Privacy Policy
How we steward personal information with dignity, care and accountability.
Every person bears God-given dignity. Information entrusted to us will be handled lawfully, honestly, carefully and respectfully.
View policy contents
Introduction
The Full Life Institute (“TFLI”, “we”, “us” or “our”) is a grace-based Christian learning and ministry-training initiative and a branch of Simon Mbatia Ministries.
This Privacy Policy explains how we collect, use, store, protect and share personal information when you visit our website, register for an account, enrol in a programme, participate in a class, complete workbook activities, make a payment, communicate with us or use another TFLI service.
We believe that every person is created by God with dignity and worth. Grace does not make privacy optional; it makes faithful stewardship essential.
Who Is Responsible for Your Information?
The Full Life Institute, a branch of Simon Mbatia Ministries, is the data controller for personal information processed through its website and learning programmes.
We may appoint approved service providers to process information on our behalf. We remain responsible for deciding why information is collected and how it is used within TFLI.
Who This Policy Applies To
- Website visitors
- Prospective and registered students
- Instructors, facilitators and applicants
- Ministry staff and authorised volunteers
- Parents or guardians of participants who are minors
- Sponsors, church or group representatives
- People who contact or otherwise interact with TFLI
Information We May Collect
Identity and contact information
This may include your full name, username, email address, telephone or WhatsApp number, country or general location, profile photograph, age or age confirmation, church or ministry affiliation and, where necessary, parent or guardian information.
A telephone or WhatsApp number may be required for registration, account support, class communication and important programme notices.
Account and security information
This may include your username, protected password, user role, account status, registration date, login records, failed login attempts, password-reset requests, authentication information and security logs.
Learning and programme information
- Programme enrolments, class groups and timetables
- Attendance, reading and lesson completion
- Workbook progress, assignments, examinations and quiz responses
- Marks, feedback, results and course retakes
- Overall progress, graduation eligibility and certificates
- Submitted questions, class participation and support records
Attendance, assignments, examinations and progress records may be used to determine whether completion or graduation requirements have been met.
Workbook, reflection and ministry information
Some activities invite personal reflections, weekly commitments, prayer responses, testimonies or spiritual questions. The workbook may distinguish between:
Private entries are not routinely reviewed by facilitators. An authorised technical administrator may access them only where reasonably necessary to resolve a technical problem, investigate a security incident, comply with law or protect a person from serious harm.
TFLI will not use spiritual reflections to shame participants, manipulate them, rank their spiritual worth or measure their acceptance before God.
Payment and financial information
TFLI operates on a cashless basis. We may collect payer identity, amount, date, transaction reference, payment status, receipt or invoice information and programme details. Payments may be handled by mobile-money providers, banks, card processors or payment gateways.
TFLI does not normally receive or store full card numbers, mobile-money PINs, banking passwords or verification codes. Never send such credentials to a TFLI staff member, instructor or facilitator.
Communications, media and technical information
We may retain communications sent through forms, email, telephone, SMS, WhatsApp, class tools, surveys and support requests. We will seek appropriate permission before publicly using an identifiable participant’s photograph, video, audio, testimony, personal story, result or quoted feedback.
- IP address, browser, device and operating-system information
- Pages requested, access time and referring website
- Session identifiers, login records, errors and performance data
- Approximate region, security signals and Cloudflare Ray IDs
Sensitive Personal Data
Participation in a Christian learning ministry may reveal religious or philosophical beliefs. Reflections may also contain health, family, marital or other private information.
We process sensitive personal data only where it is necessary, lawful and appropriately protected. Participants should avoid entering highly sensitive information that is unnecessary for the learning activity. Facilitators and administrators must access such information only for an authorised purpose.
How We Collect Information
- Directly from you and through registration, enrolment or application forms
- Through your account, classes, submissions and workbook activities
- When you make a cashless payment or contact us
- From an authorised parent, guardian, sponsor, church or group leader
- From authorised instructors, facilitators or administrators
- Automatically through cookies, server logs and security tools
- From approved hosting, payment, communication and technology providers
We will not knowingly obtain personal information through deception or unnecessary intrusion.
