AAR’s Privacy Centre
This Privacy Policy outlines how we collect, use, disclose, and protect personal information in connection with our services, including processing your medical and general insurance covers.
- Prospective policyholders their dependents and/or next of kin
- Policyholders and their dependents and/or next of kin
- Visitors to the company premises
- Website/Mobile App Users
Personal data may also include sensitive information, such as racial or ethnic origin, religious beliefs, health information (such as medical history), family information including children’s information, biometric data (such as fingerprint data collected when processing a health claim), property records, financial information (such as bank account details or statements of account, utilisation reports, premiums payable etc).
Subject to applicable law and practice, the categories of Personal Data that are typically collected and processed are: –
| Category of data subject | Type of personal data collected | |
| Prospective Policyholders (Medical and Non-Medical) | Identification details: Name of the proposer,ID/Passport, gender, nationality, marital statusContact details: telephone number, email address postal address, postal code. | |
| Medical Insurance Details: – o Information contained in the Membership Application form i.e., current permanent address, KRA PIN, occupation/nature of business, source of income, spouse and dependents details i.e., name, date of birth, height, and weight, confidential medical history, | cover option, weight and height, Next of kin details i.e., relation with applicant. o Information contained in quotations. o Medical Tests: data revealing past, present or future state of physical or mental health of an individual (for prospective members above 45 years with underlying medical conditions) o Reasons for disapproving prospective member(s)’ application. o Information contained in the List of members(for Corporate Clients and SME’s employees) | |
| Non-Medical Insurance: – o Information contained in Non-Medical Insurance Application Forms such as travel insurance, personal accident, home insurance, professional indemnity, Landlord Insurance. o Information contained in quotations. | ||
| Passport photos | ||
| Correspondence: Email/Phone calls/SMS | ||
| Online identifiers i.e., Cookies and IP addresses | ||
| CCTV footage (when you visit our premises) | ||
| Policyholders (Medical and Non-Medical) | Identification details: Name of the proposer,ID/Passport, gender, date of birth, nationality.Contact details: telephone number, email address postal address, postal code. | |
| Medical Insurance Details: – o Information contained in Member Application form: current permanent address, KRA PIN Occupation/Nature of business, source of income, spouse and dependents such | ||
| as name, date of birth, height, and weight, confidential medical history, and next of kin details such name, contact details and relationship to the applicant.o Information contained in list of members (Corporate and SME’s employees) o Information contained in medical policy covers o Claims details: pre-authorisation, admission and treatment details i.e., membership number, diagnosis and treatment notes, prescription, biometrics (like fingerprints) attending doctor’s name and signature. o Medical Cards o Scheme renewal details: information contained in scheme renewal forms, Copies of children’s birth certificates, proof of guardianship. o Information required to reimburse members i.e., invoices, treatment notes, diagnosis. | ||
| Non-Medical Insurance: – o Information contained in non-medical insurance forms such as Travel insurance, Home Insurance, Personal Accident forms,Professional Indemnity, Landlord Insurance o Information contained non-medical insurance policy covers. o Claims details: nature of claim, investigation results, claims payment details, reasons of disapproving claims and adjustment of payment details. o Policy covers renewal details. | ||
| • Payment details: KRA PIN, bank account details, premiums payable, information contained in cash receipts and invoices. • Information required to onboard members to the wellness program i.e., confidential medical history. • Passport Photos. • Customer complaints/Queries/ Complaints submitted through email, phone calls or through the website, social media or mobile app. • Online identifiers such as cookies and IP addresses • CCTV footage (when you visit our premises) | ||
| Agents and Brokers | Please refer to the Agents and Brokers Privacy Policyview policy | |
| Third-party Service Providers (Medical Service Providers, Loss Assessors, Loss Adjusters, Investigators) | Please refer to Third Party Service Providers PrivacyPolicy | |
| Job Applicants | Please refer to the Job Applicants Privacy Policy | |
| Office Visitors | • Contact details: phone number. • Identification details: name, ID, car registration number • CCTV records • Complaints/requests | |
| Website/App Users | • Identification details: name, date of birth, ID/Passport • Contact details: phone number/email address. • Information contained in online medical and nonmedical forms (when you apply insurance cover through our website or Mobile App) | |
| Online identifiers such as cookies and related tags, IP addresses | ||
| Category of Data Subject | How we Collect Your Personal Data | Purpose of Collection | Lawful Basis for Collection |
| Prospective Policyholders |
|
|
|
| |||
| Policyholders |
|
|
|
|
|
For example, if you are a prospective policyholder and you do not provide contact details or other necessary information, we may not be able to effectively communicate with you, provide relevant product information, or process your inquiries. Similarly, if you are a policyholder and fail to provide required identification or payment details, it may hinder our ability to fulfil contractual obligations or complete necessary financial transactions.
We encourage you to carefully consider the personal data requested and its importance for the intended purposes. If you have concerns about providing certain information, please contact us to discuss your specific circumstances and requirements.
We may share your personal data with third parties in the following circumstances:
- Service Providers: We may engage third-party service providers to perform various services on our behalf, such as our medical claims providers i.e. MTIBA and SMART, medical service providers, accountants, actuaries, loss assessors/adjusters, claims investigators, auditors, outsourced legal service providers, travel agencies, re-insurance service providers, call center service providers; IT systems support and hosting service providers, printing, advertising, marketing and market research and analysis service providers; banks and financial institutions that service our accounts, document and records management providers, construction consultants, engineers and document storage providers. These service providers will have access to your personal data as necessary to perform their functions but are strictly prohibited from using your personal data for any other purposes.
- Business Partners: We may share your personal data with trusted business partners who collaborate with us to provide products or services to you. These partners may use your personal data only for the purposes specified in our agreement with them.
- Legal Obligations: We may disclose your personal data if required to do so by law or in response to a valid legal request, such as a court order or government inquiry or with insurance regulators, tax auditors or other authorities when we believe in good faith that the law or other regulations requires us to share this data.
- Corporate Transactions: In the event of a merger, acquisition, or any form of corporate restructuring, we may transfer your personal data to the involved parties, if they agree to treat your personal data in accordance with this privacy policy and data protection laws.
- Consent: We may share your personal data with third parties if you have given us explicit consent to do so. You have the right to withdraw your consent at any time.
We carefully select and evaluate third-party service providers, business partners, and other recipients of your personal data. We enter into contractual agreements with these parties, imposing obligations to protect your personal data and restricting their use of the information solely for the specified purposes outlined in our agreement. Furthermore, we require these third parties to implement appropriate technical and organisational measures to prevent unauthorised access, disclosure, alteration, or destruction of your personal data.
- Technical Safeguards: To protect your information during transmission, we utilise industry-standard encryption protocols, ensuring the confidentiality of your data. Our secure network infrastructure incorporates firewalls, intrusion detection systems, and other security measures to prevent unauthorised access and mitigate external threats. Additionally, access controls are in place, restricting data access to authorised individuals through unique user credentials, strong passwords, and role-based privileges. Regular data backups and recovery processes are performed to maintain data integrity and availability.
- Organisational Safeguards: Our commitment to data security extends to our employees and third-party service providers. Strict confidentiality agreements bind them, emphasising the importance of maintaining the security and confidentiality of your personal data. Regular training programs are conducted to educate employees on data protection best practices, security protocols, and their responsibilities. Access controls and authorisation mechanisms ensure that only authorised personnel can access your data. We have established comprehensive data protection policies and procedures to guide the proper handling, storage, retention, and disposal of personal data. In the event of any security incidents, our incident response plan enables swift identification, mitigation, and notification, as well as measures to prevent future occurrences.
If you suspect any misuse or loss of or unauthorised access to your personal data, please let us know immediately by sending us an email privacy@aar.co.ke
Once the retention period expires, we securely delete or anonymise your data to ensure it is no longer identifiable or accessible.
The retention periods for each category of data subjects and their respective personal data may vary based on the specific circumstances and legal requirements. Here are some general guidelines regarding data retention:
- Prospective Policyholders: We retain your personal information as outlined in Clause 5 of this Privacy Policy period of two (2) years from the date of collection or until consent is withdrawn. This allows us to maintain effective communication, improve our marketing strategies and fulfil the purposes outlined in this Privacy Policy.
- Policy holders: We retain your personal information as outlined in Clause 5 of this Privacy Policy for the duration of your policy with AAR and seven (7) years thereafter. However, such retention may be subject to any legal or regulatory requirements, further processing historical, statistical, journalistic, literature, art or research purposes or any you give consent for longer retention periods. Where we collect information based on consent, we retain your information until you withdraw your consent.
- Website User and Visitors to the Company premises: If you are a Website/Mobile App User or a visitor to the company premises, we will retain your personal data for as long as it is necessary which duration, we have determined to be one (1) year to achieve the purpose stipulated in clause 6. If this time has come or you have expressly indicated that you are not interested in our website or mobile app services anymore, we will delete it from our systems unless we believe in good faith that the law or other regulation requires us to preserve it for example because of our obligations
- right to information: you have a right to be informed of how AAR will use your personal data.
- right of access: you are entitled to access your personal data that is in our possession or custody.
- right to object: you can object to the processing of all part of your personal data, unless we can demonstrate a compelling legitimate interest for the processing which overrides your interests or for the establishment, exercise or defence of a legal claim.
- right to rectification: you have the right to request us to rectify or correct, without undue delay, personal data in our possession or under our control that is inaccurate, outdated, incomplete or misleading.
- right to erasure: you can request us to delete or destroy, without undue delay personal data that we are no longer authorised to retain, or which is irrelevant, excessive, or obtained unlawfully.
- right to data portability: you have the right to receive personal data concerning you in a structured, commonly used and machine-readable format and to transmit the data to another data controller without hindrance. Where technically possible. have personal data transmitted directly from us to another data controller or data processor.
- automated decision making you have the right not to be subjected to a decision based solely on automated processing, including profiling, which produces legal effects concerning or that significantly affects you. AAR may from time to time make decisions based on the automated processing of your personal data. In such instances, you will be informed, in writing, whenever a decision based on automated processing is taken. In addition, you can request us to reconsider any decisions made based on automated processing or to take a new decision that is not based solely on automated processing.
- right of restriction: You have the right to request us to restrict the processing of personal data where: – oyou contest the accuracy of the personal data o the personal data is no longer required for the purpose of the processing
- the processing is unlawful, or you have opposed the erasure of the personal data and requested for restriction of its use instead.
- you have objected to the processing of personal data, pending verification as to whether the legitimate interests of the data controller or data processor override those of the data subject.
- right to raise a complaint: You can raise a complaint about our processing with the Regulator i.e., the Data Commissioner in Kenya. You may also be able to seek a remedy through the courts if you believe that your rights have been breached.
If you wish to exercise any of our rights above, please contact us on privacy@aar.co.ke We will seek to deal with your request without undue delay and in any event in accordance with the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021.
To ensure the security and accuracy of the personal data we provide, we may request additional information and verification of your identity. This is necessary to confirm that we are releasing the data to the rightful owner.
While we strive to fulfil all valid requests, there may be cases where we are unable to comply. If such a situation arises, we will inform you of the reasons for our inability to fulfil your request.
We are committed to ensuring that any transfer of personal data outside of Kenya complies with the provisions set forth by the Data Protection Act, 2019.
We prioritise the security and protection of your personal data throughout the transfer process. Therefore, we have implemented the following policy regarding international data transfers:
- Appropriate Safeguards: Before transferring personal data to another country, we ensure that we have appropriate safeguards in place to ensure the security and protection of your data. These safeguards may include technical, organisational, and legal measures to uphold data privacy standards. We will document these safeguards and provide proof to the Data Commissioner as and when required.
- Legal Grounds: We will only transfer personal data outside of Kenya when it is necessary and lawful. This includes situations where the transfer is required for the performance of a contract between you and AAR, the establishment, exercise, or defense of legal claims, the protection of vital interests, matters of public interest, or compelling legitimate interests that are not overridden by your rights and freedoms.
- Consent and Sensitive Data: If the transfer involves sensitive personal data, we will obtain your explicit consent and confirmation of appropriate safeguards before processing such data outside of Kenya.
- Data Commissioner Oversight: We acknowledge the authority of the Data Commissioner to request demonstrations of the effectiveness of security safeguards or the existence of compelling legitimate interests prior to the transfer
We are committed to maintaining the privacy and security of your personal data, regardless of its location. If you have any questions or concerns regarding our international data transfer practices, please contact our Data Protection Officer (DPO) at privacy@aar.co.ke We will strive to address your inquiries and provide you with transparent information regarding the transfer of your personal data outside of Kenya.
A “cookie” is a bite-sized piece of data that is stored on your computer’s hard drive. They are used by nearly all websites and do not harm your system. We use them to track your activity to help ensure you get the smoothest possible experience when visiting our website. We can use the information from cookies to ensure we present you with options tailored to your preferences on your next visit. We can also use cookies to analyse traffic and for advertising purposes.
If you want to check or change what types of cookies you accept, this can usually be altered within your browser settings. However, rejecting all cookies through your browser’s privacy settings means that you may not be able to take full advantage of all our website’s features.
For more information generally on cookies, including how to disable them, please refer to aboutcookies.org. You will also find details on how to delete cookies from your computer.
Data Protection Officer
Real Towers Upperhill
P.O. Box 41766 – 00100
Nairobi, Kenya.
Tel: +254 703 063 000, +254 730 633 000, +254 202 895 000
Website: https://aar–insurance.com/ke.
By providing your personal data to AAR you agree to adhere to the following responsibilities:
- Accuracy and Updates: You are responsible for providing accurate and up-todate personal data to the Company. Please inform us promptly of any changes or updates to your contact details or other relevant information.
- Third-Party Data: If you give us personal data of third parties, such as family members or associates, next of kin or your dependents, it is your responsibility to ensure that you have obtained the necessary consent or authority to share their information. Inform these individuals about the processing activities and possible international transfers of their data.
- Exercise of Rights: If you wish to exercise your rights with respect to your personal data, including the rights of access, rectification, erasure, objection, or data portability, please follow the procedures outlined in our Privacy Policy. We may require additional information or verification to process your request and ensure the security and confidentiality of your data.
- Reporting Concerns: If you have any concerns or complaints regarding the processing or transfer of your personal data, please contact our designated Data Protection Officer (DPO) at privacy@aar.co.ke We appreciate your feedback and will promptly address any issues raised.
- Prospective policyholders their dependents and/or next of kin
- Policyholders and their dependents and/or next of kin
- Visitors to the company premises
- Website/Mobile App Users
Welcome to AAR’s Job Applicant Privacy Policy.
AAR Insurance Limited (“AAR”, “We”, “Us”, “Our”) is committed to protecting the privacy and
personal data of all individuals who apply for employment with us. We recognise the importance of
handling your personal data responsibly and are committed to processing it in a lawful, fair and
transparent manner.
