This page reproduces the Safari Wallet KE policy supplied for publication. Section numbering and wording follow the source document.
1.1 Nature of the Policy and Contractual Binding Effect
This Privacy Policy (“Policy”) forms a legally binding contractual agreement between you (“User”, “Data Subject”) and WHISTLE AFRICA TOURS AND EVENTS, including its digital technology application brand Safari Wallet KE (collectively, “the Company”, “we”, “us”, or “our”). This Policy governs the collection, processing, and storage of personal information across the Safari Wallet KE mobile application, website, software systems, and all integrated digital services (collectively, “the Platform”).
1.2 Scope of Informational Disclosures
This Policy sets forth the operational frameworks under which the Company collects, receives, processes, structures, stores, profiling-analyzes, discloses, cross-border transfers, and retains your personal data and sensitive personal data. These activities apply when you download, access, or use the Platform, engage with the #TripSave feature, purchase Safari Tokens, execute voucher redemptions, initiate customer support communications, or interact with our authorized independent third-party tours, experiences, and events-related vendors.
1.3 Integration with Terms and Disclaimer of Extraneous Warranties
This Policy is an inseparable addendum to, and must be read strictly alongside, the Safari Wallet KE Terms and Conditions.
- This document is explicitly published to satisfy statutory transparency obligations under the Data Protection Act, 2019 ( “DPA” or“the Act”).
- This Policy operates strictly as a unilateral description of administrative data-processing practices. It does not constitute, and shall not be interpreted as, an absolute security guarantee, a structural warranty, or a liability-bearing representation by the Company.
1.4 Statutory Framework Compliance Boundaries
The Company processes personal data in alignment with the spirit of the Constitution of Kenya, the Data Protection Act, 2019, the Data Protection (General) Regulations, 2021, and the binding guidance notes issued by the Office of the Data Protection Commissioner (ODPC).
- While this Policy sets out how we fulfill our regulatory duties as a Data Controller or Data Processor, nothing within this document shall be construed as expanding the Company's liability beyond the explicit financial caps and tortious waivers established under Kenyan law and Clauses of this agreement.
1.5 Manifestation of Irrevocable Consent and Remedy Restrictions
By clicking "Accept," creating a digital user account, logging into the application, or continuing to browse or utilize any feature of the Platform, you acknowledge that you have read, understood, and granted your unconditional, irrevocable consent to all processing practices contained herein.
- Where the Act mandates separate, opt-in consent for highly specific data-handling channels (such as targeted commercial marketing pushes), the Company will secure such consent through individual interface checkpoints.
- Your general, active execution of the Platform serves as absolute, binding contractual authorization for all other operational, anti-fraud, contractual necessity, and legitimate-interest processing tracks detailed in this Policy. If you object to any processing method described in this document, your sole, exclusive remedy under the law is to instantly terminate your account and delete the Platform from your devices.
2. WHO IS RESPONSIBLE FOR YOUR PERSONAL DATA?
2.1 Primary Data Controller Designation
For the strict purposes of the Data Protection Act, 2019 (the “Act”), WHISTLE AFRICA TOURS AND EVENTS, a legal business entity duly incorporated in the Republic of Kenya with its operational offices in Nakuru and Nairobi, serves as the primary Data Controller solely for personal data for which it directly determines the exclusive purposes and means of processing.
2.2 Authorization of Sub-Processors and Out-Sourced Technical Vendors
To maintain, support, optimize, and secure the Platform, Safari Wallet KE utilizes authorized independent third-party sub-processors and data intermediaries. You grant the Company an unrestricted, advance mandate to engage these third-party entities to process personal data on our behalf, including but not limited to:
- Cloud infrastructure and hosting providers.
- Payment service gateways, mobile money aggregators, and banking rails.
- Customer support management suites and telecommunication platforms.
- Know-Your-Customer (KYC) screening and automated identity verification networks.
- Systems analytics engines and specialized cybersecurity defense vendors. [1]
2.3 Limitation of Liability for Sub-Processor Frameworks
Where an external third-party processes personal data on behalf of the Company, Safari Wallet KE mandates commercial data-processing agreements requiring the vendor to execute tasks for authorized purposes only. The User explicitly acknowledges and agrees that the Company utilizes globally recognized infrastructure providers (such as Amazon Web Services or Google Cloud) and shall not be held liable for any system vulnerabilities, insider breaches, data leaks, or network compromises originating within these independent vendor environments.
