Ideas into Impact. · Learn · Create · Test · Build · GrowVisit Ubunifu Innovation Hub ↗
Ubunifu Institute professional learning community
Deletion Policy

Deletion & Erasure Policy

How Ubunifu Institute handles requests to erase personal data while preserving records that must lawfully or operationally be retained.

CreativityEnterpriseUseful change
Next best actionsLive governed view

Use the next actions below to keep moving without having to understand the Institute’s internal structure.

Ubunifu InstituteEffective / reviewed: 4 September 2026Applies to the public website and relevant digitally supported relationships
01

What you can request

A person may request deletion or erasure of personal data concerning them where the applicable legal conditions are met, including where data is no longer authorised or necessary to retain, is irrelevant or excessive, was obtained unlawfully, or where another recognised erasure ground applies.

02

How to submit a request

Use the Contact page and clearly state that the request concerns privacy, deletion or erasure. Identify the relevant account, application, programme, transaction or relationship where possible. Do not send passwords, OTPs or unnecessary identity documents through an ordinary message.

03

Identity and authority verification

Ubunifu may verify identity and, where someone acts for another person, verify authority to act. Verification is proportionate to the risk because an unverified deletion request could erase or expose another person’s records.

04

Assessment and response

The request is assessed against the data held, processing purpose, lawful basis, retention requirement, third-party processing and any legal exception. Where the Kenyan General Regulations prescribe a response period for an erasure request, Ubunifu’s process is designed to operate within that applicable timeframe.

05

Deletion, anonymisation or restriction

Where deletion is approved, records may be erased from active systems, anonymised so they no longer identify the person, or otherwise securely disposed of. Where data cannot yet be erased but ordinary use should stop, access/processing may be restricted to the permitted purpose.

06

Records that may need to be retained

  • Tax, accounting, payment, reconciliation and audit evidence.
  • Contracts, legal claims, disputes and defence of rights.
  • Safeguarding, fraud prevention, security and incident evidence.
  • Research records where lawful retention or an applicable research/public-interest exception applies.
  • Records needed to demonstrate a prior consent, decision, certification, transaction or statutory compliance obligation.
07

Backups and derived systems

Protected backups can contain historical copies until the normal backup cycle expires. A deleted record should not be silently restored into ordinary use from backup. Where appropriate, deletion/restriction instructions are propagated to processors or connected systems for which Ubunifu is responsible.

08

Public profiles and demo records

Approved public profiles are removed or unpublished when the underlying publication basis ends, subject to lawful retention of private evidence. Controlled DEMO records are system test content and can be purged through their governed demo controls without deleting unrelated live records.

09

If a request cannot be fully granted

Where some data must be retained, the response should explain the relevant reason and what will happen to the affected record, subject to legal and security limits. You may raise a concern through the Contact route or exercise available rights before the Office of the Data Protection Commissioner.

Official references

Regulatory sources

These links are provided for current authoritative context. Where a policy conflicts with applicable law, the law and a formally approved instrument govern.