This Privacy Notice explains how AAR collects, uses, stores, shares, retains and otherwise processes
your personal data during the recruitment and selection process. It also explains your rights under
the Data Protection Act, 2019 and how you may exercise those rights.
AAR processes your personal data in accordance with the Data Protection Act, 2019, the Data
Protection (General) Regulations, 2021 and other applicable laws.
AAR Insurance Limited ("AAR") is a licensed insurance company offering medical and general
insurance solutions to individuals, families and businesses.
For the purposes of the Data Protection Act, 2019, AAR is the Data Controller in relation to the
personal data collected and processed during the recruitment process. This means that AAR
determines the purposes for which, and the manner in which, your personal data is processed.
Our registered office is located at:
AAR Insurance Limited
Real Towers
Upper Hill Road
P.O. Box 41766 - 00100
Nairobi, Kenya
As part of the recruitment process, AAR collects and processes personal data that is necessary to
assess your suitability for employment, communicate with you throughout the recruitment process,
comply with applicable legal obligations and, where applicable, establish an employment relationship.
The table below sets out the categories of personal data we collect, the purposes for which it is
processed and the lawful basis relied upon.
| Type of Information | Personal Data Collected | Purpose of Collection | Lawful Basis |
|---|---|---|---|
| Personal and Identification Contact Information | Full name, national identification card or passport number, nationality, passport photograph (where applicable), postal and physical address, telephone number, email address and other contact details. | To identify you, communicate with you, administer your application and verify your identity. | Pre-contractual steps; legitimate interests; compliance with legal obligations where applicable. |
| Employment, Education and Professional Information | Curriculum vitae (CV), cover letter, employment history, positions held, work experience, skills, competencies, professional memberships, academic qualifications, professional certifications, licences, transcripts and training records. | To assess your qualifications, experience, competence and suitability for the position applied for. | Pre-contractual steps; legitimate interests. |
| Recruitment and Assessment Information | Application forms, interview notes, interview recordings (where applicable), assessment results, psychometric test results, practical exercises, presentations, evaluator comments and recruitment correspondence. | To assess your application, conduct interviews and assessments, compare candidates and make recruitment decisions. | Pre-contractual steps; legitimate interests. |
| Reference and Background Verification Information | Referee names and contact details, employment references, reference responses, background verification reports, right-to-work documentation and other verification information. | To verify the information provided during the recruitment process and conduct lawful pre-employment screening. | Pre-contractual steps; legitimate interests; compliance with legal obligations where applicable. |
| Compensation Information | Current remuneration, salary expectations, benefits expectations and other compensation-related information provided during the recruitment process. | To evaluate remuneration expectations and prepare an employment offer where appropriate. | Pre-contractual steps; legitimate interests. |
| Technical Information | IP address, browser type, device information, cookies, online identifiers and information relating to your use of AAR's recruitment portal or careers website. | To administer and secure recruitment systems, improve website functionality, maintain system security and analyse recruitment platform usage. | Legitimate interests; consent where required by law. |
| Special Categories of Personal Data (where applicable) | Health information relating to fitness for work, disability information required to provide reasonable accommodation, criminal record information where authorised by law, and any other special categories of personal data permitted under applicable law. | To comply with legal obligations, facilitate reasonable accommodations, conduct lawful pre-employment checks where permitted and fulfil other employment-related legal requirements. | Compliance with legal obligations; employment obligations; explicit consent where required by law; other lawful grounds under the Data Protection Act, 2019. |
Some of the personal data requested during the recruitment process is mandatory because it is necessary for AAR to assess your application, verify your identity, conduct lawful pre-employment checks, comply with legal or regulatory obligations and determine whether to enter into an employment relationship with you. Other information is voluntary and is collected only where you choose to provide it or where it is required for a specific purpose.
AAR does not ordinarily request sensitive personal data unless it is necessary for a lawful recruitment purpose or required by applicable law. Where such information is required, AAR will process it in accordance with the Data Protection Act, 2019 and implement appropriate safeguards to protect your privacy.
If you are offered and accept employment with AAR, the personal data collected during the recruitment process will become part of your employment record and will thereafter be processed in accordance with AAR's Employee Privacy Notice.
If your application is unsuccessful, AAR will retain your personal data in accordance with this Privacy Notice and the Company's Data Retention and Disposal Policy. Where appropriate and permitted by law, we may retain your information to consider you for future employment opportunities, unless you request otherwise.
| Source of Personal Data | Examples of Personal Data Collected | Purpose of Collection |
|---|---|---|
| Directly from You | Information provided in your application form, curriculum vitae (CV), cover letter, identification documents, academic and professional certificates, interview responses and any other information you choose to provide during the recruitment process. | To assess your suitability for employment, communicate with you, verify your identity and administer the recruitment process. |
| Recruitment Assessments and Interviews | Interview notes, interview recordings (where applicable), assessment results, psychometric test results, presentations, practical exercises and evaluator comments. | To evaluate your knowledge, skills, competencies and suitability for the position. |
| Recruitment Agencies and Referrals | CVs, application details and other recruitment information received from recruitment agencies, head-hunters or employee referrals. | To identify and assess potential candidates for employment opportunities. |
| Referees and Background Verification Providers | Employment references, reference responses, background verification reports, right-to-work verification and other pre-employment screening information. | To verify the information you have provided and conduct lawful pre-employment checks. |
| Publicly Available Sources | Information from professional networking platforms (such as LinkedIn) and other publicly available professional sources, where permitted by law. | To verify professional qualifications, employment history and identify suitable candidates for employment opportunities. |
| AAR Recruitment Systems and Website | IP address, browser type, device information, cookies, online identifiers and information relating to your use of AAR's careers portal or recruitment website. | To administer recruitment systems, maintain security, improve website functionality and analyse recruitment platform usage. |
AAR may store or process your personal data using systems or service providers located outside Kenya. This may result in your personal data being transferred to, stored in or accessed from jurisdictions outside Kenya. Where such transfers occur, AAR will ensure that they are carried out in accordance with the Data Protection Act, 2019 and any other applicable laws.
AAR currently utilises cloud-based platforms and authorised third-party service providers, including infrastructure hosted in the Western Europe region, to support its recruitment processes. Such providers are required to implement appropriate security measures and process personal data only in accordance with AAR's instructions and applicable law.
AAR takes appropriate steps to ensure that your personal data is accessed only by those who require it to perform their duties and by third parties with a legitimate need to process the data for the purposes described in this Privacy Policy. Where we engage third parties to process personal data on our behalf, we require them to process the data only for authorised purposes, maintain its confidentiality, implement appropriate technical and organisational security measures, and comply with applicable data protection laws and contractual obligations.
We may share your Personal Data in the following ways:
- Authorised AAR personnel, including Human Resources, recruiting managers, interview panel members and other employees involved in the recruitment and selection process, where access is necessary for the performance of their duties.
- Third-party service providers, including recruitment agencies, applicant tracking system providers, background verification providers, psychometric assessment providers, cloud hosting providers and other service providers who support AAR's recruitment activities.
- Professional advisers, including legal advisers, auditors and other consultants, where access to your personal data is necessary for the provision of professional services or the establishment, exercise or defence of legal claims.
- Regulators, law enforcement agencies, courts or other competent authorities, where disclosure is required or authorised by law, court order or other lawful process.
- Corporate transaction parties, where disclosure is necessary in connection with a merger, acquisition, restructuring, sale of business or other corporate transaction, subject to appropriate confidentiality and data protection safeguards.
- Other third parties, where you have provided your consent or where disclosure is otherwise permitted or required under applicable law. AAR does not sell your personal data. We only share your personal data where there is a lawful basis for doing so and where appropriate safeguards have been implemented to protect your personal data.
AAR has taken appropriate technical, administrative, physical and procedural security measures, consistent with local and international information practices, to protect the personal data from misuse, unauthorised access or disclosure, loss, alteration, or destruction. These measures include:
- Physical safeguards, such as locked doors and file cabinets, controlled access to our facilities, and secure destruction of media containing personal data.
- Technology safeguards, such as use of anti-virus and endpoint protection software, passwords, encryption, and monitoring of our systems and data centres to ensure compliance with our security policies.
- Organisational safeguards, through training and awareness programs on security and privacy, to ensure employees understand the importance and means by which they must protect personal data, as well as through privacy policies and policy standards that govern how AAR treats personal data.
If you suspect any misuse, loss, or unauthorised access to your personal data, please let us know immediately by sending us an email on privacy@aar.co.ke
- Our ability to consider your application, communicate with you, verify your information, conduct lawful checks, ,comply with legal obligations, and decide whether to offer you employment may depend on AAR receiving and using certain personal data.
- If you do not provide personal data that is required for the recruitment process, or if you ask us to stop processing personal data that we need for that process, we may be unable to progress your application, conduct necessary checks, communicate with you, comply with applicable legal or regulatory obligations, or make an offer of employment. Where the information requested is optional, choosing not to provide it will not affect your application unless the information is necessary for a specific purpose that you have asked us to consider.
The Data Protection Act accords you several rights. However, these rights are not absolute and may be subject to some exceptions under data protection law.
- The right to be informed about the collection and use of your personal data, including
the purposes for which it is processed and the lawful basis for such processing.
- The right to access your personal data and obtain information about how it is processed.
- The right to object to the processing of your personal data where such processing is based on AAR's legitimate interests, unless AAR demonstrates compelling legitimate grounds or is otherwise permitted by law to continue the processing.
- The right to correction of inaccurate, incomplete, outdated or misleading personal data.
- The right to erasure of your personal data in circumstances permitted by law.
- The right to data portability, where applicable, by receiving your personal data in a structured, commonly used and machine-readable format or requesting that it be transmitted to another data controller where technically feasible.
- The right not to be subject to a decision based solely on automated processing, including profiling, where such a decision produces legal effects concerning you or similarly significantly affects you, except where permitted by law.
- The right to request restriction of processing in circumstances permitted under the Data Protection Act, 2019.
You may exercise your rights by submitting a written request to the Data Protection Officer using the contact details provided in this Privacy Policy. AAR will consider and respond to all requests in accordance with the Data Protection Act, 2019 and may request additional information to verify your identity before processing your request. In certain circumstances, AAR may decline or limit a request where permitted or required by law, in which case you will be informed of the reasons for that decision.
If you have any questions about this Privacy Notice, wish to exercise your rights under the Data Protection Act, 2019, or have any concerns regarding the processing of your personal data, you may contact AAR's Data Protection Officer using the contact details below:
Data Protection Officer
AAR Insurance Limited
Email: privacy@aar.co.ke
Telephone: +254 703 063 000, +254 730 633 000, +254 202 895 000 Postal Address: 41766 – 00100, Nairobi, Kenya.
Physical Address: Real Towers, Upper Hill Road, Nairobi, Kenya
AAR will endeavour to respond to your enquiry or complaint within the timelines prescribed under the Data Protection Act, 2019 and any other applicable laws.
If you are dissatisfied with AAR's response or believe that your personal data has been processed in contravention of the Data Protection Act, 2019, you have the right to lodge a complaint with the Office of the Data Protection Commissioner or seek any other remedy available under applicable law.
AAR may review and update this Privacy Notice from time to time to reflect changes in applicable laws, regulations, business operations, technology or the manner in which we process personal data.
Where material changes are made to this Privacy Notice, AAR will take reasonable steps to notify applicants through appropriate communication channels, including updates on our careers portal, recruitment platforms, website or other appropriate means.
The latest version of this Privacy Notice will be made available on AAR's website and through other appropriate recruitment channels and will supersede all previous versions.
The "Effective Date" and "Version Number" set out in this Privacy Notice indicate when it was last reviewed and updated.
Welcome to the AAR’s Agents Privacy Policy. We appreciate you taking the time to read all our notices carefully.
AAR Insurance Limited (“AAR”, “We” “Us” “Our”) is committed to processing your personal information in a lawful, fair and transparent manner and in accordance with data protection laws in Kenya.
This Privacy Policy outlines how we collect, use, disclose, and protect personal information in connection with our services, including provision of medical and general insurance products and services.
Please take time to read this Privacy Policy to understand how and why we collect and use your information in connection with our insurance business.
AAR Insurance Kenya Limited is a leading medical and general insurance company, providing innovative underwriting solutions to individuals, families, and businesses. We offer products ranging from Family Plans, Personal Accident Insurance, School Insurance, Homeowners Insurance, Medical Insurance for SMEs and Corporates, Professional Indemnity, WIBA Cover, Travel Insurance, Marine Insurance and Landlord Insurance.
Our offices are located at Real Towers, Upperhill, Nairobi, Kenya.
This Privacy Policy applies to all AAR Insurance Kenya Limited Agents in connection with our insurance business.
In this Privacy Policy, "personal data" refers to any information relating to an identified or identifiable individual. This includes, but is not limited to, identification details, contact details, commissions, lead management details, performance appraisals, social media profiles, HMIS Code and any other data that can be used to directly or indirectly identify an individual.
Personal data may also include sensitive information, such as racial or ethnic origin, religious beliefs, health information, family information including children’s information, biometric data, property records, financial information, transaction records, where applicable and subject to applicable laws and regulations.
- We collect Personal Data directly from you as well as from other available sources to the extent permitted by law. We endeavour to only collect Personal Data that is necessary for the purpose(s) for which it is collected and to retain such data for no longer than necessary for such purpose(s). Subject to applicable law and practice, the categories of Personal Data that are typically collected and processed are:
Data Subject | Type of personal data collected | Purpose of Collection | Lawful Basis |
Agents | § Identification details: name, date of birth, ID/Passport, HMIS Code | § For identification purposes § To grant access to My Wakalaar § To confirm that the details provided on registration on My Wakalaar match with those in AIK Agent database. § To allow for background data synchronization on My Wakaalar | § Legal Obligation
|
§ Contact details: telephone number, WhatsApp number, email address | § For communication purposes including OTP delivery § To facilitate user-agent interactions including enabling users communicate their needs and enquiries to the agent, foster engagement and communication with agent on my Wakalaar platform.
| § Legitimate interests | |
§ Recruitment details: CV, Academic Certificates, Passport Photographs, examination results | § To your determine suitable for role applied | § Legitimate interests | |
§ Onboarding details: Insurance certificate, contractual details | § To onboard you to AAR Insurrance | § Contract § Legal Requirement | |
§ Performance Management details: Weekly activity templates, productivity appraisals | § To assess your performance against set KPIs | § Contract | |
§ Commission details: Commission, monthly statements, payment details including bank account numbers | § To process your commissions | § Contract | |
§ Consent details: Consent to receive marketing communications, consent to receive OTP, consent to process customer information | § For marketing/promotional purposes § To enable you perform accurate calculations of quotations, personalize the quotation process, communicate with client and track the progress of quotation and see its eventual closure. | § Consent | |
§ One Time Password (OTP) & agents’ passwords | § For validation and authentication of agents during registration to My Wakaalar § To ensure that you have control over your account on My Wakaalar and update it when necessary. | § Legitimate interests | |
§ Social Media details: social media accounts, consent to post on linked social media accounts, access tokens | § To enable you seamlessly link your social media accounts with My Wakalaar. | § Consent | |
§ Lead Management details: lead source, lead probability, lead value, tags, notes consent to process potential customer’s information | § To enable you save lead information on My Wakaalar platform and effectively manage lead data
| § Legitimate interests | |
§ CCTV Records | § To secure company premises and assets | § Legitimate interests | |
§ Complaints/requests
| § To receive, register and resolve your complaints | § Legitimate interests | |
§ Online identifiers: such as cookies and related tags, IP addresses | § To improve your experience when you access our website | § Legitimate interests |
We collect your information directly when you call, message, email or populate your details on the Agents’ platform My Wakalaar.