2.4 Carve-Out for Downstream Third-Party Data Controllers
When you request a voucher redemption or book an excursion, the Company transmits your necessary metadata to independent tours, experiences, and events-related vendors. Upon receipt of this data, the destination vendor acts entirely as an independent Data Controller.
- The Company has no control over, and accepts zero responsibility or liability for, how these independent vendors manage, protect, or misuse your personal data.
- Any data protection grievances, claims, or regulatory complaints stemming from vendor actions must be initiated solely against that specific vendor.
2.5 Operational Duality and Registration Compliance
In specific processing workflows where Safari Wallet KE acts strictly as a Data Processor for an external ecosystem partner, that external entity shall remain entirely liable as the primary Data Controller. The Company maintains active registration and status updates with the Office of the Data Protection Commissioner (ODPC) in full compliance with Kenyan law, adapting its defensive postures to align with current ODPC guidance regarding entities acting concurrently as controllers and processors.
3. WHAT PERSONAL DATA DO WE COLLECT?
Depending on your use of the Platform, we may collect and process the following categories of personal data.
3.1 Identity and Mandatory KYC Data
This data may include but is not limited to ; Full legal name, aliases, national identification number, passport number, date of birth, nationality, and gender;
Biometric data, including profile photographs, facial recognition data, or video submissions utilized for automated Know-Your-Customer (KYC), Anti-Money Laundering (AML), and Counter-Terrorist Financing (CTF) checks.
Other information reasonably necessary to verify your identity.
Accuracy Warranty: You warrant that all identity data provided is true accurate, complete and current information. Providing false, misleading, fraudulent or materially incomplete information constitutes a material breach of our Terms and Conditions, gives us the right to forfeit your wallet balance and report you to law enforcement agencies and may result in restriction or suspension of your account.
3.2 Contact and communication data
We may collect:
- Telephone numbers, email addresses, physical/residential addresses, postal codes, and social media handles.
- Emergency contact details, next of kin data, and medical or dietary preferences when required for physical tourism and travel execution.
- Communication preferences.
We use this information to communicate with you regarding your account, transactions, bookings, vouchers, security alerts, customer support, and other matters connected with the services.
3.3 Transactional, Token, and Financial Metadata
We may collect and maintain records relating to:
- Token purchases, Token balances, Token issuance, Token redemption, Redemption requests, Digital vouchers, Booking information, Transaction dates and times, Transaction references, Payment confirmations, Refunds or adjustments where applicable, Promotional credits and Account activity.
- Granular records of Token purchases, token wallet balances, transaction times, digital vouchers issued, and #TripSave progressive accumulation history.
- Mobile money (e.g., M-Pesa) transaction IDs, bank transfer metadata, masked card elements, and payment reconciliation logs.
Safari Wallet KE does not require users to provide their mobile-money or bank password, PIN or other confidential authentication credentials through the Platform. Users should never disclose such credentials to Safari Wallet KE personnel or any third party.
3.4 Payment Information
Payments may be processed through third-party payment providers, banks, mobile-money operators, payment aggregators or other authorised payment channels.
Depending on the payment method, we may receive limited payment-related information such as:
- Transaction reference,Amount paid, Date and time of payment,Payment status,Masked account or payment identifiers, Name associated with the payment and Reconciliation information.
We generally do not require or retain your full card number, mobile-money PIN, bank password or similar authentication credentials unless specifically disclosed and lawfully required for a particular service.
Third-party payment providers may process your information under their own applicable terms and privacy policies.
3.5 Device and Technical Information
When you use the Platform, we may automatically collect certain technical information, including:
- IP address, Device type, Operating system, Browser type, Application version. Unique device identifiers, Mobile network information, network operator metadata, cookie strings. Login dates and times, Crash reports, Security logs, Authentication records and General location information derived from technical information, where applicable.
This information may be used for security, authentication, fraud prevention, system administration, troubleshooting, analytics and improvement of the Platform.
3.6 Location Information
Where location functionality is enabled, we may process location information, Precise GPS coordinates, cell tower triangulation data, and Wi-Fi hotspot connections, to provide or improve location-dependent services, including identifying tourism services or destinations relevant to you.
