Privacy Policy

Last Updated: May 10, 2026  |  Version: 2.1

1. Introduction

JYVUX-AI ("JYVUX-AI," "we," "us," or "our"), founded by Jacton Osara, is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, process, store, share, and protect your personal information when you use our website, merchant dashboard, WhatsApp bot services (Jyvux), and all related services.

This policy is drafted in compliance with the Kenya Data Protection Act, 2019 (DPA 2019) and the Data Protection (General) Regulations, 2021.

2. Information We Collect

2.1 Information You Provide Directly

Category Examples Purpose
Shop Information Business name, physical address, city, contact phone, email address, business hours Account creation, bot configuration, customer communication
WhatsApp Numbers Owner WhatsApp number, bot WhatsApp number WhatsApp Cloud API integration, message routing
M-Pesa Credentials Consumer Key, Consumer Secret, Passkey, Shortcode Payment processing via Safaricom Daraja API
Account Credentials Dashboard password (hashed), Meta OAuth tokens Account security, platform authentication
Subscription Payment Data M-Pesa phone number used for subscription payments, transaction receipts, payment amounts Processing your plan subscription payments

2.2 Information We Do NOT Collect

  • We do not store your M-Pesa PIN or customer M-Pesa PINs.
  • We do not access or read your personal WhatsApp messages.
  • We do not sell, rent, or trade your personal data or your End Customers' data.

3. How We Use Your Information

We use the information we collect for:

  1. Service Provision: To create your account, configure your WhatsApp bot, process M-Pesa payments, and deliver our core functionality.
  2. Subscription Management: To process your plan payments via M-Pesa, track trial periods, calculate overage charges, and manage your subscription status.
  3. AI Bot Operation: Customer conversation data powers jyvux's AI responses in English, Kiswahili, and Sheng.
  4. Analytics & Reporting: To generate sales reports, revenue insights, and AI-powered business recommendations.
  5. Communication: To send account notifications, billing reminders, and support messages.

Under the Kenya Data Protection Act 2019, we rely on:

  • Contractual Necessity: Processing your data to provide the Services.
  • Legitimate Interests: Improving our Services, preventing fraud, ensuring platform security.
  • Consent: Where required by law, we obtain your explicit consent.
  • Legal Obligation: Complying with applicable Kenyan laws.

5. Data Sharing & Disclosure

We do not sell your personal data. We share data only with:

  • Meta Platforms, Inc. — WhatsApp Cloud API for message delivery
  • Safaricom PLC — Daraja API for M-Pesa payment processing (both customer payments and subscription payments)
  • Google LLC — Gemini API for AI conversation processing
  • MongoDB, Inc. — Database hosting (encrypted)

6. Data Security

We implement industry-standard security measures: encryption at rest (Fernet AES-128-CBC), encryption in transit (TLS 1.3), bcrypt password hashing, and access controls with multi-factor authentication.

7. Data Retention

We retain your data only as long as necessary. Upon account termination, data is permanently deleted within 30 days, except for records we are legally required to retain.

8. Your Rights (Kenya Data Protection Act 2019)

You have the right to access, rectify, erase, restrict processing, data portability, object, withdraw consent, and lodge a complaint with the ODPC Kenya.

9. Subscription Payment Data

When you pay for your JYVUX-AI subscription via M-Pesa, we collect and process:

  • The M-Pesa phone number you use for payment
  • The transaction receipt number from Safaricom
  • The amount paid and the plan selected
  • The date and time of payment

This data is used exclusively to manage your subscription status, calculate overage charges, and maintain payment records. Subscription payments are processed through JYVUX-AI's company M-Pesa account, separate from your shop's M-Pesa credentials used for customer transactions.

10. Cookies & Tracking Technologies

Our website and dashboard use essential cookies for authentication and security. We do not use tracking cookies for advertising purposes.

11. Third-Party Services & Links

Our Services integrate with Meta WhatsApp, Safaricom M-Pesa, Google Gemini, MongoDB Atlas, and Redis. We encourage you to review their privacy policies.

12. Children's Privacy

Our Services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children.

13. International Data Transfers

Your data is primarily stored and processed in Kenya. When data is transferred internationally, we ensure adequate safeguards are in place.

14. Changes to This Privacy Policy

We may update this policy from time to time. Material changes will be communicated via email or dashboard notice.

15. Contact Information & Complaints

15.1 Contact Our Data Protection Officer

15.2 Lodge a Complaint with ODPC Kenya

JYVUX-AI — Founded by Jacton Osara, Nairobi, Kenya.