We also collect personal data indirectly when you use our website or access My Wakalaar, social medial platforms or when you visit our offices, and your images are captured by CCTV.
In some cases, if you choose not to provide certain personal data requested by us, it may impact our ability to fulfil our contractual obligations or provide you requested services or information. The specific consequences of not providing personal data will depend on the context and the purpose for which the data is requested.
For example, if you fail to provide us accurate bank account details, we may fail to process your commission statements.
We encourage you to carefully consider personal data requested and its importance for the intended purposes. If you have concerns about providing certain information, please contact us to discuss your specific circumstances and requirements. We will endeavor to find alternative solutions or assess if there are any legal or contractual obligations that require the provision of the requested data.
We may share your personal data within the Company to facilitate our internal operations and provide you with efficient services.
We may share your personal data with third parties in the following circumstances:
- Service Providers: We may engage third-party service providers to perform various services on our behalf, such as IT service providers and legal services providers. These service providers will have access to your personal data as necessary to perform their functions but are strictly prohibited from using your personal data for any other purposes.
- Business Partners: We may share your personal data with trusted business partners who collaborate with us to provide products or services to you. These partners may use your personal data only for the purposes specified in our agreement with them.
- Obligations: may disclose your personal data if required to do so by law or in response to a valid legal request, such as a court order or government inquiry.
- Corporate Transactions:In the event of a merger, acquisition, or any form of corporate restructuring, we may transfer your personal data to the involved parties, if they agree to treat your personal data in accordance with this privacy policy.
- Consent:We may share your personal data with third parties if you have given us explicit consent to do so. You have the right to withdraw your consent at any time.
When sharing your personal data with third parties, we prioritise the security and confidentiality of your information. We take stringent measures to ensure that these parties comply with strict data protection standards and handle your personal data in accordance with our instructions.
We carefully select and evaluate third-party service providers, business partners, and other recipients of your personal data. We enter into contractual agreements with these parties, imposing obligations to protect your personal data and restricting their use of the information solely for the specified purposes outlined in our agreement. Furthermore, we require these third parties to implement appropriate technical and organisational measures to prevent unauthorised access, disclosure, alteration, or destruction of your personal data.
We understand the importance of keeping your personal data secure and take appropriate measures to protect it against unauthorized access, loss, misuse, or alteration. We have implemented robust security measures to ensure the confidentiality, integrity, and availability of your information, including: -
- Technical Safeguards: To protect your information during transmission, we utilize industry-standard encryption protocols, ensuring the confidentiality of your data. Our secure network infrastructure incorporates firewalls, intrusion detection systems, and other security measures to prevent unauthorised access and mitigate external threats. Additionally, access controls are in place, restricting data access to authorised individuals through unique user credentials, strong passwords, and role-based privileges. Regular data backups and recovery processes are performed to maintain data integrity and availability.
- Organisational Safeguards: Our commitment to data security extends to our employees and third-party service providers. Strict confidentiality agreements bind them, emphasizing the importance of maintaining the security and confidentiality of your personal data. Regular training programs are conducted to educate employees on data protection best practices, security protocols, and their responsibilities. Access controls and authorization mechanisms ensure that only authorised personnel can access your data. We have established comprehensive data protection policies and procedures to guide the proper handling, storage, retention, and disposal of personal data. In the event of any security incidents, our incident response plan enables swift identification, mitigation, and notification, as well as measures to prevent future occurrences.
While we continually enhance our security measures, it is important to note that no security measure can provide absolute protection. However, we are dedicated to maintaining the highest possible standards of data security and will continue to invest in measures to safeguard your information
If you suspect any misuse or loss of or unauthorised access to your personal data, please let us know immediately by sending us an email on privacy@aar.co.ke
We retain your personal data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy, or as required by applicable laws and regulations.
Once the retention period expires, we securely delete or anonymise your data to ensure it is no longer identifiable or accessible.
The retention periods for each category of data subjects and their respective personal data may vary based on the specific circumstances and legal requirements.
Your personal data such as contact details, identification details, contract details, payment details, CCTV records, social media profiles, complaints/requests, and cookies/online identifiers, is generally retained for the duration of the business relationship and for six [6] years thereafter. This allows us to maintain effective communication, fulfil contractual obligations, and comply with legal requirements.
ice providers and agents: We may make certain Personal Data available to third parties who provide services to us such as our human resource management software, background checks and psychometric service providers, headhunter firms, cloud service providers, and recruitment service providers. When we share with these third parties, we do so on a need-to-know basis and under clear contractual terms and instructions for the processing of the Personal Data.
- With other third parties: We may also share your information with other types of third parties, such as our legal representatives, industry groups or self-regulatory bodies, on lawful grounds. For example:
- with your consent.
- to comply with our legal obligations (including to comply with laws, regulations, and contracts, to respond to court orders, administrative or judicial process and search warrants, or to meet national security and law enforcement requests);
- to establish, exercise, or defend against potential, threatened, or actual litigation.
- to protect the safety, property, or vital interests of a person.
- to protect AAR’s rights or property.
- to protect AAR our other employees, customers, or the public from harm or illegal activities.
- to respond to an emergency that we, in good faith, believe requires us to disclose data to prevent harm; and
- in connection with the sale, assignment, merger, or other reorganisation or transfer of all or part of our business.
Under the Data Protection Act, 2019, you have serval rights regarding your personal data.
- right to information: you have a right to be informed of how the Company will use your personal data.
- right to access: you are entitled to access your personal data that is in our possession or custody.
- right to object: you can object to the processing of all part of your personal data, except when we can demonstrate a compelling legitimate interest for the processing which overrides your interests or for the establishment, exercise or defence of a legal claim.
- right to rectification: you have the right to request the correction of inaccurate, outdated, incomplete or misleading personal data in our possession or under our control, without undue delay.
- right to erasure: you have the right to request deletion or destruction, without undue delay, of personal data that we are no longer authorised to retain, or that is irrelevant, excessive, or obtained unlawfully.
- right to data portability: you have the right to receive personal data concerning you in a structured, commonly used, and machine-readable format and to transmit the data to another data controller without hindrance. Where technically feasible, you may also request direct transmission of your personal data from us to another data controller or data processor.
- automated decision making : you have the right not to be subjected to a decision based solely on automated processing, including profiling, which produces legal effects affects you. If we make automated decisions based on your personal data, you will be notified in writing. You can also request us to reconsider any decisions made solely through automated processing or to make a new decision that is not solely automated
- right of restriction: : You can request the restriction of processing your personal data in certain circumstances, such as when you contest the accuracy of the data, it is no longer needed for processing, it was processed unlawfully, or you have objected to the processing pending verification of our legitimate interests.
If you wish to exercise any of the rights outlined above, please write an email to the Data Protection Officer (DPO) on privacy@aar.co.ke
We will make every effort to address your inquiries and requests via email within the timelines specified by applicable data protection laws and regulations.
To ensure the security and accuracy of the personal data we provide, we may request additional information and verification of your identity. This is necessary to confirm that we are releasing the data to the rightful owner.
While we strive to fulfill all valid requests, there may be cases where we are unable to comply. If such a situation arises, we will inform you of the reasons for our inability to fulfill your request.
As part of our business operations, we may transfer personal data to recipients located in countries outside Kenya.
We are committed to ensuring that any transfer of personal data outside of Kenya complies with the provisions set forth by the Data Protection Act, 2019.
We prioritise the security and protection of your personal data throughout the transfer process. Therefore, we have implemented the following policy regarding international data transfers:
- Appropriate Safeguards Before transferring personal data to another country, we ensure that we have appropriate safeguards in place to ensure the security and protection of your data. These safeguards may include technical, organisational, and legal measures to uphold data privacy standards. We will document these safeguards and provide proof to the Data Commissioner as and when required.
- Legal Grounds: We will only transfer personal data outside of Kenya when it is necessary and lawful. This includes situations where the transfer is required for the performance of a contract between you and AAR establishment, exercise, or defense of legal claims, the protection of vital interests, matters of public interest, or compelling legitimate interests that are not overridden by your rights and freedoms.
- Consent and Sensitive Data: If the transfer involves sensitive personal data, we will obtain your explicit consent and confirmation of appropriate safeguards before processing such data outside of Kenya.Consent and Sensitive Data: If the transfer involves sensitive personal data, we will obtain your explicit consent and confirmation of appropriate safeguards before processing such data outside of Kenya.
- Data Commissioner OversightWe acknowledge the authority of the Data Commissioner to request demonstrations of the effectiveness of security safeguards or the existence of compelling legitimate interests prior to the transfer of personal data. We will cooperate with the Data Commissioner and comply with any conditions or restrictions imposed to protect the rights and fundamental freedoms of data subjects.
13.4. We are committed to maintaining the privacy and security of your personal data, regardless of its location. If you have any questions or concerns regarding our international data transfer practices, please contact our Data Protection Officer (DPO) at privacy@aar.co.ke We will strive to address your inquiries and provide you with transparent information regarding the transfer of your personal data outside of Kenya.
iries via email within the timelines stipulated in law.
When your information is processed by third-party services providers, we will promptly request third parties to your personal data.
To ensure that we release information to the correct individual, we may request identification verification.
In some cases, we will not be able to comply with your request. If this happens, you will be duly notified.
As a data subject, it is important that you understand and fulfill certain responsibilities to ensure the protection and privacy of your personal data. By providing your personal data to the Company, you agree to adhere to the following responsibilities:
- Accuracy and Updates:You are responsible for providing accurate and up-to-date personal data to the Company. Please inform us promptly of any changes or updates to your contact details or other relevant information.
- Third-Party Data: If you give us personal data of third parties, such as prospective member, it is your responsibility to ensure that you have obtained the necessary consent or authority to share their information. Inform these individuals about the processing activities and possible international transfers of their data.
- Exercise of Rights: If you wish to exercise your rights with respect to your personal data, including the rights of access, rectification, erasure, objection, or data portability, please follow the procedures outlined in our Privacy Policy. We may require additional information or verification to process your request and ensure the security and confidentiality of your data.
- Reporting Concerns: If you have any concerns or complaints regarding the processing or transfer of your personal data, please contact our designated Data Protection Officer (DPO) at privacy@aar.co.ke .We appreciate your feedback and will promptly address any issues raised.
We may periodically update or revise this Privacy Policy to ensure its alignment with legal requirements and our evolving business practices. We encourage you to review this Policy periodically to stay informed about how we handle your personal data.
If we make any material changes to this Policy, we will notify you through appropriate means, such as by posting a notice on our website or sending a direct communication. Your continued use of our services after the effective date of any revised Privacy Policy constitutes your acceptance of the revised Policy. We recommend that you regularly check this Privacy Policy to stay updated on any changes. If you disagree with any modifications to this Policy, you should discontinue using our services and contact us to exercise your rights or request the removal of your personal data, as outlined in this Policy.
Welcome to the AAR’s Agents Privacy Policy. We appreciate you taking the time to read all our notices carefully.
AAR Insurance Limited (“AAR”, “We” “Us” “Our”) is committed to processing your personal information in a lawful, fair and transparent manner and in accordance with data protection laws in Kenya.
This Privacy Policy outlines how we collect, use, disclose, and protect personal information in connection with our services, including provision of medical and general insurance products and services.
Please take time to read this Privacy Policy to understand how and why we collect and use your information in connection with our insurance business.
AAR Insurance Kenya Limited is a leading medical and general insurance company, providing innovative underwriting solutions to individuals, families, and businesses. We offer products ranging from Family Plans, Personal Accident Insurance, School Insurance, Homeowners Insurance, Medical Insurance for SMEs and Corporates, Professional Indemnity, WIBA Cover, Travel Insurance, Marine Insurance and Landlord Insurance.
Our offices are located at Real Towers, Upperhill, Nairobi, Kenya.
This Privacy Policy applies to all AAR Insurance Kenya Limited Agents in connection with our insurance business.
In this Privacy Policy, "personal data" refers to any information relating to an identified or identifiable individual. This includes, but is not limited to, identification details, contact details, commissions, lead management details, performance appraisals, social media profiles, HMIS Code and any other data that can be used to directly or indirectly identify an individual.
Personal data may also include sensitive information, such as racial or ethnic origin, religious beliefs, health information, family information including children’s information, biometric data, property records, financial information, transaction records, where applicable and subject to applicable laws and regulations.
- We collect Personal Data directly from you as well as from other available sources to the extent permitted by law. We endeavour to only collect Personal Data that is necessary for the purpose(s) for which it is collected and to retain such data for no longer than necessary for such purpose(s). Subject to applicable law and practice, the categories of Personal Data that are typically collected and processed are:
Data Subject | Type of personal data collected | Purpose of Collection | Lawful Basis |
Agents | § Identification details: name, date of birth, ID/Passport, HMIS Code | § For identification purposes § To grant access to My Wakalaar § To confirm that the details provided on registration on My Wakalaar match with those in AIK Agent database. § To allow for background data synchronization on My Wakaalar | § Legal Obligation
|
§ Contact details: telephone number, WhatsApp number, email address | § For communication purposes including OTP delivery § To facilitate user-agent interactions including enabling users communicate their needs and enquiries to the agent, foster engagement and communication with agent on my Wakalaar platform.
| § Legitimate interests | |
§ Recruitment details: CV, Academic Certificates, Passport Photographs, examination results | § To your determine suitable for role applied | § Legitimate interests | |
§ Onboarding details: Insurance certificate, contractual details | § To onboard you to AAR Insurrance | § Contract § Legal Requirement | |
§ Performance Management details: Weekly activity templates, productivity appraisals | § To assess your performance against set KPIs | § Contract | |
§ Commission details: Commission, monthly statements, payment details including bank account numbers | § To process your commissions | § Contract | |
§ Consent details: Consent to receive marketing communications, consent to receive OTP, consent to process customer information | § For marketing/promotional purposes § To enable you perform accurate calculations of quotations, personalize the quotation process, communicate with client and track the progress of quotation and see its eventual closure. | § Consent | |
§ One Time Password (OTP) & agents’ passwords | § For validation and authentication of agents during registration to My Wakaalar § To ensure that you have control over your account on My Wakaalar and update it when necessary. | § Legitimate interests | |
§ Social Media details: social media accounts, consent to post on linked social media accounts, access tokens | § To enable you seamlessly link your social media accounts with My Wakalaar. | § Consent | |
§ Lead Management details: lead source, lead probability, lead value, tags, notes consent to process potential customer’s information | § To enable you save lead information on My Wakaalar platform and effectively manage lead data
| § Legitimate interests | |
§ CCTV Records | § To secure company premises and assets | § Legitimate interests | |
§ Complaints/requests
| § To receive, register and resolve your complaints | § Legitimate interests | |
§ Online identifiers: such as cookies and related tags, IP addresses | § To improve your experience when you access our website | § Legitimate interests |
We collect your information directly when you call, message, email or populate your details on the Agents’ platform My Wakalaar.
