Privacy Policy



GetCovered Kenya (“GetCovered”, “we”, “us”, or “our”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, disclose, store, protect and otherwise process personal data when you visit or use our website, submit an insurance enquiry, request an insurance quotation, purchase or renew an insurance policy through us, communicate with us, use our digital services, or otherwise interact with GetCovered.

Because insurance transactions can involve personal, financial, identification, health and other potentially sensitive information, we take data protection seriously.

Our objective is to process your information lawfully, fairly and transparently, collect only information that is reasonably necessary for identified purposes, protect it using appropriate safeguards, and respect the rights available to you under applicable Kenyan data-protection law.

This Privacy Policy should be read together with our Terms and Conditions, Cookie Policy, applicable insurance documentation and any specific privacy notices presented to you when we collect your information.

1. Who We Are

GetCovered Kenya is an insurance intermediary and digital insurance platform operating in Kenya.

We help customers access, compare, obtain quotations for and arrange insurance products offered by participating insurance providers.

Depending on the particular transaction, GetCovered may process personal data:

As a data controller, where we determine the purposes and means of processing your personal data;
  • As a data processor, where we process personal data on behalf of another organisation under its instructions; or
  • In some circumstances, as a party processing information jointly or in coordination with another organisation, where applicable under law.

The precise role we perform depends on the service and the particular processing activity.

Where another organisation, such as an insurance company, is independently responsible for processing your personal data, that organisation may have its own privacy notice and data-protection responsibilities.


2. Our Commitment To Privacy

We believe privacy should not be hidden behind complicated legal language.

When you give us your personal information, you should understand:

What information we collect;
  • Why we collect it;
  • How we use it;
  • Who may receive it;
  • How long we keep it;
  • How we protect it;
  • Whether it may be transferred outside Kenya;
  • Your rights regarding your information;
  • How you can contact us;
  • What you can do if you believe your privacy rights have been violated.

This Privacy Policy is therefore intended to provide a practical explanation of how GetCovered handles personal data.

3. Applicable Data Protection Law

GetCovered processes personal data in accordance with applicable Kenyan data-protection requirements, including the Data Protection Act, 2019, together with applicable regulations, guidance and other requirements issued by the Office of the Data Protection Commissioner (“ODPC”) and other competent authorities.

The Data Protection Act establishes a framework governing the processing of personal data and provides rights to individuals whose personal data is processed. (Kenya Law)

Where applicable, we also consider other laws and regulatory requirements relevant to our insurance intermediary activities, electronic communications, taxation, financial transactions, record keeping, fraud prevention and other legitimate business or legal obligations.

Where another law imposes a requirement that affects how long we must retain information, how we must disclose it or how we must process it, we will comply with that applicable requirement.


4. What Is Personal Data?


For purposes of this Privacy Policy, personal data generally means information relating to an identified or identifiable individual.

Depending on your interaction with GetCovered, personal data may include information such as:

  • Your name;
  • Telephone number;
  • Email address;
  • Physical or postal address;
  • Date of birth;
  • Nationality;
  • Identification information;
  • Passport information;
  • Vehicle registration information;
  • Vehicle ownership information;
  • Employment information;
  • Business information;
  • Insurance history;
  • Policy information;
  • Claims information;
  • Payment information;
  • Financial information;
  • Travel information;
  • Health or medical information;
  • Information concerning dependants or beneficiaries;
  • Communication records;
  • IP address;
  • Device information;
  • Browser information;
  • Website usage information;
  • Location information where applicable;
  • Information contained in documents you submit to us;
  • Any other information reasonably required to provide the requested insurance service.

The information we collect depends on the product or service you request.


5. Sensitive Personal Data

Certain information may be considered sensitive personal data under Kenyan law.

Insurance transactions can involve sensitive information, particularly in areas such as health and medical insurance.

Depending on the product and circumstances, we may process information relating to:

  • Health status;
  • Medical history;
  • Medical treatment;
  • Disability or medical conditions;
  • Financial information;
  • Identification information;
  • Family or dependant information;
  • Biometric information, where legitimately required;
  • Location information, where applicable;
  • Other categories recognised as sensitive under applicable law.

We will only process sensitive personal data where there is a lawful basis and where the processing is necessary and appropriate for the relevant purpose.

