Privacy Policy

Print Lion Branding Services Limited (“Print Lion”, “we”, “us”, “our”) is committed to protecting your personal data in accordance with Kenya’s Data Protection Act, 2019 and its subsidiary regulations. This policy explains what personal data we collect, why, how we use it, who we share it with, and the rights you have over it.

Effective date: January 2025
Last updated: 17 July 2026

1. Who we are

Print Lion is a printing and branding business based in Nairobi, Kenya. For the purposes of the Data Protection Act, 2019, Print Lion is the data controller of the personal data described in this policy — we determine the purposes and means of processing it.

Contact details:

  • Address: Room 29, 2nd Floor, Lois Plaza for Business, Latema Rd, Nairobi, 00100, Kenya
  • Phone: +254 729 276 296 / +254 736 505 858
  • Email: [email protected]

We have not appointed a formal Data Protection Officer, as our size does not require one under the Act. For any data protection question, complaint, or request, contact us using the details above — a director will handle it personally.

2. What personal data we collect

Depending on how you interact with us, we may collect:

  • Identity and contact details: name, phone number, email address, physical/delivery address
  • Order and business details: what you’ve ordered, order history, company name and KRA PIN (for VAT-registered business customers), payment confirmation details (e.g. M-Pesa transaction references)
  • Communications: WhatsApp messages and any media (images, documents) you send us, call records if you contact our phone line, notes from in-person or phone conversations
  • Website and marketing data: pages visited, the campaign/link that brought you to our site (e.g. Facebook, Google, TikTok ad clicks), and identifiers from those platforms used to measure ad performance (see section 8 below)
  • Account/access data (staff only, not customers): login information for our internal systems

We do not intentionally collect sensitive personal data (health information, biometric data, political or religious affiliation, etc.) and ask that you do not include such information in any message or form you send us.

3. How we collect it

  • Directly from you: our website’s quote-request and free-download forms, WhatsApp messages, phone calls, in-person registration in our shop
  • Automatically: cookies and similar technologies on our website (see section 8)
  • From our own records: your order history and past communications with us

4. Why we collect it, and our legal basis

PurposeWhat dataLegal basis (Data Protection Act, s.30)
Processing and fulfilling your orderName, phone, email, order details, delivery addressContractual necessity — we need this to provide the goods/services you’ve requested
Invoicing and tax recordsName, company details, KRA PIN, payment confirmationLegal obligation — required for Kenyan tax law compliance
Customer support (WhatsApp, phone, email)Name, phone, messagesContractual necessity / consent
Marketing communicationsName, phone, emailConsent — you can opt out at any time
Measuring the effectiveness of our advertisingHashed phone/email, ad-click identifiers (see section 8)Consent — captured via our website’s cookie consent banner; you can withdraw it at any time (see section 8)
Fraud and spam preventionIP address, submission metadataLegitimate interest

5. Who we share your data with

We share personal data with the following categories of recipients, only as needed to run our business:

  • Our internal systems: our customer relationship management system (built on Google Firebase/Firestore), used to record and manage your order, contact details, and communications with us
  • WhatsApp (Meta Platforms, Inc.): if you message us on WhatsApp, your messages are handled through Meta’s WhatsApp Business Cloud API
  • Zoho Books / Zoho Inventory: for generating invoices and managing stock, we share order and customer billing details with Zoho’s accounting software
  • Basecamp: production/job-card details are shared with our project-management tool (this does not typically include your full contact details, only what’s needed to produce your order)
  • Google Workspace (Contacts, Drive): customer contact details may sync to Google Contacts, and customer-specific files (e.g. artwork, branding assets) may be stored in a Google Drive folder linked to your account
  • Payment processing: M-Pesa payments (via Safaricom and I&M Bank) — see the M-Pesa/I&M Bank privacy policies for how they handle your payment data
  • Advertising platforms (Meta, Google, TikTok): when you interact with our ads or visit our website after clicking an ad, we send a cryptographically hashed (irreversibly scrambled) version of your phone number/email, plus ad-click identifiers, to these platforms to measure ad performance. They cannot use these hashes to identify you without also independently having your original phone number/email themselves.
  • Legal/regulatory authorities, if required by law

We do not sell your personal data to anyone.

Cross-border data transfers

Several of the recipients above are based, or store data, outside Kenya:

  • Our CRM’s data (Google Firebase/Firestore) is hosted on Google Cloud infrastructure in the United States.
  • Meta (WhatsApp, advertising) processes data on servers outside Kenya.
  • Google (Workspace, Google Analytics, advertising) processes data on servers outside Kenya.
  • TikTok processes advertising-measurement data outside Kenya.
  • Zoho (Books, Inventory) stores data in the United States (our account is on Zoho’s .com/global data centre).

Where we transfer your personal data outside Kenya, we rely on the fact that these providers maintain internationally recognised data protection safeguards (each is subject to its own applicable data protection law, e.g. GDPR for EU-facing operations), consistent with section 48 of the Data Protection Act.

6. How long we keep your data

  • Order and invoice records: 10 years
  • WhatsApp messages and call records: 2 years from last contact
  • Leads that never convert to a customer/order: 12 months from last activity
  • Marketing/ad-attribution data: click identifiers are automatically discarded from our systems after 30 days if not tied to a completed order; order-linked attribution data is retained with the order record
  • Website cookies: as described in section 8 below

When we no longer need your data for the purposes it was collected for, and are not legally required to keep it, we delete or anonymise it.

7. Your rights

Under the Data Protection Act, 2019, you have the right to:

  • Be informed about how your data is processed (this policy)
  • Access the personal data we hold about you
  • Correct inaccurate or outdated data we hold about you
  • Object to processing of your data, including for direct marketing
  • Request erasure of your data, subject to our legal obligations (e.g. we cannot erase invoice records required for tax purposes)
  • Data portability — request your data in a portable format
  • Withdraw consent at any time, where processing is based on consent (e.g. marketing messages, advertising-measurement cookies), without affecting the lawfulness of processing before withdrawal

To exercise any of these rights, contact us at [email protected] or +254 729 276 296. We will respond within a reasonable time and in accordance with the Act.

8. Cookies and website tracking

Our website uses cookies and similar technologies for:

  • Essential site function (e.g. remembering items in a form as you fill it in)
  • Analytics (Google Analytics / Google Tag Manager) — to understand how visitors use our site
  • Advertising measurement (Meta Pixel, TikTok Pixel, Google Ads) — to understand which of our ads led to a visit or enquiry
  • Attribution capture — when you arrive via a link containing campaign information (e.g. a Facebook or Google ad click), we store that information in your browser’s local storage so that if you later submit a quote request or download form, we know which campaign led to your enquiry

You can control or withdraw cookie consent at any time via the cookie banner on our site, or through your browser settings. Declining non-essential cookies does not affect your ability to use our core site or place an order — it only affects our own ability to measure which marketing efforts are working.

9. Security

We take reasonable technical and organisational measures to protect your personal data, including access controls on our internal systems (staff access is individually authenticated and permissioned), encrypted transmission of data (HTTPS), and restricting access to your data to staff who need it to serve you.

No system is completely secure, and we cannot guarantee absolute security, but we take these risks seriously and review our safeguards regularly.

10. Children’s data

Our services are intended for businesses and adult consumers. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Complaints

If you have a concern about how we’ve handled your personal data, please contact us first at [email protected] so we can try to resolve it directly.

You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC):

12. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top shows when it was last revised. Significant changes will be communicated via our website.