1. Who we are
Shahidi is operated by the African Parliamentarians' Network Against Corruption, Kenya Chapter (APNAC-Kenya) ("APNAC", "we", "us"), which is the data controller for the purposes of the Data Protection Act, No. 24 of 2019 (the "DPA").
Shahidi is a platform for reporting corruption and related wrongdoing in Kenya. It is not a government agency, not a law-enforcement body, and not an emergency service.
2. What anonymity means here — and its limits
Shahidi is built so that we do not ask you who you are. There is no account, no sign-up, and no field anywhere on the report form for your name, phone number, email address or ID number.
That is a real and deliberate protection. But it is not the same as being untraceable, and we would rather tell you the truth than let you rely on a promise we cannot keep. You should understand the following:
- Technical connection records exist. Like every website, Shahidi is reached over the internet through our hosting provider (Google Firebase). Connection logs — which can include your IP address, approximate location, browser and device type, and the time of your visit — are generated and held by that provider as part of operating the service. We do not use these to identify reporters and we do not link them to your case, but they are not within our power to abolish.
- Files can carry hidden information. Photographs and documents often contain embedded metadata. A photo taken on a phone may record the exact GPS coordinates where it was taken, the date and time, and the make, model or serial number of the device. If you upload such a file, that information travels with it.
- What you write can identify you. If your report describes an incident only a handful of people witnessed, or you name yourself, or you mention details unique to your role, the content itself may reveal who you are — no matter what the technology does.
- Your device remembers your case numbers. See section 9.
- The law can compel disclosure. A court order or lawful demand issued in Kenya can require us, or our hosting provider, to produce information we hold. We cannot promise to defy a valid court order.
3. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Report content | Your description of the wrongdoing, the type of issue, and any evidence reference you type in | You |
| Location of the incident | County, constituency/sub-county, ward, and any landmark you add | You |
| Evidence files | Photographs and PDF documents you attach, including any metadata embedded in them | You |
| Case number | A randomly generated code (for example SHD-XXXXXX) that identifies the case without identifying you | Generated by us |
| Messages | What you and our team write in the case chat, and any supporting documents you add later | You and our staff |
| Case handling records | Status changes, the unit a case is assigned to, investigation notes, escalation records, and the staff email that took each action | Our staff |
| Technical logs | IP address, device and browser information, timestamps — held by our hosting provider | Automatically, as described in section 2 |
We do not ask for, and you should not send us, your name, phone number, email address, ID or passport number, or any other detail that identifies you — unless you decide you want us to be able to reach you and you accept the risk that comes with it.
Reports about corruption may reveal sensitive personal data as defined in section 2 of the DPA — for example a person's political affiliation, health, or details of alleged criminal conduct. We handle such data with the heightened care that section 44 of the DPA requires.
4. Why we process it, and on what legal basis
| Purpose | Lawful basis under the DPA |
|---|---|
| Receiving, assessing and investigating reports of corruption | Section 30(1)(b)(v) — a task carried out in the public interest; and our legitimate interest in combating corruption, which does not override your rights |
| Exchanging messages with you about your case | Section 30(1)(a) — your consent, given by choosing to use the chat |
| Referring cases to the EACC, DCI, ODPP or another competent authority | Public interest, and compliance with legal obligations |
| Keeping the platform secure and preventing abuse | Legitimate interests |
| Producing anonymised statistics about where and what kind of corruption is reported | Legitimate interests; the data is aggregated and no longer identifies anyone |
You can withdraw consent for the chat at any time by simply not using it. That does not delete a report already submitted, because the public-interest basis for handling it continues.
5. People named in reports
If you are named or described in a report submitted to Shahidi, you are also a data subject and the DPA protects you too.
We process information about persons alleged to be involved in wrongdoing in order to assess and, where warranted, investigate or refer the allegation. An allegation is not a finding. A report received by Shahidi is untested information, and we do not treat it as proof of anything.
We may delay or restrict telling you that we hold information about you, and may decline access, where doing otherwise would prejudice the prevention, detection, investigation or prosecution of an offence, or would expose a reporter to risk. Section 51 of the DPA permits this. Any such restriction is applied case by case, recorded with reasons, and lifted when the reason for it falls away.
You may still write to our Data Protection Officer to ask about, correct or object to the processing of information about you. See section 11.