Where applicable, additional consent, safeguards or other legal requirements may apply.

6. Information We Collect

We may collect information through several different channels.


6.1 Information You Give Us Directly

You may provide personal information when you:

Complete an online quotation form;
  • Request an insurance quote;
  • Purchase insurance;
  • Renew insurance;
  • Contact customer support;
  • Contact us by telephone;
  • Contact us through WhatsApp;
  • Send us an email;
  • Complete a contact form;
  • Subscribe to communications;
  • Submit documents;
  • Make an enquiry;
  • Make a complaint;
  • Request assistance with a claim;
  • Participate in a survey;
  • Apply for employment;
  • Otherwise communicate with us.

7. Information Collected Through Insurance Applications

When you request an insurance quotation or apply for insurance, we may collect information necessary to assess and arrange the requested insurance.

The exact information depends on the insurance product.

For example:


Motor Insurance


We may collect:

Vehicle registration number;
  • Vehicle make and model;
  • Vehicle year;
  • Vehicle value;
  • Vehicle use;
  • Ownership information;
  • Driver information;
  • Previous insurance information;
  • Claims information;
  • Identification documents;
  • Other underwriting information.


Health Insurance

Depending on the product and underwriting requirements, we may collect:

Applicant information;
  • Age;
  • Dependants;
  • Medical information;
  • Medical history;
  • Existing conditions;
  • Desired benefits;
  • Previous insurance information;
  • Other information required by the insurer.

Travel Insurance

We may collect:

Traveller name;
  • Date of birth;
  • Passport information where required;
  • Destination;
  • Travel dates;
  • Trip information;
  • Contact information;
  • Other information required for underwriting.


Business Insurance


We may collect:

Business name;
  • Business registration information;
  • Business activities;
  • Business location;
  • Employee information;
  • Asset information;
  • Revenue or turnover information;
  • Claims history;
  • Risk information;
  • Property information;
  • Contractual information;
  • Other underwriting information.

WIBA Insurance

Depending on the quotation and insurer requirements, we may collect information concerning:

Employer;
  • Employees;
  • Employee categories;
  • Payroll or remuneration information;
  • Business activities;
  • Workplace information;
  • Other information required to assess and arrange the relevant cover.

8. Information We Collect Automatically

When you use our website or digital services, certain technical information may be collected automatically.

Depending on the technologies we use, this may include:

IP address;
  • Browser type;
  • Operating system;
  • Device type;
  • Screen information;
  • Referring website;
  • Pages visited;
  • Date and time of access;
  • Approximate location derived from technical information;
  • Website interaction data;
  • Session information;
  • Cookies and similar technologies.

This information helps us operate, secure, analyse and improve our website.

Please see our Cookie Policy for more information about cookies and similar technologies.

9. Information We Receive From Third Parties

In some circumstances, we may receive personal data from third parties.

These may include:

  • Insurance companies;
  • Insurance intermediaries;
  • Employers;
  • Business partners;
  • Payment providers;
  • Technology service providers;
  • Claims-related service providers;
  • Regulatory or government authorities;
  • Fraud-prevention service providers;
  • Professional advisers;
  • Other parties involved in providing the requested service.

We will only process such information for lawful and appropriate purposes.


Where required, we will provide the relevant privacy information or otherwise ensure that applicable legal requirements are satisfied.


10. Why We Collect Your Personal Data

We collect and process personal data for specific and legitimate purposes.

These may include:

Providing insurance quotations

We use information you provide to assess your requirements and obtain or prepare insurance quotations.

Arranging insurance

We may provide relevant information to insurers or other authorised parties so that your requested insurance can be assessed and arranged.

Processing applications

We use your information to process insurance applications and related documentation.

Issuing policy documents

Your information may be required to generate and deliver insurance certificates, policy schedules and other documentation.


Managing policies


We may use your information to administer, renew, amend or otherwise service your insurance policy.

Customer support

We use your information to respond to questions and provide support.


Claims support

Where appropriate, we may process information necessary to assist with claims communication and administration.

The insurer responsible for your policy may separately process your information for claims assessment and settlement.


Payments

We may process information required to facilitate or reconcile insurance payments.


