EXOTICDigital infrastructure for trusted markets
Skip to main content
ExoticDigital Group
CompanyTechnologyProducts
Trust⌄
Trust overviewThe group framework connecting safety, compliance and security.Trust & SafetyPlatform integrity, moderation and enforcement.Compliance CentrePolicies, governance and reporting routes.SecurityControls that support resilient operations.
NewsCareersKenya MarketplaceContact
  1. Home
  2. /Legal Centre
  3. /Privacy Policy

Privacy

Corporate website Privacy Policy.

This draft explains how personal information may be handled when someone visits the Exotic Digital Group corporate website, submits an enquiry or communicates with a corporate team.

Publication statusDevelopment draft for corporate and legal review.

Entity details, effective dates, jurisdictional wording and contact channels must be approved before launch.

Not yet a production policy
On this page
ScopeInformation we collectHow information is usedSharing and service providersInternational processingRetentionSecurityYour choices and rightsChildrenRegional platformsChanges and contact
View Legal Centre
Drafting note

This page provides the intended corporate structure and plain-language content. It must be reviewed against the group’s final legal entities, processing activities, contracts, markets and applicable laws before publication.

Effective date
To be confirmed before launch
Policy owner
Corporate Legal and Compliance
Applies to
The corporate website at exotic-online.com

1. Scope

This policy is intended to apply to the corporate website at exotic-online.com and to corporate enquiries submitted through it. It does not automatically govern accounts, listings, payments, transactions or support activity on a regional marketplace.

Each marketplace should publish a separate privacy notice identifying the responsible entity, the service involved and the information practices that apply to its users.

2. Information we may collect

The information collected will depend on how a visitor uses the website and which features are enabled at launch.

Information provided directly

  • Name, organisation, role and business contact details.
  • The subject, message and attachments included in a corporate enquiry.
  • Career or media information submitted through an approved external process.
  • Information supplied during a partnership, compliance, security or institutional discussion.

Technical and usage information

  • IP address, browser type, device information and approximate location derived from technical data.
  • Pages viewed, links used, referral source and basic interaction or performance data.
  • Security logs and information needed to detect abuse, protect the website and troubleshoot faults.
  • Cookie or consent choices where those technologies are enabled.

3. How information may be used

Personal information may be used to operate the corporate website, respond to enquiries, manage institutional relationships, protect systems, comply with obligations and improve corporate communications.

  • Route and respond to partnership, payment, regulatory, trust, security, media, career and general enquiries.
  • Verify the legitimacy of requests and prevent spam, fraud, misuse or security threats.
  • Maintain records of important corporate, contractual, regulatory or security communications.
  • Measure website reliability and understand which corporate information visitors find useful.
  • Meet legal obligations, establish or defend legal claims and cooperate with authorised requests.

The final policy must identify the lawful bases or equivalent grounds relied on in each relevant jurisdiction.

4. Sharing and service providers

Information may be shared with authorised group personnel and carefully selected providers that support hosting, security, email, analytics, recruitment, professional advice or other approved corporate functions.

Information may also be disclosed where required by law, necessary to protect rights or safety, connected to a corporate transaction, or requested by a competent authority through a valid process.

The production policy should name or categorise material service providers and describe the safeguards applied to them.

5. International processing

The group has an international growth strategy, so corporate information may be accessed or processed across more than one country. Where required, the responsible entity should use approved contractual, organisational or legal safeguards for cross-border transfers.

The final wording must reflect the locations of the actual corporate entities, hosting environment, service providers and receiving teams.

6. Retention

Information should be kept only for as long as needed for the purpose for which it was collected, including legitimate operational, contractual, security, regulatory and record-keeping needs.

Retention periods may differ for general enquiries, partnership discussions, regulatory correspondence, security reports, recruitment records and technical logs. The production policy should align with an approved retention schedule.

7. Security

The group intends to use proportionate technical and organisational measures to protect personal information. These may include access controls, encryption where appropriate, secure development practices, monitoring, backups and incident-response procedures.

No website or transmission method can be guaranteed to be completely secure. Visitors should not send passwords, payment credentials or unnecessary sensitive documents through the general corporate form.

8. Your choices and rights

Depending on location and applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, portability or withdrawal of consent. They may also have the right to complain to an appropriate authority.

The final policy must identify the process for verifying and handling requests, the responsible contact channel and any lawful limitations or exceptions.

9. Children

The corporate website is intended for business, institutional, media, recruitment and general corporate audiences. It is not designed to collect personal information from children.

Any age requirements applying to a regional marketplace must be stated in that marketplace’s own policies and service terms.

10. Regional marketplace privacy notices

Moving the existing website to /ke/ does not make the corporate privacy policy a replacement for the Kenya platform’s notice. The Kenya marketplace should retain a service-specific privacy policy covering its accounts, listings, payments, moderation, communications and support processes.

The same separation should be maintained as additional regional products are introduced.

11. Changes and contact

The policy may be updated when the website, corporate structure, service providers or legal requirements change. Material revisions should be recorded with a new effective date and, where appropriate, an explanation of the change.

Approved privacy and data-rights contact details will be inserted before production launch. General corporate enquiries can currently be routed through the Contact page.

Related policies and information

Cookie Policy→Website Terms→Security→Contact→
ExoticDigital Group

Trusted digital marketplace technologies for responsible growth.

CorporateCompanyTechnologyProductsGlobal presenceLeadership
TrustTrust overviewTrust & SafetyCompliance CentreSecurity
ConnectNewsCareersContactKenya Marketplace
LegalLegal CentrePrivacyTermsCookiesAccessibility
© 2026 Exotic Digital Group. Development content pending legal and corporate approval.
PrivacyTermsCookiesAccessibility