6. Who we share information with
- Authorised APNAC staff and assigned field units — only those who need the case to do their work. Field units see only the cases assigned to them, enforced in the system itself, not merely by policy.
- Competent authorities — the Ethics and Anti-Corruption Commission, Directorate of Criminal Investigations, Office of the Director of Public Prosecutions, or another appropriate body, where a case warrants escalation.
- Our technology provider — Google (Firebase / Google Cloud) acts as our data processor for hosting, storage and database services, under Google's data processing terms. Google processes the data only on our instructions.
- Where the law requires — in response to a valid court order or lawful demand.
We do not sell personal data, and we do not use it for advertising or marketing. Shahidi carries no advertising trackers and no third-party analytics.
7. Storage outside Kenya
Shahidi's database and evidence storage are hosted in a Google Cloud region located in Belgium (europe-west1). Your report is therefore transferred outside Kenya.
Sections 48 and 49 of the DPA permit such a transfer where appropriate safeguards exist and the transfer meets one of the statutory grounds. We rely on the public-interest ground and on the contractual safeguards in Google's data processing terms, which bind Google to security and confidentiality obligations. Belgium is subject to the EU General Data Protection Regulation, which affords protection comparable to the DPA.
8. How long we keep it
| Record | Retention |
|---|---|
| Open case (report, evidence, chat) | Until the case is resolved or closed |
| Resolved or closed case | 7 years from closure, then deleted — matching the limitation period for related civil claims and the needs of any subsequent prosecution |
| Case referred to a competent authority | Retained until that authority's process concludes, then per the rule above |
| Cases assessed as having no substance | 12 months, then deleted |
| Aggregated, anonymised statistics | Indefinitely — this data no longer identifies anyone |
| Hosting provider technical logs | Per Google Cloud's retention periods, typically short-term |
9. Cookies and local storage
Shahidi sets no advertising or tracking cookies. There is no Google Analytics, no advertising pixel, and no third-party profiling on this site.
The site stores one thing in your browser's local storage, on your device only:
| Name | Purpose | Contents | Duration |
|---|---|---|---|
shahidi.cases | Lets you reopen your cases without retyping the case number | Your case numbers and, for each, the county, ward, category and the date saved | Until you clear it or clear your browser data |
This never leaves your device and is never sent to us. But anyone who uses your device can see that list. On a shared, borrowed or seized phone this is a genuine risk. Use the "Forget cases on this device" button on the Track & Chat page to erase it — your cases remain open, and you can still reach them with the case number.
10. How we protect information
- All traffic is encrypted in transit (HTTPS/TLS), and data is encrypted at rest by our cloud provider.
- Evidence files can be opened only by signed-in, authorised APNAC staff. They are not publicly accessible, and they cannot be opened from the public side of the site — not even by the person who uploaded them.
- Access is enforced by server-side security rules, not merely by hiding buttons. A field unit cannot read another unit's cases even if it tries to.
- Staff accounts are individual, and case actions are recorded against the staff member who took them.
- Reports carry no reporter identity, so a breach of our database would not by itself reveal who reported what.
Should a personal data breach occur that poses a real risk of harm, we will notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it, and affected data subjects without undue delay, as section 43 of the DPA requires.
11. Your rights
Under section 26 of the DPA you have the right to be informed of how your data is used; to access it; to have inaccurate data corrected; to object to processing; to have data deleted where there is no lawful reason to keep it; and to data portability.
Rights are not absolute. We may decline a request where the DPA permits — for example where complying would prejudice an investigation, breach a legal obligation, or expose another person to risk. We will tell you when we rely on such an exemption and why, unless doing so would itself defeat the exemption.
12. Children
Shahidi is intended for adults. We do not knowingly seek reports from children. Where a report is evidently from or about a child, we handle it with the additional protection that section 33 of the DPA and the Children Act, 2022 require, and involve the appropriate child-protection authority where the child's welfare is at risk.
13. Changes to this policy
We will update this policy as the platform and the law change. The version number and effective date at the top of this page always show the current edition. Material changes will be signalled on the Shahidi home page.
14. Contact and complaints
Write to our Data Protection Officer at the address to be published in section 1. Quote your case number if your request concerns a report.
If you are unhappy with how we have handled your personal data, you may complain to the Office of the Data Protection Commissioner, whose contact details are published at odpc.go.ke. You may complain to the ODPC whether or not you have raised the matter with us first.