Legal

Privacy policy

How Desko AI collects, uses and protects personal data — for visitors to this website, for our clients, and for the customers who message our clients on WhatsApp.

Before you publish this. This is a working draft written for a Kenyan WhatsApp messaging business. It is not legal advice and it has not been reviewed by an advocate. Have a Kenyan data-protection lawyer check it, fill in every [SQUARE BRACKET] below, and confirm your registration position with the Office of the Data Protection Commissioner before this goes live.

Last updated: [DATE]  ·  Version: 1.0
Data controller: [REGISTERED COMPANY NAME] trading as Desko AI, [COMPANY REGISTRATION NUMBER], [PHYSICAL ADDRESS], Nairobi, Kenya.
Contact for privacy matters: privacy@deskoai.com

1. Who we are and what this covers

Desko AI is a Nairobi-based service that connects Kenyan businesses to the official WhatsApp Business Platform, and provides an AI agent, a shared team inbox and related automation on the client's own WhatsApp number.

This policy explains how we handle personal data in three situations:

  • when you visit this website or contact us about our service;
  • when you are a client of ours, or work for one;
  • when you are a customer who messages a business that uses Desko AI.

We handle personal data in line with the Data Protection Act, 2019 of Kenya and its regulations.

2. The two roles we play

This distinction matters, because it decides who you should go to about your data.

We are the data controller for

  • enquiries you send us through this website, WhatsApp or email;
  • our client records, contracts, invoices and support history;
  • website analytics and technical logs.

We are a data processor for

  • the WhatsApp conversations, contact details and customer records belonging to our clients.

In that second case our client is the data controller, not us. We only process that data on their documented instructions, for the purpose of providing the service. If you are a customer of a business that uses Desko AI and you want your data corrected or deleted, contact that business first. If you contact us, we will pass your request to them and support them in answering it.

3. What personal data we collect

From website visitors and enquirers

  • Name, business name, phone number and email address, when you send them to us.
  • What you tell us about your business in the course of an enquiry.
  • Technical data: IP address, browser and device type, pages viewed, and the date and time of your visit.

The demo form on our contact page does not store anything on this website. It assembles the details you type into a WhatsApp message on your own device, which you then choose to send. Until you press send, we have received nothing.

From and about our clients

  • Contact details of the people we deal with at the client business.
  • Business registration details and documents required for Meta's business verification.
  • Billing details, payment records and support correspondence.

On behalf of our clients, about their customers

  • WhatsApp phone number and WhatsApp profile name.
  • The content of messages exchanged with the client's business, including images, documents, voice notes and location if the customer sends them.
  • Information the customer gives during a conversation — for example a delivery address, an order number or a product preference.
  • Metadata: when messages were sent, delivered and read, and which agent or AI handled them.

We do not deliberately collect sensitive personal data. If a client's use case involves health, financial or other sensitive information, that must be agreed in writing before setup, and additional safeguards apply.

4. Why we use it, and our lawful basis

What we doWhyLawful basis
Answer your enquiryTo respond to you and prepare a quote or demo.Steps taken at your request before entering a contract.
Provide the serviceTo run the inbox, the AI agent and the integrations our client pays for.Performance of our contract with the client.
Process customer conversationsSo the client's business can answer, serve and sell to its customers.On the client's documented instructions, under their own lawful basis as controller.
Invoice and keep recordsBilling, tax and statutory record-keeping.Legal obligation and our legitimate interests.
Secure and improve the serviceDetecting abuse, fixing faults, keeping the platform reliable.Our legitimate interests in operating a safe service.
Send you service updatesChanges to pricing, features or terms that affect you.Performance of our contract.
Send you marketingOnly if you asked for it.Your consent, withdrawable at any time.

We do not sell personal data. We do not share client customer lists with anyone. We do not use one client's conversations to train or improve anything for another client.

