Skip to content

Legal

Privacy Policy

Effective date: May 13, 2026. Last updated: May 13, 2026.

This Privacy Policy describes how Timi Labs collects, uses, and protects your information in compliance with the Kenya Data Protection Act, 2019.

1. Data Controller Information

Company: Timi Labs
Incorporated: 2026
Jurisdiction: Kenya
Contact: [email protected]

For any questions about how we handle your data or to exercise your privacy rights, please contact us at the email address above.

2. What Information We Collect

Timi is a WhatsApp AI assistant for Kenyan businesses. To operate the service, we collect and process the following types of information:

2.1 Business Account Information

  • Email address and password (encrypted)
  • Business name
  • Business profile (products, services description)
  • Business hours configuration
  • Personal WhatsApp number for handoff

2.2 WhatsApp Business Integration Data

  • WhatsApp Business Account ID (WABA ID)
  • WhatsApp phone number and phone number ID
  • WhatsApp access tokens (encrypted at rest using AES-GCM)
  • WhatsApp Business catalog data synced from Meta
  • Connection and onboarding status

2.3 Customer Conversation Data

When customers message your WhatsApp Business line connected to Timi, we process:

  • Customer phone numbers (in E.164 format)
  • Customer display names from WhatsApp
  • Full message conversation history (inbound and outbound)
  • Message metadata (timestamps, delivery status)
  • Engagement data (lead status, nudge count, handoff status)
  • Bot pause status for individual conversations

2.4 Billing Information

  • Subscription status and billing cycle
  • Paystack customer and subscription codes
  • Payment method information (processed by Paystack)
  • Transaction history

2.5 Usage and Technical Data

  • Dashboard activity and feature usage
  • IP addresses and browser information
  • Cookies and local storage (session management)
  • System logs for security and troubleshooting

3. How We Use Your Information

We process your information for the following purposes:

3.1 Service Operation (Legal Basis: Contract Performance)

  • Generating AI responses to customer messages using Gemini AI
  • Managing conversations through the live feed and dashboard
  • Executing smart handoffs to your personal WhatsApp
  • Sending automated follow-up nudges during business hours
  • Syncing your WhatsApp Business catalog
  • Providing real-time updates and notifications

3.2 Billing and Account Management (Legal Basis: Contract Performance)

  • Processing subscription payments through Paystack
  • Managing your account and subscription status
  • Sending billing notifications and receipts
  • Handling cancellations and refund requests

3.3 Security and Fraud Prevention (Legal Basis: Legitimate Interests)

  • Detecting and preventing unauthorized access
  • Investigating suspicious activity or policy violations
  • Maintaining system security and integrity
  • Complying with legal obligations

3.4 Service Improvement (Legal Basis: Legitimate Interests)

  • Analyzing usage patterns to improve features
  • Troubleshooting technical issues
  • Developing new functionality
  • Improving AI response quality

3.5 Communication (Legal Basis: Contract Performance or Consent)

  • Sending service updates and important notices
  • Responding to support requests
  • Notifying you of changes to terms or policies

4. Third-Party Data Processors

To provide the service, we share data with the following third-party processors. Each processor is bound by data protection obligations:

4.1 Google LLC (Gemini AI)

Purpose: AI-powered response generation
Data shared: Customer message content, conversation context
Location: United States and other global locations
Safeguards: Google's standard contractual clauses and security measures

4.2 Meta Platforms Inc. (WhatsApp Business API)

Purpose: Message delivery, WhatsApp Business integration
Data shared: Phone numbers, message content, business profile
Location: Ireland (Meta Platforms Ireland Limited) and United States
Safeguards: Meta's data protection terms and standard contractual clauses

4.3 Paystack (Stripe)

Purpose: Payment processing and subscription management
Data shared: Email, billing information, transaction data
Location: Nigeria and Ireland
Safeguards: PCI-DSS compliant, Paystack privacy policy applies

4.4 Railway Corp.

Purpose: Cloud infrastructure hosting
Data shared: All platform data (database, files, logs)
Location: United States
Safeguards: SOC 2 Type II certified infrastructure

We do not sell your data to third parties for their marketing purposes.

5. International Data Transfers

Timi operates in Kenya, but some of our third-party processors are located outside Kenya. Your data may be transferred to and processed in:

  • United States: Railway (hosting), Google (AI processing)
  • Ireland: Meta Platforms, Paystack (payment processing)
  • Nigeria: Paystack (payment processing)

These transfers are necessary to provide the service. We ensure appropriate safeguards are in place through standard contractual clauses and data processing agreements with our processors.

6. Data Retention

We retain your data for as long as necessary to provide the service and comply with legal obligations:

  • Active conversations: Retained while your subscription is active plus 90 days after cancellation, so you can export or review data
  • Account information: Retained for 30 days after account closure, then anonymized or deleted
  • Billing records: Retained for 7 years to comply with Kenyan tax and accounting laws
  • Security logs: Retained for 1-2 years for fraud prevention and security purposes

You can request earlier deletion of your data by contacting [email protected], subject to legal retention requirements.

7. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • WhatsApp access tokens encrypted at rest using AES-GCM encryption
  • Password hashing using industry-standard algorithms
  • HTTPS/TLS encryption for all data in transit
  • Access controls and authentication on databases and systems
  • Regular security updates and monitoring
  • Secure configuration of Redis and other infrastructure components

While we take reasonable measures to protect your data, no system is completely secure. You are responsible for maintaining the confidentiality of your account credentials.

8. Your Rights Under Kenya Data Protection Act 2019

As a data subject in Kenya, you have the following rights:

8.1 Right of Access

You can request a copy of the personal data we hold about you. Most account and conversation data is already accessible through your dashboard.

8.2 Right to Correction

You can update your business profile, contact information, and other account details directly from your dashboard Settings page. For other corrections, contact [email protected].

8.3 Right to Deletion

You can request deletion of your data by canceling your subscription and contacting [email protected]. We will delete or anonymize your data within 30 days, except where we are legally required to retain it (e.g., billing records for tax compliance).

8.4 Right to Data Portability

You can export your conversation data and business information in a structured format. Contact [email protected] to request a data export.

8.5 Right to Object

You can object to processing based on legitimate interests. Note that this may affect our ability to provide the service.

8.6 Right to Lodge a Complaint

If you believe we have violated your data protection rights, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya at www.odpc.go.ke.

To exercise any of these rights, email [email protected] with your request. We will respond within 30 days.

9. Cookies and Tracking

We use essential cookies and browser local storage to:

  • Keep you logged in to your dashboard
  • Remember your preferences
  • Maintain session security

We do not use advertising or tracking cookies from third parties. Our cookies are necessary for the service to function.

10. Children's Privacy

Timi is a business service intended for users 18 years and older. We do not knowingly collect information from individuals under 18. If you are under 18, do not use this service.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify you by email to the address on your account
  • Display a notice in your dashboard

Continued use of the service after changes are posted constitutes acceptance of the updated policy.

12. Contact Us

For questions, concerns, or requests regarding this Privacy Policy or how we handle your data:

Email: [email protected]
Company: Timi Labs
Jurisdiction: Kenya

For general product questions, see the FAQ page.

Privacy Policy | Timi