1. About this policy
Sabasi is a digital data platform built and operated by Open Institute ("OI", "we", "us"). It provides tools for collecting, managing, analysing, visualising, publishing and acting on data, including surveys, dashboards, data sources, public sites, impact tracking, artificial intelligence features and workflow automation.
This policy explains how personal data is handled through Sabasi. We apply the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability. It is designed around Kenya's Data Protection Act, 2019 and its Regulations, and also reflects the principles of the EU General Data Protection Regulation (GDPR) where applicable.
2. Who is responsible for your data
Our role depends on why your data is in Sabasi.
When another organisation collects your data. Governments, NGOs, community organisations, researchers and companies use Sabasi to collect and manage information. Where such an organisation collects personal data through Sabasi, that organisation is normally the data controller and determines why the information is collected and how it is used. Open Institute acts as its data processor under the organisation's documented instructions and applicable agreement. Questions about a particular survey, consent, correction or deletion should normally be directed to the organisation that collected the information; if you contact us, we will assist the relevant controller where required.
When Open Institute controls the processing. Open Institute is the data controller for personal data relating to Sabasi account holders; visitors interacting with Sabasi or our support services; people in programmes where Open Institute itself determines the purpose of collection; and administrative, security, billing and operational information required to operate Sabasi. A specific programme or service notice may add detail where necessary.
3. Personal data we handle
Depending on how Sabasi is used, we may handle:
- Account and organisation data: name, email, profile information, organisation, role, department, preferences and authentication information.
- Survey and respondent data: answers to survey questions and, where requested by the controller, names, contact details, identifiers, location, dates, signatures, photographs, files and other information submitted in a response.
- Sensitive personal data: surveys may contain health or other sensitive information where the controller has a lawful basis and appropriate safeguards.
- Uploaded and connected data: datasets, forms, rosters and other information imported or connected by authorised users.
- Device and technical data: device information, sessions, login activity, IP or connection information, timestamps and information needed for security, troubleshooting and operation.
- Audit data: records of actions such as logins, data changes, exports, approvals, transfers and administrative activity.
- Support data: information provided when contacting us by email, form or live chat.
- Marketing and waitlist data: contact details and preferences of people who sign up for updates, waitlists or communications about Sabasi.
- Integration information: credentials, tokens or configuration required to connect services chosen by an authorised user.
We collect and process only information reasonably necessary for the relevant purpose.
4. How we collect data
Personal data may come directly from you; from an organisation using Sabasi; from an authorised field enumerator; from files or datasets uploaded by an authorised user; from services a user chooses to connect; or automatically through normal use of the Platform for security and operation.
Where an organisation collects respondent data, it is responsible for providing an appropriate privacy notice at the point of collection, including whether providing the information is mandatory or voluntary, the purpose, the lawful basis and any consequences of not providing it.
5. Why personal data is processed
Where Open Institute is the controller, we process personal data only where an appropriate legal basis applies. This may include processing necessary to provide the service or perform a contract, comply with a legal obligation, protect the security and reliability of Sabasi, pursue legitimate operational interests that do not override individual rights, perform an authorised public-interest or research activity, or act on valid consent.
Where processing relies on consent, consent may be withdrawn at any time; withdrawal does not affect processing that was lawful before withdrawal.
Where we send you updates, waitlist notices or marketing about Sabasi, we rely on your consent or a legitimate interest, and you can opt out at any time using the unsubscribe option or by contacting us.
Where another organisation is the controller, that organisation determines and documents the lawful basis, and Open Institute processes the data only as permitted by the controller's instructions and applicable law.
6. How specific Sabasi features use data
Field and offline collection. The mobile application can collect responses without an internet connection. Responses are held in the application's native local storage on an authorised field device until they are synchronised with Sabasi; the mobile application does not use browser cookies for this. Where enabled, authorised users may transfer pending field data between authorised devices before upload. Device capabilities such as location, camera or Bluetooth are used only where required by the relevant feature and permitted by the device user.
