Legal

Privacy Policy

Last updated: March 2026  ·  Effective: March 2026  ·  Version: 1.0

Plain language first. This Privacy Policy is written to be read and understood — not to confuse you. We will always tell you clearly what we collect, why we collect it, and what your rights are. If anything is unclear, email us at [email protected].

🇨🇦 PIPEDA + Quebec Law 25 🇪🇺 GDPR 🇬🇧 UK GDPR 🇺🇸 CCPA 🇳🇬 NDPA 2023 🇿🇦 POPIA 🇰🇪 Kenya DPA 2019 🇬🇭 Ghana DPA 2012

Contents

  1. Who we are
  2. What information we collect
  3. Why we collect it
  4. How we use your information
  5. Who we share it with
  6. Cookies and analytics
  7. How long we keep your data
  8. Your rights
  9. Jurisdiction-specific rights
  10. How we protect your data
  11. Children's privacy
  12. Changes to this policy
  13. Contact us

1.Who We Are

Kiriqoo is a Pan-African wellness and wealth ecosystem — a platform rooted in African wisdom, built to help people build wealth, heal the body, and free the mind. We are currently in pre-launch phase, collecting a waitlist of people interested in early access.

Data Controller: Kiriqoo Inc. (operating as Kiriqoo), Toronto, Ontario, Canada.

Data Protection Contact: [email protected]

For EU/UK residents, Kiriqoo acts as the data controller under GDPR and UK GDPR. For California residents, Kiriqoo is the "business" under CCPA.

2.What Information We Collect

We only collect what we need. Here is exactly what we collect through our waitlist form:

DataRequired?Why we collect it
Email addressRequiredTo notify you when Kiriqoo launches
First nameOptionalTo personalise communications
CountryRequiredTo understand which communities we serve
Age rangeRequiredTo ensure our services are age-appropriate
Primary interestOptionalTo understand what matters most to you
Phone numberOptionalFor SMS launch notifications (only if you provide it)
Instagram handleOptionalTo connect with our community before launch

We also automatically collect limited technical information when you visit our website:

We do not collect: payment information, government ID, biometric data, health records, or any sensitive personal data through the waitlist form.

3.Why We Collect It (Legal Basis)

Under GDPR and equivalent laws, we must have a valid legal reason ("legal basis") for processing your data. Our legal bases are:

PurposeLegal Basis
Sending you launch notificationsConsent — you actively agreed via the checkbox
Understanding our communityLegitimate interests — aggregate, anonymised data only
Analytics and website improvementConsent — via the cookie banner
Security and fraud preventionLegitimate interests — protecting the platform and community
Legal complianceLegal obligation — complying with applicable laws

You can withdraw your consent at any time by emailing [email protected] or clicking unsubscribe in any email we send.

4.How We Use Your Information

We do not use your information for: targeted advertising, selling to third parties, profiling for automated decision-making, or any purpose other than those listed above.

5.Who We Share Your Information With

We do not sell your data. We do not share your personal data with advertisers. We share data only with the following trusted service providers who help us operate Kiriqoo:

ProviderPurposeLocationSafeguards
SupabaseDatabase and backend infrastructureUSA (AWS)SOC 2 compliant, data encrypted at rest
CloudflareBot protection (Turnstile CAPTCHA)USA/GlobalPrivacy Shield, GDPR compliant
Google AnalyticsWebsite analytics (consent only)USA/GlobalIP anonymisation enabled, consent-gated
ResendEmail deliveryUSASOC 2 compliant, GDPR DPA in place

All providers are bound by data processing agreements and may only use your data to provide their services to Kiriqoo — not for their own purposes.

We may also disclose your information if required by law, court order, or to protect the safety of our community.

6.Cookies and Analytics

We use cookies and similar tracking technologies only with your explicit consent, which you provide or decline through the cookie banner on our website.

CookiePurposeDurationConsent required?
kiriqoo_cookie_consentRemembers your cookie choice1 yearNo — functional
_ga, _ga_*Google Analytics — page views, sessions2 yearsYes
_cf_bmCloudflare bot managementSessionNo — security

You can change your cookie preferences at any time by clearing your browser's local storage or emailing us. If you decline analytics cookies, Google Analytics will not load and we will not track your visit.

