Legal
Data Processing Agreement
Last updated: 25 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between you (the "Customer") and The Tech Hut ("The Tech Hut", "we", "us"). It governs our processing of personal data relating to your customers — the people who message your WhatsApp number — and is entered into under the Kenya Data Protection Act, 2019 (the "Act").
Roles. For your customers' personal data, you are the data controller and The Tech Hut is your data processor. You decide why and how that data is processed; we act on your instructions. For your own account data (your name, email, billing records) The Tech Hut is the controller, and our Privacy Policy applies instead.
1. Subject matter and duration
We process personal data only to provide Aisha to you: receiving messages sent to your WhatsApp number, generating replies, recording orders and payments, and showing you those conversations. Processing lasts for as long as your account is open, plus the retention periods in section 7.
2. Categories of data subjects and personal data
Data subjects: your customers and prospective customers who message your WhatsApp number.
Personal data processed:
- WhatsApp phone number and the display name the customer has set
- The content of messages they send and the replies Aisha sends
- Order details — items, quantities, totals
- Delivery details a customer provides, which may include a name and physical address
- Payment status and references returned by the payment provider
We do not collect payment card or M-Pesa PIN data.Payments are completed on the payment provider's own systems; we receive only a confirmation and a reference.
Aisha is not designed for sensitive personal data as defined in section 2 of the Act (health, biometric, genetic data, and similar). If your customers send such data in a message it will be processed incidentally as message content. You should not configure Aisha to solicit it.
3. Your instructions and responsibilities
We process personal data only on your documented instructions, which for ordinary use are given through your use of the Service and its settings. We will tell you if, in our opinion, an instruction infringes the Act.
As controller, you are responsible for:
- having a lawful basis to process your customers' data;
- telling your customers that an automated assistant replies on your behalf, and that their messages are processed for that purpose;
- responding to your customers' requests to access, correct or delete their data — we will help you do so (section 6);
- registering with the Office of the Data Protection Commissioner where the Act requires it for your business.
4. Confidentiality and security
Measures currently in place include:
- encryption in transit (HTTPS/TLS) for the application and its API;
- passwords stored only as salted bcrypt hashes; password reset tokens stored only as hashes;
- access to the production database restricted to named administrators;
- authentication on the API, with each account able to reach only its own data;
- daily database backups.
We are candid about the limits of this list: Aisha is an early-stage service run by a small team. We do not currently hold ISO 27001, SOC 2 or an equivalent independent certification, and we do not claim to.
5. Sub-processors
You authorise the sub-processors below. We will give you notice before adding a new one, and you may object on reasonable data-protection grounds.
- Anthropic (United States) — generates the AI replies. Message content is sent for that purpose.
- WhatsApp / Meta— the messaging channel itself. Your customers' use of WhatsApp is governed by Meta's own terms.
- Paystack — payment processing and payment links.
- Brevo (European Union) — sends account emails to you. Your customers' data is not sent to Brevo.
- Contabo (Germany) — hosting for the application and database.
6. Data subject rights
If one of your customers contacts us directly, we will refer them to you, since you are the controller. Where you need to act on a request, we will help you locate, export, correct or delete that person's data within the Service. Conversations can be deleted from your dashboard, which removes the messages and contact record from our database.
7. Retention and deletion
Conversations, contacts and orders are retained while your account is open, because the Service works by referring to earlier messages. Deleting a conversation removes it from our database.
If you close your account, we delete your data within 60 days, except records we must keep for tax or accounting purposes, which are retained for the period required by Kenyan law. Backups are overwritten on a rolling cycle and any residual copy is deleted within that cycle.
8. International transfers
Personal data is processed outside Kenya. Hosting is in Germany and AI processing takes place in the United States. Section 48 of the Act permits transfer where appropriate safeguards exist or the data subject consents; we rely on our sub-processors' contractual safeguards and on the notice you give your customers. This is a point you should raise with your advocate if you serve customers whose data is particularly sensitive.
9. Personal data breaches
We will notify you without undue delay and in any case within 72 hoursof becoming aware of a personal data breach affecting your customers' data, with the facts we hold, the likely consequences and the steps taken. As controller, you are responsible for notifying the Data Protection Commissioner and affected individuals where the Act requires it.
10. Audit
On reasonable written request, and no more than once a year unless a breach has occurred, we will provide information reasonably necessary to demonstrate compliance with this DPA. Where an on-site audit is genuinely required, we will cooperate at your cost and on reasonable notice.
11. Return and deletion on termination
On termination you may export your data from the dashboard before the account closes. After the period in section 7 we delete it. We will confirm deletion in writing on request.
Questions about this DPA, or a request to exercise data subject rights, should go to info@thetechhut.co.