Public surveys, dashboards and sites. Authorised users can publish or share surveys, dashboards, reports and public sites. Content made public may be accessible to anyone, or to anyone with the relevant link. Organisations are responsible for ensuring they have authority and a lawful basis before publishing personal data, and should not publish confidential, sensitive or personally identifiable information unless publication is lawful and intended.
Impact Tracking. Identifiers may be used to associate authorised survey records across collection rounds so that change over time can be analysed. This may involve controller-selected identity fields or authorised rosters, and remains subject to the controller's lawful basis, permissions and safeguards.
Artificial intelligence. Sabasi includes assistive AI features for querying authorised datasets, generating summaries and insights, assisting with survey content, translation and supporting analysis. AI operates within the user's existing Sabasi permissions and account context and does not provide access to information the user is not otherwise authorised to access. Ask AI conversation state is held only within your browser session and is not retained by Sabasi between sessions. AI outputs are designed not to expose raw individual-level records where an aggregated or summarised response is appropriate. Information required to perform an AI request may be processed by contracted AI service providers under appropriate data-protection terms; we require such providers not to use Sabasi customer content to train their general-purpose models except where expressly agreed and lawfully authorised. AI features are assistive and are not intended to make solely automated decisions that produce legal or similarly significant effects.
Workflow automation and integrations. Authorised users may configure Sabasi to perform automated actions, including sending notifications, creating or updating records, or transmitting selected information to systems they control. Where an organisation instructs Sabasi to transmit data to its own third-party service, that organisation is responsible for ensuring the destination and purpose are lawful.
7. Sharing personal data
We do not sell personal data and do not use Sabasi data for behavioural advertising.
We use carefully selected providers for services such as cloud hosting and storage, email delivery, security, technical support, live chat and artificial intelligence. Such providers may process personal data only for authorised purposes and are subject to contractual, confidentiality and security requirements appropriate to their role. Where Open Institute acts as a processor, sub-processors are used in accordance with our agreements with the relevant controller. A current list of sub-processors is available on request and at sabasi.io/contact.html.
Users may also connect Sabasi to external systems or disclose information through sharing, publishing, exports, APIs or workflow integrations. Those user-directed destinations are not automatically Open Institute sub-processors.
We may disclose information where required by law, court order or lawful authority, or where reasonably necessary to protect the rights, security and integrity of Sabasi, its users or others.
8. International data transfers
Some providers used to operate Sabasi may process personal data outside Kenya or outside the country in which it was collected.
Where an international transfer occurs, Open Institute applies the safeguards required by applicable data protection law. These may include contractual protections, recognised adequacy mechanisms, controller instructions, transfer assessments or consent where legally required. Sensitive personal data is transferred outside Kenya only where the additional requirements applicable to such transfers have been satisfied, including consent where Kenyan law requires it.
For security reasons we do not publish detailed infrastructure locations in this policy. The specific safeguard relied on for a given transfer is maintained in our data-protection and compliance records and is available where required by law.
9. Data retention and deletion
We do not retain personal data indefinitely merely because it can be stored. Our standard approach:
- Active accounts and services: retained while required to provide the service, fulfil the controller's instructions or meet another lawful purpose.
- Client survey and respondent data: retained according to the controller's documented instructions, contract and lawful retention requirements.
- Support data: retained for as long as needed to handle the enquiry and for a reasonable period afterwards for quality and record-keeping, then deleted or anonymised.
- Inactive accounts containing no respondent data: eligible for deletion after 365 days of inactivity, following reasonable notice to the account owner.
- Approved account or data deletion: removed from active production systems as soon as reasonably practicable and normally within 30 days, unless a shorter period is required by law.
- Backups: residual copies may remain in protected backups for up to 90 days after deletion from active systems, after which they expire through the normal backup cycle. Backups are not restored for ordinary use after a valid deletion except where necessary for disaster recovery, security or legal compliance.