We also collect personal data indirectly when you use our website or access My Wakalaar, social medial platforms or when you visit our offices, and your images are captured by CCTV.
In some cases, if you choose not to provide certain personal data requested by us, it may impact our ability to fulfil our contractual obligations or provide you requested services or information. The specific consequences of not providing personal data will depend on the context and the purpose for which the data is requested.
For example, if you fail to provide us accurate bank account details, we may fail to process your commission statements.
We encourage you to carefully consider personal data requested and its importance for the intended purposes. If you have concerns about providing certain information, please contact us to discuss your specific circumstances and requirements. We will endeavor to find alternative solutions or assess if there are any legal or contractual obligations that require the provision of the requested data.
We may share your personal data within the Company to facilitate our internal operations and provide you with efficient services.
We may share your personal data with third parties in the following circumstances:
- Service Providers: We may engage third-party service providers to perform various services on our behalf, such as IT service providers and legal services providers. These service providers will have access to your personal data as necessary to perform their functions but are strictly prohibited from using your personal data for any other purposes.
- Business Partners: We may share your personal data with trusted business partners who collaborate with us to provide products or services to you. These partners may use your personal data only for the purposes specified in our agreement with them.
- Obligations: may disclose your personal data if required to do so by law or in response to a valid legal request, such as a court order or government inquiry.
- Corporate Transactions:In the event of a merger, acquisition, or any form of corporate restructuring, we may transfer your personal data to the involved parties, if they agree to treat your personal data in accordance with this privacy policy.
- Consent:We may share your personal data with third parties if you have given us explicit consent to do so. You have the right to withdraw your consent at any time.
When sharing your personal data with third parties, we prioritise the security and confidentiality of your information. We take stringent measures to ensure that these parties comply with strict data protection standards and handle your personal data in accordance with our instructions.
We carefully select and evaluate third-party service providers, business partners, and other recipients of your personal data. We enter into contractual agreements with these parties, imposing obligations to protect your personal data and restricting their use of the information solely for the specified purposes outlined in our agreement. Furthermore, we require these third parties to implement appropriate technical and organisational measures to prevent unauthorised access, disclosure, alteration, or destruction of your personal data.
We understand the importance of keeping your personal data secure and take appropriate measures to protect it against unauthorized access, loss, misuse, or alteration. We have implemented robust security measures to ensure the confidentiality, integrity, and availability of your information, including: -
- Technical Safeguards: To protect your information during transmission, we utilize industry-standard encryption protocols, ensuring the confidentiality of your data. Our secure network infrastructure incorporates firewalls, intrusion detection systems, and other security measures to prevent unauthorised access and mitigate external threats. Additionally, access controls are in place, restricting data access to authorised individuals through unique user credentials, strong passwords, and role-based privileges. Regular data backups and recovery processes are performed to maintain data integrity and availability.
- Organisational Safeguards: Our commitment to data security extends to our employees and third-party service providers. Strict confidentiality agreements bind them, emphasizing the importance of maintaining the security and confidentiality of your personal data. Regular training programs are conducted to educate employees on data protection best practices, security protocols, and their responsibilities. Access controls and authorization mechanisms ensure that only authorised personnel can access your data. We have established comprehensive data protection policies and procedures to guide the proper handling, storage, retention, and disposal of personal data. In the event of any security incidents, our incident response plan enables swift identification, mitigation, and notification, as well as measures to prevent future occurrences.
While we continually enhance our security measures, it is important to note that no security measure can provide absolute protection. However, we are dedicated to maintaining the highest possible standards of data security and will continue to invest in measures to safeguard your information
If you suspect any misuse or loss of or unauthorised access to your personal data, please let us know immediately by sending us an email on privacy@aar.co.ke
We retain your personal data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy, or as required by applicable laws and regulations.
Once the retention period expires, we securely delete or anonymise your data to ensure it is no longer identifiable or accessible.
The retention periods for each category of data subjects and their respective personal data may vary based on the specific circumstances and legal requirements.
Your personal data such as contact details, identification details, contract details, payment details, CCTV records, social media profiles, complaints/requests, and cookies/online identifiers, is generally retained for the duration of the business relationship and for six [6] years thereafter. This allows us to maintain effective communication, fulfil contractual obligations, and comply with legal requirements.
ice providers and agents: We may make certain Personal Data available to third parties who provide services to us such as our human resource management software, background checks and psychometric service providers, headhunter firms, cloud service providers, and recruitment service providers. When we share with these third parties, we do so on a need-to-know basis and under clear contractual terms and instructions for the processing of the Personal Data.
- With other third parties: We may also share your information with other types of third parties, such as our legal representatives, industry groups or self-regulatory bodies, on lawful grounds. For example:
- with your consent.
- to comply with our legal obligations (including to comply with laws, regulations, and contracts, to respond to court orders, administrative or judicial process and search warrants, or to meet national security and law enforcement requests);
- to establish, exercise, or defend against potential, threatened, or actual litigation.
- to protect the safety, property, or vital interests of a person.
- to protect AAR’s rights or property.
- to protect AAR our other employees, customers, or the public from harm or illegal activities.
- to respond to an emergency that we, in good faith, believe requires us to disclose data to prevent harm; and
- in connection with the sale, assignment, merger, or other reorganisation or transfer of all or part of our business.
Under the Data Protection Act, 2019, you have serval rights regarding your personal data.
- right to information: you have a right to be informed of how the Company will use your personal data.
- right to access: you are entitled to access your personal data that is in our possession or custody.
- right to object: you can object to the processing of all part of your personal data, except when we can demonstrate a compelling legitimate interest for the processing which overrides your interests or for the establishment, exercise or defence of a legal claim.
- right to rectification: you have the right to request the correction of inaccurate, outdated, incomplete or misleading personal data in our possession or under our control, without undue delay.
- right to erasure: you have the right to request deletion or destruction, without undue delay, of personal data that we are no longer authorised to retain, or that is irrelevant, excessive, or obtained unlawfully.
- right to data portability: you have the right to receive personal data concerning you in a structured, commonly used, and machine-readable format and to transmit the data to another data controller without hindrance. Where technically feasible, you may also request direct transmission of your personal data from us to another data controller or data processor.
- automated decision making : you have the right not to be subjected to a decision based solely on automated processing, including profiling, which produces legal effects affects you. If we make automated decisions based on your personal data, you will be notified in writing. You can also request us to reconsider any decisions made solely through automated processing or to make a new decision that is not solely automated
- right of restriction: : You can request the restriction of processing your personal data in certain circumstances, such as when you contest the accuracy of the data, it is no longer needed for processing, it was processed unlawfully, or you have objected to the processing pending verification of our legitimate interests.
If you wish to exercise any of the rights outlined above, please write an email to the Data Protection Officer (DPO) on privacy@aar.co.ke
We will make every effort to address your inquiries and requests via email within the timelines specified by applicable data protection laws and regulations.
To ensure the security and accuracy of the personal data we provide, we may request additional information and verification of your identity. This is necessary to confirm that we are releasing the data to the rightful owner.
While we strive to fulfill all valid requests, there may be cases where we are unable to comply. If such a situation arises, we will inform you of the reasons for our inability to fulfill your request.
As part of our business operations, we may transfer personal data to recipients located in countries outside Kenya.
We are committed to ensuring that any transfer of personal data outside of Kenya complies with the provisions set forth by the Data Protection Act, 2019.
We prioritise the security and protection of your personal data throughout the transfer process. Therefore, we have implemented the following policy regarding international data transfers:
- Appropriate Safeguards Before transferring personal data to another country, we ensure that we have appropriate safeguards in place to ensure the security and protection of your data. These safeguards may include technical, organisational, and legal measures to uphold data privacy standards. We will document these safeguards and provide proof to the Data Commissioner as and when required.
- Legal Grounds: We will only transfer personal data outside of Kenya when it is necessary and lawful. This includes situations where the transfer is required for the performance of a contract between you and AAR establishment, exercise, or defense of legal claims, the protection of vital interests, matters of public interest, or compelling legitimate interests that are not overridden by your rights and freedoms.
- Consent and Sensitive Data: If the transfer involves sensitive personal data, we will obtain your explicit consent and confirmation of appropriate safeguards before processing such data outside of Kenya.Consent and Sensitive Data: If the transfer involves sensitive personal data, we will obtain your explicit consent and confirmation of appropriate safeguards before processing such data outside of Kenya.
- Data Commissioner OversightWe acknowledge the authority of the Data Commissioner to request demonstrations of the effectiveness of security safeguards or the existence of compelling legitimate interests prior to the transfer of personal data. We will cooperate with the Data Commissioner and comply with any conditions or restrictions imposed to protect the rights and fundamental freedoms of data subjects.
13.4. We are committed to maintaining the privacy and security of your personal data, regardless of its location. If you have any questions or concerns regarding our international data transfer practices, please contact our Data Protection Officer (DPO) at privacy@aar.co.ke We will strive to address your inquiries and provide you with transparent information regarding the transfer of your personal data outside of Kenya.
iries via email within the timelines stipulated in law.
When your information is processed by third-party services providers, we will promptly request third parties to your personal data.
To ensure that we release information to the correct individual, we may request identification verification.
In some cases, we will not be able to comply with your request. If this happens, you will be duly notified.
As a data subject, it is important that you understand and fulfill certain responsibilities to ensure the protection and privacy of your personal data. By providing your personal data to the Company, you agree to adhere to the following responsibilities:
- Accuracy and Updates:You are responsible for providing accurate and up-to-date personal data to the Company. Please inform us promptly of any changes or updates to your contact details or other relevant information.
- Third-Party Data: If you give us personal data of third parties, such as prospective member, it is your responsibility to ensure that you have obtained the necessary consent or authority to share their information. Inform these individuals about the processing activities and possible international transfers of their data.
- Exercise of Rights: If you wish to exercise your rights with respect to your personal data, including the rights of access, rectification, erasure, objection, or data portability, please follow the procedures outlined in our Privacy Policy. We may require additional information or verification to process your request and ensure the security and confidentiality of your data.
- Reporting Concerns: If you have any concerns or complaints regarding the processing or transfer of your personal data, please contact our designated Data Protection Officer (DPO) at privacy@aar.co.ke .We appreciate your feedback and will promptly address any issues raised.
We may periodically update or revise this Privacy Policy to ensure its alignment with legal requirements and our evolving business practices. We encourage you to review this Policy periodically to stay informed about how we handle your personal data.
If we make any material changes to this Policy, we will notify you through appropriate means, such as by posting a notice on our website or sending a direct communication. Your continued use of our services after the effective date of any revised Privacy Policy constitutes your acceptance of the revised Policy. We recommend that you regularly check this Privacy Policy to stay updated on any changes. If you disagree with any modifications to this Policy, you should discontinue using our services and contact us to exercise your rights or request the removal of your personal data, as outlined in this Policy.
- AAR Insurance Kenya Limited (“AAR”, “We”, “Us” or “Our”) is committed to protecting the privacy of the personal data of its suppliers and supplier representatives and to processing such data in a lawful, fair and transparent manner.
- This Privacy Policy explains how AAR collects, uses, stores, shares, transfers and otherwise processes personal data relating to suppliers and individuals acting on behalf of suppliers in connection with the procurement of goods and services, supplier onboarding, contract management and the ongoing administration of our business relationship.
- This Privacy Policy also explains the purposes for which we process your personal data, the lawful bases we rely on, the circumstances in which we may share your personal data, and the rights available to you under the Data Protection Act, 2019.
- For the purposes of the Data Protection Act, 2019, AAR Insurance Kenya Limited is the Data Controller responsible for determining the purposes and means of processing your personal data.
- AAR Insurance Kenya Limited is a company incorporated in Kenya and licensed to provide insurance products and services.
- For the purposes of the Data Protection Act, 2019, AAR Insurance Kenya Limited is the Data Controller responsible for determining the purposes and means of processing personal data covered by this Privacy Policy.
- AAR’s registered office is located at:
AAR Insurance Kenya Limited
Real Towers, Upper Hill Road
P.O. Box 41769 – 00100
Nairobi, Kenya
- The purpose of this Privacy Policy is to explain how AAR collects, uses, stores, shares, retains and otherwise processes the personal data of its suppliers and supplier representatives in connection with the procurement of goods and services and the management of supplier relationships.
- This Privacy Policy describes:
- the types of personal data that AAR collects and processes;
- the purposes for which your personal data is processed;
- the lawful bases relied upon for processing your personal data;
- the circumstances in which your personal data may be shared or transferred;
- how AAR protects and retains your personal data; and
- the rights available to you under the Data Protection Act, 2019 and how those rights may be exercised.
- This Privacy Policy applies to personal data relating to suppliers, prospective suppliers, contractors, consultants, service providers and individuals acting on behalf of supplier organisations, including directors, employees, authorised representatives and other contact persons.
- AAR is committed to processing your personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability as required under the Data Protection Act, 2019.
- This Privacy Policy should be read together with the following applicable laws, regulations, policies and procedures, as may be amended from time to time, including the Company’s:
- Data Protection Policy
- Information Security Policy
- Records Retention and Disposal Policy
- Data Subject Rights Procedure
- Personal Data Breach Response Procedure
- Supplier Code of Conduct (where applicable)
- Procurement Policy
- CCTV Policy
- Personal data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified directly or indirectly by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity. Examples of personal data include your name, national identification or passport number, contact details, job title, signature, bank account details, tax identification number, online identifiers and any other information that can identify you as a supplier or supplier representative.
- Sensitive personal data means personal data that reveals or relates to an individual’s race, health status, ethnic or social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details including the names of the person’s children, parents, spouse or spouses, sex or sexual orientation, or any other category of personal data specified under the Data Protection Act, 2019.
