Privacy Notice
Privacy Notice on data handling & mobile app compliance
At the Kenya Marine and Fisheries Research Institute (KMFRI) and ARBEC (developed and operated in technical partnership with Saharasoft Solutions Limited), we are committed to protecting your personal information in strict compliance with the Data Protection Act (2019) of Kenya, Apple App Store Review Guideline 5.1, and Google Play Store User Data & Data Safety policies.
This notice discloses how the ARBEC mobile applications (iOS and Android) and connected web platforms collect, use, store and share data, and how you can control your personal records.
1. Data collected & Google Play Data Safety alignment
In adherence to Google Play Data Safety standards and Apple App Privacy declarations, the app handles the following data types:
| Data category | Specific data handled | Purpose of collection |
|---|---|---|
| Personal identifiers | Full name, official email address, phone number (optional), organization or institution, job title, country of residence, and biography. | Account creation, conference accreditation, participant badge generation, and authentication. |
| Photos & documents | Profile avatar photographs, abstract and camera-ready PDF manuscripts, presentation slides, and custom registration file attachments. | User profile display, academic peer review, and conference proceedings compilation. |
| Financial & purchase data | Ticket purchase tier, invoice numbers (invoiceNumber), payment timestamps, and transaction settlement references. |
Registration fulfilment, ticketing invoicing, and financial reconciliation. Raw payment card details are never stored by ARBEC. |
| App activity & participation | Session bookmarks, saved agenda schedules, workshop selections, session attendance check-ins, and session question submissions. | Personal schedule synchronisation across devices and conference venue logistics. |
| Device & telemetry | Firebase Cloud Messaging device push tokens, device operating-system version, app version, network connectivity state, and crash error traces. | Delivering conference push alerts, offline sync diagnostics, and platform security audit logging. |
2. Device hardware permissions disclosed (iOS & Android)
The mobile app requests specific device permissions solely to provide functions you start yourself:
- Camera (
NSCameraUsageDescription/android.permission.CAMERA): used only to scan attendee QR codes for badge verification and event check-in. The camera is never accessed in the background. - Photo library & file storage (
NSPhotoLibraryUsageDescription,file_picker,image_picker): used only when you upload a profile avatar, attach verification files in custom registration forms, or submit academic PDFs for a Call for Papers. - Device calendar (
READ_CALENDAR/WRITE_CALENDAR): used by the calendar export module to save bookmarked sessions to your device calendar at your request. - Push notifications (
POST_NOTIFICATIONS): used by Firebase Cloud Messaging for schedule changes, session reminders, and official organiser announcements. This can be turned off at any time. - Audio and video playback (LiveKit / video player): used for viewing live-streamed keynotes or hybrid presentations. The app does not capture or transmit attendee microphone audio or camera video during playback.
3. Data storage, keychain & security measures
We protect user data using industry-standard technical safeguards:
- Secure token storage: authentication tokens are saved using encrypted platform storage (iOS Keychain and Android KeyStore via
flutter_secure_storage). - Transit encryption: all mobile network traffic is encrypted using Transport Layer Security (TLS 1.2 or later).
- Database isolation: multi-tenant isolation is enforced at the database layer with PostgreSQL row-level security policies and role-based access control.
- Audit trails: privileged administrative operations, registration status updates, and payment reconciliation events are recorded in an append-only audit trail.
4. Third-party service processors
Data is transferred only to the infrastructure and service providers needed to operate the platform:
- Cloud infrastructure: PostgreSQL database, TypeORM API services, Redis cache, and S3-compatible document storage.
- Google Firebase: Firebase Cloud Messaging, used strictly to transmit service and schedule notifications to registered device tokens.
- Payment gateways (Stripe and PayPal): payment processing occurs through secure hosted web views or provider SDKs. Billing credentials are submitted directly to the payment processor.
- Transactional messaging: secure email services used to dispatch verification codes, co-author invitations, and invoice receipts.
5. Account & data deletion (Apple and Google compliant)
In full compliance with Apple App Store Guideline 5.1.1(v) and the Google Play account deletion policy, users have an absolute right to permanently delete their account and personal records.
