Legal
Privacy Policy
How Autsos collects, uses, shares, and protects your personal information, worldwide.
Autsos (“we”, “us”, “our”) is based in Kenya and operates this website and its editorial content about technology, automobiles, science, and everyday life. This Privacy Policy explains what personal data we collect, why, how we use and share it, where it goes, and the rights available to you. It is written to address, where applicable to you: the EU and UK General Data Protection Regulation (“GDPR” / “UK GDPR”); Kenya’s Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021; the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”) and comparable US state laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon, Montana, and others as they take effect); Canada’s PIPEDA and CASL; Brazil’s LGPD; Australia’s Privacy Act 1988; Japan’s APPI; South Korea’s PIPA; India’s DPDP Act, 2023; South Africa’s POPIA; Nigeria’s NDPR; the UAE’s PDPL; and Switzerland’s revised FADP.
Where a term in this policy is defined differently under a specific law that applies to you, the definition under that law controls for your situation.
If you do not agree with this policy, please do not use the site.
1. Who is responsible for your data
The data controller (or, under Kenya’s Act, the “data controller”; under CCPA, the “business”) is:
Autsos, Nairobi, Kenya Email: getautsos@gmail.com
EU, UK, and Swiss representatives
Because we are established outside the EU, UK, and Switzerland but may regularly offer content to, or monitor the behaviour of, individuals there, we will appoint an EU representative (Art. 27 GDPR), a UK representative (Art. 27 UK GDPR), and a Swiss representative where our processing meets the applicable thresholds. Once appointed, their contact details will be published on this page. Until an appointment is made, you may direct any GDPR/UK GDPR-related request to getautsos@gmail.com, and we will handle it as though a representative were already in place.
Kenya
We are registered (or in the process of registering, as applicable) as a data controller with Kenya’s Office of the Data Protection Commissioner (ODPC), our lead supervisory authority.
2. Scope
This policy covers personal data collected through the website, our newsletter, and any forms, surveys, or comment features we offer. It does not cover third-party sites we link to, or advertisers’ own sites once you leave ours.
3. Personal data we collect
- Information you provide directly. Your email address when you subscribe to the newsletter; your name and message when you contact us; anything you submit through forms, surveys, or comment features; and information you send us when pitching a story.
- Information collected automatically. IP address, approximate location derived from IP, browser type and version, operating system, device type, referring URL, pages viewed, time and date of visits, and interactions with content.
- Cookies and similar technologies. Identifiers stored in cookies, local storage, and pixels. See our Cookie Settings page for full detail.
- Advertising and analytics data. Data collected by third-party advertising and analytics partners, including Google AdSense, described in Sections 7 and 8. Advertising cookies are set only where you have consented, or where consent is not legally required and we rely on legitimate interests for non-personalised advertising.
We do not intentionally collect special categories of personal data (health, biometric, genetic, political, religious, or trade-union data, or data revealing racial or ethnic origin) or, under Kenya’s Act, “sensitive personal data,” and we ask that you do not submit any of this to us.
4. How we use your data, and our legal bases
We use personal data to:
- Provide, operate, and maintain the site;
- Send the newsletter, if you subscribed (in compliance with CASL, CAN-SPAM, and equivalent anti-spam laws, including an unsubscribe link in every message);
- Respond to enquiries, pitches, and support requests;
- Measure and improve the site’s performance and content;
- Display advertising, including personalised advertising where you have validly consented or where consent is not required in your jurisdiction;
- Detect, prevent, and address fraud, abuse, security incidents, and violations of our Terms of Service;
- Comply with legal obligations and respond to lawful requests from public authorities.
Under the GDPR, UK GDPR, and Kenya’s Data Protection Act (which mirrors the GDPR’s legal-basis structure), our bases are: consent (newsletter opt-in, non-essential cookies, personalised advertising); legitimate interests (site security, product analytics, non-personalised advertising, fraud prevention) balanced against your interests and rights; performance of a contract (delivering content or services you request); and legal obligation (tax, accounting, and lawful government requests).
Under CCPA/CPRA and comparable US state laws, we process personal information for the “business purposes” and “commercial purposes” described above and do not use sensitive personal information for purposes beyond what those laws permit without additional notice.
5. How we share your data
- Service providers / processors. Hosting, email delivery, analytics, advertising, and security vendors who process data on our behalf under written data-processing agreements that impose confidentiality, security, and use-limitation obligations.
- Advertising partners, including Google and its partners (Section 7).
- Analytics partners.
- Legal and safety. When required by law, subpoena, or court order, or to protect the rights, property, or safety of Autsos, our users, or the public, after assessing the legality and proportionality of the request.
- Business transfers. In connection with a merger, acquisition, financing, restructuring, or sale of assets, subject to this policy (recipients will be bound by materially equivalent protections).
We do not sell personal data for money. Where “sale” or “sharing” is defined broadly (e.g., under CCPA/CPRA, to include cross-context behavioural advertising), you can opt out as described in Section 10.
6. International data transfers
Our service providers may process data in the United States, the European Economic Area, the United Kingdom, and other countries, including Kenya. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, the EU–US Data Privacy Framework (where the recipient is certified), and, where required, a documented Transfer Impact Assessment. Kenya’s Data Protection Act similarly requires appropriate safeguards for cross-border transfers, which we apply. You may request a summary of the safeguards used for a specific transfer by contacting us.
7. Advertising and Google AdSense
We display advertising through Google AdSense and may use other advertising networks. Google and its partners use cookies, mobile identifiers, and similar technologies to serve and measure ads.
- Google’s advertising cookies enable it and its partners to serve ads based on your visits to this and other sites.