- AAR only processes sensitive personal data where it is necessary to do so and where there is a lawful basis under the Data Protection Act, 2019. Appropriate technical and organisational measures are implemented to safeguard sensitive personal data against unauthorised access, disclosure, alteration or loss.
| Type of Information | Examples of Personal Data | Purpose of Processing | Lawful Basis |
|---|---|---|---|
| Identification and Business Information | Name, national ID/passport number, passport photograph (where required), KRA PIN, company name, business registration details, CR12 information, job title and designation. | To identify suppliers and supplier representatives, conduct supplier onboarding and due diligence, maintain supplier records and comply with legal and regulatory obligations. | Performance of a contract; Legal obligation; Legitimate interests. |
| Contact Information | Business address, postal address, telephone number, email address and other business contact details. | To communicate with suppliers, administer contracts, issue notices and manage the supplier relationship. | Performance of a contract; Legitimate interests. |
| Contract and Procurement Information | Tender documents, quotations, contracts, purchase orders, supplier questionnaires, declarations, licences, certifications, insurance certificates and supplier performance records. | To evaluate suppliers, procure goods and services, administer contracts, monitor supplier performance and comply with procurement requirements. | Performance of a contract; Legal obligation; Legitimate interests. |
| Financial and Payment Information | Bank account details, payment instructions, invoices, supplier statements, tax information and withholding tax documentation. | To process payments, manage financial records, comply with tax obligations and maintain accounting records. | Performance of a contract; Legal obligation. |
| Communications and Correspondence | Emails, letters, telephone records, meeting notes and other business communications. | To manage supplier relationships, respond to enquiries, resolve disputes and maintain business records. | Performance of a contract; Legitimate interests. |
| Security and Access Information | Visitor records, access control records, CCTV footage, vehicle registration details and system access logs. | To safeguard people, premises, information and company assets, investigate security incidents and comply with legal obligations. | Legitimate interests; Legal obligation. |
| Online and Technical Information | IP addresses, cookies, device identifiers, website usage information and other online identifiers. | To maintain the security of AAR’s systems, administer supplier portals and websites, improve user experience and protect against fraud and cyber threats. | Legitimate interests. |
| Complaints and Requests | Complaints, enquiries, requests, correspondence and supporting documentation. | To investigate and resolve complaints, respond to enquiries and comply with legal or regulatory obligations. | Legitimate interests; Legal obligation. |
| Sensitive Personal Data | Personal data required for legal, regulatory or contractual purposes, including biometric information where lawfully collected for access control or security purposes. | To comply with legal obligations, protect AAR’s premises and systems, and fulfil contractual or regulatory requirements. | Legal obligation; Explicit consent (where required by law). |
- AAR collects personal data relating to suppliers and supplier representatives from a variety of sources throughout the supplier lifecycle, including supplier onboarding, procurement, contract management and the provision of goods and services.
| Source of Personal Data | Examples |
|---|---|
| Directly from you | Information provided when you register as a supplier, submit quotations or tenders, complete supplier onboarding forms, negotiate or enter into contracts, submit invoices, communicate with AAR or otherwise interact with us. |
| During the supplier relationship | Information generated through contract performance, purchase orders, delivery notes, invoices, supplier performance reviews, meetings, correspondence, complaints, audits and other day-to-day business interactions. |
| Third parties | Information obtained from referees, credit reference agencies, regulators, government agencies, professional advisers, business partners, publicly available registers and other organisations involved in supplier due diligence or contract administration. |
| Publicly available sources | Information obtained from the Business Registration Service, company websites, professional directories, regulatory databases, public registers and other publicly available sources where permitted by law. |
| Company systems and technologies | Information collected through visitor management systems, CCTV systems, access control systems, supplier portals, email systems and other business applications used to manage supplier relationships. |
| Automatically through technology | Information generated when you access AAR’s website, supplier portals or other online platforms, including IP addresses, cookies, device identifiers and system usage information, where applicable. |
AAR will only collect personal data that is necessary for legitimate business purposes, the procurement of goods and services, the management of supplier relationships, compliance with legal and regulatory obligations, and the protection of AAR’s legitimate interests.
- AAR may share your personal data where it is necessary to administer the procurement of goods and services, manage supplier relationships, fulfil contractual, legal and regulatory obligations, protect its legitimate interests, or where otherwise permitted or required by law.
- Depending on the circumstances, your personal data may be shared with:
- Authorised personnel within AAR, including employees in Procurement, Finance, Legal and Compliance, Risk Management, Internal Audit, Information Technology and other business units that require access to the information in the performance of their duties.
- Service providers, including providers of information technology services, cloud hosting services, document management systems, payment processing services and other vendors who process personal data on AAR’s behalf under appropriate contractual safeguards.
- Professional advisers, including external legal advisers, auditors, tax advisers, consultants and other professional service providers engaged by AAR.
- Government, regulatory and law enforcement authorities, including the Kenya Revenue Authority, the Office of the Data Protection Commissioner, the Insurance Regulatory Authority and any other regulatory, judicial or law enforcement authority where disclosure is required or authorised by law.
- Financial institutions and payment service providers, where necessary to facilitate payments, verify banking information or comply with applicable financial or anti-money laundering requirements.
- Other third parties, where disclosure is necessary to establish, exercise or defend legal claims, protect the rights or property of AAR, comply with a court order or other legal process, or where you have provided your consent or another lawful basis exists under the Data Protection Act, 2019.
- Where personal data is shared with third parties acting on AAR’s behalf, AAR requires such parties to implement appropriate technical and organisational measures to safeguard personal data and to process it only in accordance with AAR’s documented instructions and applicable data protection laws.
- AAR does not sell your personal data to third parties.
- As part of AAR’s business operations, your personal data may be transferred to, stored in or accessed from countries outside Kenya. Such transfers may occur where AAR uses cloud-based technologies, engages service providers located outside Kenya, shares personal data with professional advisers or business partners operating across multiple jurisdictions, or where it is otherwise necessary for the administration of the supplier relationship.
- Where AAR transfers personal data outside Kenya, we will ensure that the transfer is undertaken in accordance with the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021.
- Where required by law, or where no other lawful transfer mechanism is available, AAR will obtain your consent before transferring your personal data outside Kenya.
- AAR periodically reviews its international data transfer arrangements to ensure that they remain compliant with applicable legal and regulatory requirements.
- AAR is committed to protecting your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, access or any other unlawful form of processing.
- We implement appropriate technical and organisational measures to safeguard the confidentiality, integrity and availability of personal data. These measures include access controls, encryption where appropriate, secure information systems, network security, physical security measures, regular monitoring, staff training and other security controls designed to protect personal data throughout its lifecycle.
- Access to your personal data is restricted to authorised employees, service providers and other third parties who require such access for legitimate business purposes or to comply with legal or regulatory obligations. All persons authorised to process personal data are subject to appropriate confidentiality obligations.
- Where AAR engages third-party service providers to process personal data on its behalf, we require such providers to implement appropriate technical and organisational measures to protect personal data and to process it only in accordance with AAR’s documented instructions and applicable data protection laws.
- While AAR takes reasonable steps to protect personal data, no method of electronic transmission or storage is completely secure. Accordingly, although we strive to protect your personal data, we cannot guarantee its absolute security of data.
- Suppliers and supplier representatives also play an important role in protecting personal data. You are expected to take reasonable steps to safeguard any personal data and confidential information shared by AAR, including using secure communication channels, protecting login credentials where applicable, restricting access to authorised personnel, and promptly notifying AAR of any actual or suspected personal data breach or security incident that may affect AAR or the personal data processed on its behalf.
- Some of the personal data requested by AAR is mandatory because it is necessary to assess prospective suppliers, conduct supplier due diligence, enter into and administer contracts, process payments, communicate with suppliers and comply with applicable legal and regulatory obligations.
- If you choose not to provide personal data that is required for these purposes, AAR may be unable to evaluate your suitability as a supplier, complete supplier onboarding or due diligence processes, enter into or perform a contract with you, process invoices or make payments, communicate with you regarding procurement activities or contract administration, comply with applicable legal or regulatory obligations or continue/effectively manage the supplier relationship.
- Where the personal data requested is optional, you may choose not to provide it. Unless the information is specifically required for the procurement process, contract administration or compliance with applicable law, your decision not to provide optional information will not, by itself, prevent AAR from considering or engaging you as a supplier.
- AAR retains your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including complying with legal, regulatory, contractual, accounting, tax and record-keeping obligations.
- The retention period applicable to your personal data will depend on the nature of the information, the purpose for which it was collected, applicable legal and regulatory requirements, contractual obligations, and AAR’s legitimate business needs.
- Certain supplier records may be retained after the supplier relationship has ended where this is necessary to:
- comply with applicable legal or regulatory obligations;
- maintain financial, procurement and contractual records;
- establish, exercise or defend legal claims;
- respond to regulatory investigations, audits or enforcement proceedings; or fulfil AAR’s legitimate business, governance and record-keeping requirements.
- Where personal data is no longer required, AAR will securely delete, destroy or anonymise the information in accordance with its Records Retention and Disposal Policy and applicable legal requirements.
- Where personal data has been anonymised so that it can no longer be used to identify you, AAR may retain and use such information for statistical, analytical, business planning or reporting purposes.
- Subject to the provisions of the Data Protection Act, 2019, you have the following rights in relation to your personal data:
- The right to be informed about the collection and use of your personal data, including the purposes for which it is processed and the lawful basis for such processing.
- The right to access your personal data and obtain information about how it is processed.
- The right to object to the processing of your personal data where such processing is based on AAR’s legitimate interests, unless AAR demonstrates compelling legitimate grounds or is otherwise permitted by law to continue the processing.
- The right to correction of inaccurate, incomplete, outdated or misleading personal data.
- The right to erasure of your personal data in circumstances permitted by law.
- The right to data portability, where applicable, by receiving your personal data in a structured, commonly used and machine-readable format or requesting that it be transmitted to another data controller where technically feasible.
- The right not to be subject to a decision based solely on automated processing, including profiling, where such a decision produces legal effects concerning you or similarly significantly affects you, except where permitted by law.
- The right to request restriction of processing in circumstances permitted under the Data Protection Act, 2019.
- You may exercise your rights by submitting a written request to AAR’s Data Protection Officer using the contact details provided in this Privacy Notice.
- AAR will consider and respond to all requests in accordance with the Data Protection Act, 2019 and may request additional information to verify your identity before processing your request. In certain circumstances, AAR may decline or limit a request where permitted or required by law, in which case you will be informed of the reasons for that decision.
- If you have any questions, concerns or requests regarding this Privacy Policy or the manner in which AAR processes your personal data, or if you wish to exercise any of your rights under the Data Protection Act, 2019, please contact our Data Protection Officer on privacy@aar.co.ke
- If you are dissatisfied with AAR’s response to your request or believe that your personal data has been processed in a manner that is inconsistent with the Data Protection Act, 2019, you may lodge a complaint with the Office of the Data Protection Commissioner or seek any other remedy available under applicable law.
- AAR may update this Privacy Policy from time to time to reflect changes in applicable laws and regulations, our business operations, technologies, services or data processing practices.
- Where we make material changes to this Privacy Policy, we will take reasonable steps to notify affected individuals through appropriate channels, where required by law. The latest version of this Privacy Policy will always be made available through AAR’s official communication channels.
- We encourage you to review this Privacy Policy periodically to remain informed about how AAR collects, uses, shares, protects and otherwise processes your personal data.
- AAR Insurance Company Limited (“AAR”, “We”, “Our” or “the Company”) is committed to protecting the privacy, dignity and personal data of employees, customers, visitors, contractors and other persons who may be captured by its closed-circuit television (“CCTV”) systems.
- AAR operates CCTV systems for legitimate security, safety, operational and legal purposes. CCTV monitoring will be carried out in a lawful, fair, transparent, necessary and proportionate manner and in accordance with the Data Protection Act, 2019, its supporting regulations and other applicable laws.
- This Policy sets out the rules governing the installation, operation, management, access, use, disclosure, retention and disposal of CCTV footage collected within or around AAR premises.
- AAR will take appropriate technical and organisational measures to protect CCTV footage against unauthorised access, use, disclosure, alteration, loss, destruction or other unlawful processing.
- CCTV systems will not be used in a manner that unreasonably intrudes upon an individual’s privacy or for purposes that are incompatible with the purposes stated in this Policy.
- CCTV footage that identifies or can reasonably identify an individual constitutes personal data and will be processed in accordance with the Data Protection Act, 2019, the Data Protection (General) Regulations, 2021 and other applicable laws.
- AAR is the Data Controller in relation to personal data collected through its CCTV systems and is responsible for determining the purposes and means of processing such personal data.
- AAR shall ensure that CCTV systems are used only for legitimate, specified and lawful purposes and that the collection and processing of CCTV footage is adequate, relevant and limited to what is necessary for those purposes.
- The Company shall implement appropriate technical and organisational measures to safeguard CCTV footage against unauthorised or unlawful access, disclosure, alteration, loss, destruction or other misuse.
- CCTV footage shall only be accessed, used, disclosed, retained and disposed of in accordance with this Policy, the Company’s Data Protection Policy, Records Retention and Disposal Policy and other applicable internal policies.
- All employees, contractors and authorised third parties who have access to CCTV footage shall maintain the confidentiality of such information and shall process it only to the extent necessary to perform their authorised duties.
- Any misuse of CCTV systems or unauthorised access, disclosure or use of CCTV footage may result in disciplinary action and, where applicable, civil or criminal liability under the relevant laws.
- AAR operates CCTV systems for the purpose of promoting the safety and security of its employees, customers, visitors, contractors, service providers and other persons who access its premises.
- The Company has installed CCTV systems for one or more of the following purposes:
- protecting the safety and security of employees, customers, visitors and other persons on Company premises
- preventing, deterring, detecting and investigating criminal activity, fraud, theft, vandalism and other unlawful conduct
- protecting the Company’s buildings, facilities, equipment, information, assets and other property
- monitoring and controlling access to Company premises and restricted areas
- assisting in the investigation of workplace incidents, accidents, health and safety incidents, security breaches and other operational matters
- supporting internal investigations, disciplinary proceedings, grievance procedures and legal proceedings where CCTV footage is relevant and lawfully required
- assisting emergency response and business continuity activities
- complying with applicable legal, regulatory and contractual obligations.
- CCTV footage shall only be processed for the purposes set out in this Policy or for any other purpose permitted or required by law.
- Any proposed use of CCTV footage for a new purpose that is incompatible with the purposes set out in this Policy shall be subject to an appropriate legal assessment and, where required, a Data Protection Impact Assessment before implementation.
