Privacy Policy
Last updated: 1 July 2025 | House Levitika Plus Ltd
1. Introduction
House Levitika Plus Ltd ("Company", "we", "us" or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose and safeguard your information when you visit store.houselevi.com or make a purchase from us. It is issued in compliance with the Kenya Data Protection Act, 2019 (DPA 2019) and the Data Protection (General) Regulations, 2021.
By using our website, you acknowledge that you have read, understood and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of our services.
2. Data Controller Information
- Controller: House Levitika Plus Ltd
- Registered Address: Nairobi, Kenya
- Data Protection Officer (DPO): dpo@houselevi.com
- General Contact: legal@houselevi.com
3. Personal Data We Collect
We may collect and process the following categories of personal data:
- Identity Data: Full name, username or similar identifier.
- Contact Data: Email address, phone number, billing and delivery addresses.
- Transaction Data: Details of purchases, products ordered, payment method (we do not store full card numbers), and transaction history.
- Technical Data: IP address, browser type and version, time zone, browser plug-in types, operating system, device identifiers, and other technology on the devices you use to access our site.
- Usage Data: Information about how you use our website, products and services.
- Marketing and Communications Data: Your preferences in receiving marketing from us and your communication preferences.
- Profile Data: Your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
We do not collect any Special Categories of Personal Data (as defined under Section 45 of the DPA 2019) including data about race, ethnic origin, health, biometric data or criminal convictions.
4. How We Collect Your Data
- Direct interactions: You provide data when creating an account, placing an order, subscribing to our newsletter, filling in a form, or contacting us.
- Automated technologies: As you interact with our site, we may automatically collect Technical Data using cookies, server logs and similar technologies. See our Cookie Policy.
- Third parties: We may receive data from payment processors, analytics providers (e.g. Google Analytics), advertising networks, and delivery partners.
5. Lawful Basis for Processing
Under Section 30 of the DPA 2019, we process your personal data on the following lawful bases:
- Contract: Processing necessary for the performance of a contract with you (e.g. fulfilling an order).
- Legitimate interests: Processing necessary for our legitimate interests (e.g. fraud prevention, improving our services), where those interests are not overridden by your rights.
- Consent: Where you have given clear consent (e.g. for marketing emails or non-essential cookies).
- Legal obligation: Processing necessary to comply with a legal obligation under Kenyan law.
6. How We Use Your Data
- To register and manage your account.
- To process and deliver your orders, including payment processing and fraud prevention.
- To manage our relationship with you, including notifying you of changes to our terms or policies.
- To send you marketing communications where you have opted in (you may opt out at any time).
- To administer and protect our business and website (troubleshooting, data analysis, testing, system maintenance, support and reporting).
- To use data analytics to improve our website, products, services, marketing, customer relationships and experience.
- To comply with applicable legal and regulatory obligations.
7. Data Sharing and Disclosure
We may share your personal data with:
- Service Providers: Third-party vendors acting as data processors on our behalf (e.g. payment processors, IT service providers, delivery companies, email platforms). They process your data only on our instructions and are bound by confidentiality obligations.
- Professional Advisors: Lawyers, auditors and insurers who provide consultancy, legal, accounting and insurance services to us.
- Regulators and Authorities: Government bodies, courts, law enforcement or regulators where required by law, including the Office of the Data Protection Commissioner (ODPC).
- Business Transfers: In the event of a merger, acquisition or sale of all or part of our business.
We do not sell your personal data to third parties.
8. International Transfers
Where we transfer your data outside Kenya, we ensure that adequate protections are in place as required by Section 48 of the DPA 2019, including transfer to countries with adequate data protection laws or through contractual safeguards such as Standard Contractual Clauses.
9. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes set out in this policy, including for legal, accounting or reporting requirements. Transaction records are retained for a minimum of seven (7) years in accordance with Kenyan tax and financial legislation. Account data is retained for the duration of your account plus three (3) years after closure, unless a longer retention period is required by law.
10. Your Rights Under the DPA 2019
Under Sections 26–34 of the DPA 2019, you have the right to:
- Access your personal data and receive a copy of it.
- Rectification of inaccurate or incomplete data.
- Erasure of your data where there is no compelling reason for its continued processing ("right to be forgotten").
- Restriction of processing in certain circumstances.
- Data portability — receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
- Lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at www.odpc.go.ke.
To exercise any of these rights, contact us at dpo@houselevi.com. We will respond within 21 days as required by the DPA 2019.
11. Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include encryption, access controls, secure socket layer (SSL) technology and regular security assessments. However, no internet transmission is completely secure; you transmit data at your own risk.
12. Children
Our services are not directed to persons under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately at dpo@houselevi.com.
13. Third-Party Links
Our website may include links to third-party websites. Clicking those links may allow third parties to collect or share data about you. We do not control those websites and are not responsible for their privacy practices.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website and, where required by law, by direct communication. The date at the top of this page indicates when this policy was last updated.
15. Contact Us
For questions about this Privacy Policy or to exercise your rights, contact our Data Protection Officer at:
Email: dpo@houselevi.com
Post: Data Protection Officer, House Levitika Plus Ltd, Nairobi, Kenya.