Burundi LimitedCK Horizon
How CK Horizon data may be used, what attribution is required, and how CK Horizon Burundi Limited intends to protect personal data across its work.
Compliance draft — pending confirmation and legal review · Last updated 2026-09-05
Verified incident records and their structured causal data may be reused for research, reporting and conservation planning, provided CK Horizon is credited and the verification status of each record is preserved in any republication.
Each record cites the source it was derived from. Those sources keep their own copyright and licence terms; CK Horizon links to them and does not relicense them.
Species, conservation status, national indicators, historical weather and place coordinates come from external providers (IUCN, GBIF, iNaturalist, World Bank, Open-Meteo, OpenStreetMap, GeoNames) and are attributed on the records that use them. Province boundary outlines are from geoBoundaries (CC0).
Coordinates released through the API are representative points, not proof of an exact incident location. Do not use them to identify individuals, households or protected sites.
Data is provided as-is. A record's evidence level and verification status indicate how much confidence to place in it; unverified and disputed records are clearly marked and should not be treated as established fact.
CK Horizon Burundi Limited is committed to protecting the privacy and personal data of people whose information it collects, uses, stores or otherwise processes. This chapter provides a non-authoritative, web-readable summary of the substantive provisions in the company's version 1.0 Data Protection and Privacy Policy.
The policy applies across CK Horizon's business activities and systems. It is intended to support compliance with applicable law in Burundi and may also draw voluntarily on internationally recognised data-protection principles, including GDPR-inspired standards where appropriate. This does not mean the GDPR applies to every CK Horizon processing activity.
The policy covers personal data handled in paper, electronic, photographic, audio, video and other formats by people and organisations working for or with CK Horizon.
The principal framework identified by the policy is Burundi Law No. 1/03 of 10 March 2026 on the Protection of Personal Data. CK Horizon will also take account of other applicable Burundian legislation and future regulations, decisions or guidance from the competent data-protection authority.
These definitions explain the main terms used throughout the policy and how CK Horizon understands its role when handling personal information.
Information relating to an identified or identifiable natural person, whether identification is direct or indirect.
Collecting, recording, organising, storing, accessing, consulting, using, transmitting, disclosing, updating, combining, restricting, deleting or destroying personal data.
The individual to whom the personal data relates.
The person or organisation that determines why and how personal data is processed. CK Horizon will generally act as controller for its own business activities.
A person or organisation that processes personal data for CK Horizon, such as a hosting, cloud-storage, payroll, accounting, recruitment or IT-support provider.
The policy requires CK Horizon to handle personal data according to a consistent set of privacy and accountability principles.
The lawful basis depends on the purpose and circumstances. Consent is not treated as the only possible basis, and any consent relied upon should be informed, voluntary and appropriately recorded.
The categories collected depend on the relationship and the service involved. CK Horizon should collect only information needed for a defined purpose.
CK Horizon will avoid collecting sensitive personal data unless there is a legitimate and lawful reason. Where it is necessary, the policy requires additional safeguards and any consent, authorisation or other legal basis required by law. It also states that CK Horizon will not knowingly collect personal data from children for purposes unrelated to legitimate business or legal requirements.
CK Horizon will normally collect personal data directly from the person or organisation concerned. If information comes from another source, the policy states that the company will take reasonable steps to ensure that collection and later use are lawful and not deceptive or unnecessary.
Where CK Horizon communicates by email, SMS, telephone, social media or another electronic channel for marketing, the policy requires compliance with applicable law.
Personal data may be disclosed only where reasonably necessary and lawful. Access should be limited to people who need the information for legitimate business purposes, and confidentiality obligations may continue after employment or a contract ends.
Before appointing a processor, CK Horizon should assess the provider, services, data involved, security, confidentiality, retention, deletion, subcontracting, international transfers, incident notification and legal compliance in proportion to risk. Where appropriate, written contracts should define responsibilities, confidentiality and security protections.
Personnel must not access or disclose data without authorisation, make unnecessary copies, use it personally, or remove or transfer it outside approved systems without permission.
The policy requires reasonable technical and organisational safeguards proportionate to the risks. Suspected personal-data breaches should be reported immediately through the company's designated internal channel, then investigated, contained where possible, assessed and documented.
Subject to applicable legal conditions and limitations, individuals may have rights concerning their personal data. The exact rights available depend on the processing and the law that applies.
CK Horizon may take reasonable steps to verify the identity of a person making a request before disclosing personal data. Legitimate requests should be answered within the timeframe required by applicable law, and any refusal should be explained where legally possible.
The supplied policy does not yet contain confirmed public privacy-contact details. A registered address, named privacy contact, email address and telephone number must be published only after CK Horizon confirms them. Until then, this page does not invent or present placeholder contact information as operational.
A person who believes CK Horizon has processed personal data improperly may complain to the company. The policy states that CK Horizon will investigate complaints fairly and within a reasonable period. Individuals may also have the right to approach the competent Burundian data-protection authority or pursue other remedies available under law.
Personal data may sometimes be transferred outside Burundi through international cloud, hosting, payment, professional-advice, customer, supplier or group-company arrangements. The policy states that, before a transfer, CK Horizon will assess whether it is lawful and will implement any required safeguards, approvals or contractual measures.
The policy requires appropriate records of material international transfers, including services operated from the United Kingdom, European Union, United States or other countries.
The policy states that CK Horizon will retain personal data only as long as reasonably necessary for its purpose. Retention decisions should consider contracts, employment, tax and accounting rules, limitation periods, regulation, disputes, legal claims, security, fraud prevention and legitimate business requirements.
At the end of the applicable retention period, personal data should be securely deleted, destroyed or anonymised where appropriate.
Privacy and data protection should be considered from the beginning of any new system, service, application, website, process or project involving personal data. Higher-risk work may require a Data Protection Impact Assessment or equivalent privacy-risk assessment.
Before deploying artificial intelligence, automated decision-making or profiling involving personal data, CK Horizon should assess privacy, fairness, security and legal risks. Automated processing should not make decisions with significant effects on individuals without appropriate legal assessment and safeguards.
Everyone handling personal data for CK Horizon is responsible for following this policy, using only the information needed for their work, maintaining confidentiality, keeping data accurate where responsible, avoiding unnecessary copies and reporting suspected breaches promptly.
Management is responsible for procedures, training, risk assessment, processor oversight, security, breach investigation, rights requests, records and periodic policy review.
CK Horizon intends to designate a person to coordinate advice, processing records, rights requests, breach response, training, regulatory liaison, monitoring and periodic privacy reviews.
The policy should be reviewed at least every two years and after significant legal, business, processing or IT changes, a material personal-data incident or a management direction.
The supplied document identifies itself as version 1.0 with an effective date of 30 June 2026, while also stating that it remains a compliance draft pending confirmation of CK Horizon's activities, systems, data flows, contracts and Burundi's implementing framework.
This web version therefore remains marked as a compliance draft pending confirmation and review by Burundian legal counsel. Internal appendices, unconfirmed contact fields, the breach-reporting template, implementation checklist and signature block are not presented as public operational information.