- Security and audit logs: normally retained for up to 365 days, and longer where reasonably necessary for an active security investigation, dispute, legal claim, contractual obligation or legal requirement.
- Billing and tax records: retained for the period required by applicable law, generally five years for records subject to Kenyan tax requirements.
Where a longer period is required for public-interest archiving, research, statistics, litigation or another lawful purpose, appropriate safeguards such as access restriction, pseudonymisation or anonymisation are applied where appropriate. Further detail about our retention practices is available on request.
10. Security
We maintain technical and organisational safeguards proportionate to the nature and risk of the information processed, including access control, authentication, encryption, logging, backups, tenant and permission controls, monitoring and restricted administrative access. Access is limited to authorised persons who require it for legitimate operational purposes.
No system can be guaranteed completely secure. We maintain incident-response procedures for suspected personal-data breaches and make notifications to controllers, affected individuals and regulators where required by applicable law.
11. Your rights
Depending on the law that applies to you, you may have rights to be informed about processing; access your personal data; correct inaccurate or incomplete information; request deletion; restrict processing; object to certain processing; receive portable personal data; withdraw consent where processing depends on it; and receive protections relating to qualifying automated decision-making.
Where Kenyan law applies, requests are handled within the applicable statutory periods; where the GDPR applies, within the periods it requires. We do not charge a fee to handle a request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act, as permitted by law. We may need to verify your identity before acting on a request.
Some rights are subject to lawful exceptions, including legal obligations, public-interest processing, research, protection of others' rights and the establishment or defence of legal claims.
If another organisation collected your information through Sabasi, that organisation is normally responsible for responding to your request, and Open Institute will assist it where required. For data controlled directly by Open Institute, contact hello@openinstitute.africa.
12. Children
Sabasi accounts are intended for adults aged 18 years or older.
Organisations may use Sabasi for lawful programmes involving children. Where they do, the relevant controller is responsible for ensuring the processing is lawful, is in the child's best interests, and uses appropriate age-verification and parental or guardian consent mechanisms where required.
Where Open Institute is itself the controller of a programme involving children's data, we process that data only where there is a lawful basis, apply age-verification and parental or guardian consent appropriate to the context, act in the best interests of the child, and follow the requirements of Kenya's Children's Act, 2022 and the Data Protection Act, 2019 and its Regulations. In all other cases, we process children's data only under appropriate controller instructions and safeguards.
13. Cookies and similar technologies
Sabasi uses cookies, browser local and session storage and similar technologies where required for authentication, security, preferences and Platform functionality. Current uses include a first-party authentication cookie, browser storage that holds preferences and unsent drafts, security and anti-abuse protection provided through Cloudflare Turnstile, and our support live-chat provided through Tawk.to. Where non-essential technologies require consent under applicable law, they are used only after the necessary consent has been obtained.
We do not use advertising cookies or cross-site behavioural advertising through Sabasi, and we do not currently use browser analytics or performance-tracking cookies. Where we use operational measurement, we rely where possible on aggregated, cookieless or internal measures. Further detail is set out in the Sabasi Cookie Policy.
14. Changes to this policy
We may update this policy to reflect changes in Sabasi, our providers, applicable law or our data-protection practices. The current version and effective date are published with the policy. Where a change materially affects how account-user personal data is processed, we will provide reasonable notice.
15. Contact and complaints
For questions, privacy requests or concerns:
Open Institute 9 Riverside Building, P.O. Box 50474-00100, Nairobi, Kenya Email: hello@openinstitute.africa Data Protection Officer: Benjamin Cheragu
If you believe your personal data has been handled unlawfully, you may lodge a complaint with the Office of the Data Protection Commissioner of Kenya (ODPC). Where another data-protection law applies to you, including the GDPR, you may also have the right to complain to the competent supervisory authority in your jurisdiction.