Privacy Policy

Last Updated: March 18, 2026

Litskill ("we", "us", or "our") operates the Litskill online learning platform. We are committed to protecting your personal data and respecting your privacy in accordance with the Constitution of Kenya (2010) and the Data Protection Act, 2019.

This Privacy Policy explains how we collect, use, store, and share your personal data when you visit our website or use our services.

1. Who We Are

For the purposes of the Data Protection Act, the Data Controller is Litskill, located in Nairobi, Kenya. If you have any questions about this policy, you may contact our Data Protection Officer at:

2. Information We Collect

We collect different types of information depending on whether you are a Student or an Instructor.

2.1 Data Collected from All Users

  • Identity Data: First name, last name, username.
  • Contact Data: Email address, phone number.
  • Technical Data: Internet Protocol (IP) address, browser type, time zone setting, and operating system (collected automatically via cookies).

2.2 Data Collected from Instructors

To facilitate payouts and verify your identity, we collect:

  • Financial Data: M-Pesa phone numbers, Bank Account numbers, and Routing numbers.
  • Verification Data: Copies of National ID or Passport (for identity verification purposes as required by financial regulations).
  • Tax Data: KRA PIN (if applicable for Kenyan tax withholding).

2.3 Data Collected from Students

  • Course Data: Progress tracking, quiz results, and certificates earned.
  • Transaction Data: Details of payments made (Note: We do not store your credit card numbers. Payment data is processed directly by our secure third-party payment processors, such as Pesapal).

3. How We Use Your Personal Data

We only use your data where the law allows us to. We use your data for the following purposes:

  • To Provide Service: To manage your account, enroll you in courses, and track your progress.
  • To Process Payouts (Instructors): To calculate your earnings and remit funds to your M-Pesa or Bank Account.
  • To Communicate: To send you essential notifications (e.g., "Payout Sent", "Password Reset") or marketing emails (only if you opted in).
  • To Comply with Law: To keep financial records for tax purposes as required by the Kenya Revenue Authority (KRA).

3A. Legal Bases for Processing

We process personal data on one or more of the following legal bases:

  • Contract: to provide the Services you request (account creation, course enrollment, certificates, instructor payouts).
  • Legal Obligation: to comply with applicable laws and regulations (e.g., tax, accounting, fraud prevention, financial compliance).
  • Legitimate Interests: to keep the Services secure, prevent abuse, understand usage trends, and improve the platform.
  • Consent: where required (for example, certain marketing communications). You can withdraw consent at any time.

4. How We Store Financial Data (Security)

We employ a "Data Minimization" strategy for your financial safety:

  • Bank/Card Details: We DO NOT store raw credit card numbers or US Bank Account numbers on our servers.
  • When an Instructor enters bank details, they are securely transmitted immediately to our regulated banking partners (Grey Finance or Wise) via API.
  • We only store a secure "Reference ID" (Token) to trigger future payouts.
  • M-Pesa Numbers: M-Pesa numbers are stored in our encrypted database solely for the purpose of processing payouts.

5. Disclosure of Your Personal Data

We may share your data with the following third-party Data Processors who help us run our business:

  • Payment Processors: Pesapal (Kenya), IntaSend (Kenya), PayPal (Global) – for collecting payments from students.
  • Payout Partners: Grey Finance (USA/Global), Wise – for sending earnings to instructors.
  • Hosting Providers: (e.g., AWS, Vercel, or Render) – who host our website infrastructure.
  • Legal Authorities: If required by law, we may disclose data to the Kenya Revenue Authority (KRA) or law enforcement agencies.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law.

5A. Public Pages & Sharing Features

Some information may be displayed publicly as part of the Services:

  • Certificate Verification: If you earn a certificate, we may host a public verification page so employers or third parties can confirm authenticity using a certificate number and/or QR code.
  • Instructor Profiles: Instructor profile pages (and courses offered) may be publicly visible.
  • Your Choices: Where the platform provides controls (for example, profile visibility), you can use those settings to limit public display where available.

Please do not include sensitive personal data in any content you choose to make public (for example, in profile descriptions, course materials, or project submissions).

5B. AI-Assisted Features & Project Review

The platform may use automated tools (including AI models and third-party APIs) to provide learning features such as project feedback, content assistance, and fraud detection. This may involve processing text and other materials you submit for these features (for example, milestone project submissions).

  • What we process: project submissions, prompts, and related context needed to generate feedback.
  • Why we process it: to provide requested features, improve learning outcomes, and help maintain academic integrity.
  • Human oversight: where applicable, we may review or override automated outcomes (for example, certificate/project verification decisions).

We do not sell your personal data. We also do not use your private project submissions to advertise unrelated third-party products to you.

6. International Data Transfers

Some of our external third parties (like Grey Finance or PayPal) are based outside Kenya. Whenever we transfer your personal data out of Kenya, we ensure a similar degree of protection is afforded to it by ensuring they comply with the Data Protection Act (Section 48) regarding cross-border transfers.

7. Data Retention

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for.

  • Account Data: Kept as long as your account is active.
  • Financial Transaction Data: Kept for seven (7) years as required by Kenyan Tax Laws.

7A. Security & Breach Notification

We use appropriate technical and organizational measures designed to protect personal data (including access controls, encryption where appropriate, and monitoring for suspicious activity).

If we become aware of a personal data breach that is likely to result in risk to your rights and freedoms, we will take steps required by applicable law, including notifying relevant authorities and affected individuals where required.

8. Your Rights Under the Data Protection Act

Under the Kenyan DPA 2019, you have the right to:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request that we delete your data where there is no good reason for us to continue processing it (subject to legal retention requirements).
  • Right to Object: Object to the processing of your data for direct marketing.
  • Right to Data Portability: Request the transfer of your data to another service provider.

To exercise any of these rights, please email support@litskill.com. We may request specific information to confirm your identity before processing your request.

8A. Account Deletion & Data Requests (Operational Details)

When you request account deletion, we will delete or anonymize personal data where feasible, subject to legal and operational retention requirements (for example, financial records).

  • Identity verification: we may request information to confirm you are the account owner before fulfilling certain requests.
  • Response timelines: we aim to respond to verified requests within a reasonable time, and in any case within timelines required by applicable law.
  • What may remain: certain records may be retained to comply with law, resolve disputes, enforce agreements, or prevent fraud/abuse.

9. Cookies

We use cookies and similar technologies (like local storage) to make the Services work and to help understand how the platform is used.

  • Essential cookies: required for core functionality such as authentication, session management, and security.
  • Preferences: to remember settings and improve your experience.
  • Attribution & sharing: if you visit via an instructor referral link, we may store referral attribution information in your session to properly credit referral-based sales during an attribution window.

You can set your browser to refuse all or some browser cookies, but some parts of the website (like logging in) may become inaccessible.

9A. Children's Privacy

The Services are not directed to children under 13. If you believe a child has provided personal data to us without appropriate consent, please contact us and we will take appropriate steps.

10. Complaints

If you have concerns about our privacy practices, please contact us first at support@litskill.com. You may also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) in Kenya or another relevant regulator, depending on your location.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last Updated" date.