Fraud prevention

We may process information to detect, investigate and prevent fraud, attempted fraud, identity theft, money laundering or other unlawful activity where applicable.


Legal and regulatory compliance


We may process personal data where necessary to comply with legal, regulatory, court or governmental requirements.


Security

We process technical and other information to protect our website, systems, customers and business from unauthorised access, attacks, fraud and misuse.

Improving our services

We may analyse usage information to understand how customers interact with our website and improve our services.

Communications

We may use your contact information to respond to enquiries, send service-related messages and, where legally permitted and subject to your preferences, send marketing communications.

11. Lawful Bases For Processing

We will process personal data only where we have a lawful basis to do so.

Depending on the circumstances, our lawful basis may include:


Consent


Where required, we may ask for your consent to process personal data for a specified purpose.

You should be able to understand what you are consenting to before providing consent.

Where consent is the lawful basis, you may generally withdraw your consent, subject to legal or contractual limitations and the circumstances of the processing.

Withdrawal of consent does not necessarily affect the lawfulness of processing that occurred before the withdrawal.


Performance Of A Contract

We may need to process personal data to provide a service you have requested or to take steps at your request before entering into a contract.

For example, information may be necessary to:

Prepare an insurance quotation;
  • Process an application;
  • Arrange insurance;
  • Administer a policy;
  • Process a transaction.

Legal Obligation

We may process personal data where necessary to comply with a legal or regulatory obligation.

This may include requirements relating to:

  • Insurance regulation;
  • Taxation;
  • Accounting;
  • Record keeping;
  • Fraud prevention;
  • Court orders;
  • Regulatory investigations;
  • Law enforcement;
  • Other legal obligations.

Vital Interests

In limited circumstances, personal data may be processed where necessary to protect the vital interests of an individual or another person, where permitted by law.

Legitimate Interests

Where permitted by applicable law, we may process personal data for legitimate interests, provided that those interests are not overridden by your rights and interests.

Examples may include:

Improving website security;
  • Preventing fraud;
  • Maintaining IT security;
  • Improving customer service;
  • Managing business operations;
  • Protecting our legal rights;
  • Maintaining records;
  • Analysing service performance.

Where we rely on legitimate interests, we consider whether the processing is necessary and whether the individual's rights and interests are adequately protected.


12. When We Ask For Consent

Where consent is required, we will seek it in an appropriate manner.

Consent should be:

Freely given;
  • Specific;
  • Informed;
  • Unambiguous;
  • Capable of being withdrawn where applicable.

We will not treat consent to marketing as a condition of receiving an insurance service where the law requires marketing consent to be separate.


13. Marketing Communications

We may wish to communicate with you about products, services, offers or educational content that may be relevant to you.

Marketing communications may include:

  • Email;
  • SMS;
  • WhatsApp;
  • Telephone;
  • Website notifications;
  • Other digital communication channels.

Where required by law, we will obtain appropriate consent before sending direct marketing.


You may opt out of marketing communications at any time.


For example, you may:


  • Use an unsubscribe link in an email;
  • Follow the opt-out instructions in an SMS;
  • Contact us;
  • Ask us to stop marketing communications.


Even if you opt out of marketing, we may continue sending essential service communications, such as:


  • Policy notices;
  • Payment confirmations;
  • Renewal information;
  • Security notifications;
  • Claims-related communications;
  • Important service announcements.


14. Who We Share Your Personal Data With


We do not sell your personal information as a commodity.


However, providing insurance services may require us to share relevant information with third parties.


These may include:


Insurance Companies


Where you request an insurance quotation or policy, relevant information may be shared with the insurer or insurers involved in assessing and arranging the insurance.


The insurer may process your personal data under its own privacy policy.


Insurance Service Providers


Depending on the insurance product, relevant information may be shared with parties involved in underwriting, policy administration, claims or other insurance services.


Payment Providers


Payment information may be processed through banks, mobile-money providers, card networks or other payment service providers.


We do not necessarily receive or store your complete card credentials where payment is processed directly by a third-party payment provider.


Technology Providers


We may use third-party technology providers for:


  • Website hosting;
  • Cloud storage;
  • Customer relationship management;
  • Email;
  • SMS;
  • WhatsApp or messaging;
  • Analytics;
  • Cybersecurity;
  • Software;
  • Document management;
  • Backup;
  • Customer support.


