Hope Nest Privacy Policy

Children's Home Management System (CHMS) — Organizational Data Protection

DRAFT FOR ORGANIZATIONAL & LEGAL REVIEW

1. Introduction & Commitment to Child Protection

Hope Nest is committed to safeguarding the privacy, dignity, and rights of all children in our care, our staff, volunteers, and supporters in strict compliance with the Kenya Data Protection Act, 2019 and statutory child protection guidelines.

2. Categories of Data Collected

The system securely processes:

3. Authentication & Access Controls

All administrative access requires verified Google OAuth/OpenID Connect authentication or cryptographically signed session tokens. Multi-tenant home isolation guarantees that authorized personnel only access records relevant to their assigned home workspace.

4. Sensitive Data & Safeguarding Isolation

Child safeguarding reports and sensitive medical records are strictly partitioned from general staff feeds and financial ledgers. All break-glass access to sensitive dossiers is recorded in an immutable audit log.

5. Retention & Security Measures

Data is protected at rest using AES-256-GCM encryption and in transit using TLS 1.2+. Automated backup snapshots are retained in accordance with statutory requirements.

6. Contact & Data Subject Requests

For data access, correction, or inquiries regarding child protection data handling, please contact the Hope Nest Designated Safeguarding Lead (DSL) or Data Controller.

← Return to Login