πŸ›‘οΈKenya Data Protection Act, No. 24 of 2019

Your Privacy,
Our Commitment.

This policy explains how MorduMark collects, uses, and protects your personal data in full compliance with Kenyan data protection law.

Effective Date
2026-04-01
Last Updated
2026-04-01
Jurisdiction
Nairobi, Kenya
01

About MorduMark & This Policy

MorduMark is a product of Mordulabs, a recruitment and hiring platform duly registered and operating in Nairobi, Kenya. We empower organizations to create job postings, receive applications, conduct AI-assisted CV analysis, and manage end-to-end recruitment workflows with efficiency and precision.

This Privacy Policy explains how MorduMark, acting as a Data Controller under the Kenya Data Protection Act, No. 24 of 2019 ("the Act"), collects, uses, stores, processes, discloses, and protects personal data. It applies to all users β€” employer organizations, their personnel, and job applicants.

By registering an account or submitting an application through our platform, you acknowledge that you have read and understood this Privacy Policy.

02

Our Role Under the Kenya DPA

MorduMark operates as a Data Controller in respect of all personal data processed through the platform. Where we engage third-party service providers (e.g., cloud infrastructure providers), those parties act as Data Processors under our instructions, pursuant to written data processing agreements as required by Section 37(3) of the Act.

MorduMark is registered with the Office of the Data Protection Commissioner (ODPC) as required under the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021.

03

Data Protection Principles

In accordance with Section 25 of the Act, MorduMark ensures all personal data is:

  • Processed in accordance with the right to privacy of the data subject
  • Processed lawfully, fairly, and in a transparent manner
  • Collected for explicit, specified, and legitimate purposes and not further processed in incompatible ways
  • Adequate, relevant, and limited to what is necessary (data minimisation)
  • Accurate and kept up to date, with inaccurate data erased or rectified without delay
  • Kept for no longer than is necessary for the purposes collected
  • Not transferred outside Kenya unless adequate data protection safeguards are in place or consent is given
04

Personal Data We Collect

A. Employer / Organisation Registration Data

  • First Name and Last Name
  • Organisation Name and Industry
  • Country and Billing Currency
  • Hiring Frequency
  • Company Website (optional)
  • Email Address
  • Encrypted Password

B. Job Posting Data

  • Job Title, Department, and Job Type
  • Industry / Category and Experience Level
  • Salary Range and Work Policy (Remote / Hybrid / Onsite)
  • Job Description, Requirements, and related metadata

C. Applicant / Candidate Data

  • First Name and Last Name
  • Email Address
  • Phone Number (optional)
  • Resume / CV document
  • Cover Letter (optional)
  • Application activity timestamps

Note: Applicants are the primary data subjects in respect of this data. Employers accessing applicant data through our platform do so as authorised parties acting under our data processing terms.

D. Technical & Usage Data

  • IP address and device information
  • Browser type and version
  • Login records and session timestamps
  • Usage analytics and platform navigation data
  • Security logs
05

Lawful Basis for Processing

MorduMark processes personal data under one or more of the following lawful bases under Section 30 of the Act:

  • Consent β€” freely given, specific, informed, and unambiguous consent for one or more purposes
  • Contractual Necessity β€” necessary for the performance of a contract with the data subject
  • Legal Obligation β€” necessary for compliance with Kenyan law
  • Legitimate Interests β€” necessary for MorduMark's legitimate interests, where not overridden by the data subject's rights

Where we rely on consent, data subjects may withdraw it at any time without detriment. Withdrawal does not affect the lawfulness of prior processing.

06

Sensitive Personal Data

MorduMark does not deliberately collect sensitive personal data as defined under Section 2 of the Act (including data on health, race, ethnic origin, religious beliefs, genetic or biometric data, marital status, or criminal history).

If such data is incidentally included in a CV or cover letter, it will be handled with additional care and accessed only where strictly necessary. Applicants are advised to omit sensitive data from applications where not directly relevant.

07

How We Use Personal Data

  • Creating and managing organisation accounts and user profiles
  • Publishing and managing job listings on behalf of employers
  • Receiving, storing, and processing job applications
  • Providing AI-assisted CV analysis and candidate matching (see Section 8)
  • Communicating with users regarding accounts, applications, or listings
  • Improving and maintaining platform functionality and user experience
  • Preventing fraud, abuse, and security threats
  • Complying with legal and regulatory obligations under Kenyan law
08

AI-Based CV Analysis

MorduMark utilises internally developed AI models hosted on Microsoft Azure to assist with resume/CV analysis, including:

  • Automated skills and qualification extraction
  • Experience relevance scoring
  • CV summarisation and candidate-job fit recommendations
  • Matching of candidate profiles to role requirements
βš–οΈ Human Oversight Guarantee

In accordance with Section 32 of the Act: applicants are informed when their CV is subject to automated processing; final hiring decisions are always made by a human; and data subjects may request that significant decisions not be made solely on the basis of automated processing.

