Logo
Your Privacy Matters

Privacy Policy

We take your privacy seriously. This policy explains how we collect, use, and protect your personal information when you use the NextGen Platform.

Effective: April 1, 2026

DPA 2019 Compliant

Our Privacy Promise

We never sell your personal data
We encrypt all sensitive information
You control your data rights

1. Introduction

Last updated: March 15, 2026

NextGen ("we," "our," or "us") is a joint initiative of the United Nations Development Programme (UNDP) Kenya and the Kenya Private Sector Alliance (KEPSA). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the NextGen Platform.

1.1 Scope

This policy applies to all users of the NextGen Platform, including candidates, company representatives, and administrators. By using the Platform, you consent to the data practices described in this policy.

1.2 Data Controller

For the purposes of Kenya's Data Protection Act, 2019, the joint data controllers are:

  • UNDP Kenya, UN Complex, Gigiri, Nairobi
  • KEPSA, KEPSA Building, 5th Floor, Muthaiga, Nairobi
Important: This policy should be read together with our Terms of Use. Capitalized terms not defined here have the meaning given in the Terms.

2. Data We Collect

We collect information to provide, improve, and secure the NextGen Platform. The types of data we collect depend on how you interact with us.

2.1 Information You Provide

When you create an account or apply to the programme, you may provide:

  • Identity Data: Full name, national ID number, date of birth, gender
  • Contact Data: Email address, phone number, county of residence, emergency contact details
  • Educational Data: Institution name, degree, field of study, graduation year, GPA
  • Professional Data: Work experience, skills, certifications
  • Disability Information: If voluntarily disclosed, for accommodation purposes
  • Documents: Academic transcripts, national ID copies, professional certifications

2.2 Information We Collect Automatically

When you use the Platform, we automatically collect:

  • Usage Data: Pages visited, features used, time spent on Platform
  • Device Data: IP address, browser type, operating system, device identifiers
  • Log Data: Access times, error logs, performance metrics

2.3 Sensitive Personal Data

Certain information we collect may be considered "sensitive" under Kenyan law, including:

  • National ID number
  • Disability status and accommodation needs
  • Biometric data (if ID verification is implemented)

We collect sensitive data only with your explicit consent and use it solely for the purposes disclosed.

3. How We Use Your Data

We use your personal data exclusively for purposes related to the NextGen Programme:

Verify identity and eligibility
Evaluate and score applications
Match with partner companies
Send status updates and notifications
Detect and prevent fraud
Improve Platform performance
Respond to support requests
Comply with legal obligations

3.1 Automated Decision-Making

We use automated scoring algorithms to evaluate applications based on:

  • Academic performance relative to institution and field
  • Relevance and depth of skills and experience
  • Application completeness and quality

You have the right to request human review of any automated decision. See Section 8 (Your Rights) for details.

5. Data Sharing

We share your data only as necessary to operate the NextGen Programme. We never sell your personal data.

5.1 Programme Partners

Your data is shared with:

  • UNDP Kenya: Programme administration, verification, oversight
  • KEPSA: Employer coordination, matching, placement management
  • Partner Companies: When your application is forwarded for placement consideration. Companies receive only information necessary for evaluation.

5.2 Service Providers

We engage trusted third-party service providers who assist with:

  • Cloud hosting and data storage
  • Email and notification delivery
  • Document verification services
  • Analytics and performance monitoring

All service providers are bound by strict data processing agreements and may not use your data for their own purposes.

5.3 Legal Disclosures

We may disclose your data if required by law, court order, or government regulation, or if we believe disclosure is necessary to protect the rights, property, or safety of NextGen, our users, or the public.

Partner companies are independent data controllers for the information we share with them. Their use of your data is governed by their own privacy policies and Kenyan law.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal data.