This Policy should be read in conjunction with the regulations and policies and procedures in force from time to time, including without limitation to AAR’s:
- Data Protection Policy
- Employee Privacy Notice
- Data Subject Rights Procedure
- Personal Data Breach Management Procedure
- Data Retention and Disposal Policy
- Information Security Policy
- Any other related policies or procedures issued by the Company from time to time.
- Board of Directors: The Board of Directors has overall responsibility for ensuring that the Company maintains an effective governance framework for the lawful and responsible use of CCTV systems, including ensuring compliance with applicable legal and regulatory requirements.
- Management: Management is responsible for ensuring that CCTV systems are operated in accordance with this Policy, that adequate resources are available for their effective management, and that appropriate corrective action is taken where non-compliance is identified.
- Head of Information Technology: The Head of Information Technology is responsible for the day-to-day management and operation of the CCTV system, including: • overseeing the installation, maintenance and operation of CCTV equipment;
- ensuring the security, integrity and availability of CCTV systems and recordings;
- implementing appropriate technical controls to protect CCTV footage from unauthorised access, alteration, disclosure or loss;
- maintaining appropriate user access controls and audit logs where applicable;
- ensuring CCTV recordings are retained and securely disposed of in accordance with this Policy and the Company’s Data Retention and Disposal Policy; and
- supporting investigations requiring CCTV footage in collaboration with the Legal Department, the Data Protection Officer and other authorised personnel.
- Data Protection Officer: The Data Protection Officer is responsible for providing oversight on the privacy and data protection aspects of the CCTV system, including: • advising on compliance with applicable data protection laws and this Policy;
- b) conducting or reviewing Data Protection Impact Assessments for new CCTV installations or significant changes to existing systems where required;
- handling data subject requests, privacy enquiries and complaints relating to CCTV footage;
- monitoring compliance with this Policy and recommending corrective actions where necessary;
- providing data protection awareness and guidance relating to the use of CCTV systems; and
- supporting investigations involving the processing or disclosure of CCTV footage from a data protection perspective.
- Employees and Authorised Users: Employees and other authorised users who have access to CCTV systems or recordings shall:
- comply with this Policy and all related Company policies;
- access CCTV footage only where authorised and only for legitimate business purposes;
- maintain the confidentiality and security of CCTV footage;
- immediately report any suspected misuse, unauthorised access or security incident involving CCTV footage; and
- not copy, disclose, record, download, share or otherwise use CCTV footage except as authorised under this Policy.
MANAGEMENT AND CONTROL OF THE CCTV SYSTEM
- The CCTV system is owned and managed by the Company.
- The Head of Information Technology is responsible for the day-to-day administration, maintenance and operation of the CCTV system in accordance with this Policy.
- AAR is the Data Controller in relation to personal data collected through its CCTV systems and is responsible for determining the purposes and means of processing CCTV footage.
- Access to CCTV systems, live camera feeds and recorded footage shall be restricted to authorised personnel whose duties require such access. User access rights shall be granted on a need-to-know basis and reviewed periodically in accordance with the Company’s policies.
- Access to, retrieval, export and disclosure of CCTV footage shall be appropriately authorised and, where practicable, recorded in an audit trail.
- The Company shall implement appropriate technical and organisational measures to safeguard CCTV systems and recordings against unauthorised access, alteration, disclosure, destruction or loss.
DESCRIPTION OF SYSTEM
- CCTV cameras are installed at strategic locations within and around Company premises based on operational, safety and security requirements.
- The CCTV system operates continuously, twenty-four (24) hours a day and seven (7) days a week, unless temporarily unavailable due to maintenance, technical failure or other operational requirements.
- CCTV systems record video images. Audio recording shall not be undertaken unless specifically authorised by the Company and permitted by applicable law.
- Clear and visible CCTV signage shall be displayed at the entrances to, and within, monitored areas to notify individuals that CCTV surveillance is in operation.
- Any new CCTV installation or significant modification to an existing CCTV system shall be subject to an appropriate privacy and security assessment and, where required, a Data Protection Impact Assessment prior to implementation.
SITING OF CAMERAS
- CCTV cameras shall be positioned only where necessary to achieve the purposes set out in this Policy.
- Camera placement shall be designed to minimise unnecessary intrusion into the privacy of employees, customers, visitors and neighbouring properties.
- Cameras are sighted in prominent positions where they are clearly visible.
- Cameras are not sited to focus on areas not intended to be monitored.
- Cameras shall not be directed towards areas where individuals have a reasonable expectation of privacy, including washrooms, changing rooms, nursing rooms, prayer rooms or similar private spaces
- The Company shall take reasonable steps to ensure that CCTV cameras do not unnecessarily capture images beyond Company premises unless this is unavoidable for legitimate security purposes.
- CCTV cameras shall be installed in visible locations wherever reasonably practicable and shall not be used for covert surveillance except where authorised by law and approved through the Company’s internal governance processes.
In operating its CCTV system, AAR shall adhere to the following principles:
- Lawfulness, Fairness and Transparency
CCTV footage shall be collected and processed lawfully, fairly and transparently. Individuals shall be informed of CCTV monitoring through appropriate signage and this Policy. - Purpose Limitation
CCTV footage shall be collected solely for the legitimate purposes set out in this Policy and shall not be processed in a manner that is incompatible with those purposes unless otherwise permitted or required by law. - Data Minimisation
The Company shall ensure that CCTV cameras are positioned and operated to capture only the information that is necessary to achieve the stated purposes. Monitoring shall be proportionate and shall avoid unnecessary intrusion into individuals’ privacy. - Storage Limitation
CCTV footage shall be retained only for as long as is necessary to fulfil the purposes for which it was collected or to comply with legal, regulatory or evidentiary requirements. - Integrity and Confidentiality
The Company shall implement appropriate technical and organisational measures to protect CCTV footage against unauthorised or unlawful access, disclosure, alteration, destruction or accidental loss. - Accountability
The Company shall maintain appropriate governance measures to demonstrate compliance with this Policy and applicable data protection laws, including restricting access to CCTV footage, maintaining appropriate records where applicable and periodically reviewing the effectiveness of its CCTV controls. - International Transfers
Where CCTV footage is transferred outside Kenya, AAR shall ensure that such transfers are carried out in accordance with the Data Protection Act, 2019 and that appropriate safeguards are implemented to protect the personal data.
- Individuals whose personal data is processed through the Company’s CCTV system are entitled to exercise their rights under the Data Protection Act, 2019, subject to the limitations and exemptions provided under the law.
- Subject to applicable law, data subjects have the right to:
- be informed that their personal data is being collected and processed through CCTV surveillance
- request access to CCTV footage containing their personal data
- request the correction of inaccurate personal data where applicable
- request the erasure of CCTV footage where the requirements of the Data Protection Act, 2019 are met
object to the processing of their personal data in circumstances permitted by law - request the restriction of processing in appropriate circumstances
request data portability, where applicable - not to be subject to a decision based solely on automated processing, where applicable.
- Requests relating to CCTV footage shall be submitted to the Data Protection Officer and will be handled in accordance with the Company’s Data Subject Rights Procedure and applicable law.
- Before responding to a request, the Company may require sufficient information to verify the identity of the requester and to enable it to locate the relevant CCTV footage.
- Where CCTV footage contains the personal data of other identifiable individuals, the Company may:
- redact, blur, mask or otherwise anonymise the images of those individuals before disclosure;
- refuse to disclose the footage where disclosure would unreasonably infringe the privacy or rights of another individual; or
- rely on any exemption or limitation permitted under the Data Protection Act, 2019.
- The Company may refuse, restrict or defer a request where permitted by law, including where disclosure would prejudice the prevention or detection of crime, ongoing investigations, legal proceedings, regulatory functions or the rights and freedoms of another person.
- Where a request is refused, wholly or in part, the Company shall inform the requester of the reasons for the decision, unless prohibited by law, and advise them of any available right of review or complaint.
- CCTV footage shall be treated as confidential and shall only be accessed, used or disclosed where there is a lawful and legitimate business purpose or where disclosure is required or permitted by law.
- The Company may disclose CCTV footage to authorised internal personnel where access is necessary for the performance of their official duties, including the Head of Information Technology, the Data Protection Officer, the Legal Department, Internal Audit, Human Resources or other authorised investigators.
- The Company may disclose CCTV footage to external parties where such disclosure is lawful and necessary, including:
- law enforcement agencies for the prevention, detection or investigation of crime;
- courts, tribunals or regulatory authorities where disclosure is required by law or pursuant to a lawful order;
- legal advisers for the establishment, exercise or defence of legal claims;
- insurers, loss adjusters or investigators in connection with the investigation or resolution of incidents, claims or disputes;
- external auditors or professional advisers where access is necessary for the performance of their professional duties and appropriate confidentiality obligations apply; or
- any other person or organisation where disclosure is authorised by law or the data subject, or is otherwise permitted under the Data Protection Act, 2019.
- Any request for CCTV footage from an external party shall, wherever practicable, be made in writing and shall specify the purpose for which the footage is required.
- The disclosure of CCTV footage shall be approved by the Head of Information Technology in consultation with the Data Protection Officer and the Legal Department, unless immediate disclosure is required by law or to respond to an emergency involving a risk to life, health or safety.
- Where CCTV footage is disclosed, the Company shall maintain an appropriate record of the disclosure, including the recipient, the purpose of the disclosure, the date of disclosure and the footage disclosed, where practicable.
- CCTV footage shall not be copied, downloaded, shared, published or otherwise distributed except in accordance with this Policy or as required by law.
- CCTV footage shall be retained for a period of sixty (60) days from the date of recording, after which it shall be automatically overwritten or securely deleted, unless a longer retention period is required in accordance with this Policy or applicable law.
- CCTV footage may be retained beyond the standard retention period where it is required:
- for the investigation of an incident, accident, security breach or suspected unlawful activity;
- for disciplinary, grievance or other internal proceedings;
- for the establishment, exercise or defence of legal claims;
- to comply with a legal, regulatory or law enforcement requirement; or
- for any other lawful purpose approved by the Company.
- Any request to preserve CCTV footage beyond the standard retention period shall be made to the Head of Information Technology in consultation with the Data Protection Officer and, where appropriate, the Legal Department.
- CCTV footage retained beyond the standard retention period shall only be kept for as long as is necessary to fulfil the purpose for which it has been preserved and shall thereafter be securely deleted or destroyed in accordance with the Company’s Data Retention and Disposal Policy.
- Access to CCTV footage retained for investigations or legal proceedings shall be restricted to authorised personnel with a legitimate need to access the footage.
- The Company shall take appropriate measures to ensure that CCTV footage is securely disposed of in a manner that prevents unauthorised recovery, access or reconstruction.
- Any individual who has questions about this Policy, wishes to exercise their rights in relation to CCTV footage, or has concerns regarding the processing of their personal data through the Company’s CCTV system may contact the Data Protection Officer using the contact details below to privacy@aar.co.ke
- The Data Protection Officer shall receive, assess and coordinate the handling of all enquiries, complaints and requests relating to the processing of personal data through the Company’s CCTV system.
- Where necessary, the Company may request additional information to verify the identity of the requester before responding to an enquiry, complaint or request.
- The Company shall investigate all complaints relating to the processing of CCTV footage and respond within the timelines prescribed under the Data Protection Act, 2019 and any other applicable laws.
- Where an individual is dissatisfied with the Company’s response, they may lodge a complaint with the Office of the Data Protection Commissioner or pursue any other remedy available under applicable law.
- The Data Protection Officer shall maintain appropriate records of enquiries, complaints and their resolution in accordance with the Company’s records management requirements.
- The Company shall periodically monitor compliance with this Policy to ensure that the CCTV system is operated in a lawful, secure and effective manner and in accordance with applicable legal and regulatory requirements.
- The Head of Information Technology, in collaboration with the Data Protection Officer, shall conduct periodic reviews of the CCTV system and its operation to assess compliance with this Policy, the Company’s internal policies and applicable data protection laws.
- Any actual or suspected misuse of the CCTV system, unauthorised access to or disclosure of CCTV footage, or breach of this Policy shall be reported immediately in accordance with the Company’s incident reporting and personal data breach management procedures.
- Any employee, contractor or other authorised person who breaches this Policy may be subject to disciplinary action, up to and including termination of employment or engagement, and where applicable, civil or criminal proceedings in accordance with the laws.
- This Policy shall be reviewed periodically and updated as necessary to reflect changes in applicable laws, regulatory requirements, technology, operational practices or identified risks.
- AAR Insurance Kenya Limited (“AAR”, “We”, “Us” or “Our”) is committed to protecting the privacy of the personal data of its directors and to processing such data in a lawful, fair and transparent manner.
- This Privacy Policy explains how AAR collects, uses, stores, shares, transfers and otherwise processes the personal data of members of its Board of Directors in accordance with the Data Protection Act, 2019 and other applicable laws of Kenya.
- This Privacy Policy also explains the purposes for which we process your personal data, the lawful bases we rely on, the circumstances in which we may share your personal data, and the rights available to you under the Data Protection Act, 2019.
- For the purposes of the Data Protection Act, 2019, AAR Insurance Kenya Limited is the Data Controller responsible for determining the purposes and means of processing your personal data.
- This Privacy Policy applies to all members of the Board of Directors of AAR Insurance Kenya Limited, including executive, non-executive, independent and alternate directors, where applicable.
- This Privacy Policy applies to the personal data collected and processed by AAR before, during and, where necessary, after your appointment as a director.
- The Privacy Policy applies to personal data processed in both electronic and physical formats, regardless of the medium in which it is stored.
- This Privacy Policy should be read together with AAR’s other applicable policies, procedures and notices relating to privacy, information security, records management and corporate governance.
- The purpose of this Privacy Policy is to explain how AAR collects, uses, stores, shares, retains and otherwise processes the personal data of its directors in connection with their appointment and service on the Board of Directors.
- This Privacy Policy describes the following:
- the types of personal data that AAR collects and processes;
- the purposes for which your personal data is processed;
- the lawful bases relied upon for processing your personal data;
- the circumstances in which your personal data may be shared or transferred;
- how AAR protects and retains your personal data; and
- the rights available to you under the Data Protection Act, 2019 and how those rights may be exercised.
- AAR is committed to processing your personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability as required under the Data Protection Act, 2019.
- This Privacy Policy should be read together with the following policies and procedures, as may be amended from time to time:
- Data Protection Policy
- Information Security Policy
- Records Retention and Disposal Policy
- Personal Data Breach Response Procedure
- Board Charter
- Code of Conduct and Ethics
- ICT Acceptable Use Policy
- CCTV Policy
- Personal data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified directly or indirectly by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.
- Examples of personal data include your name, national identification or passport number, contact details, date of birth, photographs, signatures, online identifiers, board appointment records and any other information that can identify you as a director.
