Privacy Policy
Verity Legal Advisory — Trading name of Mishi Ponda and Company Advocates
Effective Date: 31st August 2026 • Last Updated: 3rd September 2026
1. Who We Are
Verity Legal Advisory ("Verity", "we", "us" or "our") is the trading name of Mishi Ponda and Company Advocates, a law firm incorporated and practising in Kenya.
Verity provides legal and advisory services through its practice areas, including Verity Growth, Verity Privacy, and Verity Legacy.
We are committed to handling personal data responsibly and in accordance with the Data Protection Act, 2019 of Kenya, the regulations and guidance issued under it, and, where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.
Registered Office: Indigo Cowork Space, General Mathenge Road, Spring Valley, P.O. Box 48620-00100, Nairobi, Kenya. Email: info@mishipondaadvocates.co.ke. Telephone: +254 781 335 956 / +254 758 793 110. Website: www.mishipondaadvocates.co.ke
For purposes of applicable data protection law, Mishi Ponda and Company Advocates is responsible for determining how and why personal data is processed in connection with our business and services.
2. About This Privacy Policy
This Privacy Policy explains how we collect, use, store, disclose and otherwise process personal data when you:
- visit our website;
- contact us by email, telephone or other digital means;
- submit an enquiry or request a Legal Health Check;
- book a consultation or appointment;
- engage us for legal or advisory services;
- communicate with us in relation to a legal matter;
- interact with our digital platforms or communications; or
- otherwise provide personal data to us in the course of our business.
Different processing activities may be subject to additional notices or contractual terms.
Client matters and professional confidentiality
Where you engage Verity as a client, the personal data contained in your matter file is also subject to the terms of your engagement with us and our professional duties as advocates, including duties of confidentiality and legal privilege.
Those obligations may affect how personal data in a client matter is accessed, disclosed, retained or deleted. In particular, requests to exercise data protection rights may be subject to limitations where compliance would conflict with legal professional privilege, confidentiality, our professional obligations, legal requirements or the establishment, exercise or defence of legal claims.
This Privacy Policy should therefore be read together with your engagement letter and any other terms applicable to the services we provide.
3. Personal Data We Collect
The information we collect depends on how you interact with us.
3.1 Information you provide to us
This may include:
Contact information
Your name, email address, telephone number, postal address and organization, or company name.
Enquiry information
The information you provide when you contact us, including the nature of your enquiry, messages, correspondence, and documents you choose to submit.
Consultation and appointment information
Information required to arrange and manage a consultation or appointment, including your name, contact details, reason for the appointment, and selected date and time.
Legal matter information
Information necessary to advise or represent you, which may include information relating to you, your organization, your legal matter, and other individuals involved in the matter.
Depending on the nature of the matter, this may include personal data belonging to third parties and, where legally relevant, sensitive or special categories of personal data.
Professional and business information
Information such as your organization, role, industry, business activities, funding stage and other information relevant to the legal or advisory services you seek.
Communication records
Records of correspondence and communication between you and Verity.
3.2 Information collected automatically
When you use our website, we may automatically collect certain technical and usage information, including:
- IP address;
- browser and device information;
- pages visited;
- approximate location derived from technical information;
- date and time of access;
- referring website or URL; and
- information about how you interact with our website.
The information collected will depend on the cookies, analytics, and other technologies actually operating on our website.
4. How We Use Personal Data
We process personal data for purposes including:
- responding to enquiries and requests;
- providing legal advice and representation;
- providing privacy, data protection and other advisory services;
- assessing whether and how we can assist you;
- managing consultations and appointments;
- communicating with clients, prospective clients and other relevant persons;
- opening, managing and maintaining client and matter files;
- carrying out conflict checks and other professional checks;
- complying with legal, regulatory and professional obligations;
- protecting our legal rights and interests;
- managing our business and internal administration;
- maintaining the security of our systems and information;
- preventing, detecting and responding to fraud, misuse or security incidents;
- improving our website, services and client experience; and
- carrying out any other purpose communicated to you at the point of collection or otherwise permitted by law.
