Momentum AdWorks

Privacy Policy

Last updated: 27 August 2026

Momentum AdWorks is a registered business name in Kenya, operated by Elijah Oling Wanga as a sole proprietor. In this policy, “Momentum AdWorks”, “we”, “us” and “our” refer to that business.

Our operating address is Karen Ridge Road, Nairobi, Kenya. You can reach us at administrator@momentumadworks.net or +254 702 549117.

We provide search engine optimisation and paid acquisition services to business-to-business software and financial technology companies, primarily in the United States and the United Kingdom. Much of our work is in regulated and semi-regulated categories — payments, lending, wealth, insurance, banking infrastructure and compliance software — where advertising platforms apply additional verification and disclosure rules.

For the personal data described in this policy, Momentum AdWorks is the data controller. Where we handle personal data inside a client’s own advertising or analytics accounts, we act as a data processor on that client’s instructions; section 8 explains the difference and what it means for you.

1. What this policy covers

This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it and what rights you have. It applies to visitors to momentumadworks.net, people who enquire about our services, our clients and their staff, and anyone else whose personal data reaches us in the course of running the business.

We have written it to meet:

  • the Data Protection Act, 2019 of Kenya, where we are established;
  • the UK GDPR, where we offer our services to companies in the United Kingdom;
  • the EU General Data Protection Regulation, so far as it reaches people in the EEA who visit this site — we do not sell into the EU, but the site is readable from it and our analytics see those visits;
  • US state privacy laws, including the California Consumer Privacy Act as amended, where they apply to residents of those states.

Where two of these give you different rights, we apply whichever gives you more.

If we change this policy we will update the date at the top. If a change materially affects how we use data we already hold, we will say so on the site or by email before it takes effect.

2. The personal data we collect

When you visit the site. Your IP address, browser and device type, operating system, the pages you view, how long you spend on them, and the site or search that sent you. This comes from server logs and from the analytics and advertising tools listed in section 5.

When you contact us or fill in a form. Your name, email address, company name, website, role, and whatever you write in the message field. Our enquiry form also asks for your company’s annual recurring revenue band, your marketing budget band and your product category. Those are business details rather than personal ones, but they arrive attached to your name, so we treat them with the same care.

When you subscribe to something. Your name and email address, and a record of what you subscribed to and when. Every marketing email we send carries an unsubscribe link.

When you become a client. The above, plus the contact details of the people we work with on your side, billing details, access credentials or delegated access to the accounts we are engaged to work in, and the material you send us to do the work.

What we do not collect. We do not ask for, and do not want, special category data — health, biometrics, political opinions, religious beliefs, trade union membership, sexual orientation, or data about criminal convictions. We do not knowingly collect data about anyone under 18. We do not buy contact lists, and we do not scrape personal contact data for outbound marketing.

3. Why we use it, and our legal basis

What we doWhyLegal basis
Reply to your enquiry, scope work, send a proposalYou asked us toSteps taken at your request before entering a contract
Deliver the services we are engaged forTo perform the contractContract
Invoice you and keep accounting recordsTo get paid and to meet tax lawContract; legal obligation
Send you our newsletter or contentTo stay in touch with people who asked us toConsent, which you can withdraw at any time
Measure how the site is used and improve itTo run a business that worksLegitimate interests, balanced against your privacy
Keep the site and our systems secureTo prevent fraud and abuseLegitimate interests
Respond to a legal request or defend a claimBecause we have toLegal obligation; legitimate interests

We do not make decisions about you by automated means that produce legal or similarly significant effects.

4. How we collect it

Directly from you, through the contact form on this site, by email, on calls, or during client onboarding. Automatically, through cookies and the analytics tools in section 5, when you use the site. Occasionally from public business sources — a company website, a public directory or a professional network — when we are researching a company that has approached us.

5. Who we share it with

We do not sell personal data, and we do not share it for anyone else’s advertising.

We use the following service providers, each of which processes some personal data on our behalf under a data processing agreement:

ProviderWhat it doesWhere it processes data
Brevo (Sendinblue SAS)Our CRM. Holds enquiry and client contact records, and sends both our marketing email and the transactional mail this site generatesEuropean Union (France)
Namecheap / EasyWPHosts this website and its database, which is where form submissions are first storedUnited States
Google — Analytics 4, Search Console, Site KitWebsite analytics and search performance measurementUnited States and other Google locations
Meta — Meta Pixel, deployed via PixelYourSiteMeasures the performance of our own advertisingUnited States
PaystackProcesses client payments. Card details go to Paystack directly; we never see or store themNigeria, South Africa and their sub-processors

We may also disclose personal data to our professional advisers where they need it to advise us, to a public authority where the law requires it, and to a buyer and their advisers if we ever sell or transfer the business — in which case we would tell you first.

