1.Who we are
Kasa is a WhatsApp sales assistant for sellers in Ghana. This policy explains what we do with personal data, and it applies to our website, the seller dashboard, and the assistant that answers messages for a shop.
If you have a question about anything here, write to support@kasarm.com and put Data protection in the subject line so it reaches the right person quickly.
2.Two roles, and why the difference matters
Under the Data Protection Act, 2012 (Act 843), whoever decides why personal data is used is the data controller and answers for it. Whoever only handles it on someone else's instructions is the data processor. Kasa is both, in different places.
- For a seller's own data we are the controller. Your name, your email address, your shop details, your billing records and how you use the dashboard. This policy covers all of it.
- For a buyer's data we are the seller's processor. When someone messages a shop, that shop decides why the conversation happens and what to do with it. The shop is the controller. We hold and handle that conversation on the shop's instructions and for no purpose of our own. The terms of that arrangement are in the Data Processing Agreement.
In practice: if you are a buyer and you want your chat deleted, the shop you messaged is the one to ask, and we give every shop the tools to do it. If they cannot help, write to us and we will act on the shop's behalf as their processor.
3.What we collect
From sellers
- Account details: your name, email address, password (stored only as a strong one way hash, never as text we can read), your workspace handle, and the second step of sign in if you switch it on.
- Shop details: your shop name, your products, prices, photos, delivery areas and charges, your business phone numbers, and the WhatsApp number you connect.
- Payment details for receiving money: your mobile money number and name, which we store encrypted and show only in a masked form.
- Billing records: your plan, invoices, payments to us, and the assistant usage counted against your allowance.
- Support conversations: the requests you send us and our replies.
From buyers, on behalf of the shop they messaged
- Their WhatsApp number and profile name as the channel provides it.
- The messages they send and receive, including voice notes, photos and screenshots.
- Any delivery location or landmark they give.
- Their orders with that shop, and the record of what was agreed and confirmed.
Buyers are not asked for sensitive information such as health, religion or political views, and no part of the product needs it. If someone volunteers something like that in a chat, it is held as ordinary message content and nothing is built on it.
Automatically, when the service is used
- A record of requests to our systems, holding the time, the route, the result, the IP address, a coarse location (country, and at most a region) and a plain description of the browser and device family.
- Sign in events, including failures, which is what lets us lock an account that is under attack and tell you about a sign in from a new device.
- Aggregate page speed and page view measurements for our website, which carry no identifier and no cookie.
Location is worked out on our own servers from a local database, so no visitor's IP address is ever sent to an outside location service. Device details are grouped into families, so we know a request came from a phone browser without recording which phone.
4.Why we use it, and on what basis
Every use below is tied to a lawful basis under the Data Protection Act, 2012 (Act 843). We do not sell personal data, we do not rent it, and we do not profile buyers for advertising.
| What we use it for | What that involves | Basis |
|---|---|---|
| Running your shop | Answering buyer messages, quoting your prices, agreeing a price within your floor, recording orders and showing your payment details. | Performing the agreement we have with you, and for buyer data the instruction of the shop under its own basis. |
| Your account | Signing you in, keeping your session, letting you invite staff, and sending account and security emails. | Performing our agreement with you. |
| Billing | Issuing invoices, recording payment, counting assistant conversations against your allowance and telling you when a period is ending. | Performing our agreement, and our legal obligation to keep financial records. |
| Keeping the service safe | Locking accounts under attack, spotting a flood of automated messages, rate limiting, fraud checks and investigating incidents. | Our legitimate interest in a secure service, which is also what protects your shop and your buyers. |
| Support | Answering the request you sent, and looking at the record of what happened so we can explain it. | Performing our agreement with you. |
| Improving Kasa | Counting how features are used and where the product is slow or failing, using figures rather than message content. | Our legitimate interest in a product that works. |
| Legal duties | Keeping records that tax law and other Ghanaian law require us to keep, and responding to a lawful request from an authority. | Our legal obligation. |
5.How the assistant uses conversations
The assistant reads the recent part of a conversation, along with the shop's products and rules, and drafts a reply. To do that, the conversation text, any photo the buyer sent and any voice note they recorded are sent to the artificial intelligence providers listed below, for that single request.
