Effective / last reviewed: 6 October 2026.
1. Website operator and privacy contact
This policy applies to the website creative-dynamics.top. A separate legal company name, company registration number and tax/VAT identifier have not been provided for publication, so this notice does not invent or imply those details.
For privacy questions relating to this site, use the following contact details:
- Address: 26 Church Road, Nairobi, Kenya
- Email: [email protected]
- Phone: +254 715 148 388
For purposes of the website’s own contact-form processing, the site operator determines why the submitted information is processed and how the form is used. No representation is made here that a separate incorporated entity exists where none has been supplied.
2. Scope and Kenyan privacy framework
The website is intended primarily for readers in Kenya. Kenya’s Data Protection Act, 2019 provides a legal framework for processing personal data and establishes the Office of the Data Protection Commissioner (ODPC). Among other things, the framework addresses lawful, fair and transparent processing, purpose limitation, data minimisation, accuracy, retention and safeguards for transfers.
The ODPC describes data-subject rights including the right to be informed about use of personal data, access personal data held by a controller or processor, object to processing, request correction of false or misleading data, and request deletion of false or misleading data.
This policy is an operational website notice, not a statement that every legal obligation that may apply to a particular operator has been conclusively determined. Registration and other compliance duties can depend on the nature and scale of processing and on the operator’s circumstances. No ODPC registration number has been provided and none is claimed.
3. Categories of data the website may process
3.1 Contact-form data
If you submit the contact form, the website receives the name, email address, subject and message you choose to provide. The form also receives a technical anti-forgery token and a hidden anti-spam field. The hidden field is not intended for ordinary users to complete.
3.2 Direct email or phone contact
If you contact the listed email address or telephone number directly, the data you provide through that communication channel is processed so the communication can be handled. Email or telecommunications providers may process technical metadata as part of delivering the message or call.
3.3 Server and security data
The web server or hosting environment may create ordinary technical logs such as IP address, request time, requested path, response status, browser/user-agent data and security events. Those logs are typically used for reliability, abuse prevention, troubleshooting and security. The exact hosting provider and its log-retention configuration have not been supplied to this build, so this policy does not claim a provider name or a specific provider-controlled retention period.
3.4 Data not requested by the site
The site does not ask for account registration, payment-card details, national identification numbers, insurance information, glucose logs, laboratory reports, medication lists or medical records. Please do not place those items in the contact form.
4. Purposes of processing and operational basis
Information submitted through the contact form is used to receive and respond to a communication, handle a correction or accessibility request, address a privacy request, answer a general website question, and protect the form against spam or abuse.
Where you voluntarily send a message asking for a response, processing is connected to acting on that request. The site also has a legitimate operational need to secure the service, prevent misuse and maintain basic server reliability. Where consent is the appropriate basis for a particular optional technology, that technology should not be activated before the required consent mechanism is in place.
Personal data collected for one purpose should not be reused incompatibly. The website does not currently use contact-form submissions to build advertising profiles, sell personal data or create health-risk scores.
5. Health and sensitive information
Creative Dynamics publishes health education, but the contact form is not designed to collect health information. Do not submit diagnoses, glucose readings, laboratory results, prescriptions, treatment plans or other sensitive health details.
If such information is sent despite this instruction, the site may receive it as part of the message. The preferred approach is to avoid collecting it in the first place. If the information is unnecessary to answer the website-related request, it should not be intentionally retained for a new purpose.
For personal medical advice, contact a qualified healthcare professional through an appropriate clinical channel rather than this website.
6. Cookies, sessions and local storage
The current build does not load advertising cookies or analytics cookies. It uses limited first-party storage for two practical functions:
| Technology | Purpose | Typical duration |
|---|---|---|
| PHP session cookie (commonly named PHPSESSID) | Supports the contact form’s session and CSRF security token. | Session-based; actual expiry depends on the hosting PHP configuration. |
Local storage key cd_privacy_notice | Remembers that the privacy/cookie notice was dismissed so it is not repeatedly shown. | Persists in the browser until cleared by the user or site code. |
For more detail, including browser-control information, see the Cookie Policy.