By enabling location features, you grant us a perpetual license to track your location data. You may disable location permissions through your device settings, although doing so may affect certain Platform features.
3.7 Communications and Customer Support Information
When you contact us, we may retain information relating to the communication, including:
- Emails;
- Chat messages;
- Support tickets;
- Telephone-call records where lawfully recorded;
- Complaints;
- Feedback;
- Documents submitted for verification;
- All support tickets, phone call audio recordings (for quality and dispute resolution), chat transcripts, and written representations made to support personnel.
- Information necessary to investigate a transaction or dispute.
We retain such information for customer service, quality assurance, security, dispute resolution and legal compliance purposes.
4. PROCESSING OF SENSITIVE PERSONAL DATA
Pursuant to Section 25 of the DPA, you grant us express, separate, and informed consent to process Sensitive Personal Data (including but not limited to health data, biometric data, precise location data, and next-of-kin information) whenever: [1]
- It is required to safely execute a travel booking or handle medical emergencies during tours.
- It is required to satisfy automated KYC/AML verification protocols.
You should not provide us with sensitive personal information that is not requested by the Platform or necessary for the service you are seeking.
5. HOW DO WE COLLECT YOUR DATA?
We capture your personal data via but not limited to three comprehensive vectors:
- Direct Submissions: Data you input when opening an account, editing your profile, token purchasing, submitting a redemption request, when making or receive a booking or writing to support, and automatically through your use of the Platform
- Automated Surveillance: Telemetry, background cookies, tracking pixels, and software development kits (SDKs) operating inside the app when running in the background.
- Third-Party Integrations: Data received from telecommunication networks, integrated payment gateways, credit reference bureaus (CRBs), and Partners who report on your booking fulfillment or defaults. from identity-verification or fraud-prevention providers, from tourism and service partners where necessary to provide a requested service; from publicly available or lawfully accessible sources where necessary for verification, fraud prevention or legal compliance.
6. WHY DO WE PROCESS YOUR PERSONAL DATA?
We process personal data for specific, lawful and legitimate purposes, including:
6.1 Account Management
To create, authenticate, maintain and administer your Safari Wallet KE account.
6.2 Provision of Services
To enable you to purchase Tokens, participate in #TripSave, request redemptions, receive digital vouchers and access tourism, travel, branding and other services available through the Platform.
6.3 Payment and Transaction Processing
To facilitate, verify, reconcile and record payments and transactions and to investigate disputed or unsuccessful transactions.
6.4 Identity Verification
To verify identity, prevent impersonation, protect accounts and comply with applicable legal and regulatory obligations.
6.5 Fraud and Security
To detect, prevent, investigate and respond to suspected fraud, unauthorised access, account compromise, abuse, manipulation of Token balances, cyberattacks and other unlawful or prohibited activity.
6.6 Customer Support
To respond to enquiries, complaints, requests and disputes and to investigate service-related issues.
6.7 Service Improvement
To understand how users interact with the Platform, identify technical problems, improve functionality and develop new features.
6.8 Legal and Regulatory Compliance
To comply with applicable laws, court orders, regulatory requirements, lawful requests from government authorities and obligations relating to financial records, taxation, fraud prevention, consumer protection, data protection and other applicable requirements.
6.9 Communications
To send essential service communications, including account notifications, transaction confirmations, security alerts, voucher information, service updates and changes to our Terms or Privacy Policy.
6.10 Marketing
Where permitted by law, we may send promotional communications about Safari Wallet KE, tourism packages, offers, destinations, products or services.
Where consent is required for direct marketing, we will obtain the appropriate consent and provide a practical mechanism to withdraw that consent or opt out.
Withdrawal from marketing communications will not prevent us from sending essential transactional, security or legal communications.
7. LAWFUL BASIS FOR PROCESSING
7.1 Multi-Ground Processing & Unnotified Disclosures
The Company does not rely on a single legal basis for its data processing activities. To the maximum extent permitted by the Data Protection Act, ("the Act", “the Law” or “DPA”), the Company reserves the absolute right to process and share your personal data without prior notice to you, utilizing any applicable legal ground.
7.2 Recognized Grounds
Depending on the specific nature, context, and purpose of the processing activity, personal data may be processed under any of the following statutory bases:
- Contractual Necessity: Where processing is strictly necessary for the negotiation, execution, performance, or termination of a contract with you.