Why We Use Personal Information
- Create, verify and manage accounts
- Enrol participants and administer programmes
- Provide lessons, materials and online classes
- Record attendance, assignments and examinations
- Monitor progress, completion and graduation eligibility
- Issue certificates and manage course retakes
- Provide student, instructor, pastoral or technical support
- Process cashless payments and maintain financial records
- Send schedules, meeting links, announcements and security notices
- Respond to questions, complaints and requests
- Protect the website against fraud, abuse, bots and cyberattacks
- Maintain backups and technical records
- Improve programme delivery and produce anonymous statistics
- Meet legal, accounting, safeguarding and regulatory duties
We will not use information for a materially different purpose without an appropriate lawful basis and any notice or consent required by law.
Lawful Bases for Processing
- Your consent
- Providing a requested service or programme
- Administering enrolment or an account
- Compliance with a legal obligation
- Legitimate educational, administrative, ministry or security interests
- Protection of vital interests
- Establishment, exercise or defence of a legal claim
Where we rely on consent, you may withdraw it. Withdrawal does not make earlier lawful processing unlawful. Some information is required for registration, payment, attendance, assessment or certification.
Our Grace-Based Privacy Commitments
We will not sell or rent personal information.
We will not trade student information for advertising.
We will not use private reflections to embarrass or condemn participants.
We will collect only what is reasonably needed.
Private reflections will remain private by default where the platform supports that choice.
Access will be limited by role and responsibility.
We will seek permission before publishing identifiable testimonies.
We will correct, delete or anonymise information where appropriate.
Grace does not remove accountability. It calls us to exercise responsibility without manipulation, harshness or secrecy.
How We May Share Information
Authorised TFLI personnel
Staff and administrators may access information required for accounts, programmes, payments, support, records, security and legal duties. Access should be limited by role.
Instructors and facilitators
They may receive names, necessary contact information, attendance, coursework, results, progress, submitted questions and information deliberately shared with them. Private workbook responses should not be visible unless the participant chooses to share them or access is otherwise lawfully necessary.
Service and payment providers
We may use approved providers for hosting, cloud security, email, backups, maintenance, file storage, online meetings, communication, analytics, technical support and electronic payments.
Legal and safety reasons
We may disclose information to comply with law or a lawful request; investigate fraud or crime; protect a person from serious harm; secure the website; enforce applicable rules; or establish, exercise or defend legal rights.
TFLI does not sell personal information to data brokers.
Cloudflare Security and Website Delivery
The TFLI website uses Cloudflare to help provide Domain Name System services, secure traffic routing, content delivery, caching, Distributed Denial-of-Service protection, web application firewall protection, bot and malicious-traffic detection, security challenges, secure connections and performance services.
Cloudflare may process technical information including:
- IP address, request date and time
- Requested page or resource
- Browser and device characteristics
- Request headers, security signals and traffic patterns
- Approximate location and Cloudflare Ray ID
- Information required to detect bots, attacks or suspicious traffic
Cloudflare cookies
Depending on enabled services, Cloudflare may place strictly necessary cookies such as __cf_bm for certain bot-management services, cf_clearance to remember completion of a security challenge, and __cflb where load-balancing session affinity is enabled.
These cookies are intended to protect and operate the website, not to create advertising profiles for TFLI.
Cloudflare may automatically challenge, delay or block traffic that appears malicious or automated. Those security decisions are not used by TFLI to evaluate a person’s character, faith, spiritual maturity, academic ability or ministry eligibility.
Cloudflare operates globally, so technical information may be processed outside Kenya where Cloudflare or its approved subprocessors operate.
Cookies and Similar Technologies
Essential cookies
These support login, authentication, security, session management, form submission, course progress, website preferences, load balancing and Cloudflare security. The site may not function correctly if they are blocked.
