CONFIDENTIALITY POLICY

Effective Date: 5 September 2026
 

At ASTRA SOURCESS LTD., we recognise that confidentiality is fundamental to building trusted and long-term business relationships.


In the course of providing investment advisory, market-entry, business establishment, commercial and operational support services, we may receive information that is confidential, commercially sensitive, proprietary or otherwise not publicly available. We are committed to protecting such information and using it responsibly.


1. Purpose

This Confidentiality Policy explains how ASTRA SOURCESS LTD. protects confidential and commercially sensitive information received from clients, prospective clients, business partners, investors, suppliers and other stakeholders.

Our objective is to ensure that information entrusted to us is handled with appropriate discretion, security and professional care
.

2. Information We Treat as Confidential

Confidential information may include, but is not limited to:

Business plans and investment strategies;

Financial information, forecasts and commercial terms;

Investment proposals and transaction information;

Market-entry strategies and expansion plans;

Technical, operational and project information;

Customer, supplier and business-partner information;

Corporate, legal and organisational information;

Personal information provided in connection with our services;

Proprietary processes, documents, concepts and intellectual property; and

Any information expressly identified as confidential or which would reasonably be understood to be confidential.

 

3. How We Use Confidential Information

Confidential information is used only for legitimate business purposes connected with the services we provide, including evaluating opportunities, preparing recommendations, coordinating professional services, establishing businesses and supporting operational activities.

We do not use confidential information for purposes unrelated to the engagement without appropriate authorisation.
 

4. Disclosure to Third Parties

ASTRA SOURCESS will not disclose confidential information to third parties unless:

Disclosure is authorised by the relevant client or information owner;

Disclosure is necessary to deliver an agreed service;

Information must be disclosed to professional advisers, consultants, contractors or service providers acting on our behalf;
 

Disclosure is required by law, regulation, court order or a competent authority; or

Disclosure is otherwise permitted under an applicable agreement.

Where third-party involvement is necessary, we seek to ensure that information is shared only to the extent reasonably required and that appropriate confidentiality obligations are maintained.


5. Personal Data

Where confidential information contains personal data, ASTRA SOURCESS will handle such information in accordance with applicable data protection and privacy laws, including the Kenya Data Protection Act, 2019 and applicable regulations.
 

We apply appropriate organisational and technical measures designed to protect personal data against unauthorised access, disclosure, alteration, loss or misuse. The Kenya Data Protection framework requires personal data to be processed lawfully, fairly and transparently and for specified, legitimate purposes.


6. Information Security

Access to confidential information is restricted to individuals who have a legitimate business need to access it.

Depending on the nature of the information, we may use access controls, secure storage, password protection, confidentiality agreements and other reasonable administrative, technical and organisational safeguards.


7. Confidentiality After Completion of Services

Our confidentiality obligations do not automatically end when an engagement, project or business relationship ends.

Unless disclosure is required by law or otherwise agreed, we will continue to treat confidential information as confidential after completion or termination of the relevant engagement.

Information will be retained only for as long as reasonably necessary for the purposes for which it was collected, or where retention is required by applicable legal, regulatory, accounting or contractual obligations. This approach is consistent with Kenya's data-protection principle that personal data should not be retained in identifiable form longer than necessary for its purpose.
 

8. Exceptions

Information will generally not be considered confidential where it:

Is already publicly available through no breach of confidentiality;

Was lawfully known to ASTRA SOURCESS before disclosure;

Is independently developed without reference to confidential information; or

Is lawfully received from another source without a confidentiality obligation.
 

9. Legal and Regulatory Disclosure

Nothing in this Policy prevents ASTRA SOURCESS from making a disclosure where it is legally required to do so.

Where legally permissible and reasonably practicable, we will seek to notify the relevant party before making such disclosure and will limit the disclosure to the information required.
 

10. Confidentiality of Client Engagements

We respect the confidentiality of our clients' commercial activities and do not publicly disclose the details of client engagements, investment plans, transactions or projects without appropriate permission.

Client names, project details, case studies or other commercially sensitive information may only be used for marketing, business development or public communications where appropriate authorisation has been obtained.
 

11. Responsibilities of Our Team

All ASTRA SOURCESS personnel and individuals working on our behalf are expected to exercise appropriate discretion when handling confidential information.

Where appropriate, confidentiality obligations may be incorporated into employment agreements, consultancy agreements, service agreements, non-disclosure agreements or other contractual arrangements.
 

12. Breach of Confidentiality

Any suspected or actual unauthorised access, disclosure, loss or misuse of confidential information should be reported to ASTRA SOURCESS promptly.
 

We will assess reported incidents and, where required, take appropriate corrective, contractual, legal or regulatory action
.

Where an incident involves personal data, we will follow applicable data-breach notification and response requirements. The Office of the Data Protection Commissioner (ODPC) provides specific mechanisms for reporting personal-data breaches in Kenya.


13. Changes to This Policy

ASTRA SOURCESS may periodically review and update this Confidentiality Policy to reflect changes in our business practices, applicable laws, regulatory requirements or information-security standards.

The latest version published on our website will constitute the current version of this Policy.
 

14. Contact

If you have any questions regarding confidentiality, privacy or the handling of information by ASTRA SOURCESS LTD., please contact us:
 

ASTRA SOURCESS LTD.
Nairobi, Kenya
Tel: +254 722 819 552
Email: info@astrasourcess.com
Website: astrasource.co.ke