All documents

Legal

Data Processing Agreement

Your buyers’ data is yours to answer for. This sets out how we handle it for you, what we will never do with it, and what happens when you ask us to delete it.

Version v1.0 · In force from 25 July 2026

1.What this agreement does

When a buyer messages your shop, their personal data is involved: their number, what they said, where they want it delivered, what they bought. Under the Data Protection Act, 2012 (Act 843) somebody has to answer for that data. This agreement sets out that you do, and that we handle it for you and on your instructions.

It is between you, the account holder, and Kasa. It applies automatically from the moment you open an account and for as long as we hold buyer data for you. It forms part of our Terms of Service, and where the two disagree on the handling of buyer personal data, this document wins.

2.Roles, and the instructions we act on

You are the data controller of your buyers' personal data. You decide why you hold it and what you do with it, and you own the relationship with the buyer. We are your data processor.

Your documented instruction to us is this, and nothing wider: run your shop on the channels you connect. Receive and answer buyer messages, negotiate within the limits you set, take and track orders, present your payment details, and keep the record of what happened.

We process buyer data only to carry that out, or where Ghanaian law requires something more of us. We never process it for our own purposes. We do not sell it, we do not advertise on it, and we do not allow it to be used to train anyone's AI models. If we ever believe an instruction from you would break the law, we will tell you rather than quietly follow it.

3.What is processed

Detail
Subject matterRunning your shop on WhatsApp and any other channel you connect.
DurationFor as long as your account is open, then as set out in section 9.
Nature of the processingReceiving, storing, displaying, analysing and sending messages; drafting replies with AI models; recording orders and payments; backing up; and deleting on schedule.
PurposeServing the buyer who contacted your shop, and keeping the record of that sale.
People affectedYour buyers and anyone who messages your shop.
Data involvedPhone number and profile name, message content including voice notes and images, stated delivery location, and order history with your shop.
Sensitive dataNone is asked for and none is needed. Anything a buyer volunteers is held as ordinary message content.

4.What we commit to as your processor

  • To process buyer data only on your instructions and only to provide the service.
  • To keep it confidential, and to bind everyone at Kasa who can reach it to confidentiality.
  • To apply the security measures in section 5, and to keep them at least as strong as they are described there.
  • To use only the sub-processors listed in section 6, to hold them to these same duties, and to tell you before that list changes materially.
  • To help you answer a buyer’s request about their data, as set out in section 7.
  • To tell you about a personal data breach without undue delay, as set out in section 8.
  • To delete or return buyer data when you leave, as set out in section 9.
  • To give you what you reasonably need to show a regulator that this arrangement is sound.

5.The security measures we apply

  • Separation between shops enforced inside the database itself, not only in the application, so one shop cannot reach another’s data. Every release is tested for it.
  • Encryption of data while it travels and while it is stored, with mobile money numbers, sign in secrets and channel tokens separately encrypted on top and never displayed in full.
  • Access by role, with staff accounts unable to reach money, billing or data requests, and our own administrators behind a mandatory second step of sign in.
  • An append only record of every action that touches money, and of every administrative action, neither of which can be edited afterwards.
  • Encrypted backups held in a separate account with keys kept apart from the data, restored regularly to prove they work.
  • Continuous automated monitoring, rate limiting, account lockout under attack, and alerting to a person when something is wrong.

These measures develop as the product does. We may change them, and we will not weaken the protection they provide.

6.Sub-processors

You authorise us to use the companies listed in the Privacy Policy, which names each one, what it does and what it can reach. Each is bound by written terms at least as protective as this agreement.

Before we add or replace a sub-processor that handles buyer personal data we will tell you, by email or in your dashboard. If you object on reasonable data protection grounds, tell us within 14 days and we will look for an alternative. If there is none, you may close your account for that reason without penalty, and we will refund any period you have paid for and not used.

We remain responsible to you for what our sub-processors do with your buyers' data.

7.Helping you answer a buyer

A buyer can ask you for a copy of their data or ask you to delete it. The tools to answer are in your dashboard, they belong to the owner of the account, and they ask for your second step of sign in before they run, because they move real data.