Functional and analytics cookies
Functional cookies may remember display, reading, accessibility or language choices. Where analytics is enabled, it may help us understand general website use. Consent will be sought for non-essential cookies where required.
Embedded services
Google Meet, YouTube, social-media content, document viewers or payment tools may set their own cookies or collect technical information under their own policies.
International Transfers
Cloud, hosting, security, communication, meeting and payment providers may process information outside Kenya.
Where information is transferred internationally, we will take reasonable steps to ensure a lawful purpose and appropriate contractual, organisational or technical safeguards, and to obtain any consent required by law.
How Long We Keep Information
- Account information may be kept while the account is active.
- Learning records may be kept to verify attendance, completion and certification.
- Financial records may be kept for applicable accounting, audit and legal periods.
- Security logs are kept for limited periods needed to protect and troubleshoot the website.
- Private workbook information may be deleted or anonymised when no longer required, subject to legal, technical and backup limitations.
- Public testimonies may remain published until permission is withdrawn or the material is no longer needed.
Backup copies may remain temporarily until replaced through the normal backup cycle.
Security and Data Breaches
We use reasonable safeguards including secure connections, protected passwords, role-based access, Cloudflare security, software updates, backups, monitoring, verification, logging, confidentiality instructions and incident-response procedures.
No internet service can guarantee absolute security. Users should use strong passwords, keep devices secure and report suspicious activity promptly.
Where a personal-data breach occurs, we will investigate, limit harm and notify affected people and the appropriate authority where required by law.
Your Privacy Rights
Subject to applicable law and lawful limitations, you may have the right to:
- Be informed about how your information is used
- Request access, correction or deletion
- Object to or request restriction of certain processing
- Withdraw consent where consent is the basis
- Request portability where applicable
- Request human review of a significant automated decision
- Complain about the handling of your information
To exercise a right, email study@simonmbatia.com. We may need to verify your identity.
Some information cannot be deleted immediately where it must be kept for legal compliance, accounting, certification, safeguarding, fraud prevention, security or legal claims.
You may also lodge a complaint with the Office of the Data Protection Commissioner of Kenya.
Communication Preferences
We may send account notices, security alerts, schedules, meeting links, assignment or examination notices, payment confirmations, programme announcements and ministry news.
Messages necessary for an active account or programme may continue even if you opt out of optional updates. Leaving a WhatsApp group does not automatically remove messages already posted or stored on another participant’s device.
Children and Participants Under Eighteen
Where a person under eighteen is accepted, we may require verifiable parent or guardian consent, age information, guardian contact details and additional privacy and safeguarding controls.
A parent or guardian may exercise appropriate rights on behalf of a minor, subject to the child’s best interests and applicable law. We will not knowingly use a child’s information for behavioural advertising, commercial profiling or unnecessary public exposure.
Group Discussions and Confidentiality
Participants are expected to treat personal matters shared in classes, prayer sessions and discussion groups as confidential.
TFLI cannot guarantee that another participant will not repeat, copy, photograph, record or distribute information shared in a group. Avoid disclosing information that would place yourself or another person at unnecessary risk.
Recording a class, copying private messages or publishing another participant’s testimony without permission may violate TFLI rules and applicable privacy rights.
External Services and Automated Processing
The website may link to services we do not control. TFLI is not responsible for the privacy practices, security or content of those services.
TFLI does not intend to make decisions with serious legal or similarly significant effects solely through automated processing. Automated tools may calculate progress, mark objective quizzes, send reminders, detect suspicious logins, block malicious traffic or confirm whether stated requirements appear complete. A participant may request human review where a result appears incorrect.
Changes to This Policy and Contact
We may update this Policy when programmes, website features, providers, security practices or legal requirements change. The updated version will be posted with a revised “Last Updated” date. Additional notice or consent will be provided where required.
We will seek to respond fairly, respectfully and within the period required by applicable law.