Privacy Policy

At Ekonava Impact Partners, we operate on a core principle: your data always remains yours. We are committed to enterprise-grade protection for all confidential client data.

Enterprise Security Updated: August 2025

Introduction

Ekonava Impact Partners ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-driven Environmental and Social assessment platform.

We provide enterprise-grade data protection with a fundamental principle: your data always remains yours. We implement stringent security measures and partner only with compliant third parties to ensure your information is protected according to the highest industry standards.

Core Principle: By using our Services, you maintain ownership of your data. We process it only to deliver our environmental and social assessment services and delete it immediately after analysis.

Data Ownership Principle

Your Data, Your Control

At Ekonava, we operate on the fundamental principle that your data always remains yours. We never claim ownership over any data you submit to our platform. All environmental and social data, documents, and assessment results belong exclusively to you.

We act as a data processor on your behalf, meaning we only process your data to provide the services you've requested. We do not use your data for any purpose beyond delivering our AI-driven environmental and social assessments, and we never sell or share your data with third parties for marketing purposes.

Regulatory Compliance

We exclusively partner with third parties that uphold full compliance with both global and local data protection regulations:

GDPR Compliant

Our platfrom is designed with GDPR compliant IN MIND with the EU General Data Protection Regulation

KDPA Compliant

We strive to Adheres to Kenya Data Protection Act (2019) requirements

PCI DSS Level 1

Payment processing meets highest security standards

Account & Access Security

Secure Credentials

All login credentials are protected using advanced hashing and salting algorithms to prevent unauthorized access.

Strict No-Access Policy

Ekonava staff are contractually prohibited from accessing client accounts, logs, or profile data without your explicit, case-by-case consent.

Activity Monitoring

Comprehensive real-time monitoring and auditing capabilities track all platform activities.

Multi-Factor Authentication

Mandatory 2FA and MFA scheduled for rollout in upcoming deployment to enhance account security.

We have implemeneted 2FA and MFA to any personnel who logs into our AWS Cloud accounts.

Secure Document Handling Workflow

Our document processing follows a strict security workflow designed to protect your sensitive information:

1
Document Submission

Secure upload with end-to-end encryption

2
Data Processing

Analysis in isolated, secure containers

3
PII Anonymization

Automatic removal of personally identifiable information. Users need to activate this setting within their accounts.

4
Analytical Modelling

AI analysis using industry-leading models

5
Automated Deletion

Immediate permanent deletion after analysis

6
Results Delivery

Secure delivery of assessment results in near real time.

Payment Security

Our Partnership with Paystack

All financial transactions are securely processed by Paystack, a PCI DSS Level 1 certified provider—the highest level of certification in the payments industry.

Complete Data Isolation

Your payment card details never touch our systems. All transactions are processed directly through Paystack's certified secure environment.

End-to-End Encryption

From browser to bank, all transactions are secured with strong encryption and signed APIs to ensure authenticity and integrity.

Full Transaction Transparency

Complete transaction logs are available in your Ekonava portal for full visibility and auditing purposes.

Secure AI Processing

Industry-Leading Models

We leverage OpenAI's GPT models to deliver accurate and intelligent environmental and social insights.

No Model Training

Your data is never used to train or fine-tune GPT models. Your proprietary information remains confidential.

No Third-Party Retention

Data is not stored or reused by OpenAI or any other external party beyond the immediate processing session.

Session-Only Processing

All inputs are processed securely for your session only and then permanently erased from all systems.

Data Retention & Deletion Policy

Ephemeral Processing Architecture

Ekonava is architected on the principle of ephemeral processing. Client documents are never permanently retained on our servers.

Containerization

Each client session is isolated within secure container, guaranteeing zero data crossover.

Immediate Automatic Deletion

All uploaded documents and session data are automatically and permanently deleted immediately after analysis completion.

Right to Save Results to our Database

OAfter the analysis, users may choose to save their results. Only the analysis outcomes are stored—original uploaded documents are never retained.

In-Memory Analysis Only

All document assessment is conducted within secure, temporary memory, eliminating risks of persistent storage.

Self-Service Audit (Coming Soon)

We are developing an in-platform audit log to give clients direct visibility into all data access and processing activities.

Your Data Protection Rights

Your Rights Under Data Protection Laws

Depending on your location, you may have the following rights regarding your Personal Data under GDPR, KDPA, and other privacy regulations:

Right to Access

You can request copies of your Personal Data that we hold.

Right to Rectification

You can request correction of inaccurate or incomplete data.

Right to Erasure

You can request deletion of your Personal Data under certain conditions.

Right to Restrict Processing

You can request limitation of how we use your data.

Right to Data Portability

You can request transfer of your data to another organization.

Right to Object

You can object to our processing of your Personal Data.

To exercise any of these rights, please contact us using the information provided in the "Contact Us" section. We will respond to your request within 30 days.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer:

Email

privacy@ekonavaimpactpartners.com

Our Mission

Accelerating Responsible Investment Decisions through secure, AI-driven environmental and social assessments.

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically for any changes.