Privacy Policy
Last updated: 14 September 2026
1. Who this policy is from
This policy explains how Datalyst Africa ("we") handles personal data in the course of operating the Datalyst Africa AI platform. Our contact point for privacy questions is munyaradzi@datalystafrica.com, and our registered address is Corner Rotten Row & Pennefather Road, Harare City Library, Harare, Zimbabwe. We do not currently have a dedicated Data Protection Officer — a business of our size and processing scope is not required to appoint one under Zimbabwean law. Direct any data protection query to the email above.
2. Two different relationships
This distinction matters, because our obligations differ in each case:
- Our customers (the businesses who buy the platform) — for their own account data we are the controller. This policy describes what we do with it.
- Our customers' end customers (people who talk to an Agent on a business's website or messaging channel) — for those conversations we are a processor acting on that business's instructions. That business decides what is collected and why, and its own privacy policy governs it.
If you spoke to an AI assistant on a company's website and want your data removed, contact that company. They can action it themselves in their dashboard, and we support them doing so.
3. What we collect about our customers
- Account data: name, email address, hashed password, role, and an optional phone number for alerts.
- Business data: your company name, plan, billing state, and branding you upload.
- Content you supply: documents, website content and FAQs you add to your knowledge base, and the instructions you give your Agent.
- Configuration: the tools, channels and integrations you connect. Credentials for those are encrypted at rest and never shown back to you or anyone else.
- Usage and billing records: request counts, token volumes, cost estimates, payment references and invoices.
- Audit records: who did what in your account, including anything our setup staff did on your behalf.
- Support correspondence: tickets you raise with us and our replies.
4. What is stored from Agent conversations
To operate an Agent we store, on behalf of the business that deployed it:
- The conversation itself — the messages exchanged, and metadata such as channel, outcome, sentiment trend and any satisfaction rating the customer chose to give.
- The customer's WhatsApp phone number and profile name, which WhatsApp provides so the business can reply. The business that deployed the Agent can see them in its inbox; they are never shown to other businesses.
- The customer's messaging preferences, including any STOP or opt-out request, so that we can honour it.
- Facts a customer has stated across conversations, where the business has enabled longer-term memory — for example a stated preference or a prior issue raised. Not full transcripts by default.
The Agent is designed not to present something as a fact the customer stated unless they actually stated it, and not to claim an action succeeded unless it was confirmed.
5. Why we process it
- To provide the service — answering questions, taking configured actions, and recognising a returning customer.
- To bill accurately, and to show usage against a plan allowance.
- To keep the platform secure, including detecting attempts to manipulate an Agent's instructions.
- To support you, investigate faults, and improve reliability.
- To meet legal and accounting obligations.
Where the law requires a lawful basis, ours is performance of our contract with you, our legitimate interest in operating and securing the platform, and compliance with legal obligations. Your own basis for your customers' data is yours to determine.
6. AI processing
To generate a reply, the relevant conversation content and the retrieved extract of your knowledge base are sent to a third-party AI provider. We route across more than one provider for reliability. These providers process the content to return a response and are contractually restricted from using it to train their models.
We do not use your content, or your customers' conversations, to train general-purpose AI models.
7. Who else sees the data
We share data only with service providers that make the platform work:
- AI model providers, to generate replies.
- Cloud hosting and database providers, to run and store the service.
- The messaging platforms you choose to connect, to deliver messages on those channels.
- Our payment provider, to take payment. We never see or store your full card details.
- Email and SMS providers, to send the notifications you have enabled.
- Error monitoring, to detect faults.
Our current sub-processors:
- Neon, Inc. — PostgreSQL database hosting (United States).
- Railway Corporation — application hosting for the API and background workers (United States).
- Vercel Inc. — dashboard hosting and content delivery (United States, global edge network).
- Cloudflare, Inc. — encrypted document/logo storage and bot-verification on our sign-in forms (global network, United States-headquartered).
- Anthropic PBC, OpenAI, L.L.C. and Google LLC — AI model providers used to generate Agent replies (United States).
- Google LLC — additionally used for "Sign in with Google" and, where a customer connects it, Google Calendar (United States).
- Brevo (Sendinblue SAS) — transactional email delivery, e.g. sign-in codes and alerts (European Union).
- Meta Platforms, Inc. — WhatsApp Business Platform, used to send and receive your customers' WhatsApp messages (United States).
- Twilio Inc. — SMS alert delivery, only for customers who enable that channel (United States).
- Paynow (Zimbabwe) — payment processing, only for customers on a paid plan (Zimbabwe).
We do not sell personal data, and we do not share it for advertising.
8. Where data is held
The platform currently operates primarily from the United States (see the sub-processor list above); Cloudflare's global network may cache static assets and file uploads closer to you. If you have a regulatory requirement for data to stay in a particular region, tell us before you go live — we record that requirement against your account, but you should not assume data is physically relocated unless we have confirmed that in writing.
Where data crosses a border, we rely on the standard contractual data-processing safeguards each provider listed above already has in place, rather than a bespoke agreement of our own.
9. How we protect it
- Each business's data is isolated at the database level, not only by application code, so one business cannot read another's.
- Credentials and channel access tokens are encrypted at rest.
- Passwords are stored only as salted hashes.
- Access to production data is limited to staff who need it, and staff actions inside a customer's account are logged and attributable.
- Traffic is encrypted in transit.
No system is perfectly secure. If a breach affects your data we will notify you without undue delay, and regulators where required.
10. How long we keep it
Conversation and memory data is kept for the retention period configured on your account, then deleted automatically. The default is 365 days.
Account, billing and audit records are kept for as long as you are a customer and then for as long as we are legally required to keep them — typically 6 years for accounting records, in line with Zimbabwean tax record-keeping requirements. Audit logs are kept deliberately, because they are the record of who changed what.
11. Your rights
Depending on where you are, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to complain to a regulator. To exercise any of these, contact munyaradzi@datalystafrica.com. We will respond within 30 days.
You can delete a specific customer's stored memory from your dashboard at any time; that action is recorded in your audit log.
If you are a member of the public who has chatted with one of these assistants, our data deletion page explains what is held about you and the three ways to have it erased.
The regulator for our jurisdiction is the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), the Data Protection Authority under Zimbabwe's Cyber and Data Protection Act.
12. Cookies
The dashboard stores a session token in your browser so you stay signed in, and remembers small interface preferences. We do not use advertising or cross-site tracking cookies.
13. Children
The platform is sold to businesses and is not intended for children. We do not knowingly collect data from children. If you configure an Agent that will be used by children, that is your responsibility to handle lawfully.
14. Changes
If we change this policy in a way that materially affects how we handle your data, we will tell you before it takes effect. The date at the top always reflects the current version.