Where third-party processors process personal data on our behalf, we seek to ensure appropriate contractual and security safeguards are in place.


Professional Advisers


We may disclose information to professional advisers such as:


  • Lawyers;
  • Accountants;
  • Auditors;
  • Consultants;
  • Compliance advisers;
  • Other professional service providers.


Regulators And Government Authorities


We may disclose information where required or permitted by law to:


  • Insurance Regulatory Authority;
  • Office of the Data Protection Commissioner;
  • Kenya Revenue Authority;
  • Police;
  • Courts;
  • Other competent authorities.


Fraud Prevention And Security Providers


Information may be shared where necessary to detect or prevent fraud, cybercrime, identity theft or other unlawful activity.


15. Insurance Companies And Independent Data Controllers


When you request insurance through GetCovered, the relevant insurer may independently process your personal information.


This is particularly important because the insurer may be responsible for:


  • Underwriting;
  • Policy issuance;
  • Claims assessment;
  • Claims settlement;
  • Policy administration;
  • Regulatory reporting;
  • Other insurance functions.


The insurer may therefore have its own privacy policy.


We encourage you to review the privacy information provided by the relevant insurer.


Where GetCovered and an insurer each determine their own purposes and means of processing, each organisation may have separate data-protection responsibilities.


16. Third-Party Service Providers


We may engage third-party service providers to help operate our business.


These providers may support:


  • Hosting;
  • Cloud computing;
  • Data storage;
  • Website management;
  • Customer support;
  • Email;
  • SMS;
  • WhatsApp communications;
  • Analytics;
  • Cybersecurity;
  • Payment processing;
  • Document processing;
  • Backup;
  • IT support.


We aim to use reputable service providers and apply appropriate contractual and technical safeguards.


Where a provider acts as our data processor, we seek to ensure that it processes information only for authorised purposes and maintains appropriate confidentiality and security measures.


17. International Transfers Of Personal Data


Some of the technology and service providers we use may process or store information outside Kenya.


This may occur where we use:


  • Cloud infrastructure;
  • International software providers;
  • Email platforms;
  • Analytics platforms;
  • Customer relationship management systems;
  • Messaging platforms;
  • Other technology services.


Where personal data is transferred outside Kenya, we will take steps required by applicable law to ensure that the transfer is lawful and that appropriate safeguards are in place.


Depending on the circumstances and applicable legal requirements, safeguards may include:


  • Appropriate contractual protections;
  • Adequacy or other legally recognised safeguards;
  • Consent where required;
  • Security measures;
  • Data minimisation;
  • Access controls;
  • Other measures required by law.


We will maintain appropriate records of relevant international data transfers where required.


18. Where Is Your Data Stored?


Your personal data may be stored on systems operated by GetCovered or third-party service providers.


These systems may be located in Kenya or other jurisdictions depending on the technology services we use.


We seek to ensure that storage arrangements provide appropriate security and comply with applicable legal requirements.


For specific information about our current data-hosting locations and international processors, contact our Privacy/Compliance Team.


19. Data Retention


We do not retain personal data indefinitely without a reason.


We retain personal data for as long as reasonably necessary for the purposes for which it was collected and processed.


The appropriate retention period depends on factors including:


  • The nature of the information;
  • The purpose for which it was collected;
  • Whether there is an ongoing customer relationship;
  • Insurance policy requirements;
  • Claims;
  • Legal obligations;
  • Regulatory requirements;
  • Tax and accounting requirements;
  • Dispute resolution;
  • Fraud prevention;
  • Legal proceedings;
  • Our legitimate business requirements.


For example, information relating to an insurance transaction may need to be retained after the policy expires because of legal, regulatory, accounting, claims or dispute-resolution requirements.


When personal data is no longer required, we will take appropriate steps to securely delete, anonymise or otherwise dispose of it, subject to applicable legal requirements.


20. Data Minimisation


We aim to collect personal data that is adequate, relevant and reasonably necessary for the purpose for which it is being processed.


We do not intentionally collect personal information simply because it might be useful in the future.


The information required will depend on the service you request.


