Privacy Policy
Last updated: June 10, 2026
This Privacy Policy explains how Hesbon Tinega ("I", "me", or "my") collects, uses, and protects your personal data when you visit hesbon.design (the "Site") or get in touch about a project. I am committed to handling your data responsibly and in accordance with the Kenya Data Protection Act, 2019 and its accompanying regulations.
1. Who Is Responsible for Your Data
For the purposes of the Data Protection Act, 2019, I (Hesbon Tinega) am the data controller responsible for your personal data. You can reach me at hello@hesbon.design regarding anything in this policy.
2. Information I Collect
Information you give me directly — for example when you email me, book a consultation, or send a project enquiry: your name, email address, and any details you choose to share about your business or project.
Information collected automatically — when you browse the Site, limited technical data such as your approximate location, browser type, device, and anonymous performance and usage metrics may be collected to keep the Site fast and reliable.
3. How I Use Your Information
- To respond to your enquiries and communicate with you about a potential or active project.
- To provide, deliver, and improve the Services.
- To operate, maintain, secure, and improve the performance of the Site.
- To send project-related or administrative information (for example proposals or invoices).
- To comply with legal obligations.
I do not sell your personal data, and I do not send marketing emails without your consent.
4. Legal Basis for Processing
I process your personal data where it is necessary to take steps at your request before entering into a contract or to perform a contract with you, where you have given consent, where I have a legitimate interest (such as keeping the Site secure), or where required to comply with the law.
5. Cookies & Analytics
The Site uses minimal, privacy-respecting analytics (Vercel Speed Insights) to measure performance and aggregate usage. This does not build advertising profiles of you. The Site does not use intrusive advertising or tracking cookies. You can control cookies through your browser settings.
6. Third-Party Services
To run the Site and deliver Services, I rely on trusted third-party providers who process limited data on my behalf or under their own policies, including:
- Vercel — website hosting and performance analytics.
- Sanity — content management for the Site's content.
- Google — web fonts served by the Site and the calendar booking link used to schedule consultations.
- Email and social platforms (e.g. LinkedIn, Instagram) — used to communicate with you when you choose to contact me through them.
Each of these providers maintains its own privacy policy governing how it handles data.
7. Sharing & Disclosure
I do not sell or rent your personal data. I only share it with the service providers above as needed to operate, or where I am legally required to disclose it (for example to comply with a lawful request from a competent authority).
8. Data Retention
I keep personal data only for as long as necessary to fulfil the purposes described in this policy, including to meet legal, accounting, or reporting obligations. Project communications and records may be retained for the duration of our working relationship and a reasonable period afterward.
9. Data Security
I take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. However, no method of transmission or storage over the internet is completely secure, and I cannot guarantee absolute security.
10. Your Rights Under the Data Protection Act, 2019
As a data subject, you have the right to:
- Be informed of the use to which your personal data is put.
- Access the personal data I hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your personal data where there is no lawful reason to keep it.
- Object to or request restriction of the processing of your data.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact me at hello@hesbon.design. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya if you believe your data has been mishandled.
11. International Transfers
Some of the third-party providers I use may store or process data on servers outside Kenya. Where this happens, I take reasonable steps to ensure your data continues to be protected in line with the Data Protection Act, 2019.
12. Children's Privacy
The Site and Services are intended for businesses and adults. I do not knowingly collect personal data from children. If you believe a child has provided me data, please contact me so I can remove it.
13. Changes to This Policy
I may update this Privacy Policy from time to time. The "Last updated" date above reflects the latest revision. Please review this page periodically.
14. Contact
If you have any questions about this Privacy Policy or how your data is handled, contact me at hello@hesbon.design.