Lady Justice
NCHOKO & COMPANYADVOCATES

Weighing the evidence…

Home > Privacy Policy

Privacy Policy

Privacy Policy & Data Protection

Enforcing Constitutional Rights under Article 31 of the Constitution of Kenya, 2010

Last Updated: July 13, 2026

Preambular Statement & Constitutional Basis

Nchoko & Company Advocates operates with absolute fidelity to the rule of law. This Privacy Policy outlines how we collect, store, transmit, and protect personal data. Crucially, this policy serves to implement the constitutional guarantees of the right to privacy under Article 31 of the Constitution of Kenya (2010), which dictates that:

“Every person has the right to privacy, which includes the right not to have— (c) information relating to their family or private affairs unnecessarily required or revealed; or (d) the privacy of their communications infringed.”

Additionally, this policy adheres to the statutory provisions of the Data Protection Act, 2019 and the regulations promulgated by the Office of the Data Protection Commissioner (ODPC) of Kenya.

1. Data Minimization & Scope of Collection

Consistent with Section 3 of the Data Protection Act, 2019 (Principles of Data Protection), we enforce strict data minimization. We only collect the minimal personal data required to address client inquiries, schedule appointments, and coordinate consultations:

  • Identity Information: Name, professional titles (minimizing background disclosures).
  • Contact Coordinates: Email address and telephone number (exclusively for appointment alerts).
  • Enquiry Matter: General details regarding the legal dispute or consultation requirements.

We explicitly request that clients do not transmit highly sensitive PII, credit card details, or health documents through our web inquiry portal. Detailed legal briefs are only collected in person or via encrypted legal chambers files.

2. Cryptographic Controls (TLS 1.3 & AES-256)

To secure user communications against intercept, we maintain rigorous cryptographic safeguards:

  • Data in Transit: Encrypted using TLS 1.3 (Transport Layer Security) for all API traffic.
  • Data at Rest: Encrypted at rest using AES-256 (Advanced Encryption Standard) on Vercel Postgres servers.
  • Pseudonymization: Unique identifiers and hash keys (SHA-256) replace direct names in internal logs.
  • Data Masking: Database credentials and developer configuration keys are stored in secure Vercel environment files, eliminating hardcoded exposures in public repositories.

3. Data Retention & Automated Purging

Data is not retained longer than legally required under the principles of rule of law:

We programmatically purge contact log records and expired pending appointments within 180 days of resolution. Active client consultation cases are subject to the Advocates Act (Cap 16, Laws of Kenya) professional record-keeping standards, securely filed offline in paper format.

4. Data Subject Rights

Under the Data Protection Act 2019 and international standards, users possess the right of access, correction, block, and erasure of their records. Direct inquiries regarding database records should be addressed to our Compliance Officer at info@nchoko.law.

A Boutique Law Firm Built on Integrity, Excellence & Results. Trusted counsel for individuals, businesses and institutions.

Chambers

Opening Hours:

Mon - Fri, 08 am - 05 pm

Sunday Closed

2025 © All rights reserved by Nchoko & Company Advocates | Designed by cytech