Ottico Eye Care

Privacy Policy

How we collect, use, and protect your personal information

Effective: April 2026 Website: otticoeyecare.co.ke Jurisdiction: Republic of Kenya
Legal framework: This policy is made in accordance with the Kenya Data Protection Act, 2019 (No. 24 of 2019) and the Data Protection (General) Regulations, 2021, administered by the Office of the Data Protection Commissioner (ODPC). It is also informed by the Kenya Information and Communications Act (Cap. 411A). As a data controller, Ottico Eye Care is obligated to process your personal data lawfully, fairly, and transparently.

1. Who we are

Ottico Eye Care is a registered eye care practice operating in Kenya. Our website is https://otticoeyecare.co.ke. We are the data controller for personal information collected through this website, as defined under Section 2 of the Kenya Data Protection Act, 2019.

As a data controller, we are responsible for determining the purposes and means by which your personal data is processed, and we are committed to handling your data in compliance with applicable Kenyan law.

2. Data we collect

Under Section 25 of the Data Protection Act, 2019, we only collect personal data that is adequate, relevant, and not excessive for the purpose for which it is processed. When you leave a comment on this site, we collect:

  • Your name and email address (as entered in the comment form)
  • Your website URL (optional)
  • Your IP address and browser user agent string — used for spam detection only
  • An anonymised hash of your email address may be shared with Gravatar to retrieve your profile photo if you use that service

The legal basis for this processing is your consent (Section 30, Data Protection Act, 2019), given when you voluntarily submit a comment. You may withdraw consent at any time by contacting us.

3. Cookies

In line with the Kenya Information and Communications (Consumer Protection) Regulations and best practice under the Data Protection Act, 2019, we use cookies as follows:

  • Comment cookies (opt-in): If you leave a comment, you may opt in to saving your name, email, and website in a cookie lasting 1 year, so you need not re-enter details next time.
  • Session/login cookies: A temporary cookie is set when you visit the login page to check browser compatibility — it holds no personal data and expires when you close your browser.
  • Authentication cookies: On login, cookies store your session (2 days) and display preferences (1 year). "Remember Me" extends login persistence to 2 weeks. These are cleared on logout.
  • Editorial cookie: If you edit or publish content, a cookie records the post ID. It contains no personal data and expires after 1 day.

You may manage or disable cookies via your browser settings. Note that disabling cookies may affect the functionality of this website.

4. Media uploads

If you upload images to this website, you should avoid uploading images with embedded location data (EXIF GPS). Under the Data Protection Act, 2019, location data qualifies as personal data. Visitors to this website can download and extract any location data from images you post.

We recommend stripping EXIF metadata from images before uploading. Ottico Eye Care is not liable for location data embedded in user-uploaded media.

5. Embedded content from other websites

Articles on this site may include embedded content such as videos, images, or articles from third-party platforms. Embedded content behaves exactly as if you had visited those external websites directly.

Those third-party websites may collect data about you, use their own cookies, embed additional tracking, and monitor your interaction with that content — including if you are logged into those platforms. We have no control over those third parties' data practices. We encourage you to review their respective privacy policies.

6. Who we share your data with

We do not sell or rent your personal data to third parties. Under Section 25(d) of the Data Protection Act, 2019, we only share your data where necessary and proportionate:

  • Password resets: Your IP address is included in password reset emails as a security measure.
  • Spam detection: Visitor comments may be checked through an automated spam detection service (e.g., Akismet). This service processes comment content and metadata for spam classification only.
  • Gravatar: An anonymised hash of your email may be sent to Gravatar to retrieve your avatar.
  • Legal obligations: We may disclose data where required by Kenyan law, court order, or lawful request by a public authority under Section 51 of the Data Protection Act, 2019.

7. How long we retain your data

In accordance with the data minimisation principle under Section 25(c) of the Data Protection Act, 2019, we retain your data only as long as necessary for the purpose for which it was collected:

  • Comments: Comments and associated metadata are retained indefinitely so that we can recognise and approve follow-up comments automatically. You may request deletion at any time (see Your Rights below).
  • Registered users: Personal information in user profiles is retained for as long as the account is active. All users may view, edit, or delete their information at any time (except usernames). Website administrators may also access and edit this information.
  • Security and legal data: Certain data (e.g., logs required for fraud prevention or legal compliance) may be retained longer where required by law.

8. Your rights under Kenyan law DPA 2019

Under Part IV of the Kenya Data Protection Act, 2019, you have the following rights regarding your personal data:

Right of access

Request a copy of personal data we hold about you (Section 26).

Right to rectification

Request correction of inaccurate or incomplete data (Section 26).

Right to erasure

Request deletion of your personal data, subject to legal retention obligations (Section 26).

Right to data portability

Receive an export of your data in a structured, commonly used format (Section 28).

Right to object

Object to processing of your data in certain circumstances (Section 26).

Right to withdraw consent

Withdraw consent for processing at any time without affecting prior lawful processing (Section 30).

To exercise any of these rights, contact us at the details below. We will respond within 21 days as stipulated by the Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021.

9. Where your data is sent

Some of your data may be transferred to, and processed in, countries outside Kenya — for example when using third-party services such as Gravatar (operated by Automattic, Inc., USA) or spam detection services. Where data is transferred outside Kenya, we take steps to ensure adequate protection in line with Section 48 of the Data Protection Act, 2019, which requires that the recipient country provides an equivalent level of data protection, or that appropriate safeguards (such as contractual clauses) are in place.

10. Contact us & complaints

If you have questions about this policy or wish to exercise your data rights, please contact us through our website: https://otticoeyecare.co.ke.

If you are not satisfied with how we handle your data or your request, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) — the supervisory authority established under Section 5 of the Data Protection Act, 2019:

This policy may be updated periodically. Any material changes will be communicated via this website. Continued use of our services after any update constitutes acceptance of the revised policy.

Ottico Eye Care

Questions or data requests? Visit our website →

Regulated under

Kenya Data Protection Act, 2019