- Legal and Regulatory Compliance: Where processing is required to satisfy a statutory, tax, judicial, regulatory, or law enforcement obligation binding upon the Company.
- Legitimate Interests: Where processing is necessary for the legitimate interests pursued by Safari Wallet KE or an authorized third party, except where overridden by your fundamental rights.
7.3 Consent and Mechanics of Withdrawal
Where consent serves as our explicit lawful basis, you retain the right to withdraw such consent at any time in accordance with applicable law. You expressly acknowledge that:
- The withdrawal of consent shall not affect or invalidate the lawfulness of any processing operations undertaken by the Company prior to such withdrawal.
- The withdrawal of consent may immediately restrict, suspend, or completely prevent our ability to provide specific optional features, system utilities, or services on the Platform.
8. TOKEN, #TRIPSAVE AND DATA PROCESSING
8.1 Mandatory Metadata Tracking
All data, tracking records, and historical logs relating to your Safari Tokens and #TripSave activity are permanently captured and maintained as an inseparable component of your account architecture and transaction profile. This structural tracking encompasses all Token purchases, accumulated balances, redemptions, system-generated vouchers, travel bookings, and related transaction metadata.
8.2 Purpose of Processing
Such information is systematically processed to administer the prepaid utility voucher service model, maintain accurate internal cryptographic and ledger records, detect and mitigate fraud, resolve user disputes, and facilitate seamless vendor redemptions.
8.3 Explicit Banking Disclaimer
Your Token information, wallet balances, and #TripSave records do not constitute, represent, or mimic a bank account, deposit account, or investment product. The definitive legal, commercial, and regulatory nature of Tokens is governed exclusively by the Safari Wallet KE Terms and Conditions.
9. WHO MAY RECEIVE YOUR PERSONAL DATA?
The Company reserves the right to disclose personal data, where reasonably necessary, lawful, and aligned with platform operations, to the following recipient categories:
9.1 Payment Providers
Integrated third-party payment gateways, mobile-money providers, banks, payment aggregators and other providers involved in processing or reconciling your transactions.
9.2 Tourism and Service Partners
Hotels, safari lodges, tour operators, transport companies, experience hosts, event organizers, ticketing platforms, and external excursions vendors and other service providers where disclosure is necessary to fulfil a service or redemption requested by you.
9.3 Technology and Infrastructure Providers
Cloud-hosting providers, software-as-a-service (SaaS) and software providers, database providers, cybersecurity providers, analytics providers, communication platforms and other technology vendors supporting the Platform.
9.4 Professional Advisers
Lawyers, auditors, accountants, insurers, consultants and other professional advisers where necessary for legitimate business,risk mitigation compliance, dispute resolution or legal purposes.
9.5 Government and Regulatory Authorities
Judicial courts, tax enforcement bodies, data protection regulators, police forces, or statutory bodies where disclosure is mandated or authorized by law, court order, or formal administrative requests.
9.6 Corporate Transactions
In the event of a merger, acquisition, restructuring, financing, sale of assets, business transfer or similar corporate transaction, personal data may be transferred as part of the relevant business assets or operations, subject to applicable legal requirements and appropriate safeguards.
10. THIRD-PARTY SERVICE PROVIDERS
The Platform may connect you with independent tourism, accommodation, travel, events or other service providers.
Where you request a service, certain personal information may need to be provided to the relevant provider to enable fulfilment.
Those providers may independently process your personal data under their own privacy notices and applicable legal obligations.
Safari Wallet KE disclaims all legal responsibility, liability, or oversight for any independent processing, data breaches, leaks, or misuse undertaken by a third party outside the specific purposes for which Safari Wallet KE disclosed the data. The Company’s obligations are strictly limited to protecting your data while it remains within our direct, exclusive possession.
12. CROSS-BORDER DATA TRANSFERS
Some technology, hosting, payment, communication or service providers may operate outside Kenya.
Where personal data is transferred outside Kenya, Safari Wallet KE will take appropriate steps to ensure that the transfer and subsequent processing comply with applicable Kenyan data-protection requirements, including applicable requirements relating to adequate safeguards, contractual protections, consent or other lawful transfer mechanisms.
You acknowledge that certain international technology infrastructure may be necessary to operate a modern digital platform.