- Sensitive personal data means personal data that reveals or relates to an individual’s race, health status, ethnic or social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details including the names of the person’s children, parents, spouse or spouses, sex or sexual orientation, or any other category of personal data specified under the Data Protection Act, 2019.
- AAR only processes sensitive personal data where it is necessary to do so and where there is a lawful basis under the Data Protection Act, 2019. Appropriate technical and organisational measures are implemented to safeguard sensitive personal data against unauthorised access, disclosure, alteration or loss.
- AAR collects and processes the following categories of personal data relating to directors for the purposes set out below:
| Type of Information | Examples of Personal Data | Purpose of Processing | Lawful Basis |
|---|---|---|---|
| Identification and Personal Details | Name, photograph, national ID/passport number, passport photograph, nationality, date of birth and signature. | To verify identity, maintain statutory records, facilitate director appointments and comply with legal and regulatory obligations. | Legal obligation; Legitimate interests. |
| Contact Information | Residential address, postal address, telephone number and email address. | To communicate with directors, circulate Board papers and notices, and maintain corporate records. | Legal obligation; Legitimate interests. |
| Board Appointment and Governance Records | Curriculum vitae, professional qualifications, appointment documentation, declarations of independence, fit and proper assessments, declarations of interests, committee memberships, board evaluation records and continuing professional development records. | To assess eligibility for appointment, support Board governance, comply with corporate governance requirements and maintain accurate Board records. | Legal obligation; Legitimate interests. |
| Company Secretarial and Statutory Information | KRA PIN, directorship information, statutory declarations, regulatory filings, Companies Registry records and other information required for statutory filings. | To comply with the Companies Act, insurance regulatory requirements and other legal obligations. | Legal obligation. |
| Remuneration and Payment Information | Bank account details, remuneration records, expense reimbursement details and tax information. | To process directors’ remuneration, reimburse expenses and comply with tax and financial reporting obligations. | Legal obligation; Performance of a contract; Legitimate interests. |
| Board Meeting Information | Board packs, attendance records, minutes, resolutions, declarations made during meetings, meeting recordings (where applicable) and action logs. | To facilitate the administration of Board and Committee meetings, maintain corporate records and support decision-making. | Legal obligation; Legitimate interests. |
| Security and Access Information | Visitor logs, building access records, CCTV footage, access card records and system access logs. | To safeguard people, premises, information and company assets and investigate security incidents where necessary. | Legitimate interests; Legal obligation. |
| Communications and Technology Information | Business correspondence, emails, telephone records, video conferencing records, IP addresses, device identifiers and online activity on AAR systems. | To facilitate communications, maintain IT security, manage business operations and ensure compliance with internal policies. | Legitimate interests; Legal obligation. |
| Photographs and Audio-Visual Information | Photographs and video recordings taken during Board meetings, corporate events, training sessions or official engagements. | For identification, corporate communications, governance records and other legitimate business purposes. | Legitimate interests; Consent (where required). |
- It is important to note that failing to provide certain personal data may have consequences in relation to processing payments and compliance with legal obligations. These consequences may include limitations in non-compliance with legal requirements, difficulties in communication and documentation
- AAR collects personal data relating to directors from a variety of sources in connection with their appointment, service on the Board and compliance with legal and regulatory obligations.
| Source of Personal Data | Examples |
|---|---|
| Directly from you | Information provided during the nomination and appointment process, declarations, questionnaires, statutory forms, correspondence, expense claims, conflict of interest declarations, fit and proper forms, and information you provide during your tenure as a director. |
| Board appointment and governance processes | Information generated during the nomination, appointment, induction, Board and Committee meetings, Board evaluations, director training, governance reviews and other Board activities. |
| Company records and systems | Information created or maintained through Board administration, company secretarial records, access control systems, corporate email systems, meeting platforms, visitor management systems and other business systems. |
| Third parties | Information obtained from referees, professional advisers, recruitment or executive search firms, regulators, government agencies, credit reference agencies (where appropriate), and other organisations involved in the appointment or governance of directors. |
| Publicly available sources | Information obtained from public registers, regulatory databases, company filings, professional bodies, publicly available profiles and other publicly accessible sources where permitted by law. |
| Automatically through technology | Information generated through your use of AAR’s information systems, including system access logs, IP addresses, device information, electronic communications and CCTV footage where applicable. |
- AAR may share your personal data where it is necessary to fulfil its legal, regulatory and corporate governance obligations, administer the affairs of the Company, protect its legitimate interests, or where otherwise permitted or required by law.
- Depending on the circumstances, your personal data may be shared with:
- Authorised personnel within AAR, including the Board of Directors, Company Secretary, Legal and Compliance Department, Finance Department, Internal Audit, Risk Management and other employees who require access to the information in the performance of their duties.
- Professional advisers, including external legal advisers, auditors, tax advisers, governance consultants, insurers and other professional service providers engaged by AAR.
- Service providers, including providers of information technology services, cloud hosting, document management systems, board portal solutions, payment processing services and other vendors who process personal data on AAR’s behalf under appropriate contractual safeguards.
- Government, regulatory and law enforcement authorities, including the Registrar of Companies, the Insurance Regulatory Authority, the Kenya Revenue Authority, the Office of the Data Protection Commissioner and any other regulatory, judicial or law enforcement authority where disclosure is required or authorised by law.
- Financial institutions and payment service providers, where necessary to facilitate the payment of directors’ remuneration, reimbursement of expenses or other authorised payments.
- Other third parties, where disclosure is necessary to establish, exercise or defend legal claims, protect the rights or property of AAR, comply with a court order or other legal process, or where you have provided your consent or another lawful basis exists under the Data Protection Act, 2019.
- Where personal data is shared with third parties acting on AAR’s behalf, AAR requires such parties to implement appropriate technical and organisational measures to safeguard personal data and to process it only in accordance with AAR’s instructions and applicable data protection laws.
- AAR does not sell your personal data to third parties.
- AAR implements reasonable and proportionate monitoring measures to safeguard its people, premises, information, systems and other assets.
- Where directors access AAR’s premises, information systems or other facilities, certain monitoring activities may result in the processing of their personal data. Such monitoring is undertaken solely for legitimate business purposes, including maintaining the security of AAR’s premises and information systems, protecting confidential information, preventing and investigating fraud or other unlawful activities, ensuring compliance with applicable laws and internal policies, and supporting business continuity and incident response
- Monitoring activities may include:
- CCTV surveillance at AAR’s premises;
- visitor management records and building access control systems;
- electronic access logs for AAR’s networks, systems, applications and board portals;
- monitoring of the use of AAR-issued devices, corporate email accounts and other authorised communication platforms, where applicable; and
- security logs generated by AAR’s information technology infrastructure.
- Monitoring activities are conducted in accordance with the Data Protection Act, 2019, AAR’s internal policies and applicable corporate governance requirements. Appropriate technical and organisational measures are implemented to protect any personal data collected through such monitoring.
- As part of AAR’s business operations, your personal data may be transferred to, stored in or accessed from countries outside Kenya. Such transfers may occur where AAR uses cloud-based technologies, engages service providers located outside Kenya, or shares personal data with members of the AAR Group, professional advisers or other authorised third parties that operate across multiple jurisdictions.
- Where AAR transfers personal data outside Kenya, we will ensure that the transfer is undertaken in accordance with the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021.
- Where required by law, or where no other lawful transfer mechanism is available, AAR will obtain your consent before transferring your personal data outside Kenya.
- AAR periodically reviews its international data transfer arrangements to ensure that they remain compliant with applicable legal and regulatory requirements.
- AAR is committed to protecting your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, access or any other unlawful form of processing.
- We implement appropriate technical and organisational measures to safeguard the confidentiality, integrity and availability of personal data. These measures include access controls, encryption where appropriate, secure information systems, network security, physical security measures, regular monitoring, staff training and other security controls designed to protect personal data throughout its lifecycle.
- Access to your personal data is restricted to authorised personnel, directors, service providers and other third parties who require such access for legitimate business purposes or to comply with legal or regulatory obligations. All persons authorised to process personal data are subject to appropriate confidentiality obligations.
- Where AAR engages third-party service providers to process personal data on its behalf, we require such providers to implement appropriate technical and organisational measures to protect personal data and to process it only in accordance with AAR’s documented instructions and applicable data protection laws.
- While AAR takes reasonable steps to protect personal data, no method of electronic transmission or storage is completely secure. Accordingly, although we strive to protect your personal data, we cannot guarantee its absolute security.
- Directors are also expected to take reasonable steps to safeguard personal data and confidential information obtained in the course of their duties. This includes protecting login credentials, using authorised communication channels and devices where applicable, maintaining the confidentiality of Board papers and other sensitive information, and promptly reporting any actual or suspected data breach, loss of information or security incident to AAR.
- AAR retains your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including complying with legal, regulatory, corporate governance and record-keeping obligations.
- The retention period applicable to your personal data will depend on the nature of the information, the purpose for which it was collected, applicable legal and regulatory requirements, and AAR’s legitimate business needs.
- Certain records relating to directors may be retained after you cease to hold office where this is necessary to:
- comply with applicable legal or regulatory obligations;
- maintain statutory registers and corporate records;
- establish, exercise or defend legal claims;
- respond to regulatory investigations, audits or enforcement proceedings; or
- fulfil AAR’s legitimate corporate governance and business record-keeping requirements.
- Where personal data is no longer required, AAR will securely delete, destroy or anonymise the information in accordance with its Records Retention and Disposal Policy and applicable legal requirements.
- Where personal data has been anonymised so that it can no longer be used to identify you, AAR may retain and use such information for statistical, analytical, governance or historical record-keeping purposes.
- Subject to the provisions of the Data Protection Act, 2019, you have the following rights in relation to your personal data:
- The right to be informed about the collection and use of your personal data, including the purposes for which it is processed and the lawful basis for such processing.
- The right to access your personal data and obtain information about how it is processed.
- The right to object to the processing of your personal data where such processing is based on AAR’s legitimate interests, unless AAR demonstrates compelling legitimate grounds or is otherwise permitted by law to continue the processing.
- The right to correction of inaccurate, incomplete, outdated or misleading personal data.
- The right to erasure of your personal data in circumstances permitted by law.
- The right to data portability, where applicable, by receiving your personal data in a structured, commonly used and machine-readable format or requesting that it be transmitted to another data controller where technically feasible.
- The right not to be subject to a decision based solely on automated processing, including profiling, where such a decision produces legal effects concerning you or similarly significantly affects you, except where permitted by law.
- The right to request restriction of processing in circumstances permitted under the Data Protection Act, 2019.
- You may exercise your rights by submitting a written request to AAR’s Data Protection Officer using the contact details provided in this Privacy Notice.
- AAR will consider and respond to all requests in accordance with the Data Protection Act, 2019 and may request additional information to verify your identity before processing your request. In certain circumstances, AAR may decline or limit a request where permitted or required by law, in which case you will be informed of the reasons for that decision.
- If you wish to exercise any of your rights under the Data Protection Act, 2019, you may submit a written request to AAR’s Data Protection Officer using the contact details provided in this Privacy Policy.
- If you have any questions about this Privacy Policy, wish to exercise your rights under the Data Protection Act, 2019, or have any concerns regarding the manner in which AAR processes your personal data, please contact AAR’s Data Protection Officer using the details below:
Data Protection OfficerAAR Insurance Kenya Limited
Physical Address: Real Towers, Upper Hill Road, Nairobi, Kenya
Postal Address: P.O. Box 41769 – 00100, Nairobi, Kenya
Telephone: +254 709 820 000
Email: privacy@aar.co.ke
- AAR is committed to addressing privacy-related enquiries and complaints promptly, fairly and transparently. We will acknowledge and respond to your enquiry or complaint within the timelines prescribed under the Data Protection Act, 2019 and any other applicable laws.
- If you are dissatisfied with AAR’s response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner or to seek any other remedy available under applicable law.
- AAR may review and update this Privacy Policy from time to time to reflect changes in applicable laws, regulations, business operations, technology, corporate governance requirements or the manner in which we process personal data.
- Where material changes are made to this Privacy Policy, AAR will take reasonable steps to notify directors through appropriate communication channels, including Board communications, email or other official means.
- The latest version of this Privacy Policy will be made available to directors and will supersede all previous versions.
- The Effective Date and Version Number set out in this Privacy Policy indicate when it was last reviewed and updated.
In order to access any of the Services you will be required to accept these terms and conditions. You will be deemed to have accepted these terms by: Completing our online registration process and confirming that you have read and accepted these terms; or Viewing, accessing or using content on the Site which does not require registration.
We suggest that you print out and keep a copy of these terms for your records. In addition to these terms, there may be additional terms and conditions which apply to individual Services which you will be required to accept when registering for that Service.
Registration and use of the Services In order to access or continue to use certain Services, you may be required to provide information about yourself (such as identification or contact details). You agree to provide true, accurate, current and complete information when registering for the Services.
You agree to use the Services only for purposes that are permitted by
(i) these terms and (ii) any applicable law or regulation. You specifically agree not to access (or attempt to access) any of the Services through any automated means (including use of scripts or web crawlers) and shall ensure that you comply with the instructions set out in any part of the Site. You agree that you will not engage in any activity that interferes with or disrupts the Services (or the servers and networks which are connected to the Services). You agree that you will not reproduce, duplicate, copy, sell, trade or resell the Services for any purpose. You agree that you are solely responsible for (and that AAR has no responsibility to you or to any third party for) any breach of your obligations under these terms and for the consequences (including any loss or damage which AAR may suffer) of any such breach.
Password and Account Security For certain Services e.g. registration for use of the AAR Online services you will be required to choose a user name and a password. For any such Services: The user name you choose must not be obscene, threatening, menacing, racist, offensive, derogatory, defamatory or in violation of any intellectual property or proprietary rights of any third party; and If we consider in our sole and absolute discretion that the user name selected by you is inappropriate, we reserve the right to reject and prevent your use of such user name at any time with or without notice to you.
You will be prompted to change your password from time to time in a span of one month in accordance to AIK IT policy. Your password is confidential and being aware of this you agree and understand that you are responsible for maintaining the confidentiality of password(s) associated with your account(s). Accordingly, you agree that you will be solely responsible to AAR for all activities that occur under your account.
You, and any persons you allow to use the Services through your access to the Services, are not allowed to: Copy, disclose, modify, reformat, display, distribute, licence, transmit, sell, perform, publish, transfer, link to, reverse engineer or decompile (except to the extent expressly permitted by applicable law) or otherwise make available the Services or any part thereof except as set out in these terms; Include or create links (including deep-links) to or from the Services; Replicate the Site or create a separate border around any part of the Services (also known as “framing”); Use the Services for storing, reproducing, transmitting, communicating or receiving any Offending Material.