6.1 Security Measures

Encryption in transit (TLS 1.3) and at rest (AES-256)
Multi-factor authentication for administrative access
Regular security audits and penetration testing
Secure, access-controlled data centers
Automated backup and disaster recovery
24/7 security monitoring and incident response

6.2 Document Security

Uploaded documents receive additional protection:

  • Virus scanning upon upload
  • Access restricted to authorized verification personnel only
  • Documents are never publicly accessible
  • Secure, time-limited viewing URLs for verification

6.3 Your Responsibilities

You are responsible for maintaining the confidentiality of your account credentials. Notify us immediately if you suspect unauthorized access to your account.

7. Data Retention

We retain your personal data only as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law.

7.1 Retention Periods

Active Applications

Throughout application and placement process

Up to 12 months

Placed Interns

Programme duration plus follow-up period

24 months post-placement

Unsuccessful Applications

For programme analysis and improvement

6 months

Account Data

If inactive, after last login

24 months

7.2 Data Deletion

After the retention period expires, we securely delete or anonymize your personal data. You may also request earlier deletion (see Section 8).

8. Your Rights

Under Kenya's Data Protection Act, 2019, you have the following rights regarding your personal data:

Right to Access

Request a copy of the personal data we hold about you.

Right to Rectification

Correct inaccurate or incomplete data.

Right to Erasure

Request deletion of your data (subject to legal requirements).

Right to Restrict Processing

Limit how we use your data in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests.

8.1 How to Exercise Your Rights

To exercise any of these rights, contact our Data Protection Officer at dpo@nextgen.ke. We will respond within 30 days as required by law.

8.2 Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya:

ODPC Kenya, Britam Centre, 8th Floor, Hospital Road, Upper Hill, Nairobi
Email: info@odpc.go.ke | Website: www.odpc.go.ke

9. Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze usage, and improve the Platform.

9.1 Types of Cookies We Use

Essential Cookies

Required for Platform functionality, including authentication, security, and session management.

Analytics Cookies

Help us understand how users interact with the Platform so we can improve performance.

Preference Cookies

Remember your settings and preferences (e.g., language, theme).

9.2 Managing Cookies

You can control cookies through your browser settings. Note that disabling essential cookies may prevent you from using certain Platform features.

9.3 Do Not Track

We do not currently respond to "Do Not Track" signals. However, we do not track users across third-party websites for advertising purposes.

10. Children's Privacy

The NextGen Platform is intended for users aged 18 and above. We do not knowingly collect personal data from individuals under 18.

10.1 Age Verification

We verify age through national ID and date of birth information. Applications from individuals under 18 are automatically rejected.

10.2 Parental Rights

If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@nextgen.ke. We will promptly delete such information.

11. International Data Transfers

As part of UNDP's global operations, your data may be transferred to and processed in countries outside Kenya. UNDP maintains appropriate safeguards for all international data transfers in accordance with its Data Privacy Principles.

11.1 Safeguards

When we transfer data internationally, we ensure adequate protection through:

  • Standard contractual clauses approved by the ODPC
  • UNDP's internal data protection policies and procedures
  • Data processing agreements with strict confidentiality requirements

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements.

12.1 Notification of Changes

When we make material changes, we will:

  • Post the updated policy on this page with a new "Effective" date
  • Send an email notification to registered users
  • Display a notice on the Platform for at least 30 days

12.2 Your Acceptance

Your continued use of the Platform after changes become effective constitutes your acceptance of the revised Privacy Policy. If you disagree with the changes, you must stop using the Platform and may request deletion of your data.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Protection Officer

dpo@nextgen.ke

For privacy-related inquiries and to exercise your data rights.

Security Team

security@nextgen.ke

Report security vulnerabilities or suspected data breaches.

Physical Address

UNDP Kenya, United Nations Complex, Gigiri, P.O. Box 30218-00100, Nairobi, Kenya

We aim to acknowledge all privacy-related inquiries within 48 hours and provide a substantive response within 30 days as required by law.

By continuing to use NextGen, you acknowledge that you have read and understood this Privacy Policy.