13. DATA RETENTION
The Company retains personal data only for the period reasonably required to fulfill the purposes for which it was originally collected. This includes but is not limited to retaining data to provide active services, maintain immutable transaction ledgers, resolve operational disputes, prevent financial fraud, satisfy tax or anti-money laundering regulations, enforce contractual rights, or defend active legal claims.
Different categories of data may therefore be retained for different periods.
Closing your account does not automatically result in immediate deletion of every record associated with your account. Certain records may need to be retained for a legally prescribed period or where necessary to protect the Company's legal rights, comply with regulatory obligations or resolve outstanding matters.
Once personal data is no longer required, we will take reasonable steps to securely delete, anonymise or otherwise dispose of it.
14. DATA SECURITY
We implement reasonable technical, organisational and administrative measures designed to protect personal data against:
- Unauthorised access;
- Unauthorised disclosure;
- Loss;
- Destruction;
- Alteration;
- Misuse;
- Accidental or unlawful processing.
Security measures may include access controls, authentication mechanisms, encryption where appropriate, system monitoring, secure infrastructure, staff confidentiality obligations, vendor controls, backups and incident-response procedures.
However, no internet-based platform can guarantee absolute security. You acknowledge that transmission of information over the internet carries inherent risks.
Accordingly, while the Company implements proportionate, commercial steps to safeguard your profile, the Company does not warrant or guarantee that the Platform will be completely immune to sophisticated cyberattacks, zero-day exploits, malicious insider leaks, system hardware failures, or force majeure events entirely beyond our reasonable control.
15. YOUR RESPONSIBILITY FOR ACCOUNT SECURITY
15.1 Exclusive Duty of Care
You maintain the sole, non-delegable responsibility for preserving the strict confidentiality of your platform login credentials, passwords, one-time PINs (OTPs), and the physical security of devices used to access the Platform.
15.2 Mandatory Reporting Protocol
You must notify the Company immediately upon suspecting or discovering:
- Any unauthorized access to or compromise of your digital account.
- The loss, theft, or cloning of your registered mobile device.
- Any Compromise of your account, unauthorized Token redemption or suspicious transaction velocity.
- Any unauthorized modifications to your account metadata.
15.3 Credentials Credibility Safe
You strictly agree never to share your password, PIN, or OTP with any individual, including personnel claiming to represent Safari Wallet KE.
15.4 Allocation of Risk
Where an unauthorized transaction, token drain, or security incident occurs due to your intentional disclosure, personal negligence, or failure to secure your devices and credentials, Safari Wallet KE shall be completely insulated from liability. The Company reserves the right to investigate the breach and allocate financial responsibility directly to you in accordance with our Terms and Conditions.
16. DATA BREACHES AND SECURITY INCIDENTS
If Safari Wallet KE becomes aware of a personal-data breach, we will assess the incident and take reasonable steps to contain, investigate and mitigate its effects.
Where notification to the ODPC or affected data subjects is required under applicable Kenyan law, we will make the relevant notification via the company’s selected means.
Users should promptly report suspected breaches or unauthorised access through our designated support channels and or via email to mysafariwalletke@gmail.com.
17. YOUR DATA-PROTECTION RIGHTS
Subject to applicable law and any lawful limitations, you may have the right to:
- Be informed about how your personal data is being processed;
- Request correction of inaccurate, outdated, false or misleading information;
- Request deletion of personal data where legally permissible;
- Withdraw consent where processing is based on consent;
- Request restriction of certain processing where applicable;
The exercise of these rights may be subject to lawful exceptions.
18. HOW TO EXERCISE YOUR RIGHTS
Requests relating to personal data should be submitted through:
Email: mysafariwalletke@gmail.com
To protect your information, we may need to verify your identity before responding to a request.
We will respond within a minimum of fourteen working days.
Where a request is manifestly unfounded, excessive or otherwise permitted to be refused under applicable law, we may decline or appropriately limit the request.
19. AUTOMATED DECISION-MAKING AND PROFILING
The Platform may use automated systems for purposes such as fraud detection, account security, transaction monitoring, system optimisation and personalised service recommendations.
20. MARKETING AND COMMUNICATIONS
We may send you service-related communications necessary for operating your account.
These may include:
- Transaction confirmations;
- Token purchase confirmations;
- Voucher notifications;
- Booking reminders;
- Security alerts;
- Changes to services;
- Changes to these Terms or this Privacy Policy.
Where permitted by law, we may separately send promotional communications.
