CROCrostar Energy
OverviewValue ChainMarketplaceTourismOrganisationsShippingLearningResearchApps
Policy & agreement centre

Privacy Policy

Structured for practical use across public access, registration, marketplace and authenticated workflows. The applicable mandatory law and signed agreement prevail where they differ from this public summary.

Purpose and scope

Clear obligations, rights, evidence and escalation pathways.

Purpose and scope

This document governs use of the relevant AfriEuro Links, LaDOS or CEOS service, including public, marketplace, registration and authenticated-workspace interactions. Access to a feature does not override role permissions, contractual controls, law or a separate signed agreement.

Accountability and records

Material approvals, changes, consents, transactions and high-risk decisions are recorded through role-based workflows and audit logs. Records are retained according to purpose, legal requirements and approved retention schedules.

Sensitive information

Identity documents, financial credentials, protected research information, health/safeguarding data, private designs and confidential commercial information are restricted to authorised workflows. Public pages expose only approved information.

Security and fraud prevention

The service uses layered controls including secure sessions, MFA where required, access control, CSRF protection, rate limiting, security logging, encryption in transit, restricted file handling and incident-response workflows. Users must not share passwords, authentication codes or private keys.

Rights and complaints

Participants can use the applicable service channels to request correction, access, objection, withdrawal where legally available, complaint handling and escalation. Contractual and statutory rights remain subject to the governing jurisdiction and the facts of the relationship.

Applicable privacy framework

For European participants/entities, personal-data processing is designed around the GDPR principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality and accountability. Electronic identification and trust-service workflows are designed to interoperate with the current eIDAS/European Digital Identity framework where applicable.

International transfers

Cross-border transfers require an appropriate legal basis, approved data-sharing scope, minimisation and contractual/technical safeguards. Federation is not permission for unrestricted replication.

Lawful processing

The system records processing purpose, consent where consent is relied on, role/relationship and disclosure scope. Consent is not used where another lawful basis is the correct basis.

Data subject requests

Requests are authenticated before personal information is disclosed or changed. Sensitive records can require enhanced verification and human review.

Retention and deletion

Retention is defined by record class, legal/contractual obligation, dispute/audit need and evidence integrity. Data that no longer has an approved purpose is deleted, anonymised or archived under controlled retention.

Official contact

Use the contact channel published by the applicable operating organisation or AfriEuro Links. Do not send passwords, authentication codes, private keys or full payment credentials by email or chat.

Crostar Energy LTD
info@crostarenergy.co.ke
https://www.crostarenergy.co.ke