BASIL & ALRED
PRIVACY POLICY
Last updated: 23 October 2023
1. Introduction
Welcome to Basil & Alred (“we”, “our”, “us”). We are a professional services firm based in Dar es Salaam, Tanzania. We respect your privacy and are committed to protecting your personal data in accordance with applicable law, including the Personal Data Protection Act, 2022 and its Regulations.
This Privacy Policy explains how we collect, use, store and share your personal data when you visit our website (the “Website”), engage with us via the Website, or otherwise contact us.
2. Data Controller & Contact Details
We are the Data Controller for the purposes of the PDPA.
If you have any questions or concerns about this policy, your personal data or our processing practices, please contact us at:
Basil & Alred
ACE Building, 1st Floor, Haile Selassie Road, Oysterbay, Dar es Salaam, Tanzania
Email: info@basilalred.com
Telephone: +255 22 260 0342
3. Personal Data We Collect
When you use our website’s contact form, we collect the following personal data:
- Full Name (or name and surname)
- Email address
- Phone number / contact number
- Message or enquiry you submit
In addition, we may collect certain usage or technical data automatically via our Website such as your IP address, browser type, time and date of access, pages visited, referral source, device type, and cookies/analytics data.
We do not collect sensitive personal data (as defined under the PDPA) via the contact form (for example information concerning health, biometric data, political beliefs, etc).
4. How We Collect Data
We collect personal data from you directly when you submit the contact form or otherwise interact with us via email or telephone. We also collect technical/usage data automatically when you access our website.
In some cases, we may receive data about you from third-party sources only if you have given consent or if the data is publicly available, but this is not our standard method.
5. Purpose & Legal Basis for Processing
We process your personal data for the following purposes:
- To respond to your enquiry or message and communicate with you about our services;
- To record and maintain internal records of enquiries for business purposes;
- To improve our Website, user-experience and service offerings (including via analytics);
- To comply with legal or regulatory obligations where applicable.
Under the PDPA, the processing of personal data must be lawful, fair and transparent, for a specified purpose and only to the extent necessary.Where you submit your data via the contact form, you are giving your consent to use the information for those purposes. We rely on this consent as well as our legitimate interest in operating our business and website.
6. Data Minimisation, Accuracy & Retention
We only collect the personal data that is reasonably required for the purposes described above. We endeavour to ensure that the personal data we hold is accurate, complete and current. You can ask us to correct the data if it is inaccurate or incomplete.
We will retain your personal data only for as long as necessary to fulfil the purpose for which it was collected (for example: to respond to your enquiry) or for a longer period if required by applicable laws or regulations. After that period, your data will be securely deleted or anonymised.
The PDPA requires that data not be kept longer than is reasonably necessary.
7. Cookies, Analytics & Tracking
Our Website uses cookies and may incorporate analytics tools to collect non-identifiable information, such as the number of visitors, pages visited, browser type, etc. This helps us monitor and improve the performance and usability of our website.
You can choose to refuse or disable cookies via your browser settings. Please note that disabling cookies may affect certain functions of the Website.
8. Sharing and Disclosure of Personal Data
We will not sell your personal data to third parties. However, we may disclose your personal data:
- To our trusted service providers (such as web hosting, IT support, marketing or analytics tools) who act as data processors on our behalf and are contractually bound to protect your data;
- To comply with legal or regulatory obligations or when required by law (for example under the PDPA or other applicable Tanzanian legislation) or a lawful order of a court;
- In connection with the sale, merger, reorganisation or transfer of our business or assets (in which case your data may form part of transferred assets, subject to safeguards).
Where the PDPA requires it, transfers of personal data to third parties (especially outside Tanzania) will only be made if adequate safeguards are in place.
9. International / Cross-Border Transfers
Because we are based in Tanzania, but our hosting or service providers may operate outside Tanzania, your personal data may be transferred to and processed in jurisdictions other than Tanzania. When this happens, we will ensure that the transfer is lawful under the PDPA and that appropriate safeguards (such as contractual protections) are in place. The PDPA provides that transfers may only occur if the destination jurisdiction provides adequate protection or other conditions are satisfied.
10. Data Security
We implement reasonable technical and organisational measures to protect your personal data against unauthorised or unlawful access, loss, alteration, disclosure or destruction. Our security measures take into account the nature of the data we hold, the potential risks, and the current state of technology. The PDPA requires controllers to do so.
However, no system is 100% secure; you should also take reasonable steps to protect your data (for example by ensuring your own device and internet connection are secure).
11. Your Rights
Under the PDPA, you have the following rights in relation to your personal data:
- The right to be informed that your data is being collected and how it is processed;
- The right to access the personal data we hold about you;
- The right to request correction, blocking, erasure or destruction of your personal data (where applicable);
- The right to object to the processing of your personal data, particularly where such processing would cause adverse effects;
- The right to prevent processing for direct marketing;
- The right to not be subject to fully automated decision-making or profiling (if applicable);
- The right to withdraw your consent at any time (where processing is based on consent).
You may exercise these rights by contacting us using the details in section 2. We may ask you for proof of identity before fulfilling any request.
12. Data Breach Notification
In the event of a personal data breach that risks your rights or freedoms, we will take appropriate steps to contain and mitigate the breach and, where required under applicable law including the PDPA, we will notify the oversight authority (the Personal Data Protection Commission) and affected data subjects without undue delay.
13. Children’s Data
Our Website and contact form are not designed for or intended to collect data from children (i.e., persons under the age of eighteen). If we become aware that we have collected data from a child without appropriate consent, we will take steps to delete it promptly.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time (for example, to reflect changes in our practices or applicable law). Whenever we make a material change, we will update the “Last updated” date at the top of this page and, where appropriate, notify you via our Website or other communication. We encourage you to review this Policy periodically.
15. Contact Us
If you have any questions about this Privacy Policy or our privacy practices, or if you wish to exercise any of your rights, please contact us at:
Basil & Alred
ACE Building, 1st Floor, Haile Selassie Road, Oysterbay, Dar es Salaam, Tanzania
Email: info@basilalred.com
Telephone: +255 22 260 0342
16. Consent
By using our website and/or submitting your personal data via the contact form, you consent to our collection, use and transfer of your personal data as described in this Privacy Policy.