You may opt out of promotional communications through the unsubscribe mechanism provided.
Opting out of marketing will not prevent us from sending communications necessary for the operation and security of your account.
21. COOKIES AND ANALYTICS
The Platform may use cookies, SDKs, pixels, log files and similar technologies to maintain sessions, authenticate users, analyse performance, improve functionality, detect security threats and understand general usage patterns.
Where required, we will provide appropriate notices or obtain consent before deploying technologies that require consent.
You may be able to manage certain permissions through your browser or device settings.
Disabling certain technologies may affect the functionality or performance of some Platform features.
22. ABSOLUTE AGE RESTRICTIONS AND CHILDREN'S DATA
22.1 Strict Legal Capacity Requirements
The Platform is engineered and exclusively intended for use by persons who have reached the age of majority (eighteen (18) years and older) and who possess the full, uncompromised legal capacity to enter into binding contractual obligations under the laws of the Republic of Kenya. [1]
22.2 Absolute Prohibition on Independent Use
Independent access to, registration on, or use of the Platform by children (any person under the age of 18 years) is strictly prohibited. The Company does not knowingly target, solicit, or collect personal data from children.
22.3 Complete Shift of Parental and Guardian Liability
- By allowing a minor to access your device, account, credentials, or the Platform, you explicitly warrant that you are the legal parent or statutory guardian of that child.
- The legal parent or guardian assumes absolute, unrestricted civil, criminal, and financial liability for any transactions, Token purchases, #TripSave accumulations, account usage, or data inputs initiated by a minor on the Platform.
- The Company is completely insulated from, and the parent or guardian explicitly waives, any claims arising out of a child's unauthorized activity, including accidental redemptions or wallet allocations.
22.4 Mandatory Statutory Safeguards
In highly exceptional circumstances where the processing of a child’s personal data is strictly necessary to execute a travel booking, tour itinerary, or experiential event request:
- Such processing shall never be initiated independently by the minor.
- Data processing shall be performed strictly subject to the explicit, verifiable, written consent of the parent or legal guardian, obtained in the manner prescribed under Section 22 of the Data Protection Act, 2019. [1]
- The Company reserves the unilateral right to demand certified birth certificates, legal guardianship orders, and parental identification at any time to verify the validity of such consent.
22.5 Immediate Triage and Forfeiture for Breach
If the Company discovers, detects, or is notified that an account has been opened or operated by a person under the age of eighteen (18) years without verifiable parental consent:
- The Company reserves the right to instantly freeze or permanently terminate the account without prior notice.
- To the maximum extent permitted by law, any stored Token balances or data assets associated with the fraudulent underage account may be locked indefinitely pending internal investigation, or reported directly to the Office of the Data Protection Commissioner (ODPC)
23. ACCURACY OF INFORMATION
23.1 Exclusive User Warranty
You maintain the sole, absolute, and non-delegable responsibility to ensure that any and all information, identity credentials, contact details, metadata, and representations provided to Safari Wallet KE are strictly accurate, legally authentic, structurally complete, and current at all times.
23.2 Mandatory Real-Time Update Duty
You are strictly required to update your platform account profile immediately upon any modification to your contact numbers, email addresses, statutory identification details, or travel metadata. The Company disclaims all obligations to independently audit, monitor, verify, or cross-check the validity or accuracy of user-submitted data.
23.3 Data Reliance
- The Company shall rely blindly and implicitly on the information supplied by you.
- The Company, its directors, and affiliates shall be completely insulated from, and accept zero liability for, any direct, indirect, incidental, or consequential losses, damages, failed redemptions, rejected travel bookings, missed excursions, or regulatory penalties resulting from inaccurate, outdated, fraudulent, or misleading information provided by you.
23.4 Discretionary Rectification Rights
While the Company reserves the unilateral right—strictly at its sole, absolute discretion—to patch, flag, or restrict blatantly inaccurate personal data, this right does not create a binding legal duty. The Company is under no obligation to correct, update, or maintain your data profile for you, and any failure by the Company to detect user errors shall not diminish your strict liability under this section.
24. FRAUD, SECURITY AND LAWFUL INVESTIGATIONS
24.1 Unilateral Surveillance and Investigative Powers
The Company reserves the absolute, unreviewable right to process, profile, and audit any personal data, transaction velocity, or system metadata at any time. This processing is deployed to track, detect, isolate, and eliminate financial fraud, unauthorized Token activity, account takeovers, identity theft, system exploits, #TripSave manipulation, and any other unlawful conduct.