7. Analytics, tag managers, consent platforms and other external services
The site contains configuration fields for common services, but the fields are currently blank. Therefore this production build does not load Google Analytics 4, Google Tag Manager, Cookiebot, Google reCAPTCHA or Google Maps. Search Console verification is also not embedded because no verification value was supplied.
If any of those services are enabled later, the operator must review this policy, the cookie notice and the consent implementation before activation. The policy should identify the actual service, purpose, categories of data, recipient, transfer implications and consent controls where applicable.
8. Recipients and processors
Contact-form messages are configured to be sent to [email protected] using the hosting server’s PHP mail capability. The hosting provider and mailbox provider may process data in order to deliver and store the message. Their identities are deployment details and were not provided for this build; this policy therefore does not fabricate them.
Data may also be disclosed where required by applicable law, to protect legal rights, to investigate abuse or security incidents, or to obtain professional advice where appropriate. The site does not state that contact-form data is routinely sold or shared with advertisers because that is not part of the implemented flow.
9. International transfers
The website code does not intentionally configure a third-party analytics or advertising transfer. However, internet hosting and email infrastructure can involve servers or service providers outside Kenya depending on deployment choices. Because those providers have not been specified, this notice cannot truthfully identify a transfer destination or mechanism.
Before deployment with a hosting or email provider that processes Kenyan personal data outside Kenya, the operator should assess the applicable safeguards and disclosure obligations under Kenyan data-protection law.
10. Retention
Contact messages should be retained only as long as reasonably necessary to respond, document the request, resolve a dispute or meet a legal obligation. As an operational default for this site, routine contact-form correspondence should be reviewed for deletion after 12 months when there is no continuing reason to keep it.
Security logs and session records follow the configuration of the hosting environment. Because those settings are controlled at deployment level, no fixed server-log period is claimed here. Local browser storage remains on the user’s device until cleared or changed.
11. Security measures
The contact form includes server-side validation, a CSRF token, a honeypot field and output escaping. The site is designed to be served over HTTPS at its production domain. These measures reduce common risks but no internet service can promise absolute security.
Operational security also depends on factors outside the page code, including secure hosting, updates, access controls, backups, email security and credential management. Those responsibilities should be addressed by whoever deploys and administers the site.
12. Privacy rights and requests
Depending on the circumstances and applicable Kenyan law, you may have rights to be informed about processing, request access, object to processing, request correction, or request deletion of inaccurate or improperly held information. You may also have rights or remedies through the ODPC.
To make a privacy request, email [email protected] with enough information to understand the request. Do not send extra identity documents unless they are genuinely required to verify a request. The operator may need to take proportionate steps to confirm that a requester is entitled to the data requested.
The Office of the Data Protection Commissioner provides public information and complaint channels at odpc.go.ke.
13. Children and minors
The educational material may be read by a broad audience, but the contact form is not designed to knowingly collect personal data from children. A parent, guardian or appropriate adult should assist a minor with privacy-sensitive communications where required.
The website does not knowingly run behavioural advertising directed at children and does not ask minors to create accounts.
14. Third-party links
Some educational and legal pages link to official sources such as the Kenya Ministry of Health, the World Health Organization and the ODPC. Those external websites have their own privacy practices. A link is provided for reference and does not place that third party under the control of Creative Dynamics.
15. Changes to this policy
This notice should be reviewed whenever the website’s data flow changes — for example, when analytics, reCAPTCHA, an affiliate platform, a new form destination or a different hosting arrangement is introduced. Material changes should be reflected in the effective date and in the description of actual technologies.
16. Contact
Privacy questions can be sent to [email protected], by phone at +254 715 148 388, or by post/contact at 26 Church Road, Nairobi, Kenya.