Independent health informationNot a diagnosis serviceKenya-focused privacy approach

Privacy Policy

Last updated 6 October 2026. This policy explains how personal data is handled when you use menvira.online or contact the site.

1. Scope and identity

MenVira is the editorial name used by menvira.online. A separate legal company name, registration number and tax identifier have not been provided for publication. The contact details currently provided for this website are: Monrovia Street, Loita Street, City Centre, Nairobi, Kenya; +254 715 741 619; [email protected].

This policy is written for a Kenya-focused website and reflects the principles and data-subject rights in Kenya's Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021. The Office of the Data Protection Commissioner (ODPC) is Kenya's supervisory authority for personal-data protection.

2. Personal data we may process

Contact data. If you use the contact form, we request your name, email address, subject and message. The form is intended for editorial, privacy and website enquiries only.

Health data is not requested. MenVira is not a health-care provider and does not invite visitors to send symptoms, diagnoses, medical history, prescriptions, laboratory results, scans or other health information. The contact form includes a warning and a basic filter intended to discourage such submissions. If sensitive health information is sent incidentally, we will avoid using it for health assessment and may delete it where practical.

Technical data. The web server may generate standard security and access logs such as IP address, timestamp, requested path, response code and user-agent string. Hosting providers may process these logs to operate and secure the service.

Privacy preferences. The site's lightweight consent interface stores a local preference in your browser. At launch, Google Analytics, Google Tag Manager, Cookiebot and reCAPTCHA IDs are not configured, so no optional analytics tag is loaded by this build.

3. Why data is used

Contact details are used to answer the enquiry you send, keep an appropriate record of correspondence, protect the site from abuse, and establish or defend legal claims where necessary. We do not use the contact form to provide a diagnosis or treatment advice. Server logs are used for site delivery, troubleshooting, fraud prevention and security.

If analytics is configured later, it must remain disabled until the user allows analytics through the preference interface, and the Privacy and Cookies pages should be reviewed so the published policy matches the active technology.

4. Legal basis and data minimisation

Processing should be lawful, fair and transparent, limited to explicit purposes and no more extensive than necessary. For ordinary contact enquiries, processing may be necessary to respond to a request initiated by the visitor and for legitimate site administration. Where consent is the appropriate basis for an optional technology, refusal must not block basic access to editorial content.

5. Sharing and service providers

Personal data may be handled by infrastructure providers that host, secure or deliver the website, and by an email service or mail server used to deliver contact messages. We do not publish a vendor name that has not been supplied. We do not state that data is shared with an affiliate network because no affiliate partner has been configured at launch.

We do not sell personal data. If a future service provider processes data outside Kenya, the operator should assess applicable transfer safeguards under Kenyan data-protection law before enabling that service.

6. Retention

Contact messages should be kept only as long as reasonably required to respond, manage follow-up and address legal or security needs. Routine access logs should follow the hosting provider's operational retention schedule. We do not claim a fixed retention period that is not technically enforced. When information is no longer required, it should be deleted or anonymised where practical.

7. Your data-protection rights

Kenyan data-protection law provides rights that include being informed about the use of personal data, accessing personal data, objecting to processing, correcting false or misleading data, and seeking deletion in appropriate circumstances. ODPC guidance also describes rights relating to restriction and data portability in applicable cases.

To make a privacy request, contact [email protected] and clearly identify the request. We may need reasonable information to verify that the request concerns your data. If you believe your data-protection rights have been infringed, you may also contact or file a complaint with Kenya's Office of the Data Protection Commissioner.

8. Security

Reasonable safeguards include minimising form fields, rejecting obvious automated submissions, using CSRF protection, validating data server-side, using HTTPS in production, and limiting administrative access. No website can promise absolute security. If a personal-data breach creates notification obligations under applicable law, the operator should follow the required reporting and mitigation process.

9. Children

This site is written for a general adult audience. It does not intentionally provide accounts or child-directed services and should not knowingly collect personal data from a child through the contact form.

10. Changes to this policy

This notice should be updated when material processing changes—for example, when GA4, GTM, Cookiebot, reCAPTCHA, a new form backend or an affiliate partner is activated. The update date at the top should change when the policy is materially revised.

11. Privacy contact

Email: [email protected]
Phone: +254 715 741 619
Address: Monrovia Street, Loita Street, City Centre, Nairobi, Kenya