For example, a motor insurance quotation may require vehicle information that would not be necessary for a general website enquiry.


21. Accuracy Of Personal Data


We rely on customers to provide accurate and up-to-date information.


You should notify us if information you have provided changes or is incorrect.


This is particularly important for insurance because inaccurate information can affect:


  • Underwriting;
  • Premium calculations;
  • Policy terms;
  • Policy administration;
  • Claims.


We may take reasonable steps to ensure personal data we hold is accurate and up to date.


22. Data Security


We take reasonable and appropriate technical and organisational measures to protect personal data against:


  • Unauthorised access;
  • Unauthorised disclosure;
  • Loss;
  • Destruction;
  • Accidental alteration;
  • Unlawful processing;
  • Theft;
  • Cybersecurity threats.


Depending on the nature of the information and the systems involved, safeguards may include:


Access Controls


Access to personal data is restricted to authorised persons who need it for legitimate business purposes.


Authentication


We use appropriate authentication and account-security measures for relevant systems.


Encryption


Where appropriate and technically feasible, encryption or equivalent safeguards may be used to protect information during transmission or storage.


Secure Systems


We seek to maintain systems using appropriate security configurations and updates.


Backups


Where appropriate, data is backed up to reduce the risk of permanent loss.


Monitoring


We may monitor systems for suspicious activity, security incidents and unauthorised access.


Employee Confidentiality


Employees and contractors who have access to personal data are expected to maintain confidentiality and comply with applicable information-security and data-protection requirements.


Security Awareness


Relevant personnel may receive training or guidance concerning data protection and information security.


Incident Response


We maintain processes for identifying, responding to and managing potential data-security incidents.


23. No System Is Completely Secure


Although we take security seriously, no website, database, communication channel or electronic transmission can be guaranteed to be completely secure.


You should therefore take reasonable precautions when interacting with us online.


For example:


  • Use a secure device;
  • Keep your passwords confidential;
  • Do not share one-time passwords;
  • Do not provide payment credentials to unknown persons;
  • Verify suspicious communications;
  • Report suspected account compromise promptly.


If you believe your information or account has been compromised, contact us immediately.


24. Data Breaches And Security Incidents


If we become aware of a personal-data breach or security incident, we will assess the incident and take appropriate action in accordance with applicable law.


Depending on the nature and severity of the incident, this may include:


  • Containing the incident;
  • Investigating its cause;
  • Assessing affected information;
  • Taking corrective measures;
  • Notifying relevant authorities where required;
  • Notifying affected individuals where required;
  • Strengthening security controls.


25. Your Rights As A Data Subject


Subject to applicable law and any lawful limitations, you have rights concerning your personal data.


These may include the right to:


Be informed


You have the right to receive information about how your personal data is collected and processed.


Access


You may request access to personal data we hold about you, subject to applicable legal limitations.


Correction


You may request correction of inaccurate or incomplete personal data.


Deletion


You may request deletion of personal data where applicable, subject to lawful reasons for retaining or processing the information.


Restriction


Where applicable, you may request restriction of processing in circumstances permitted by law.


Object


You may object to certain processing activities where permitted by law.


Withdraw consent


Where processing is based on consent, you may withdraw your consent, subject to applicable legal and contractual limitations.


Data portability


Where applicable under law, you may request your personal data in a structured, commonly used and machine-readable form or request its transfer to another data controller.


Lodge a complaint


You may complain to the Office of the Data Protection Commissioner if you believe your data-protection rights have been infringed.


26. Exercising Your Data Protection Rights


To exercise your rights, contact our Privacy or Compliance Team.


Your request should provide enough information for us to understand:


  • Who you are;
  • What right you wish to exercise;
  • What information or processing your request concerns;
  • Any relevant details that may help us locate the information.


Privacy/Compliance Contact


Email:
compliance@getcoveredkenya.com


Telephone:
075849207


Physical Office:
Methodist Ministries, Oloitoktok Road, Nairobi, Kenya


We may need to verify your identity before responding to certain requests.


This is a security measure intended to prevent us from disclosing personal data to an unauthorised person.


27. Identity Verification


When you exercise certain data-protection rights, we may request reasonable information to verify your identity.


The information requested should be proportionate to the nature and sensitivity of the request.