- Open the ARBEC mobile app and sign in to your account.
- Tap the Profile tab in the bottom navigation bar.
- Select Privacy & visibility.
- Tap Delete account and confirm your choice.
Web or email deletion request: if you cannot access the app, email director@kmfri.go.ke or nelson@saharasoftsolutions.com with the subject ARBEC Account Deletion Request from your registered email address.
What is deleted: your account profile, authentication credentials, biographical details, profile photograph, device push notification tokens, and personal session bookmarks are permanently purged from active systems within 30 days.
What is retained: historical tax, billing and accounting invoices (including invoiceNumber and settlement records) are retained strictly as required by the statutory financial audit laws of Kenya.
6. User privacy controls & consents
Through the in-app Profile > Privacy & visibility settings, attendees can manage:
- Directory visibility: whether your profile is discoverable by other delegates within the app.
- Marketing consent (
marketingConsent): opt in or out of conference news and promotional notices. - Data export (
dataExportConsent): download or request a machine-readable export of your participation data. - Notification topics: which categories of push notification you receive, via the notification preferences screen.
7. Statutory rights under the Kenya Data Protection Act, 2019
As a data subject you hold statutory rights to access your personal data, correct inaccuracies, object to processing, and lodge complaints with the Office of the Data Protection Commissioner of Kenya.
8. Contact information & data protection officer
Kenya Marine and Fisheries Research Institute (KMFRI) • ARBEC Secretariat
Email: director@kmfri.go.ke • nelson@saharasoftsolutions.com
Telephone: +254 (20) 8021561 / +254 712 003 853
Postal: P.O. Box 81651-80100, Mombasa, Kenya
Technical partner: Saharasoft Solutions Limited, Nairobi, Kenya.
Terms and Conditions
Terms and conditions of conference participation & platform use
These terms and conditions of conference participation and platform use (the "terms") govern your use of the ARBEC multi-tenant conference platform, including the official mobile applications distributed through the Apple App Store and Google Play Store, and the connected web services.
The platform is co-organised by the Kenya Marine and Fisheries Research Institute (KMFRI) and operated in technical partnership with Saharasoft Solutions Limited.
By creating an account, registering for a conference edition, submitting an abstract, or downloading and using the mobile application, you agree to these terms.
1. Platform scope and role-based permissions
ARBEC provides digital tools structured around explicit conference roles:
- Attendees: browse multi-day programmes (today, sessions, tracks, rooms, speakers, posters), bookmark sessions, sync schedules across devices, view ticket QR codes, and take part in session questions.
- Authors and presenters: submit abstracts and full manuscripts, manage co-author invitations, upload camera-ready papers, and review peer-review decisions.
- Reviewers: access assigned submission workloads, evaluate scientific contributions, and record review recommendations.
- Organisers and staff: manage conference configurations, build custom registration forms, publish announcements, moderate listings, process refunds, and verify admissions using on-site QR code scanning.
2. User account registration and security
- Account credibility: you agree to provide true, accurate and current information when creating an account and registering for conference editions.
- Credential confidentiality: you are responsible for safeguarding your password. Authentication tokens are securely managed on your device; you must not attempt to extract, share or tamper with them.
- Device security: you must immediately report any suspected compromise of your account or unauthorised access to the ARBEC Secretariat.
3. Conference discovery, registration & applications
Conferences and editions are listed through the ARBEC marketplace:
- Ticket types: organisers configure the available ticket types, such as standard, early-bird, student, group or complimentary. Registration completes once you select an eligible ticket type and provide the required responses.
- Custom registration forms: attendees must give complete and truthful responses to the questions set by conference organisers, for example dietary, institutional or accreditation requirements.
- Attendance requests: where an edition requires attendee approval, applicants submit a request and admission is confirmed only on organiser review (approved, rejected or pending).
- Group bookings: corporate or group purchasers are responsible for correctly allocating ticket assignments to the intended attendees.
4. Ticketing, payments, invoicing & refunds
- Payment gateways: online registration payments are processed securely through licensed payment processors (Stripe and PayPal). Organisers may also record verified offline payments such as official bank transfers.