24.2 Unconditional Information Sharing & Whistleblower Immunity
Where the Company, in its sole discretion, suspects fraudulent or unlawful activity, it may instantly share any and all user information, transaction logs, and communication archives with payment gateways, credit reference bureaus, external legal counsel, statutory regulators, and law enforcement authorities (including the Directorate of Criminal Investigations and the Financial Reporting Centre). The User explicitly waives all rights to privacy, data confidentiality, or statutory claims against the Company for data disclosures executed under this clause.
24.3 Instant Account Seizure and Token Freezing
The Company maintains the unilateral right to instantly suspend, restrict, or permanently lock any account, wallet balance, or pending Digital Voucher during an investigation into suspected fraud, system abuse, or security anomalies. The User acknowledges and agrees that the Company shall incur zero financial or legal liability for freezing assets, denying system access, or causing missed travel bookings during the investigative window.
24.4 Immediate Action Without Prior Notice
All defensive actions, wallet freezes, and system bans may be executed by the Company instantaneously and without any prior notice, justification, or administrative warning. The User completely releases the Company, its directors, and its operators from any liability for losses, reputational damage, or inconveniences resulting from such unannounced security actions.
25. LINKS TO THIRD-PARTY WEBSITES AND SERVICES
25.1 Intermediary Hyperlinks and System Redirection
The Platform systematically embeds and features external links, web hooks, redirect portals, and application programming interfaces (APIs) leading to independent third-party websites, external hospitality booking systems, global travel platforms, and third-party payment rails.
25.2 Complete Absence of Operational Control
The User explicitly acknowledges and agrees that Safari Wallet KE maintains zero operational oversight, digital control, or regulatory monitoring over the security frameworks, privacy practices, data handling algorithms, or technical architectures of independent third parties.
25.3 Non-Endorsement Covenant
The inclusion, publication, or promotion of any third-party link, system, or widget on the Platform is for user convenience only. It does not constitute, represent, or imply an endorsement, warranty, representation, or guarantee of that third party’s privacy standards, cyber security posture, data compliance, or commercial viability.
25.4 Strict Assumption of Risk and Waiver of Recourse
- The User maintains an absolute, non-delegable duty to review and understand the independent privacy policies, terms of service, and cookie disclosures of any external platform before submitting personal information or financial data to it.
- The Company, its directors, and its technology operators are completely insulated from, and explicitly disclaim all liability for, any data breaches, metadata leaks, identity theft, financial fraud, phishing losses, system malware, or privacy violations occurring on, or executed by, any third-party website, booking engine, or service platform linked from Safari Wallet KE. The User accesses external links strictly at their own peril and fully waives all rights to legal or financial recourse against the Company for third-party failures.
26. CHANGES TO THIS PRIVACY POLICY
26.1 Absolute Right to Overhaul
The Company reserves the sole, absolute, and unreviewable right to modify, amend, rewrite, or completely overhaul this Privacy Policy at any time, in whole or in part, without prior individualized notification or administrative justification to you.
26.2 Catalysts for Revision
Such amendments may be deployed at the Company's sole discretion to reflect shifting technical and operational realities, including but not limited to:
- Service Architecture: Upgrades, structural shifts, or feature additions to our travel utilities or platform mechanisms.
- Technology Stacks: Deployments of new security measures, software systems, secure databases, or integrated analytics engines.
- Statutory Frameworks: Evolutionary shifts in applicable Kenyan laws, decisions by the judiciary, or binding guidance notes issued by the Office of the Data Protection Commissioner (ODPC).
- Ecosystem Oversight: Updates to operational risk controls, fraud detection models, and third-party data processing agreements with independent tours, experiences, and events-related vendors.
26.3 Mechanism of Public Notice
The publication of the modified Policy directly on the Platform interface, with an updated “Last Updated” timestamp, shall serve as complete, definitive, and legally sufficient notice to all Users. The Company disclaims any legal duty to push individual electronic mail alerts or in-app pop-up warnings for routine operational adjustments.
26.4 Automatic Binding Effect and Waiver of Challenge
- Your continued download, access, navigation, account retention, or general use of the Platform following the publication of any update constitutes your automatic, immediate, and irrevocable acceptance of the revised Policy.