We will not request unnecessary information simply to delay or prevent you from exercising your rights.


28. What Happens After You Submit A Privacy Request?


Once we receive a valid request, we will:


  1. Acknowledge the request where appropriate;
  2. Verify your identity where necessary;
  3. Determine the nature of the request;
  4. Identify the relevant information;
  5. Assess whether any lawful exemptions or restrictions apply;
  6. Take appropriate action;
  7. Respond within the applicable legal timeframe.


Where we cannot comply fully with a request, we will explain the applicable reason to the extent permitted by law.


29. Children And Minors


Our general insurance services are intended for adults and businesses.


We do not knowingly collect children's personal data for independent commercial purposes without an appropriate lawful basis and required parental or guardian involvement.


Where a product or service requires information about a child or dependent, such information may be provided by a parent, guardian or another person lawfully authorised to provide it.


Where children’s personal data is processed, we will apply safeguards required by applicable law.


30. Cookies And Similar Technologies


Our website may use cookies and similar technologies.


Cookies may help us:


  • Operate the website;
  • Remember preferences;
  • Maintain sessions;
  • Understand website usage;
  • Improve performance;
  • Analyse traffic;
  • Measure marketing performance;
  • Improve user experience.


Some cookies may be necessary for the website to function.


Others may require consent depending on their purpose and applicable law.


For detailed information, please see our:



31. Analytics


We may use analytics services to understand how visitors use our website.


Analytics information may include:


  • Pages visited;
  • Time spent on pages;
  • Device type;
  • Browser;
  • Approximate location;
  • Traffic source;
  • Interaction information.


Analytics data helps us understand website performance and improve our services.


Where applicable, we will configure analytics tools and privacy settings in accordance with our legal and compliance requirements.


32. Advertising And Marketing Technologies


We may use digital advertising technologies to promote GetCovered services.


Depending on the tools used, this may involve technologies such as:


  • Advertising cookies;
  • Conversion tracking;
  • Remarketing;
  • Analytics pixels;
  • Social-media pixels;
  • Similar technologies.


The exact technologies used may change as our marketing infrastructure changes.


Where consent is required, we will seek the appropriate consent before deploying non-essential tracking technologies.


You may also be able to manage advertising preferences through your browser, device or the relevant advertising platform.


33. WhatsApp And Messaging Services


GetCovered may use WhatsApp, SMS, email or other messaging channels to communicate with customers.


These channels may be used for:


  • Quotations;
  • Customer support;
  • Policy information;
  • Document delivery;
  • Payment-related communications;
  • Renewal reminders;
  • Claims-related communications;
  • Other service communications.


Where a third-party messaging platform processes information, that platform may process data according to its own privacy terms.


You should avoid sending unnecessary highly sensitive information through messaging channels.


Where sensitive information is required, we may provide an alternative secure method of submission.


34. Telephone Calls And Communications


Telephone calls or other communications with GetCovered may be recorded or documented where permitted by law and where reasonably necessary for purposes such as:


  • Customer service;
  • Training;
  • Quality assurance;
  • Dispute resolution;
  • Fraud prevention;
  • Compliance;
  • Record keeping.


Where required, we will provide appropriate notice.


35. Payment Information


When you pay for insurance, payment may be processed through third-party payment providers, banks, mobile-money services or other financial institutions.


Depending on the payment method, we may receive information such as:


  • Payment reference;
  • Transaction amount;
  • Transaction date;
  • Payment status;
  • Account or mobile-money identifier;
  • Other transaction information.


Where payment is processed directly by a third-party provider, that provider may independently process your information under its own privacy policy.


We do not intentionally store full card numbers or authentication credentials where such information is handled directly by a compliant third-party payment provider, unless necessary and lawfully permitted.


36. Fraud Prevention


Insurance is vulnerable to fraud and other forms of financial crime.


We may process personal data to:


  • Detect suspicious activity;
  • Verify identities;
  • Prevent fraudulent applications;
  • Investigate potentially fraudulent claims;
  • Protect customers;
  • Protect insurers;
  • Protect our business;
  • Comply with legal obligations.


Where appropriate and lawful, we may share relevant information with insurers, authorities, fraud-prevention providers or other relevant organisations.