- Invoices and digital tickets: on verified payment the platform issues an electronic invoice with a unique invoice number and generates an attendee ticket with a check-in QR code.
- Refunds: cancellation and refund requests are administered by the hosting conference edition according to its published deadlines and terms. Approved refunds, full or partial, are processed through the originating payment gateway or recorded as an offline adjustment.
- Ticket transfers: ticket reassignments or attendee substitutions may be made where the organiser permits, using the ticket transfer workflow.
5. Call for papers, abstract submissions & academic rights
For conferences using the call for papers module:
- Submission stages: submissions move through the configured stages of abstract, full paper and camera-ready upload. Authors must follow track guidelines and posted deadlines.
- Co-authorship: submitting authors may invite co-authors by email. Invited co-authors must confirm their participation and affiliations to be credited in the official programme.
- Edits and withdrawals: authors may edit or withdraw submissions before the track deadline or before formal peer review begins.
- Author copyright: authors retain full copyright and ownership of their submitted abstracts, manuscripts, posters and presentation slides.
- Licence to publish: by submitting an abstract or camera-ready manuscript, authors grant KMFRI, ARBEC and the hosting conference edition a non-exclusive, royalty-free, worldwide licence to review, index, display in the programme, and publish accepted works in official proceedings, repositories and digital platforms.
- Academic integrity: submitting authors warrant that their contributions are original, accurately attributed, and compliant with standard scientific research ethics.
6. Programme, sessions, bookmarks & on-site check-in
- Live agenda access: attendees can view the schedule, rooms, speaker line-ups and posters. Organiser changes synchronise to the mobile app.
- Personal bookmarks: session bookmarks and custom schedules are stored locally and synchronised with your account for offline and multi-device access.
- Session engagement: questions submitted during sessions through the app must be relevant, respectful and in keeping with professional academic standards.
- On-site check-in: admission to physical venues is verified by scanning the attendee ticket QR code in the organiser on-site module. Badges are non-transferable once checked in.
- Calendar synchronisation: the calendar export feature generates standard calendar records containing session titles, timings and room details.
7. Communications & push notifications
The platform delivers official conference announcements and operational notices:
- Organisers may broadcast urgent schedule changes, keynote announcements or logistical notices to registered delegates.
- Push notifications are transmitted through Firebase Cloud Messaging. Attendees can customise notification topics and preferences in the mobile app settings.
8. Acceptable platform use & abuse reporting
Users agree not to:
- attempt to circumvent authentication, exploit API endpoints, or bypass database row-level security;
- carry out automated scraping of attendee profiles, speaker directories or unpublished manuscripts;
- post fraudulent marketplace listings, unauthorised commercial solicitations or deceptive content;
- disrupt live sessions or misuse session engagement tools.
9. Account erasure and data management
You may close your account at any time using the in-app deletion option (Profile > Privacy & visibility > Delete account). Deletion permanently purges authentication credentials, personal profile data and push tokens, subject to the statutory retention of invoice and audit records required by law.
10. Service availability, offline operation & disclaimers
The ARBEC platform is provided on an as-is and as-available basis. The mobile app caches content locally so downloaded agendas and tickets can be viewed offline. While the operators aim for continuous reliability during active conferences, neither KMFRI nor Saharasoft Solutions Limited guarantees uninterrupted server availability or accepts liability for network provider disruptions.
Conference programme content, speaker attendance, session room allocations and organiser policies are the responsibility of the hosting conference edition.
11. Governing law and dispute resolution
These terms are governed by and construed in accordance with the laws of the Republic of Kenya, including the Kenya Information and Communications Act and the Data Protection Act (2019). Any dispute arising out of or in connection with these terms shall be resolved through good-faith consultation, or submitted to the courts of Kenya.
12. Inquiries and notices
Kenya Marine and Fisheries Research Institute (KMFRI) • ARBEC Secretariat
Email: director@kmfri.go.ke • nelson@saharasoftsolutions.com
Telephone: +254 (20) 8021561 / +254 712 003 853
Postal: P.O. Box 81651-80100, Mombasa, Kenya