How Achla handles personal data
Privacy policy
A clear explanation of the information we collect, why we use it, and the choices available to you.
Last updated · 25 September 2026
Who this applies to
This policy applies when you browse Achla, create an account, buy tickets or merchandise, organize an event, submit a partnership enquiry, or contact us. Achla’s legal operating entity and contact address will be added before public launch.
Information we collect
We collect the information needed to operate the service. This can include your name, email address, account role, password hash, phone number when you provide it, order details, event and merchandise choices, support messages, and technical security records such as IP-derived rate-limit data.
- Payment details are processed by the payment provider; Achla does not receive or store card credentials.
- For organizer verification, Didit handles identity documents and biometric checks. Achla stores only the result, provider session reference and minimal status information needed to enable payouts.
- For payout setup, bank details are sent to Paystack. Achla retains only limited masked details and the provider’s subaccount reference.
Why we use information
We use personal data to provide accounts, process and confirm orders, communicate about purchases and events, protect the service against fraud and abuse, respond to support requests, meet legal obligations, and improve the reliability of the platform. Where required, we ask for consent; otherwise we use data only where a valid basis under applicable law applies.
Who receives information
We share information only as needed with service providers that help operate Achla, including payment providers, identity-verification providers, transactional email providers, secure cloud and database providers, and event organizers for an attendee’s order. Each recipient should use the data only for the relevant service or its own lawful obligations.
Retention and security
We keep information only for as long as it is needed for the purpose collected, lawful recordkeeping, disputes, fraud prevention and security. We use access controls, encrypted connections where available, input validation, signed webhooks and other reasonable safeguards. No system is perfectly secure, so you should also protect your account credentials.
Your choices and rights
You can ask to know what personal data we hold, correct inaccurate information, object to certain processing, request deletion where appropriate, or raise a concern. We may need to verify your identity before acting and may retain information where required for law, security or transaction records.
- Use the Data Rights page to understand how to make a request.
- If you are unhappy with our response, you may contact Kenya’s Office of the Data Protection Commissioner.
- We will publish a monitored privacy contact before public launch; do not send ID documents by ordinary email.
Cross-border processing
Some service providers may process data outside Kenya. Where this occurs, Achla will use safeguards or obtain consent where required by applicable data-protection law.