Last updated: 17 August 2026 · Effective: 17 August 2026
Castalia is a venture evaluation platform built on the SVIE OS framework. We are operated by Castalia Kenya Limited, registered in Kenya. When this policy says "Castalia", "we", "us", or "our", it means us.
Our contact for data matters: dataprivacy@castalia.co.ke · castalia.co.ke · Nairobi, Kenya.
We only collect data that is necessary to operate the platform. Here is what that means in practice:
When you create an account, we collect your name, email address, and (if you sign in with Google) your Google profile name and profile picture. We use this to identify you, secure your account, and contact you about your evaluation. We do not sell this to anyone.
The answers you provide during an SVIE OS evaluation — your problem description, customer validation evidence, business model details, and all other module responses — are private to you by default. This is your venture intelligence. It belongs to you.
Your evaluation data is shared with third parties only in two circumstances: (a) you explicitly choose to share your profile with a Tier 2 or Tier 3 partner on the platform, or (b) we are required to by law. We will tell you before sharing unless a court order prevents us from doing so.
If you use the in-app chat helper, we store your conversation — your messages, the assistant's replies, and any files you attach — so you can return to past conversations and so the assistant can use earlier context in the same thread. This history is private to your account: we don't use it to answer other users' questions, and staff cannot browse your conversation content directly. You can delete any conversation permanently at any time from the chat panel, which also removes any files you attached to it.
We do keep a separate, lightweight record of the questions asked and answers given (without your full conversation thread) so we can identify common questions and improve the platform's help content. This record is used for improving the product, not for personalising ads or profiling you individually.
If your evaluation includes sector-specific compliance modules, any evidence you upload (licences, permits, registration documents, or other supporting files) is stored against your evaluation and treated with the same privacy protections as your other evaluation data. It is not shared with regulators or third parties by us; you remain responsible for your own regulatory filings.
If you pay for a plan or credits, we collect the billing details needed to process payment. Card payments are handled by Stripe; M-Pesa payments are handled via Safaricom's M-Pesa API. We do not store your full card number. For M-Pesa, we retain your phone number and transaction reference to confirm and reconcile payment. We do not have access to your M-Pesa PIN or banking credentials.
If you contact support or raise a ticket, we store your message and any files you attach so we can respond and keep a record of the resolution. If you subscribe to our newsletter, we store your email address and subscription status; you can unsubscribe at any time via the link in any newsletter email or by contacting us.
If you upload a profile photo, or if you create or join a studio or investor organisation, we store that image and the organisation's name, logo, and country. Organisation admins can see the profile information of members associated with their organisation (for example, a studio can see the founders in its cohorts).
If a studio invites you into a cohort, or an investor invites you to evaluate via their invite link, the studio or investor may provide us with your name and email address to send that invitation. If you are matched to an investor thesis, or an investor leaves notes on your venture in their deal pipeline, that information is stored against your venture profile. If you do not match an investor's thesis, the investor is told that you applied and did not match, and why — this explanation may reference details from your evaluation.
We collect basic usage data — which pages you visit, how long you spend on each module, whether you complete an evaluation. We use this to improve the platform. We do not build advertising profiles. We do not sell usage data.
Your evaluation answers are processed by Google Gemini to generate your scored results and evaluation feedback. This is subject to Google's own data processing terms, and we configure our use of their API to prevent your data from being used to train their underlying models. If you have questions about this processing, email us.
Under the Kenya Data Protection Act 2019, we must have a lawful reason to process your data. Our reasons are:
If you are using Castalia from Nigeria, your data processing is also conducted in accordance with Nigeria's Nigeria Data Protection Act 2023 (NDPA). If you are in South Africa, it is conducted in accordance with the Protection of Personal Information Act 2013 (POPIA). In all cases, the Kenya DPA 2019 standard applies as our baseline, and where another country's law is stricter, we apply the stricter standard.
Some of the infrastructure providers we use to run Castalia are hosted outside Kenya. This means your personal data may be transferred to and processed in other countries, including the United States and the European Union, by the following categories of provider:
Under the Kenya Data Protection Act 2019, we may only transfer personal data outside Kenya where appropriate safeguards are in place. Our safeguards include: using providers that are contractually bound by their own data processing terms and industry-standard security certifications, transmitting all data over encrypted connections, and limiting what is sent to each provider to what is necessary for the service they perform. We do not transfer sensitive personal data outside Kenya without your consent.
Under the Kenya Data Protection Act 2019 (and applicable regional laws), you have the right to:
To exercise any of these rights, email dataprivacy@castalia.co.ke. We aim to acknowledge your request within 7 days and resolve it within 30 days — the same timeframe the Act sets for data portability requests, which we apply as our standard for all rights requests. Complex or unusual requests may take longer; we will tell you if that's the case and why.
We take data security seriously. Specifically:
No system is perfectly secure. If we ever suffer a data breach that affects your personal data, we will notify you within 72 hours and report it to the Office of the Data Protection Commissioner (Kenya) within the legally required timeframe.
We use only the cookies necessary to keep you logged in (session cookies). We do not use advertising cookies, tracking pixels, or third-party analytics cookies. You can disable cookies in your browser, but doing so will prevent you from staying logged in.
Castalia is designed for adults operating or evaluating businesses. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, contact us at dataprivacy@castalia.co.ke and we will delete the account immediately.
If we make material changes to this policy, we will notify you by email at least 14 days before the changes take effect. Non-material changes (like fixing typos) will be updated without notice. The "last updated" date at the top of this page always shows when the policy was last changed.
For privacy questions: dataprivacy@castalia.co.ke
If you are not satisfied with our response, you have the right to complain to the Office of the Data Protection Commissioner (ODPC) in Kenya at odpc.go.ke.