7.How Long We Keep Your Data

DataRetention PeriodReason
Waitlist signup dataUntil Kiriqoo launches + 12 months, or until you request deletionTo notify you at launch
Analytics data14 months (Google Analytics default)Trend analysis
Security logs90 daysFraud and abuse prevention

After the retention period, data is permanently deleted from our systems and those of our service providers. You can request deletion at any time — see Section 8.

8.Your Rights

You have the following rights over your personal data. These apply regardless of where you are in the world:

Right to Access

Request a copy of all personal data we hold about you.

Right to Deletion

Request that we permanently delete your data ("right to be forgotten").

Right to Correction

Request that we correct any inaccurate data we hold about you.

Right to Portability

Request your data in a machine-readable format to take to another service.

Right to Withdraw Consent

Withdraw your consent at any time. We will stop processing your data immediately.

Right to Object

Object to processing based on legitimate interests.

To exercise any of these rights, email [email protected] with the subject line "Privacy Request." We will respond within 30 days (EU/UK: within 1 month as required by GDPR).

We will never charge a fee for handling privacy requests unless they are manifestly unfounded or excessive.

9.Jurisdiction-Specific Rights

🇨🇦 Canada — PIPEDA + Quebec Law 25

Canadian residents have the right to access and correct their personal information under PIPEDA. Quebec residents have additional rights under Law 25, including the right to data portability and the right to de-index information. You may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca or the Commission d'accès à l'information du Québec.

🇪🇺 European Union — GDPR

EU residents have all rights listed in Section 8 under Articles 15–22 of the GDPR. You have the right to lodge a complaint with your national Data Protection Authority (DPA). A list of EU DPAs is available at edpb.europa.eu. We respond to EU requests within 30 days and will extend to 60 days only for complex requests, with notification.

🇬🇧 United Kingdom — UK GDPR

UK residents have equivalent rights under UK GDPR. You may file a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

🇺🇸 United States — CCPA (California)

California residents have the right to know what personal information is collected, the right to delete, the right to opt-out of the sale of personal information (we do not sell personal information), and the right to non-discrimination for exercising privacy rights. To exercise CCPA rights, email [email protected] with subject "CCPA Request." We will respond within 45 days.

🇳🇬 Nigeria — NDPA 2023

Nigerian residents have rights under the Nigeria Data Protection Act 2023, including rights of access, rectification, erasure, restriction, portability, and objection. You may file a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.

🇿🇦 South Africa — POPIA

South African residents have rights under the Protection of Personal Information Act (POPIA), including the right to access, correction, and deletion of personal information. Complaints may be lodged with the Information Regulator at inforegulator.org.za.

🇰🇪 Kenya — Data Protection Act 2019

Kenyan residents have rights under the Data Protection Act 2019, overseen by the Office of the Data Protection Commissioner at odpc.go.ke.

🇬🇭 Ghana — Data Protection Act 2012

Ghanaian residents have rights under the Data Protection Act 2012, overseen by the Data Protection Commission at dataprotection.org.gh.

10.How We Protect Your Data

In the event of a data breach that affects your rights and freedoms, we will notify you and the relevant regulatory authority within 72 hours of becoming aware of the breach (as required by GDPR and PIPEDA).

11.Children's Privacy

Kiriqoo's waitlist and services are intended for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has submitted information to us, please contact us at [email protected] and we will delete the information immediately.

12.Changes to This Policy

We may update this Privacy Policy from time to time as Kiriqoo evolves. When we make material changes, we will:

Continued use of our services after changes take effect constitutes acceptance of the updated policy. If you do not agree with changes, you may request deletion of your data at any time.

13.Contact Us

Privacy requests and questions

Email: [email protected]

Subject line: "Privacy Request" for data access/deletion, "GDPR Request" for EU/UK, "CCPA Request" for California

Response time: Within 30 days for all jurisdictions (GDPR: within 1 month)

Kiriqoo Inc. · Toronto, Ontario, Canada · kiriqoo.com