09

Data Storage & Security

A. Data Localisation

In compliance with Section 25(h) of the Act, MorduMark ensures that at least one serving copy of personal data is stored on a server or data centre located in Kenya.

B. Cross-Border Data Transfers

Where personal data is processed outside Kenya through Microsoft Azure infrastructure, MorduMark implements safeguards under Sections 48–50 of the Act, including contractual protections, transfer to adequate jurisdictions, and explicit informed consent where required.

C. Security Measures

  • Encrypted data transmission using HTTPS/SSL protocols
  • Role-based access controls limiting data access to authorised personnel
  • Authentication and credential protection mechanisms
  • Regular data backups and recovery systems
  • Continuous activity monitoring and security logging
  • Secure cloud hosting standards via Microsoft Azure
10

Data Breach Notification

In the event of a personal data breach posing a real risk of harm, MorduMark will comply with Section 43 of the Act, including:

  • Notifying the ODPC without undue delay
  • Informing affected data subjects as soon as reasonably practicable
  • Documenting the nature of the breach, data affected, and remedial measures taken
11

Data Retention

  • Applicant and recruitment data is retained for up to 90 days following job closure
  • Employer account data is retained for the duration of the active account and a reasonable period thereafter
  • Employers may request earlier deletion of applicant data
  • Technical logs may be retained longer for security, fraud prevention, or legal compliance

At the end of the retention period, personal data is securely deleted or anonymised so it can no longer be attributed to an identifiable individual.

12

Sharing & Disclosure of Personal Data

MorduMark does not sell, rent, or trade personal data. We may share data only in limited circumstances:

  • With registered employer organisations, solely for evaluating applications to their listed vacancies
  • With authorised MorduMark personnel who require access to perform their duties
  • With trusted cloud infrastructure providers (e.g. Microsoft Azure) under written data processing agreements
  • With the ODPC, regulatory bodies, courts, or law enforcement where required by law
13

Your Rights as a Data Subject

Under the Act, you have the following rights regarding your personal data:

πŸ”
Right of Access (S.26)
Request confirmation and a copy of your personal data we hold.
✏️
Right to Rectification (S.40)
Request correction of inaccurate or outdated personal data.
πŸ—‘οΈ
Right to Erasure (S.39)
Request deletion of your personal data where no longer necessary.
🚫
Right to Object (S.35)
Object to processing of your data in certain circumstances.
⏸️
Right to Restrict (S.34)
Request restriction of processing in certain circumstances.
πŸ“¦
Right to Portability (S.38)
Receive your data in a structured, machine-readable format.
↩️
Withdraw Consent
Withdraw consent at any time without affecting prior processing.
πŸ“£
Lodge a Complaint
File a complaint with the ODPC if your rights have been violated.

To exercise any right, contact us at the details in Section 17. We will respond within the timeframes prescribed by the Act.

14

Automated Decision-Making

MorduMark uses automated processing tools to assist with CV analysis and candidate ranking. In accordance with Section 32 of the Act, you have the right to:

  • Be informed when automated decision-making processes are applied to your personal data
  • Request that a significant decision affecting you not be based solely on automated processing
  • Request human review of any automated recommendation that materially affects your application

MorduMark ensures that no hiring decision is made without meaningful human involvement by the relevant employer.

15

Cookies & Tracking Technologies

MorduMark uses cookies and similar technologies for:

  • Authentication β€” to keep you securely logged in
  • Performance β€” to improve platform speed and reliability
  • Security β€” to detect and prevent fraudulent activity
  • User Preferences β€” to remember your settings
  • Analytics β€” to understand how users interact with our platform

You may control or disable cookies through your browser settings. Disabling certain cookies may affect platform functionality.

16

Children & Minors

MorduMark is a professional recruitment platform intended exclusively for adults. We do not knowingly collect or process personal data of persons under the age of 18. If you believe a minor has submitted data through our platform, please contact us immediately and we will delete such data promptly, in line with Section 33 of the Act.

17

Data Protection Officer

MorduMark has appointed a Data Protection Officer (DPO) responsible for overseeing compliance with the Act and acting as a point of contact for data subjects and the ODPC.

πŸ“‹ MorduMark DPO
  • Name: Dorcas Mosiori
  • Email: dorcas.mosiori@mordulabs.com
  • Address: Westlands, Nairobi, Kenya
πŸ›οΈ ODPC Contact
  • Website: www.odpc.go.ke
  • Britam Towers, 12th Floor
  • Hospital Road, Upperhill, Nairobi
18

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. When we make material changes, we will:

  • Post the updated policy on our platform with a revised effective date
  • Notify registered users by email where the changes are significant

Continued use of the platform following notification of any updates constitutes acceptance of the revised Privacy Policy.

Nairobi, Kenya
www.mordumark.com Β· www.mordulabs.com Β· privacy@mordulabs.com
Β© 2026 MorduMark. All rights reserved.