37. Legal Requests And Law Enforcement


We may disclose personal data where required or authorised by law.


This may include responding to:


  • Court orders;
  • Warrants;
  • Regulatory requests;
  • Government requests;
  • Law-enforcement requests;
  • Tax requirements;
  • Investigations;
  • Other lawful processes.


We will seek to limit disclosures to information that is reasonably relevant to the lawful request.


38. Business Transfers


If GetCovered undergoes a merger, acquisition, restructuring, financing, sale of assets or other corporate transaction, personal data may be transferred as part of that transaction where legally permitted.


Any such transfer will be handled in accordance with applicable data-protection requirements.


39. Links To Other Websites

39. Links to Other Websites


Our website may contain links to third-party websites, including:


  • Insurance companies;
  • Payment providers;
  • Government websites;
  • Regulatory websites;
  • Business partners;
  • Other service providers.


This Privacy Policy does not govern third-party websites.


We encourage you to review the privacy policy of any third-party website you visit.


We are not responsible for the privacy practices of independent third parties.


40. Insurance Partners' Privacy Policies


When an insurance company receives your information, that insurer may have its own privacy policy governing its processing activities.


You should review the privacy notice of the relevant insurer where provided.


GetCovered cannot control every aspect of how an independent insurer processes information after receiving it for underwriting, policy administration or claims purposes.


41. Complaints About Privacy


We want customers to raise privacy concerns with us first so that we have an opportunity to investigate and resolve them.


If you believe that:


  • We have processed your data unlawfully;
  • We have used your information for an unauthorised purpose;
  • We have failed to protect your information;
  • We have ignored a valid data-protection request;
  • Your information has been disclosed improperly;


please contact our Privacy/Compliance Team.


GetCovered Privacy & Compliance Team


Email:
compliance@getcoveredkenya.com


Telephone:
075849207


Physical Office:
Methodist Ministries, Oloitoktok Road, Nairobi, Kenya


Please provide enough information for us to investigate your concern.


42. Complaining To The Office Of The Data Protection Commissioner


You also have the right to seek assistance from the Office of the Data Protection Commissioner (ODPC) where applicable.


The ODPC provides mechanisms through which data subjects can lodge complaints concerning alleged infringements of their data-protection rights. (Office of the Data Protection Commission)


You can access the ODPC's complaint platform through its official website.


[Lodge a Data Protection Complaint with the ODPC]


We encourage customers to contact us first where appropriate, but this does not remove any rights you have under applicable law.


43. Data Protection Officer / Privacy Contact


GetCovered has designated responsibility for handling data-protection and privacy matters.


Privacy & Compliance Contact


Department:
Privacy & Compliance


Email:
compliance@getcoveredkenya.com


Telephone:
075849207


Physical Address:
Methodist Ministries, Oloitoktok Road, Nairobi, Kenya


If GetCovered appoints or designates a Data Protection Officer in accordance with applicable requirements, the relevant contact information will be published here.


44. Privacy By Design


We seek to incorporate data-protection considerations into the design and operation of our products and services.


This includes considering:


  • What information is actually necessary;
  • Who needs access;
  • How information is secured;
  • How long information should be retained;
  • Whether information can be minimised;
  • Whether a processing activity creates unnecessary privacy risk;
  • Whether additional safeguards are required.


Where appropriate, we may conduct privacy or data-protection assessments before implementing processing activities that present significant risks.


45. Automated Decision-Making And Profiling


We may use automated systems to assist with website analytics, customer communication, fraud detection, quotation workflows or other operational functions.


Unless otherwise disclosed, GetCovered does not intend for customers to be subject to significant decisions based solely on automated processing without appropriate safeguards where applicable under law.


Where automated decision-making or profiling has a significant impact on you and applicable law provides relevant rights, we will provide appropriate information and mechanisms as required.


If our use of automated decision-making changes materially, we will update this Privacy Policy or provide additional notice where appropriate.


46. Insurance Underwriting Decisions


47. Accuracy And Insurance Applications


It is important to distinguish GetCovered's role from the insurer's underwriting decisions.


An insurer may assess information you provide to determine matters such as:


  • Whether to offer cover;
  • The applicable premium;
  • Policy conditions;
  • Limits;
  • Exclusions;
  • Whether additional information is required.


