Privacy Policy
Last Updated: May 10, 2026 | Version: 2.1
1. Introduction
JYVUX-AI ("JYVUX-AI," "we," "us," or "our"), founded by Jacton Osara, is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, process, store, share, and protect your personal information when you use our website, merchant dashboard, WhatsApp bot services (Jyvux), and all related services.
This policy is drafted in compliance with the Kenya Data Protection Act, 2019 (DPA 2019) and the Data Protection (General) Regulations, 2021.
2. Information We Collect
2.1 Information You Provide Directly
| Category | Examples | Purpose |
|---|---|---|
| Shop Information | Business name, physical address, city, contact phone, email address, business hours | Account creation, bot configuration, customer communication |
| WhatsApp Numbers | Owner WhatsApp number, bot WhatsApp number | WhatsApp Cloud API integration, message routing |
| M-Pesa Credentials | Consumer Key, Consumer Secret, Passkey, Shortcode | Payment processing via Safaricom Daraja API |
| Account Credentials | Dashboard password (hashed), Meta OAuth tokens | Account security, platform authentication |
| Subscription Payment Data | M-Pesa phone number used for subscription payments, transaction receipts, payment amounts | Processing your plan subscription payments |
2.2 Information We Do NOT Collect
- We do not store your M-Pesa PIN or customer M-Pesa PINs.
- We do not access or read your personal WhatsApp messages.
- We do not sell, rent, or trade your personal data or your End Customers' data.
3. How We Use Your Information
We use the information we collect for:
- Service Provision: To create your account, configure your WhatsApp bot, process M-Pesa payments, and deliver our core functionality.
- Subscription Management: To process your plan payments via M-Pesa, track trial periods, calculate overage charges, and manage your subscription status.
- AI Bot Operation: Customer conversation data powers jyvux's AI responses in English, Kiswahili, and Sheng.
- Analytics & Reporting: To generate sales reports, revenue insights, and AI-powered business recommendations.
- Communication: To send account notifications, billing reminders, and support messages.
4. Legal Basis for Processing
Under the Kenya Data Protection Act 2019, we rely on:
- Contractual Necessity: Processing your data to provide the Services.
- Legitimate Interests: Improving our Services, preventing fraud, ensuring platform security.
- Consent: Where required by law, we obtain your explicit consent.
- Legal Obligation: Complying with applicable Kenyan laws.
5. Data Sharing & Disclosure
We do not sell your personal data. We share data only with:
- Meta Platforms, Inc. — WhatsApp Cloud API for message delivery
- Safaricom PLC — Daraja API for M-Pesa payment processing (both customer payments and subscription payments)
- Google LLC — Gemini API for AI conversation processing
- MongoDB, Inc. — Database hosting (encrypted)
6. Data Security
We implement industry-standard security measures: encryption at rest (Fernet AES-128-CBC), encryption in transit (TLS 1.3), bcrypt password hashing, and access controls with multi-factor authentication.
7. Data Retention
We retain your data only as long as necessary. Upon account termination, data is permanently deleted within 30 days, except for records we are legally required to retain.
8. Your Rights (Kenya Data Protection Act 2019)
You have the right to access, rectify, erase, restrict processing, data portability, object, withdraw consent, and lodge a complaint with the ODPC Kenya.
9. Subscription Payment Data
When you pay for your JYVUX-AI subscription via M-Pesa, we collect and process:
- The M-Pesa phone number you use for payment
- The transaction receipt number from Safaricom
- The amount paid and the plan selected
- The date and time of payment
This data is used exclusively to manage your subscription status, calculate overage charges, and maintain payment records. Subscription payments are processed through JYVUX-AI's company M-Pesa account, separate from your shop's M-Pesa credentials used for customer transactions.
10. Cookies & Tracking Technologies
Our website and dashboard use essential cookies for authentication and security. We do not use tracking cookies for advertising purposes.
11. Third-Party Services & Links
Our Services integrate with Meta WhatsApp, Safaricom M-Pesa, Google Gemini, MongoDB Atlas, and Redis. We encourage you to review their privacy policies.
12. Children's Privacy
Our Services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children.
13. International Data Transfers
Your data is primarily stored and processed in Kenya. When data is transferred internationally, we ensure adequate safeguards are in place.
14. Changes to This Privacy Policy
We may update this policy from time to time. Material changes will be communicated via email or dashboard notice.
15. Contact Information & Complaints
15.1 Contact Our Data Protection Officer
- Email: privacy@jyvuxai.co.ke
- WhatsApp: +254 108 305 015
- Postal Address: Data Protection Officer, JYVUX-AI, Nairobi, Kenya
15.2 Lodge a Complaint with ODPC Kenya
- Office of the Data Protection Commissioner (ODPC)
- Website: https://www.odpc.go.ke
- Email: info@odpc.go.ke
JYVUX-AI — Founded by Jacton Osara, Nairobi, Kenya.