- By continuing to use the platform, you fully waive any right to claim that you were unaware of the modifications or that the terms of the updated Policy are non-binding. If you object to any modified term, your sole, exclusive remedy is to immediately stop using the Platform and close your account. [1]
26.5 Discretionary Consent Triggers
Where applicable Kenyan data protection regulations explicitly mandate separate, opt-in consent for a highly distinct processing mechanism (such as direct marketing to a completely new asset class), the Company will present a separate verification prompt on the interface. A refusal to click "accept" on such separate prompts shall grant the Company the immediate, unilateral right to restrict your access to the affected features, without any financial liability or Token reimbursement obligations.
27. COMPLAINTS
27.1 Condition Precedent and Pre-Action Notice
If you suspect, allege, or believe that your Personal Data or Sensitive Personal Data has been processed, leaked, or exposed in breach of this Privacy Policy, the Data Protection Act, 2019, or any applicable Kenyan data protection regulations, you are strictly required to exhaust the internal dispute resolution mechanism set out in this section before initiating any formal legal actions, escalating to judicial courts, or filing an official complaint with the Office of the Data Protection Commissioner (ODPC).
27.2 Filing Mechanics and Strict Claim Limitations
- Any alleged privacy grievance must be formally lodged in writing with the Company’s designated Data Protection Officer via email at mysafariwalletke@gmail.com within forty-eight (48) hours of the occurrence or discovery of the event giving rise to the complaint.
- Failure to lodge the complaint within this explicit forty-eight (48) hour window constitutes an absolute, binding, and irrevocable waiver of any right to claim damages, seek administrative action, or pursue legal remedies against the Company for that specific incident.
27.3 Internal Investigation Window and Right to Remediate
Upon receiving a valid, detailed pre-action notice, the Company will investigate the circumstances of the report and take commercially reasonable, proportionate steps to remediate, patch, or address legitimate vulnerabilities. The User explicitly grants the Company a mandatory sixty (60) business day window from the date of receipt to complete its internal review and implement structural fixes.
27.4 Complete Waiver of Tortious and Consequential Liability
- The Company’s internal investigation and remediation protocol shall serve as your exclusive administrative remedy.
- To the maximum extent permitted by Kenyan law, the Company, its directors, and its operational affiliates completely disclaim, and the User fully waives, any right to seek civil damages, tortious compensation, emotional distress payouts, exemplary damages, or punitive financial penalties arising out of data handling flaws or security incidents.
- This section does not strip away your statutory right to bring a complaint before the ODPC under Section 56 of the Act if internal remediation fails, but it hard-locks your financial claims against the Company to zero, provided the Company takes active steps to contain and mitigate verified data breaches upon discovery.
28. GOVERNING LAW AND JURISDICTION
This Privacy Policy shall be governed by and interpreted in accordance with the laws of the Republic of Kenya.
Any dispute concerning this Privacy Policy or the processing of personal data by Safari Wallet KE shall, subject to any mandatory statutory rights or procedures, be subject to the jurisdiction of the competent courts of Kenya.
29. NO WAIVER OF STATUTORY RIGHTS
Where any provision of this Policy is found to be unlawful, invalid or unenforceable, that provision shall be interpreted or severed to the minimum extent necessary, while the remaining provisions shall continue in effect.
30. CONTACT INFORMATION
For questions, requests, complaints or concerns concerning privacy or personal data, please contact:
SAFARI WALLET KE
Legal Entity: Whistle Africa Tours and Events
Email Address: support@safariwalletke.com
Postal Address: P.O. Box 92 - 20100, Nakuru, Kenya
31. USER ACKNOWLEDGEMENT
By continuing to use the platform and or selecting “I Agree & Continue”, you acknowledge that:
- You have been provided with an opportunity to read this Privacy Policy;
- You understand how Safari Wallet KE processes personal data;
- You understand that different processing activities may rely on different lawful bases;
- You understand your rights under applicable Kenyan data-protection law;
- You understand how to contact Safari Wallet KE regarding your personal data;
- You will provide accurate and lawful information when using the Platform.
SIGN BELOW BY TYPING YOUR FULL NAMES TO CONFIRM THAT YOU HAVE READ AND UNDERSTAND THE PRIVACY POLICY