We do not use personal data for purposes that are incompatible with the purpose for which it was collected unless permitted by applicable law.
5. Lawful Basis for Processing
We process personal data only where there is a lawful basis for doing so.
Depending on the circumstances, our lawful basis may include:
Consent
Where you have given consent to a specific processing activity, we may process your personal data on that basis.
You may withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Performance of a Contract
We may process personal data where processing is necessary to enter into or perform an agreement with you, including providing legal or advisory services.
Legal Obligation
We may process personal data where necessary to comply with a legal, regulatory or professional obligation applicable to Verity or the advocates practising through the Firm.
Legitimate Interests
We may process personal data where necessary for our legitimate interests, including managing our practice, responding to enquiries, maintaining business relationships, protecting our systems and rights, and improving our services, provided that doing so does not unfairly prejudice your rights and interests.
Other Lawful Bases
Where applicable, we may rely on other lawful grounds recognized under Kenyan law or, for EU data subjects, under the GDPR.
The applicable lawful basis will depend on the nature and circumstances of the processing.
6. Cookies and Similar Technologies
Our website may use cookies and similar technologies to support website functionality, understand how visitors use our website, and improve our services. Depending on the technologies operating on our website, these may include strictly necessary cookies, performance and analytics cookies (such as Google Analytics), functional cookies, and targeting or marketing cookies.
Where we use non-essential cookies, such as analytics, functional or marketing cookies, we will provide appropriate information and, where required by law, obtain your consent before using them.
You may also manage cookies through your browser settings. Disabling certain cookies may affect the functionality of the website.
7. When We Share Personal Data
We may disclose personal data where necessary and lawful for the purposes described in this Privacy Policy.
Depending on the circumstances, recipients may include:
Service Providers
We may use third-party providers to support our operations, including providers of:
- cloud storage and document management;
- website hosting;
- information technology and security services;
- email and communications services;
- appointment and scheduling services;
- customer or client relationship management systems;
- analytics services; and
- other business support services.
These providers may process personal data on our behalf. We take reasonable steps to ensure that such providers handle personal data in accordance with applicable data protection requirements.
Professional Advisers and Other Persons Assisting on a Matter
Where appropriate and lawful, we may share information with other advocates, lawyers, consultants, accountants, auditors, experts, investigators or other professional advisers involved in providing or supporting legal or advisory services.
Courts, Regulators and Public Authorities
We may disclose personal data where required or permitted by law, including to courts, tribunals, the Law Society of Kenya, the Office of the Data Protection Commissioner and other competent authorities.
Other Third Parties
We may disclose personal data where you have authorized us to do so or where disclosure is otherwise lawful and necessary to provide the services you have requested or to protect our legal rights and interests.
We Do Not Sell Personal Data
We do not sell your personal data to third parties.
8. International Transfers
Some of our service providers or other recipients of personal data may be located outside Kenya.
Where personal data is transferred outside Kenya, we will ensure that the transfer is undertaken in accordance with applicable Kenyan data protection requirements, including where applicable through appropriate safeguards, an adequacy decision, necessity or consent.
Where the GDPR applies, we will also comply with the applicable requirements governing international transfers of personal data under the GDPR.
We take reasonable steps to ensure that personal data transferred internationally receives an appropriate level of protection.
9. Data Security
We take reasonable and appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
Depending on the nature of the information and the risks involved, these measures may include:
- access controls;
- authentication mechanisms;
- encryption where appropriate;
- secure document and information storage;
- security monitoring;
- system and software updates;
- secure disposal procedures;
- confidentiality obligations;
- staff awareness and training; and
- measures designed to prevent and respond to security incidents.
No method of transmitting or storing information is completely secure. We therefore cannot guarantee absolute security, but we continuously seek to maintain appropriate safeguards having regard to the nature of the information and the risks involved.
10. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, or for as long as required or permitted by law.
When personal data is no longer required, we will take reasonable steps to securely delete, destroy or anonymise it, subject to any lawful retention requirement.
