical safeguards appropriate to the nature and risks associated with the personal information we process. Depending on the system, service, or platform involved, these measures may include:
  • Encrypted servers and data storage.
  • Secure Sockets Layer (SSL/TLS) encryption for supported website connections.
  • Password-protected systems and databases.
  • Multi-factor authentication for relevant staff and administrative accounts.
  • Role-based access controls and account permissions.
  • Security monitoring and system reviews.
  • Firewalls and appropriate malware and antivirus protections.
  • Secure backup and recovery procedures.
  • Software, platform, and security updates where appropriate.
Security measures are reviewed and updated as our technology, programs, risks, and operational requirements evolve.
04 | Breach Detection & Response
We maintain processes intended to identify, assess, contain, investigate, and respond to suspected personal data breaches or other significant security incidents. Where appropriate, our response process may include:
  • Detecting and documenting suspected security incidents.
  • Assessing the nature, scope, and potential impact of an incident.
  • Taking reasonable steps to contain and mitigate the incident.
  • Investigating the circumstances and identifying affected systems or data.
  • Notifying affected individuals where required by applicable law.
  • Reporting incidents to relevant regulatory authorities within legally required timelines.
  • Implementing corrective and preventative measures to reduce the likelihood of recurrence.
Not every security incident constitutes a legally reportable personal data breach. Where an incident occurs, we assess the circumstances and respond according to applicable legal and regulatory requirements.
05 | Third-Party Processors & Service Providers
We may use trusted third-party service providers to support our websites, programs, events, communications, data storage, ticketing, payment processing, analytics, email delivery, and other operational activities. Where a third party processes personal data on our behalf, we seek to ensure that appropriate data protection and security safeguards are in place. Depending on the nature of the relationship, service providers may be required to:
  • Maintain appropriate technical and organizational security measures.
  • Process personal data only for authorized purposes.
  • Maintain confidentiality obligations.
  • Comply with applicable data protection requirements.
  • Enter into appropriate Data Processing Agreements (DPAs) where required.
  • Assist with applicable data protection obligations and incident response.
Third-party providers may have their own privacy policies and terms governing their services. Additional information about third-party processing is provided in our Privacy Policy and Cookie Policy.
06 | International Data Processing & Transfers
Some of our service providers, platforms, or technology infrastructure may process or store information outside Kenya. Where personal data is transferred internationally, we seek to implement appropriate safeguards and comply with applicable requirements governing international data transfers. Depending on the circumstances, safeguards may include adequacy arrangements, contractual protections, Standard Contractual Clauses (where applicable), or other legally recognized transfer mechanisms. Further information about international data processing is available in our Privacy Policy.
07 | Data Retention & Secure Disposal
Personal data is retained only for as long as reasonably necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by applicable law. Retention considerations may include:
  • Program and service delivery requirements.
  • Legal and regulatory obligations.
  • Contractual requirements.
  • Financial, accounting, or audit requirements.
  • Historical records and legitimate organizational purposes.
  • Research, reporting, and impact assessment requirements.
When personal data is no longer required, we seek to securely delete, anonymize, or otherwise dispose of it in an appropriate manner.
08 | Your Role in Protecting Data
Data security is a shared responsibility. We encourage users, participants, partners, volunteers, and other individuals interacting with our platforms to take reasonable steps to protect their own information. We encourage you to:
  • Use strong and unique passwords where passwords are required.
  • Avoid sharing passwords or account credentials with others.
  • Keep your devices, browsers, and software reasonably up to date.
  • Exercise caution when responding to suspicious emails, messages, or links.
  • Use secure networks when submitting sensitive information.
  • Report suspected unauthorized access or suspicious activity promptly.
If you believe your account or information may have been compromised, please contact us as soon as possible.
09 | Your Data Protection Rights
Depending on your location and the applicable law, you may have rights concerning your personal information, including rights to access, correction, deletion, restriction, objection, or withdrawal of consent where applicable. Our approach to personal information and individual data protection rights is described in greater detail in our Privacy Policy. Requests relating to your personal information should be directed to our Data Protection contact using the details provided below.
10 | Children & Young People
Where our programs or activities involve children or young people, we take additional care to ensure that personal information is handled appropriately and in accordance with applicable child protection and data protection requirements. Appropriate consent, safeguarding, access, and information-handling measures may be applied depending on the nature of the activity and the age of the individual involved. Further information is available through our applicable privacy, safeguarding, and conduct policies.
11 | Monitoring & Continuous Improvement
Data protection and information security are ongoing responsibilities. We periodically review our policies, systems, processes, and safeguards to identify opportunities for improvement. This may include:
  • Security reviews and assessments.
  • Policy and procedure updates.
  • Staff and volunteer awareness training.
  • Review of third-party service providers.
  • Incident and breach response reviews.
  • Updates to technical and organizational safeguards.
No electronic system or method of transmission can be guaranteed to be completely secure. We therefore continuously seek to reduce risk and strengthen our security practices.
12 | Contact & Data Protection Concerns
If you have questions, concerns, or requests relating to data protection, privacy, or information security, please contact us: Data Protection Contact Spice Without Borders (SWOB) Email: privacy@spicewithoutborders.org General inquiries: info@spicewithoutborders.org Website: www.spicewithoutborders.org | www.spicyawards.com

See Other Terms of Use

By using our websites, you agree to be bound by our applicable policies and terms:

If you do not agree with our applicable policies or terms, please do not use our websites.
OUR COMMITMENT

Our Commitment

Spice Without Borders and the Spicy Awards recognize that trust is fundamental to meaningful participation, collaboration, recognition, and community impact. We are committed to handling personal information responsibly and to maintaining appropriate safeguards that protect the confidentiality, integrity, and availability of the information entrusted to us. We will continue to review and strengthen our data protection and security practices as our programs, technologies, partnerships, and responsibilities evolve.
Scroll to Top