- EEA, UK, and Switzerland: we obtain consent for personalised advertising. Google’s Consent Mode is configured with all consent signals set to “denied” by default and updated when you make a choice in the banner. Non-personalised ads are shown where consent is declined or not yet given, and no personalised-advertising cookies are set in that case.
- Elsewhere: you can opt out of personalised advertising via Google Ads Settings (adssettings.google.com) or aboutads.info.
- We do not knowingly enable personalised advertising to users we believe are under the applicable age of consent in their jurisdiction (16 in the EEA by default, 13 under COPPA in the US, unless a lower age applies and consent is properly obtained).
- Where Google’s Restricted Data Processing setting is relevant to you (e.g., California), it is applied per Google’s published mechanism.
8. Cookies and similar technologies
We use strictly necessary, analytics, and advertising cookies, described in full including specific cookie names, providers, and durations — in our Cookie Settings page, which forms part of this policy. You can accept or reject non-essential cookies when the banner is shown, and you can reset your choice at any time by clearing your browser’s cookies or site data for this domain and reloading the page. You can also block cookies through your browser settings. We do not currently respond to the Global Privacy Control (GPC) signal.
9. Your rights, by region
European Economic Area, UK, and Switzerland (GDPR/UK GDPR/FADP): access, rectification, erasure, restriction, objection (including to direct marketing and profiling), data portability, withdrawal of consent, and the right to lodge a complaint with your supervisory authority.
Kenya (Data Protection Act, 2019): access, correction, erasure, objection to processing, restriction, data portability, and the right to complain to the ODPC.
California and other US states with comprehensive privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, and others): the right to know/access, delete, correct, opt out of sale/sharing and targeted advertising, limit use of sensitive personal information, opt out of certain profiling/automated decision-making, data portability, and non-discrimination for exercising these rights.
Canada (PIPEDA): access, correction, and the right to complain to the Office of the Privacy Commissioner of Canada; newsletter communications comply with CASL’s consent and unsubscribe requirements.
Brazil (LGPD): confirmation of processing, access, correction, anonymisation/blocking/deletion of unnecessary or excessive data, portability, information about sharing, revocation of consent, and the right to complain to the ANPD.
Australia (Privacy Act 1988): access and correction, and the right to complain to the OAIC if unresolved.
Japan (APPI), South Korea (PIPA), India (DPDP Act 2023), South Africa (POPIA), Nigeria (NDPR), UAE (PDPL): access, correction, deletion, and objection rights broadly consistent with the above, and the right to complain to your local regulator (respectively the PPC, PIPC, Data Protection Board of India, Information Regulator, NITDA/NDPC, and UAE Data Office).
This list is a good-faith summary, not exhaustive of every local variation. Where a right described above is broader than what local law actually requires, we will still make reasonable efforts to honour your request.
10. How to exercise your rights
Email getautsos@gmail.com with your request and enough information for us to verify you are the person the data relates to (or an authorised agent, in which case we may also need to verify the agent’s authority). We will respond within the timeframe required by the law that applies to you (generally 30 days under GDPR/Kenya’s Act, 45 days under CCPA/CPRA, extendable where legally permitted). We do not charge a fee for a reasonable request and will not discriminate against you for making one.
11. Data retention
| Data category | Typical retention | Basis |
|---|---|---|
| Newsletter subscription data | Until you unsubscribe, plus a short suppression-list period | Consent / legitimate interest in honouring opt-outs |
| Contact / pitch enquiries | Up to 24 months after last contact | Legitimate interest in managing correspondence |
| Analytics data | Up to 26 months | Consent / legitimate interest |
| Advertising identifiers | Per Google’s and partners’ published retention periods | Consent / legitimate interest |
| Security and fraud-prevention logs | Up to 12 months | Legitimate interest / legal obligation |
We delete or anonymise data once it is no longer needed for these purposes, unless a longer period is required by law.
12. Security and breach notification
We use administrative, technical, and organisational measures designed to protect personal data, including encryption in transit, access controls, and vendor due diligence. No method of transmission or storage is completely secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within the timeframe required by applicable law (e.g., 72 hours under GDPR, without unreasonable delay under Kenya’s Act and most US state laws) and will notify affected individuals without undue delay where the risk is high, as required by the law that applies to you.
13. Children’s privacy
The site is not directed to children. We do not knowingly collect personal data from children under 13 (the threshold under the US COPPA), or under the applicable age of digital consent in the EEA/UK (13–16, depending on member state), Kenya, or your local law, without verifiable parental consent where required. We do not knowingly serve personalised advertising to users we believe are under these thresholds. If you believe a child has provided us data without appropriate consent, contact us and we will delete it.
14. Automated decision-making and profiling
We do not make decisions that produce legal or similarly significant effects about you through fully automated processing without human involvement. Advertising personalisation is based on inferred interests and can be disabled as described in Sections 7–10, including, where applicable, opting out of automated profiling used for targeted advertising under CPRA and similar laws.
15. Do Not Sell/Share and Global Privacy Control
We do not sell personal data for money. To the extent any data sharing with advertising partners is treated as a “sale” or “sharing” under CCPA/CPRA or similar laws, you can opt out at any time by clearing your browser’s cookies or site data for this domain, which resets your stored preference and shows the consent banner again on your next visit. We do not currently treat the Global Privacy Control signal as an opt-out request; where required by law, we honour opt-out requests submitted by email to getautsos@gmail.com.
16. Third-party links
Our content links to third-party sites we do not control. This policy does not apply to them; review their own privacy policies before providing them data.
17. Changes to this policy
We may update this policy to reflect changes in our practices or the law. Material changes will be posted on this page with a new effective date, and, where required, we will seek fresh consent. The previous version’s date is noted at the top of this page. Continued use of the site after changes take effect constitutes acceptance to the extent permitted by law.
18. Contact
Questions, requests, or complaints: getautsos@gmail.com.