6. Sending data across borders

We are based in Kenya, our clients are in the United States and the United Kingdom, and our providers are in the EU, the US and elsewhere — so your personal data will be transferred across borders.

Where data covered by the GDPR or the UK GDPR leaves the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses, or on the provider’s own approved transfer mechanism, together with the security measures in section 7. Where the Kenyan Data Protection Act applies, we transfer data only where the conditions in section 48 of that Act are met.

You can ask us for details of the safeguards that apply to a specific transfer.

7. How we protect it

The site runs over HTTPS. Access to our CRM, hosting and analytics accounts is restricted to people who need it and protected by strong, unique passwords and two-factor authentication where the provider supports it. Client credentials are held in a password manager, never in email or documents, and we ask for delegated account access rather than shared logins wherever a platform allows it. We remove access when an engagement ends.

We are a small business and we describe our security honestly: these are proportionate measures, not a certified information security management system. We do not currently hold SOC 2 or ISO 27001 certification. If your procurement process requires specific controls, tell us early and we will tell you plainly whether we meet them.

No system is completely secure. If a breach affects your personal data and is likely to cause you harm, we will notify you and the relevant authority — within 72 hours of becoming aware of it, as required under the GDPR and the Kenyan Act.

8. Data we handle for clients

When we run advertising or analytics inside a client’s own accounts, the client decides what is collected and why. They are the controller; we act on their instructions as a processor, and we do not use anything we see there for our own purposes.

In practice this means we may see audience definitions, conversion data and lead records inside a client’s Google, Meta, LinkedIn, analytics or CRM accounts. We do not export that data, we do not combine it with anything else, and we delete or lose access to it when the engagement ends.

If you are a client and need a written data processing agreement, ask and we will provide one before work starts.

9. How long we keep it

DataRetention
Enquiries that do not become clients24 months from your last contact with us, then deleted
Client records and correspondenceFor the engagement, then 7 years, to meet Kenyan tax and limitation periods
Invoices and accounting records7 years, as required by law
Marketing subscribersUntil you unsubscribe, then a suppression record only, so we do not email you again
Website analytics14 months in Google Analytics 4; server logs are kept for a shorter period by our host

10. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you, and get a copy;
  • correct anything inaccurate or incomplete;
  • delete it, where we have no continuing basis to keep it;
  • restrict or object to how we use it, including objecting to direct marketing at any time;
  • receive it in a portable format, where we hold it on the basis of consent or a contract;
  • withdraw consent you have given, without affecting what we did before you withdrew it.

If you are a California resident, you also have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA.

To exercise any of this, email administrator@momentumadworks.net. We will respond within 30 days, or sooner where the law requires it. We may ask you to confirm your identity first, and we do not charge for a reasonable request.

If you are unhappy with how we have handled it, you can complain to the Office of the Data Protection Commissioner in Kenya (odpc.go.ke), or to the supervisory authority in your own country if you are in the EEA or the UK. We would rather you came to us first.

11. Cookies and tracking

We use cookies and similar technologies for three things:

  • Essential — making the site work: page delivery, security, and remembering that you submitted a form. These cannot be turned off.
  • Analytics — Google Analytics 4, so we can see which pages people read and where they arrive from.
  • Advertising — the Meta Pixel, so we can measure whether our own advertising works.

You can block or delete cookies in your browser settings; the essential ones aside, the site will still work. Where a consent banner is shown, your choice is recorded and applied. We honour Global Privacy Control and Do Not Track signals where the underlying tool supports them.

Google and Meta set cookies under their own policies: Google Privacy Policy · Meta Privacy Policy.

12. Children

Our services are sold to businesses and are not directed to anyone under 18. We do not knowingly collect their data, and if we learn that we have, we delete it.

13. Contact

Momentum AdWorks
Karen Ridge Road, Nairobi, Kenya
administrator@momentumadworks.net
+254 702 549117

For anything in this policy, including a data processing agreement or details of a specific transfer safeguard, email us and put “Privacy” in the subject line.