CROCrostar Energy
OverviewValue ChainMarketplaceTourismOrganisationsShippingLearningResearchApps
Policy & agreement centre

Privacy Policy

Structured for practical use across public access, registration, marketplace and authenticated workflows. The applicable mandatory law and signed agreement prevail where they differ from this public summary.

Purpose and scope

Clear obligations, rights, evidence and escalation pathways.

Purpose and scope

This document governs use of the relevant AfriEuro Links, LaDOS or CEOS service, including public, marketplace, registration and authenticated-workspace interactions. Access to a feature does not override role permissions, contractual controls, law or a separate signed agreement.

Accountability and records

Material approvals, changes, consents, transactions and high-risk decisions are recorded through role-based workflows and audit logs. Records are retained according to purpose, legal requirements and approved retention schedules.

Sensitive information

Identity documents, financial credentials, protected research information, health/safeguarding data, private designs and confidential commercial information are restricted to authorised workflows. Public pages expose only approved information.

Security and fraud prevention

The service uses layered controls including secure sessions, MFA where required, access control, CSRF protection, rate limiting, security logging, encryption in transit, restricted file handling and incident-response workflows. Users must not share passwords, authentication codes or private keys.

Rights and complaints

Participants can use the applicable service channels to request correction, access, objection, withdrawal where legally available, complaint handling and escalation. Contractual and statutory rights remain subject to the governing jurisdiction and the facts of the relationship.

Applicable privacy framework

For Kenyan participants/entities and, by programme rule, participants outside Europe unless a different mandatory law applies, personal-data processing is designed around the Kenya Data Protection Act and applicable regulations, including lawful processing, transparency, purpose limitation, data minimisation, security and data-subject rights.

Cross-border processing

Personal data is exchanged across systems or borders only for an approved purpose, with minimisation, access controls, auditability and the safeguards required by the applicable Kenyan data-protection framework and contracts.

Lawful processing

The system records processing purpose, consent where consent is relied on, role/relationship and disclosure scope. Consent is not used where another lawful basis is the correct basis.

Data subject requests

Requests are authenticated before personal information is disclosed or changed. Sensitive records can require enhanced verification and human review.

Retention and deletion

Retention is defined by record class, legal/contractual obligation, dispute/audit need and evidence integrity. Data that no longer has an approved purpose is deleted, anonymised or archived under controlled retention.

Official contact

Use the contact channel published by the applicable operating organisation or AfriEuro Links. Do not send passwords, authentication codes, private keys or full payment credentials by email or chat.

Crostar Energy LTD
info@crostarenergy.co.ke
https://www.crostarenergy.co.ke