5. Who we share it with

We share personal data only with the parties needed to deliver the service:

  • Meta Platforms, Inc. — WhatsApp message content and metadata necessarily pass through the WhatsApp Business Platform. Meta's own handling of that data is governed by its terms and privacy policy, not by ours.
  • Our messaging platform and hosting providers — the infrastructure the inbox and dashboard run on. [NAME YOUR BSP AND HOSTING PROVIDER HERE.]
  • Our AI processing provider — message text is sent for the AI to generate a reply. [NAME YOUR AI PROVIDER AND STATE WHETHER THEY RETAIN OR TRAIN ON THE DATA.]
  • Payment and accounting providers — for invoicing and reconciliation. [NAME THEM.]
  • Integrations you ask us to connect — such as your CRM, e-commerce platform or M-Pesa, and only the data needed for that integration.
  • Professional advisers and authorities — where we are legally required to disclose, or need to establish or defend a legal claim.

Every provider we use is bound by a written agreement requiring them to protect the data and to act only on our instructions.

6. Transfers outside Kenya

Some of the providers above are based outside Kenya, so personal data may be transferred and stored abroad. Where that happens we rely on the transfer conditions permitted under the Data Protection Act, 2019, including appropriate safeguards in our contracts with those providers. [CONFIRM WITH YOUR ADVISER WHICH CONDITION YOU RELY ON AND NAME THE COUNTRIES INVOLVED.]

7. How long we keep it

DataKept for
Enquiries that do not become clients[12] months from the last contact
Client conversations and contactsFor as long as the client's account is active, then [30] days for export, unless the client instructs otherwise
Invoices and tax records[7] years, as required by Kenyan tax law
Technical and security logs[12] months

Clients can set shorter retention periods for their own conversation data, and we will apply them.

8. How we protect it

  • Encryption in transit for all connections to our dashboard and APIs.
  • Role-based access, so each person sees only what their job needs.
  • Access logging, so every view and export can be traced to a person.
  • Two-factor authentication on administrative accounts.
  • Written confidentiality obligations for everyone who works with us.

No system is perfectly secure. If a breach occurs that is likely to result in a real risk to anyone's rights, we will notify the Office of the Data Protection Commissioner and the affected people without undue delay, as the Act requires.

9. Your rights

Under the Data Protection Act, 2019 you have the right to:

  • be informed of how your personal data is being used;
  • access the personal data we hold about you;
  • have inaccurate or misleading data corrected;
  • have your data deleted, where there is no lawful reason for us to keep it;
  • object to processing, including for direct marketing;
  • restrict processing in certain circumstances;
  • receive your data in a portable format, where that applies.

To exercise any of these, email privacy@deskoai.com. We respond within the timeframe set by the Act and will not charge you for a reasonable request. We may need to verify your identity first.

If your data is held by us on behalf of a client, we will forward your request to that client, who is the controller, and tell you that we have done so.

10. Complaints

If you are unhappy with how we have handled your personal data, tell us first — we would rather fix it. If you are still not satisfied, you can complain to the Office of the Data Protection Commissioner (ODPC), Kenya. [ADD THE ODPC CONTACT DETAILS AND COMPLAINT PORTAL LINK CURRENT AT THE TIME OF PUBLISHING.]

11. Cookies and this website

This website is deliberately simple. It sets no advertising or tracking cookies of its own. It loads a web font from Google Fonts, which means your browser makes a request to Google's servers and Google receives your IP address as part of that request.

If you later add analytics, a chat widget or advertising pixels to this site, this section must be updated and a consent banner added. [DELETE THIS SENTENCE ONCE YOU HAVE DECIDED.]

12. Children

Our service is sold to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, contact us and we will delete it.

13. Changes to this policy

We update this policy when our service or the law changes. The date at the top always shows the current version. If a change materially affects our clients, we tell them directly rather than relying on this page.

14. How to contact us

[REGISTERED COMPANY NAME], trading as Desko AI
[PHYSICAL ADDRESS], Nairobi, Kenya
Privacy: privacy@deskoai.com
General: hello@deskoai.com
WhatsApp: +254 716 960 098

Chat with us