Momentum AdWorks is a registered business name in Kenya, operated by Elijah Oling Wanga as a sole proprietor. In this policy, “Momentum AdWorks”, “we”, “us” and “our” refer to that business.
Our operating address is Karen Ridge Road, Nairobi, Kenya. You can reach us at administrator@momentumadworks.net or +254 702 549117.
We provide search engine optimisation and paid acquisition services to business-to-business software and financial technology companies, primarily in the United States and the United Kingdom. Much of our work is in regulated and semi-regulated categories — payments, lending, wealth, insurance, banking infrastructure and compliance software — where advertising platforms apply additional verification and disclosure rules.
For the personal data described in this policy, Momentum AdWorks is the data controller. Where we handle personal data inside a client’s own advertising or analytics accounts, we act as a data processor on that client’s instructions; section 8 explains the difference and what it means for you.
This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it and what rights you have. It applies to visitors to momentumadworks.net, people who enquire about our services, our clients and their staff, and anyone else whose personal data reaches us in the course of running the business.
We have written it to meet:
Where two of these give you different rights, we apply whichever gives you more.
If we change this policy we will update the date at the top. If a change materially affects how we use data we already hold, we will say so on the site or by email before it takes effect.
When you visit the site. Your IP address, browser and device type, operating system, the pages you view, how long you spend on them, and the site or search that sent you. This comes from server logs and from the analytics and advertising tools listed in section 5.
When you contact us or fill in a form. Your name, email address, company name, website, role, and whatever you write in the message field. Our enquiry form also asks for your company’s annual recurring revenue band, your marketing budget band and your product category. Those are business details rather than personal ones, but they arrive attached to your name, so we treat them with the same care.
When you subscribe to something. Your name and email address, and a record of what you subscribed to and when. Every marketing email we send carries an unsubscribe link.
When you become a client. The above, plus the contact details of the people we work with on your side, billing details, access credentials or delegated access to the accounts we are engaged to work in, and the material you send us to do the work.
What we do not collect. We do not ask for, and do not want, special category data — health, biometrics, political opinions, religious beliefs, trade union membership, sexual orientation, or data about criminal convictions. We do not knowingly collect data about anyone under 18. We do not buy contact lists, and we do not scrape personal contact data for outbound marketing.
| What we do | Why | Legal basis |
|---|---|---|
| Reply to your enquiry, scope work, send a proposal | You asked us to | Steps taken at your request before entering a contract |
| Deliver the services we are engaged for | To perform the contract | Contract |
| Invoice you and keep accounting records | To get paid and to meet tax law | Contract; legal obligation |
| Send you our newsletter or content | To stay in touch with people who asked us to | Consent, which you can withdraw at any time |
| Measure how the site is used and improve it | To run a business that works | Legitimate interests, balanced against your privacy |
| Keep the site and our systems secure | To prevent fraud and abuse | Legitimate interests |
| Respond to a legal request or defend a claim | Because we have to | Legal obligation; legitimate interests |
We do not make decisions about you by automated means that produce legal or similarly significant effects.
Directly from you, through the contact form on this site, by email, on calls, or during client onboarding. Automatically, through cookies and the analytics tools in section 5, when you use the site. Occasionally from public business sources — a company website, a public directory or a professional network — when we are researching a company that has approached us.
We do not sell personal data, and we do not share it for anyone else’s advertising.
We use the following service providers, each of which processes some personal data on our behalf under a data processing agreement:
| Provider | What it does | Where it processes data |
|---|---|---|
| Brevo (Sendinblue SAS) | Our CRM. Holds enquiry and client contact records, and sends both our marketing email and the transactional mail this site generates | European Union (France) |
| Namecheap / EasyWP | Hosts this website and its database, which is where form submissions are first stored | United States |
| Google — Analytics 4, Search Console, Site Kit | Website analytics and search performance measurement | United States and other Google locations |
| Meta — Meta Pixel, deployed via PixelYourSite | Measures the performance of our own advertising | United States |
| Paystack | Processes client payments. Card details go to Paystack directly; we never see or store them | Nigeria, South Africa and their sub-processors |
We may also disclose personal data to our professional advisers where they need it to advise us, to a public authority where the law requires it, and to a buyer and their advisers if we ever sell or transfer the business — in which case we would tell you first.
We are based in Kenya, our clients are in the United States and the United Kingdom, and our providers are in the EU, the US and elsewhere — so your personal data will be transferred across borders.
Where data covered by the GDPR or the UK GDPR leaves the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses, or on the provider’s own approved transfer mechanism, together with the security measures in section 7. Where the Kenyan Data Protection Act applies, we transfer data only where the conditions in section 48 of that Act are met.
You can ask us for details of the safeguards that apply to a specific transfer.
The site runs over HTTPS. Access to our CRM, hosting and analytics accounts is restricted to people who need it and protected by strong, unique passwords and two-factor authentication where the provider supports it. Client credentials are held in a password manager, never in email or documents, and we ask for delegated account access rather than shared logins wherever a platform allows it. We remove access when an engagement ends.
We are a small business and we describe our security honestly: these are proportionate measures, not a certified information security management system. We do not currently hold SOC 2 or ISO 27001 certification. If your procurement process requires specific controls, tell us early and we will tell you plainly whether we meet them.
No system is completely secure. If a breach affects your personal data and is likely to cause you harm, we will notify you and the relevant authority — within 72 hours of becoming aware of it, as required under the GDPR and the Kenyan Act.
When we run advertising or analytics inside a client’s own accounts, the client decides what is collected and why. They are the controller; we act on their instructions as a processor, and we do not use anything we see there for our own purposes.
In practice this means we may see audience definitions, conversion data and lead records inside a client’s Google, Meta, LinkedIn, analytics or CRM accounts. We do not export that data, we do not combine it with anything else, and we delete or lose access to it when the engagement ends.
If you are a client and need a written data processing agreement, ask and we will provide one before work starts.
| Data | Retention |
|---|---|
| Enquiries that do not become clients | 24 months from your last contact with us, then deleted |
| Client records and correspondence | For the engagement, then 7 years, to meet Kenyan tax and limitation periods |
| Invoices and accounting records | 7 years, as required by law |
| Marketing subscribers | Until you unsubscribe, then a suppression record only, so we do not email you again |
| Website analytics | 14 months in Google Analytics 4; server logs are kept for a shorter period by our host |
Depending on where you live, you may have the right to:
If you are a California resident, you also have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA.
To exercise any of this, email administrator@momentumadworks.net. We will respond within 30 days, or sooner where the law requires it. We may ask you to confirm your identity first, and we do not charge for a reasonable request.
If you are unhappy with how we have handled it, you can complain to the Office of the Data Protection Commissioner in Kenya (odpc.go.ke), or to the supervisory authority in your own country if you are in the EEA or the UK. We would rather you came to us first.
We use cookies and similar technologies for three things:
You can block or delete cookies in your browser settings; the essential ones aside, the site will still work. Where a consent banner is shown, your choice is recorded and applied. We honour Global Privacy Control and Do Not Track signals where the underlying tool supports them.
Google and Meta set cookies under their own policies: Google Privacy Policy · Meta Privacy Policy.
Our services are sold to businesses and are not directed to anyone under 18. We do not knowingly collect their data, and if we learn that we have, we delete it.
Momentum AdWorks
Karen Ridge Road, Nairobi, Kenya
administrator@momentumadworks.net
+254 702 549117
For anything in this policy, including a data processing agreement or details of a specific transfer safeguard, email us and put “Privacy” in the subject line.