For the purpose of these terms Offending Material means any content transmitted using the Service that is: In breach of any law, regulation or code of practice invoked by AAR, industry regulator or any other competent authority or any policy adopted by AAR with regard to the acceptable use of the Services, or Abusive, indecent, defamatory, obscene, pornographic, offensive or menacing (or that has the effect (as may be contemplated by a reasonable person) of causing the recipient to feel so harassed, abused or offended; or Designed to cause annoyance, inconvenience or needless anxiety to any person; or In breach of confidence, intellectual property rights, privacy or any right of a third party.
Hack into, make excessive traffic demands, probe or port scan other computers, deliver viruses, mail bombs, chain letters or pyramid schemes or otherwise engage in any other behaviour intended to inhibit other users from using and enjoying the Services or any other website; Collect and process others’ personal data except in accordance with applicable data protection law; Advertise or offer to sell goods or services on the pretext that the same are endorsed, offered for sale or originate from AAR; Infringe any other person’s intellectual property rights; Use the Services to harvest or collect information about users of the Services or to post or otherwise distribute unauthorized or unsolicited advertising, junk or bulk email (also known as “spam”); Use the Services or the Content in any way that we in our sole and absolute discretion consider objectionable, inappropriate, likely to injure our brand and reputation or otherwise unacceptable; Use the Services to send emails and other content coached, phrased or written in such a manner as to give an impression that the email is correspondence from AAR.
You are responsible for any misuse of the Services even if it is by another person using your access to the Services.
4.3 We reserve the right to block, remove, edit or refuse to post any material that you attempt to transmit through the Services that we deem to be in contravention of these terms and to take such other action as we in our sole and absolute discretion consider necessary to prevent or remedy any breach of these terms. If you become aware of any content or material circulated using the Services and that is in breach of these terms or content or material on the Site that is similarly in breach of these terms then we encourage you to promptly inform us by contacting our customer care service.
We are not responsible or liable for any failure to remove, block or delay in removing, any such infringing content or material or third party material from the Service or for any good faith but wrongful removal of third party material.
Equipment You will need to provide all equipment necessary to access the Service. If your equipment does not support the relevant technology allowing you to access the internet then you will not be able to use this Service.
Cost and Charges AAR will currently not charge you to sign up/register for the Services, save as may otherwise be communicated by AAR from time to time. However, AAR reserves the right to charge for access or all of Services in the future, subject to a clear notice when accessing Services that are charged.
Although AAR will take all reasonable steps to ensure that the Services are available to you at all times, it cannot guarantee a continuous fault free service. The quality and availability of Services may be affected by factors including (but not limited to) acts of God, planned maintenance or rectification work, or your equipment may interfere adversely with the quality and provision of the Services. We therefore do not warrant and shall not be liable for any delay or failure to send, receive or process messages, pictures, video clips and other communications or the quality of the materials received.
You accept and recognise that the Internet is not a secure environment and as such messages, pictures, video clips and other communications may be intercepted or accessed by those other than the intended recipient, manipulated, distorted, adapted, modified, stored or forwarded by others to you which may give unauthorised persons access to information stored on your PC or mobile device or may cause damage to your PC or mobile device. AAR accepts no liability for any loss or damage resulting from the receipt of any messages, pictures, video clips or other communications from any third parties. You will be required to take reasonable precautions while accessing websites, sending or receiving emails using the Services.
AAR may establish limits concerning the use of the Services for example the maximum number of characters that may be posted or received on the online services, the maximum capacity allocated to you for storage and/or transmission of Content.
You irrevocably agree to indemnify us (AAR Holdings Limited) and any of our third party providers (“together indemnified persons”)fully against and to hold the indemnified persons harmless on demand from all losses, costs, proceedings, damages, expenses (including reasonable legal costs and expenses) or liabilities howsoever incurred by the indemnified persons as a result of any claim by a third party resulting from your use of the Service (or use of the Service by anyone who accesses the Service via your password) in breach or non-observance of these terms.
We shall notify you of any claim that we or any of the other indemnified persons receives and you hereby agree to provide us and/or any of the indemnified persons with full authority to defend or settle such claims and shall provide us and/or any of the indemnified persons with all reasonable assistance necessary to defend such claims, at your sole expense.
AAR reserves the right to vary the terms and conditions of this Agreement at any time by placing the revised terms and conditions on its website www.aar-insurance.com and you will be deemed to have been bound by such variation by continuing to use the Services. You should periodically check the websites www.aar-insurance.com to make yourself aware of any variations.
The construction, validity and performance of these terms and conditions shall be governed in all respects by the Laws of Kenya.
If any provision of these terms and conditions are declared by any judicial or other competent authority to be void, voidable, illegal or otherwise unenforceable, such a term shall be amended or at the discretion of AAR it may be severed from these terms and conditions and the remaining provisions of these terms and conditions shall remain in full force and effect.
Except where this terms and conditions provides otherwise, the rights and remedies contained in it are cumulative and not exclusive to rights or remedies provided by law. The failure by AAR to enforce at any time or for any period any one or more of the terms and conditions shall not be a waiver of them or of the right at any time subsequently to enforce all terms and conditions.
No delay or failure by AAR shall constitute a breach or give rise to any claim for damages or loss of anticipated profits if such delay or failure is caused by force majeure. Force majeure shall mean an occurrence which is beyond and without fault or negligence of AAR affected and which AAR is unable to prevent or provide against by the exercise of reasonable diligence including, but not limited to, acts of God or of the public enemy, appropriation of confiscation of facilities, terrorists activity or other catastrophe, strike or any other concerted acts of employees or other similar occurrences.
You shall not assign these terms and conditions to a third party. Any unauthorized assignment or attempt to assign will automatically terminate this Service. AAR may assign these terms and conditions in whole or part to any third party at its discretion.
14.7 You acknowledge and agree that in entering into this Agreement you do not rely on, shall have no remedy in respect of, any statement, representation, warranty or understanding (whether negligently or innocently made) of any person (whether party to these terms and conditions or not) other than as expressly set out in these terms and conditions as a warranty. Nothing in this clause shall, however, operate to limit or exclude liability for fraud.
We may suspend, vary or terminate your use of the Service or the Site without compensation for any period during which: AAR is required or requested to comply with an order or instruction of or a recommendation from the government, court, regulator or other competent authority; AAR reasonably suspects or believes that you are in breach of these terms and conditions; Such a suspension or variation is necessary as a consequences of technical problems or for reasons of safety; In order to update or upgrade the contents or functionality of the Service from time to time; Upon any detection of abuse/misuse, breach of content, fraud or attempted fraud relating to your use of the Service; Where you remain inactive for any period of time chosen by us in our reasonable discretion or where we believe, in our sole and absolute discretion; AAR suspends the provision of the Services for its commercial reasons or for any other reason as it may determine in its absolute discretion.
If we suspend your access to the Service to investigate or prevent a potential breach of these, terms shall continue to apply during such period of suspension and you shall remain liable for any charges payable by you during such period.
If your access to the Services is terminated for any reason then we may proceed to delete all information that you have stored on the Service. We therefore recommend that you save copies of all information that you wish to keep on another storage device apart from the Service.
If we terminate your access to the Service for material breach of these terms (including non-payment of any sums due by you-where applicable) then you shall remain liable for any such sums and for any other sums which you have contracted to pay prior to such termination, whether or not such charges relate to Services to be provided before or after such termination date and whether.
15.5 In the event that we decide to permanently withdraw the Services then we shall communicate this decision using such means as we shall deem. However please remain aware that depending on the nature of the reason for the suspension, change or termination of the services it may not always be possible to give advance notice. Consequently AAR shall not be liable to you for any ensuing loss or damages occasioned to you from such a suspension, change or termination. Termination shall however not affect the accrued rights and liabilities of either you or us.
You may terminate your use of the Services at any time by sending a message to the email address info@aar.co.ke or following such other instructions as may be communicated on the website or contacting us, as set out above. Termination of the Service will not affect your obligation to pay for Services used by you or any third party services or goods previously purchased using the Services.
Identify in sufficient detail the copyrighted work or intellectual property that you claim has been infringed so that we can locate the material. For example, “The copyrighted work is my content that appears at https://www.mycontentpage.com/content If multiple copyrighted works at a single online site are covered by your Notification, you may provide a representative list of such works at that site.
Identify the URL or other specific location on the application or website provided by us that contains the material that you claim infringes your copyright described in Item 1 above. You must provide us with reasonably sufficient information to locate the alleged infringing material. For example, “The content at the following URL infringes on my copyright: https://www.anothercontent.com/content.Provide the electronic or physical signature of the owner of the copyright or a person authorized to act on the owner’s behalf.Include a statement by you that you have a good faith belief that the disputed use is not authorized by the copyright owner, its agent, or the law.Include a statement by you that the information contained in your Notice is accurate and that you attest under the penalty of perjury that you are the copyright owner or that you are authorized to act on the owner’s behalf.Include your name, mailing address, telephone number and email address. You may submit your Notification of Alleged Copyright Infringement to our Head Office by fax, mail, or E-Mail as set forth below:
Phone: +254 20 2895000
Fax: +254 20 2715328
E-Mail: privacy@aar.co.ke
Please note that you may be liable for damages, including court costs and legal fees, if you materially misrepresent that content on our website and/or application is copyright infringing.Upon receiving a proper Notification of Alleged Copyright Infringement as described in this Section A, we will expeditiously remove or disable access to the allegedly infringing material and promptly notify the alleged infringer of your claim. We also will advise the alleged infringer of the Counter Notification procedure described below in Section B by which the alleged infringer may respond to your claim and request that we restore this material. If we receive a Notification of Alleged Copyright Infringement that does not contain all of the information described above, but provides a way for us to contact you, we will promptly follow up with you to request that you provide any information not previously provided.
For any questions or concerns regarding your data privacy, including data access requests, complaints, or inquiries about our data protection practices:
- You can contact our customer service team at 254 703 063 000 and info@aar.co.ke
- You can also contact our Data Protection Officer at privacy@aar.co.ke
Service Update on Technology Partner
Service Update on our Claims Management Process
At AAR Insurance Kenya (AIK), we are committed to continuously improving your experience and optimizing our operations to serve you better. As part of our digital transformation journey, we are pleased to announce a significant enhancement to our claims processing services.
Update to Our Privacy Notice
We have updated our Privacy Notice. Please read it to understand how we collect, use, and protect your personal data.
Dear Esteemed Client,
We are currently in the process of a digital transformation aimed at improving our services and optimizing operations. As part of our ongoing commitment to delivering exceptional service, we are implementing a strategic decision to optimize member experience and fully manage our claims processing digitally. As AAR Insurance - Kenya (AIK) we are pleased to announce an expansion of our collaboration with M-TIBA (Carepay Limited), our health technology partner. This strategic partnership will streamline our customer service and claims management processes, to enhance efficiency and accuracy. By leveraging M-TIBA's expertise, we will dedicate our resources even more effectively to meet your insurance needs with the highest standards of excellence.
Notable benefits arising from the digitization process include:
- Optimized Customer Experience: Members can now access their Outpatient and Inpatient benefits real time, and have continued customer service support 24/7 on their mobile phone.
- Enhanced Efficiency: The specialised expertise of our chosen technology partner M-TIBA will lead to faster turnaround times in service delivery.
- Improved Customer Service: Our customer service teams are dedicated to addressing your individual needs and concerns, for a more personalised experience.
- Technological Advancement: Use of cutting-edge technology to enhance the overall efficiency of claims management.
- Upgrade from photo card to virtual M-TIBA: With this upgrade, the Inpatient only cover customers can view their benefits balance by dialling *253# and selecting 2. MY M-TIBA
We wish to notify you that your personal data with us shall be shared with M-TIBA in order to administer your policy and receive services efficiently.
AAR Insurance- Kenya (AIK) is committed to upholding the highest standards of data security and privacy, to ensure the complete confidentiality and integrity of your information. Please visit our website for more details about our data privacy – https://aar-insurance.com/policy-center/ and the link with more details on accessing benefits and onboarding – https://mtiba.com/aar-health-insurance-through-m-tiba/
For any queries, please reach us through our customer service team on info@aar.co.ke.
We sincerely appreciate your continued trust in AAR Insurance, and look forward to continue serving you with great efficiency and effectiveness.
Dear Esteemed Client,
At AAR Insurance Kenya (AIK), we are committed to continuously improving your experience and optimizing our operations to serve you better. As part of our digital transformation journey, we are pleased to announce a significant enhancement to our claims processing services.
We are transitioning the processing and payment of SMART claims to our health technology partner, M-TIBA (Carepay Limited). This move is designed to streamline operations, improve service efficiency, and enhance your overall claims experience.
The AAR and M-TIBA Partnership
- M-Tiba (Carepay Limited) is a health technology company specializing in claims processing and management.
- AAR Insurance Kenya (AIK) has entered into a strategic collaboration with MTIBA for provision of claims management services. This partnership is driven by our commitment to providing exceptional member experience. By leveraging on M-TIBA’s advanced digital claims processing capabilities, we aim to provide faster, more efficient, and seamlessly integrated claims processing services.
- This partnership has been reviewed and approved by the Insurance Regulatory Authority.
What The Change Means for You
- No changes on insurer or cover benefits: AAR will remain your health insurance provider. Your policy and cover benefits will continue to run for the policy cover period.
- No changes in the claims submission process: The claims submission process will remain the same. You can continue submitting your claims through the channels and procedures that have been communicated to you.
- No changes in healthcare providers: You will still have access to the same healthcare providers, allowing you to receive services as you have been, with no disruption to your existing care arrangements.
- Data Sharing between AIK and M-TIBA: To facilitate, streamline, and enhance claims processing, relevant data will be shared between AAR Insurance and MTIBA Limited, subject to applicable laws and regulations.
- Data Privacy and security: We prioritize the protection of your personal information. All data shared with M-TIBA will be managed with the utmost care and in full compliance with applicable data protection laws and regulations. Both AAR Insurance Kenya and MTIBA have implemented robust security measures, including encryption, access controls, and regular audits, to safeguard your data from unauthorized access, loss, or misuse. Additionally, your information will only be shared to the extent necessary for the efficient processing of claims, and we will always ensure your privacy and confidentiality are maintained. Please visit our website for more details about our data privacy: https://aar-insurance.com/policy-center/
- Claims Payment:
What Should You Do if You Have a Question or Concern Regarding Your Policy or a Claim?
If you have any questions or concerns about your policy or the changes to the claims processing, our customer service team is here to assist you. You can reach us through the following channels:
- Email: info@aar.co.ke
- Phone: 0703063000 / 0730063000
- Website: https://aar-insurance.com/
Our team is dedicated to addressing your inquiries promptly and ensuring that you fully understand any updates or adjustments to your coverage. Your satisfaction and peace of mind are our top priorities.
We sincerely appreciate your continued trust in AAR Insurance, and look forward to continue serving you.





