1. Who We Are
CCK Global operates people-powered contact centre, inside sales, and revenue acceleration services from hubs across Africa, the Middle East, Asia-Pacific, and Europe. We act as a data processor for our clients while also serving as controller for our own business contacts, talent, and marketing audiences.
2. Data We Collect
The information we process depends on the relationship we have with you and may include:
- Identity and contact data such as name, email, phone number, job title, and mailing address.
- Engagement data generated through calls, chats, emails, or digital interactions handled on behalf of our clients.
- Professional data such as CVs, certifications, language proficiency, and assessments submitted by job applicants.
- Technical data including device identifiers, IP addresses, browser type, and analytics collected through our digital properties.
3. How We Use Personal Data
We only use personal data for legitimate business purposes, including to:
- Deliver contracted services to clients and their customers.
- Respond to enquiries, provide proposals, and manage partner relationships.
- Recruit, onboard, and develop team members.
- Monitor quality, train teams, and improve product and service performance.
- Comply with legal, regulatory, and security obligations.
4. Legal Bases for Processing
Depending on the jurisdiction, we rely on one or more of the following legal grounds: performance of a contract, legitimate interests, consent, compliance with legal obligations, and vital interests when safeguarding individuals.
5. Kenyan Regulatory Compliance
As a Kenya-headquartered organisation, CCK Global is committed to protecting your privacy in accordance with the Data Protection Act, 2019 and the Computer Misuse and Cybercrimes Act, 2018. We ensure that your personal data is collected only with your prior consent and processed lawfully, transparently, and securely.
6. Data Sharing & Transfers
We may share personal data with trusted third parties, including technology partners, analytics providers, payroll processors, and affiliated entities, strictly for the purposes outlined in this policy.
When data is transferred outside the originating jurisdiction, we implement appropriate safeguards such as Standard Contractual Clauses, data processing agreements, and rigorous vendor assessments.
7. Security & Retention
CCK Global applies layered technical and organisational controls—access management, encryption, secure facilities, and continuous monitoring—to protect personal data. We retain information only for as long as necessary to fulfil the purpose for which it was collected or to satisfy legal requirements.
8. Your Rights
Individuals may have rights to access, correct, delete, restrict, or port their personal data, as well as to object to processing or withdraw consent. Requests can be submitted using the contact details below. We will respond within applicable regulatory timelines.
Where we process data on behalf of clients, we will coordinate with the relevant controller to fulfil your request.
9. Cookies, Caching & Analytics
Our websites and digital platforms may leverage cookies, tags, server-side caching, and similar technologies to understand user behaviour and improve experiences. You can manage cookie preferences through your browser settings or the consent tools provided on our sites.
Static assets (such as CSS, JavaScript, images, and media) are delivered through secured Nginx servers configured to apply Cache-Control: public, immutable headers for up to one year. This accelerates page loads without storing or exposing sensitive personal data, as dynamic content, forms, and authentication endpoints bypass long-term caching.
We may also employ trusted third-party edge networks or content delivery networks (CDNs) to cache publicly available assets or anonymised telemetry at geographically distributed locations. These providers act under data processing agreements that bind them to the Kenyan DPA, CMCA, and any other applicable regulations, prohibit the inspection of payloads containing personal data, and require timely purge requests whenever you exercise your rights.
Where a CDN or DDoS-mitigation partner temporarily collects connection metadata (for example IP addresses, user agent strings, or timestamped request identifiers) to detect abuse, the data is retained for the minimum duration necessary—typically fewer than 30 days—and is not combined with marketing profiles. You may request that we purge cached assets or related logs at any time; we will relay those instructions to our providers and confirm once the purge completes.
10. Children's Privacy
CCK Global does not knowingly collect or process personal data relating to children under the age required by applicable laws. If we learn we have inadvertently captured such information, we will delete it promptly.
11. Updates to This Policy
We may update this Privacy Policy to reflect new regulations, operational changes, or enhancements to our data protection programme. The "Last Updated" date at the top of this page will indicate the latest revision. Material changes will be communicated through appropriate channels.
12. Contact Us
For questions, requests, or concerns about this Privacy Policy or our data handling practices, contact the CCK Global Data Protection Team at devteam@cckglobal.org or write to Head Office, Nairobi, Kenya. Kenyan residents may also contact the Office of the Data Protection Commissioner if they believe their rights under the Data Protection Act have been infringed.