11. Your Data Protection Rights
Subject to applicable law and any lawful limitations, you may have rights in relation to your personal data, including the right to:
- be informed about the processing of your personal data;
- request access to personal data we hold about you;
- request correction of inaccurate or misleading personal data;
- request deletion of personal data in circumstances permitted by law;
- object to certain processing;
- request restriction of processing where applicable;
- request portability of personal data where the applicable legal requirements are satisfied; and
- withdraw consent where processing is based on consent.
These rights are not absolute. They may be limited where, for example, we are required or permitted by law to retain information, where disclosure would affect the rights of another person, or where information is protected by legal professional privilege or our professional duties of confidentiality.
To exercise your rights, contact us using the details in Section 17.
We may need to verify your identity before responding to a request.
We will respond to requests within the period required by applicable law, generally within twenty-one (21) days under the Data Protection Act, 2019 of Kenya, and within thirty (30) days under the GDPR, where applicable.
12. Legal Professional Privilege and Confidentiality
As a law firm, Verity is subject to professional duties of confidentiality and, where applicable, legal professional privilege.
Personal data contained in client and matter files may therefore be subject to legal or professional restrictions on access, disclosure, deletion or other forms of processing.
Nothing in this Privacy Policy is intended to waive, limit or override those protections.
13. Personal Data Relating to Other People
You may provide us with personal data relating to another person, for example in connection with a legal matter.
Where you do so, you should ensure that you are authorized to provide that information and, where required by law, that the relevant person has been appropriately informed.
In legal matters, however, it may not always be possible or appropriate for you to obtain the consent of every person whose information is relevant to a matter. In such circumstances, Verity will process the information only where there is a lawful basis for doing so.
14. Children's Data
Our services are generally directed towards adults and organizations.
However, because legal matters may involve children or information relating to children, we may process children's personal data where this is necessary and lawful in connection with a legal matter or our professional obligations.
Where we process children's data, we will apply the additional protections required under applicable law.
15. Personal Data Breaches
We maintain measures designed to prevent, detect, and respond to personal data breaches.
Where a personal data breach occurs, we will assess the nature and severity of the breach and take appropriate remedial action.
Where notification to the Office of the Data Protection Commissioner or affected individuals is required by applicable law, we will make the necessary notification within the applicable statutory timeframe.
16. Third-Party Websites and Services
Our website may contain links to third-party websites, platforms, or services.
We are not responsible for the privacy practices, security or content of third-party websites or services that we do not control.
We encourage you to review the privacy notices of those third parties before providing them with personal data.
17. How to Contact Us
If you have a question about this Privacy Policy, want to exercise a data protection right, or have a concern about how we handle personal data, please contact us first.
Verity Legal Advisory
Trading name of Mishi Ponda and Company Advocates
Email: info@mishipondaadvocates.co.ke. Telephone: +254 781 335 956 / +254 758 793 110
Address: Indigo Cowork Space, General Mathenge Road, Spring Valley, P.O. Box 48620-00100, Nairobi, Kenya
18. Complaints
We encourage you to contact us first if you have concerns about how we process your personal data so that we can have an opportunity to address them.
You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) where you believe that your rights under applicable Kenyan data protection law have been infringed.
Office of the Data Protection Commissioner
Website: www.odpc.go.ke
Where the GDPR applies, you may also have the right to lodge a complaint with the relevant supervisory authority in the European Union.
19. GDPR
The GDPR may apply to certain processing activities where its territorial requirements are met.
Where the GDPR applies, we will comply with the requirements applicable to that processing, including requirements relating to data subject rights, security, personal data breaches and international transfers.
Individuals to whom the GDPR applies may contact us using the details in Section 17 to exercise their applicable rights or raise concerns about our processing of their personal data.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in:
- our services or business operations;
- the way we process personal data;
- technology and security practices;
- applicable laws or regulatory requirements; or
- our privacy practices.
The Effective Date at the beginning of this Privacy Policy indicates when the current version took effect.
Where changes are material, we may provide additional notice where appropriate.
We encourage you to review this Privacy Policy periodically.
Last Updated: 3rd September 2026