Privacy Policy

1. Data Controller

The data controller is the owner

Musa Joshua Salimu
info[at]amani-safaris.com
+254 702 202004

Ali Siasa Bakari
Post Box # 1028
0202 Watamu
Kenya

European representation:
Antje Baxpehler
info[at]jua-assistenz.de

2. Hosting

This website is hosted externally. The hosting provider is netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany.

Personal data collected on this website is stored on the servers of netcup GmbH. This includes, amongst other things, IP addresses, contact enquiries, metadata and communication data, and website visits.

The hosting provider is used for the purpose of fulfilling my contractual obligations towards my (potential) clients (Article 6(1)(b) of the GDPR) and in the interest of ensuring the secure and rapid provision of the website by the provider (Article 6(1)(f) of the GDPR). The hosting provider will only process your data to the extent necessary to fulfil its service obligations.
Further information and netcup GmbH’s applicable data protection policy can be found here: https://www.netcup.de/kontakt/datenschutzerklaerung

3. SSL encryption

This website uses SSL encryption for security reasons and to protect the transmission of confidential content. You can recognise this either by the ‘s’ in ‘https://’ or by the padlock icon in the browser address bar.

When SSL encryption is enabled, the data you send to me cannot be read by third parties.

4. Enquiries by email or telephone

If you contact us by email or telephone, your enquiry, including any personal data it contains (name, enquiry, email address), will be stored and processed for the purpose of handling your enquiry. The processing of this data is based on Article 6(1)(b) of the GDPR, provided that your enquiry relates to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on my legitimate interest in the effective handling of enquiries addressed to us, in accordance with Article 6(1)(f) of the GDPR.

The personal data you have provided will remain with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies. Statutory provisions (retention periods) remain unaffected.

5. Contact form

This website uses the WPForms contact form plugin. By submitting an enquiry via the contact form, you consent to the transfer of the data provided in the form. This data will be retained by us until the purpose of the data processing no longer applies. All data you enter, including your message, is stored locally but is not transferred to WPForms’ servers.

Your data will be deleted if you request that we delete it or if you withdraw your consent to its storage. You can find further details on WPForms’ privacy policy here.

6. Wordfence

We use the Wordfence plugin provided by Defiant Inc., Attn: Legal Department, 1700 Westlake Ave N Ste 200, Seattle, WA 98109, USA (“Wordfence”). It is used to protect this website against attacks. In doing so, Wordfence stores users’ IP addresses and sets various cookies. Further details can be found at https://www.wordfence.com/help/general-data-protection-regulation/. Protecting the website against brute-force and DDoS attacks constitutes a legitimate interest pursuant to Article 6(1)(f) of the GDPR.

Even attempting to gain unauthorised access to my website, user accounts or restricted areas is a criminal offence. Any unauthorised access or attempt to log in without authorisation may result in criminal and civil liability. We reserve the right to report such activities to the authorities in accordance with applicable law.

The systems are regularly checked for security incidents. Any irregularities or attempted attacks may be logged and forwarded to the relevant authorities for further investigation.

7. Cloudflare

This website uses the CAPTCHA-like Turnstile system provided by Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich, Germany (Cloudflare), to enhance the website’s security. This is in line with our legitimate interest (Article 6(1)(f) of the GDPR).

Turnstile analyses, for example, the IP address, mouse movements and the length of time users spend on the page to verify that a visitor wishing to send a message via the contact form is a real person.

The functionality of the website cannot be guaranteed without this processing.

Your personal data will be stored by Cloudflare for as long as is necessary for the purposes described.

Further information on your rights to object and request erasure in relation to Cloudflare can be found at: Cloudflare DPA

Cloudflare has implemented compliance measures for international data transfers. These apply to all global activities in which Cloudflare processes personal data of natural persons in the EU. These measures are based on the EU Standard Contractual Clauses (SCCs). Further information can be found at: https://www.cloudflare.com/cloudflare_customer_SCCs-German.pdf

8. Retention period

Unless a more specific retention period is stated in my privacy policy, I will retain your personal data until the purpose for which the data is processed no longer applies. Your data will be deleted if you submit a request for deletion or withdraw your consent to its storage. Provided I have no other legally permissible grounds for storing your personal data (e.g. time limits under commercial or tax law), I will delete your data. In the latter case, deletion will take place once the grounds (time limits) no longer apply.

9. Data Subject Rights

As a data subject, you have the following rights:

  1. Under Article 15 of the GDPR, the right to request information, to the extent specified therein, about your personal data processed by us.
  2. Under Article 16 of the GDPR, the right to request, without undue delay, the rectification of inaccurate personal data or the completion of your personal data stored by us.
  3. Under Article 17 of the GDPR, you have the right to request the erasure of your personal data stored by me, unless further processing
    1. is necessary for the exercise of the right to freedom of expression and information,
    2. to comply with a legal obligation,
    3. for reasons of public interest, or
    4. to establish, exercise or defend legal claims.
  4. Under Article 18 of the GDPR, you have the right to request the restriction of the processing of your personal data, provided that
    1. you contest the accuracy of the data;
    2. the processing is unlawful, but you object to its erasure;
    3. I no longer require the data, but you require it to establish, exercise or defend legal claims; or
    4. you have objected to the processing in accordance with Article 21 of the GDPR.
  5. Under Article 20 of the GDPR, you have the right to receive your personal data in a structured, commonly used and machine-readable format, or to request that it be transferred to another controller.
  6. Under Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority in your place of residence (place of abode) for this purpose.
  7. Under Article 21 of the GDPR, you have the right to object in specific cases and to object to direct marketing.

 

Where data processing is carried out on the basis of Article 6(1)(e) or (f) of the GDPR, you have the right to object to the processing of your personal data at any time. You can find the specific legal basis on which processing is based in this privacy policy. If you object, I will no longer process your personal data in question, unless I can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims (objection under Article 21(1) of the GDPR). If your personal data is processed for the purposes of direct marketing, you have the right to object to this type of data processing at any time.

10. Data transfer to the USA

We use tools provided by suppliers based in the USA. Personal data may be transferred to the servers of the respective companies. The USA is not a safe third country within the meaning of EU data protection law. US companies are obliged to disclose personal data (including that of European citizens) to security authorities.

We employ appropriate and up-to-date security measures, as well as robust technical and organisational measures, to protect your data from loss, misuse and alteration. I do everything in my power to prevent any infringement of your rights or any risk to your personal data.

Please bear in mind that data transmission over the internet is never completely secure. We cannot guarantee the security of data entered on my website whilst it is being transmitted over the internet. This is at your own risk.

Would you like to request a custom safari with us?

Contact us now with all the necessary information. We’ll get back to you as soon as possible with a no-obligation quote.