Where the insurer makes such decisions, the insurer may have its own legal and data-protection responsibilities.


GetCovered does not guarantee that an insurer will accept an application or offer a particular premium or policy.

47. Accuracy and Insurance Applications


You are responsible for providing accurate information when applying for insurance.


Do not deliberately omit, conceal or misrepresent material information.


Incorrect information can affect:


  • Whether an insurer accepts your application;
  • The premium;
  • The terms of your policy;
  • The validity of your cover;
  • The assessment of a claim.


If you discover that information you provided is incorrect, notify us or the relevant insurer promptly.


48. Data You Provide About Other People


You may sometimes provide personal information about another person, such as:


  • A spouse;
  • Child;
  • Dependant;
  • Employee;
  • Director;
  • Beneficiary;
  • Driver;
  • Business partner.


Where you provide someone else's personal data, you should ensure that you are authorised to provide it and that you have provided any information or obtained any consent required by applicable law.


This is particularly important where sensitive information is involved.


49. Business Customers


If you use GetCovered on behalf of a business, you confirm that you are authorised to provide information concerning the business and relevant individuals.


Where your organisation provides us with employee, director, customer or other personal data, the organisation remains responsible for ensuring that it has a lawful basis and appropriate authority for providing that information to us.


Where GetCovered processes such information on behalf of a business, the parties may enter into an appropriate data-processing agreement where required.


50. Your Responsibilities

50. Your Responsibilities


Data protection is a shared responsibility.


You should:


  • Provide accurate information;
  • Keep your passwords confidential;
  • Avoid sharing account credentials;
  • Verify suspicious requests;
  • Use secure devices;
  • Keep copies of important documents;
  • Notify us of suspected security incidents;
  • Avoid sending unnecessary sensitive information through unsecured channels;
  • Inform us when your personal information changes.


51. Changes To This Privacy Policy


Our services, technology, insurance partnerships and legal obligations may change over time.


We may therefore update this Privacy Policy periodically.


When we make changes, we will update the:


“Last Updated”


date at the top of this policy.


Where changes are material and applicable law requires additional notification, we may provide a more prominent notice.


We encourage you to review this Privacy Policy periodically.


52. Effective Date


This Privacy Policy is effective from:


01/01/2021


and was last updated on:


01/04/2026


53. Contact Us

53. Contact Us


If you have questions about this Privacy Policy, how we process your information or your data-protection rights, please contact us.


GetCovered Kenya


Physical Office:
Methodist Ministries, Oloitoktok Road, Nairobi, Kenya


Privacy & Compliance Email:
compliance@getcoveredkenya.com


Telephone:
075849207


Website:
getcoveredkenya.com


54. Quick Privacy Summary


We know privacy policies can be long.


Here is the short version.


We collect information


We collect information you provide when you request insurance, communicate with us or use our website.


We use it to provide insurance services


This includes quotations, applications, policy administration, payments, documentation, customer support and claims-related assistance.


We may share information with insurers


Your information may need to be shared with the insurance company that assesses and underwrites your policy.


We use service providers


Technology, payment, communication, hosting and other service providers may process information on our behalf.


We protect information


We use appropriate technical and organisational safeguards designed to protect personal data.


We do not sell your personal data


We do not sell personal information as a commercial product.


We may need to retain information


Insurance, legal, regulatory, tax, claims and other requirements may require us to retain information for specified periods.


Your rights matter


You have rights concerning your personal data, subject to applicable law.


You can contact us


For privacy questions:


compliance@getcoveredkenya.com


You can complain to the regulator


Where applicable, you may lodge a complaint with the Office of the Data Protection Commissioner.


Final Statement

Final Statement


At GetCovered Kenya, we believe that buying insurance should be based on informed decisions and trust.


That trust extends beyond the insurance policy itself.


You should know what information you are providing, why it is needed, who may receive it, how it is protected and what rights you have.


We are committed to handling personal data responsibly and transparently while helping customers access and arrange insurance in Kenya.


Your information belongs to you.


Our responsibility is to handle it lawfully, fairly, securely and transparently.


© [2026] GetCovered Kenya. All rights reserved.




Get insurance tips & exclusive offers