Privacy Policy
Protecting Your Privacy with Ethan’s Logistics
Effective Date: February 27, 2025
At Ethan’s Logistics, we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information in compliance with the Data Protection Act, 2019 of Kenya, international data protection laws (such as the EU General Data Protection Regulation [GDPR]), and industry best practices. We prioritize transparency, accountability, and your rights as a data subject, reflecting the evolving trends in data privacy for logistics companies globally and in Kenya.
1. Who We Are
Ethan’s Logistics is a logistics and freight solutions provider based in Mombasa, Kenya, offering services such as air freight, ocean freight, road freight, warehousing, customs clearance, and special logistics solutions. We process personal data as a data controller and, in some cases, as a data processor, as defined under applicable laws.
2. Scope of This Policy
This Privacy Policy applies to personal data we collect through our website (www.ethanslogistics.com), mobile applications, customer interactions, tracking systems, and other services. It covers data subjects located in Kenya and internationally, including EU residents, ensuring compliance with both local and extraterritorial regulations.
3. Personal Data We Collect
We collect the following types of personal data, depending on your interaction with us:
- Contact Information: Name, email address, phone number, and physical address (e.g., for booking shipments or inquiries).
- Tracking Information: Bill of Lading (BL) numbers, shipment details, and real-time tracking data for logistics services.
- Payment Information: Payment details (e.g., credit card numbers or bank details) processed via secure third-party providers.
- Business Information: Company name, job title, and business contact details for corporate clients.
- Sensitive Data: Special handling data for sensitive cargo (e.g., health-related or perishable goods), processed only with explicit consent or legal necessity.
- Technical Data: IP addresses, cookies, browser information, and device data when you use our website or apps.
We collect data directly from you (e.g., forms, emails) or automatically (e.g., via tracking tools, cookies). We minimize data collection to what is strictly necessary for our services (data minimization principle).
4. How We Use Your Personal Data
We process your personal data for the following purposes, in line with legal bases under Kenyan and international laws:
- Providing Services: To fulfill logistics contracts (e.g., shipping, tracking, warehousing), manage bookings, and deliver door-to-door or airport-to-airport services.
- Customer Support: To respond to inquiries, provide updates, and resolve issues.
- Marketing: To send promotional offers or newsletters (with your consent, which you can withdraw anytime).
- Compliance: To meet legal obligations, such as customs clearance, tax reporting, or data protection regulations.
- Security: To protect against fraud, cyberattacks, and unauthorized access to logistics systems.
- Analytics: To improve our services, optimize website performance, and understand user behavior (anonymized where possible).
Legal bases include:
- Your consent (e.g., for marketing).
- Contractual necessity (e.g., processing shipment data).
- Legal obligation (e.g., customs compliance in Kenya).
- Legitimate interests (e.g., ensuring service security, subject to your rights).
- Kenya’s Data Protection Act, 2019: We adhere to the rights of data subjects (e.g., right to access, rectify, erase data), appoint a Data Protection Officer (DPO), conduct Data Protection Impact Assessments (DPIAs) for high-risk processing, and register with the Office of the Data Protection Commissioner (ODPC) as required.
- International Regulations: For EU residents, we comply with GDPR, including lawful, fair, and transparent processing, data subject rights, and secure data transfers. We assess cross-border transfers under Sections 48–50 of the DPA and GDPR Article 44–50, ensuring adequate safeguards (e.g., Standard Contractual Clauses or consent) when data is transferred outside Kenya.
- Global Trends: We follow emerging trends like AI-driven logistics (ensuring ethical data use), cybersecurity (implementing Zero Trust models), and big data analytics (anonymizing data where possible), as outlined in recent industry insights.
- Service Providers: Third-party logistics partners, payment processors, or IT vendors, under strict confidentiality agreements and data protection standards.
- Legal Authorities: Government agencies (e.g., Kenya Revenue Authority, ODPC) for compliance or law enforcement, as required by law.
- International Partners: For cross-border shipments, data may be transferred to countries outside Kenya (e.g., EU, USA). We ensure compliance with Kenya’s transfer limitation principle, storing at least one copy of data in Kenya and using appropriate safeguards (e.g., EU Standard Contractual Clauses, binding corporate rules) for international transfers.
- Encryption of data at rest and in transit.
- Regular cybersecurity audits and penetration testing.
- Access controls and authentication protocols.
- Incident response plans, notifying the ODPC and affected individuals within 72 hours of a data breach, as required by the DPA.
- Privacy by design, ensuring systems are secure by default (e.g., Zero Trust architecture for logistics platforms).
- Right to Access: Request a copy of your personal data.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your data, where applicable.
- Right to Restrict Processing: Limit how we use your data.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Oppose processing for marketing or profiling.
- Right to Withdraw Consent: Revoke consent for non-essential processing (e.g., marketing).
- Right to Complain: Lodge complaints with the ODPC or relevant authorities (e.g., EU DPAs).
- AI and IoT in Logistics: Ensuring ethical use of data in automated systems, minimizing risks of breaches or profiling.
- Big Data Analytics: Anonymizing data for analytics to protect privacy while optimizing logistics.
- Cybersecurity: Adopting Zero Trust models and continuous monitoring, as recommended for Kenyan businesses.
- Global Harmonization: Aligning with GDPR, California Consumer Privacy Act (CCPA), and other frameworks for international clients, especially for cross-border shipments.
- Data Protection Officer (DPO): dpo@ethanslogistics.com
- Address: Ethan’s Logistics HQ, NSSF Building, Nkrumah Rd, Mombasa, Kenya
- Phone: +254111668898
- Office of the Data Protection Commissioner (ODPC): complaints@odpc.go.ke
5. Legal Compliance
Ethan’s Logistics complies with:
6. Data Sharing and Transfers
We may share your data with:
We do not sell personal data and limit sharing to what’s necessary for our services.
7. Data Security
We implement robust security measures to protect your data, including:
8. Your Rights as a Data Subject
Under Kenyan and international laws, you have the following rights:
To exercise these rights, contact our Data Protection Officer (DPO) at dpo@ethanslogistics.com. We respond within 30 days, as required by law.
9. Cookies and Tracking Technologies
Our website uses cookies and similar technologies for functionality, analytics, and user experience. You can manage cookie preferences via our Cookie Consent Tool or browser settings. We comply with Kenya’s DPA and GDPR cookie requirements, ensuring transparency and consent for non-essential cookies.
10. Retention of Data
We retain personal data only as long as necessary for the purposes outlined or as required by law (e.g., customs records for 7 years in Kenya). After retention periods, data is securely deleted or anonymized.
11. Children’s Privacy
We do not knowingly collect data from children under 18 without parental consent. If we discover such data, we will delete it promptly.
12. International Trends and Compliance
We stay ahead of industry trends, such as:
13. Contact Us
For privacy concerns or inquiries, contact:
14. Policy Updates
We may update this Privacy Policy to reflect changes in laws, trends, or our practices. We’ll notify you via email or our website before significant changes take effect. Your continued use of our services after updates constitutes acceptance.