What the buyer asks forWhat the tool does
A copy of their dataExports every conversation, the full transcript, and their orders and events with your shop.
DeletionErases the content of their messages and removes what identifies them, then leaves orders and money records in place with nothing naming them.
A copy of everything in the shopExports the whole workspace. Your mobile money number is never included in an export.

Every request is written to a log that cannot be edited, so you can show what you did and when. If a buyer comes to us directly, we point them to you and tell you. Where you ask us to act for you, we aim to complete it within 7 business days.

Deletion does not erase the fact of a sale. Orders and payment records are kept for the period tax law and disputes require, with everything that names the buyer removed. This protects you as much as them.

8.If there is a breach

If personal data we hold for you is lost, exposed or reached by someone who should not have it, we will tell you without undue delay and within 72 hours of becoming aware of it. We will tell you what happened, which data and roughly how many people are affected, what we have done, and what we suggest you do.

We will help you meet your own duty to notify the Data Protection Commission of Ghana or the buyers affected where the law requires that, and we will keep you updated as we learn more rather than waiting for a complete picture.

9.Data outside Ghana

Some of our providers hold data outside Ghana, including the database, the media and backup storage, and the AI providers. You authorise those transfers. Where one happens we protect it with written agreements limiting each provider to our instructions, encryption in transit and at rest, and a ban on any use of their own, consistent with the Data Protection Act, 2012 (Act 843). The regions in use are recorded internally and available on request.

10.When you leave

Export what you want before you close your account. The dashboard can export the whole workspace at any time while the account is open.

After closure we delete or make anonymous the buyer data we hold for you, within 30 days, except where Ghanaian law requires us to keep something for longer. Records tied to money are kept for their statutory period with everything that names a buyer removed. Media files are deleted after a short grace period, which exists so that an account closed by mistake can be recovered.

Backups, stated plainly

Deletion takes effect in our live systems immediately. Copies inside encrypted backups expire on their normal rotation, which is 30 days for daily copies and 12 months for monthly ones. We do not promise deletion on demand from a backup, because a backup that can be reached into and edited is not a backup. Those copies are encrypted, their keys are held somewhere other than the backup store, access is restricted to administrators and logged, and no restored copy is ever used to bring erased data back into service.

11.Showing that this works

On reasonable notice, and no more than once a year unless a regulator or a breach requires otherwise, we will answer your questions about how we handle your buyers' data and give you the documentation you need to satisfy yourself and a regulator. Because Kasa serves many shops on shared systems, this takes the form of documentation and answers rather than access to the systems themselves, which would expose other shops'data.

12.What you commit to as the controller

  • To have a lawful basis for the buyer data you collect, which for an ordinary sale is serving the buyer who contacted you.
  • To tell your buyers how their data is used. A notice you can copy is in section 12.
  • To keep your account and your staff accounts secure, and to remove staff who no longer work with you.
  • Not to enter into Kasa personal data you have no reason to hold, and not to ask buyers for sensitive information through it.
  • To answer requests from your buyers, using the tools we provide.

13.A notice you can give your buyers

Copy this, fill in the two blanks, and send it as a pinned message, in your WhatsApp profile, or on your website. It is written to be read on a phone by a customer, not by a lawyer.

How we use your details

You are chatting with [your shop name]. We use Kasa, a WhatsApp assistant, to help answer your messages and take your orders.

We keep your WhatsApp number, the messages you send us including voice notes and photos, any delivery location you give us, and your order history with us. We use it only to serve you: to answer your questions, agree a price, take and deliver your order, and arrange payment. We do not sell your details and we do not use them for unrelated advertising.

Your details are seen by us and by the technology providers who help us run the chat and store it securely, including Kasa, WhatsApp and our AI provider, who may only use them to provide the service to us.

We keep your chat for as long as we need it to serve you and then remove its content. Order records are kept longer where the law requires, for example for tax.

You can ask us for a copy of your details or ask us to delete them. Message us here or contact [your email or phone]. If we delete them, we may still keep order and payment records the law requires, with your details removed from them. You can also contact the Data Protection Commission of Ghana if you have a concern.

14.Liability, changes and law

Liability under this agreement is subject to the limits in our Terms of Service.

We may update this agreement as the law and the product develop, and we will tell you before a material change takes effect. Every version carries a number and a date at the top of this page.

It is governed by the laws of Ghana. Questions go to support@kasarm.com with Data protection in the subject line.