Three limits apply, and they are built into the product:
- Your content is not used to train anyone’s models. Our agreements with those providers do not permit it.
- Secrets never leave. Passwords, one time codes, recovery codes, mobile money numbers and access tokens are never included in what is sent to a model.
- The model never decides money. Prices, floors, stock, payment details and the state of an order are filled in by our own server from your records after the model has drafted the words.
Product photos are also turned into a numeric representation so the assistant can match a screenshot a buyer sends to the right item. That representation cannot be turned back into the photo.
7.Cookies and what is kept in your browser
We do not use advertising cookies, and we do not track you across other websites. Our page view and page speed measurements are collected without cookies and without an identifier for you.
The dashboard does keep a few things in your own browser, on your own device, which never leave it except when you are talking to us:
- Your sign in token, so you stay signed in between visits. Signing out removes it.
- The page you were heading to before you signed in, which is discarded as soon as you get there.
- Drafts of anything you were typing, such as a support request, so a lost connection does not lose your words.
Clearing your browser storage removes all of it and signs you out. If we ever introduce a cookie that is not strictly necessary, we will ask you first.
8.How long we keep things
Chat content is kept only as long as it is useful and is then removed from the record. Money records are kept longer, because tax law and disputes need them, and where a buyer asks to be erased those records stay but stop naming them.
| What | How long | Counted from | Then |
|---|---|---|---|
| Buyer messages and chat details | 2 years | the last activity in that chat | the content is erased and an anonymous shell of the thread remains |
| Orders and their event history | 6 years | the order closing | kept, and stripped of anything naming the buyer if they are erased |
| Mobile money change records | 6 years | the change | kept, already masked |
| Records of data requests | 6 years | the request | kept, as proof the request was honoured |
| Incoming message ledger | 30 days | receipt | deleted |
| Sign in sessions | 90 days after expiry | expiry | deleted |
| Request logs | 90 days | the request | deleted, leaving only counts that name nobody |
| Security related request logs | 12 months | the request | deleted |
| Encrypted backups | 30 days for daily copies, 12 months for monthly copies | the copy being taken | expire on their own rotation |
A nightly job applies these windows automatically. Account details are held while your account is open, and after it closes they are removed or made anonymous on the same timetable.
Deletion in our live systems happens straight away. Copies inside encrypted backups expire on the rotation above rather than on demand, because a backup that can be edited is not a backup. No restored copy is ever used to bring erased data back into service.
9.How we protect it
- Every shop’s data is separated inside the database itself, so one shop cannot read another’s even if the application is wrong. This is tested on every change.
- Data is encrypted while it travels and while it is stored. Mobile money numbers, second step secrets and channel tokens are separately encrypted on top of that, and are never shown in full.
- Passwords are stored as a strong one way hash. Nobody at Kasa can read your password.
- Access is limited by role. Staff accounts cannot reach money, billing or data requests. Our own administrators work behind a second step of sign in, and what they do is written to a record that cannot be edited.
- Every action that touches money is written to an append only log.
- Backups are encrypted, stored in a separate account, and restored regularly to prove they work.
- Automated checks watch the service continuously and raise an alert when something looks wrong.
If a breach affects personal data we hold, we investigate at once, tell the sellers affected without undue delay, and notify the Data Protection Commission of Ghana where the law requires it. Where the incident is a cybersecurity incident of the kind the Cybersecurity Act, 2020 (Act 1038) covers, we report it as that Act requires.
10.Where the data is held
Kasa is built and run in Ghana, and some of the companies that host it store data outside Ghana. That is the case for our application hosting, our database, our media and backup storage, and the AI providers that draft replies.
Where data leaves Ghana we make sure it is protected to a standard consistent with the Data Protection Act, 2012 (Act 843): written agreements with each provider limiting what they may do with it, encryption while it travels and while it is stored, and a ban on using it for their own purposes. The regions used are recorded internally and are available to a seller who asks.
11.Your rights
Under the Data Protection Act, 2012 (Act 843) you can ask us to do the following with personal data we hold about you:
- Tell you what we hold and why, and give you a copy of it.
- Correct anything that is wrong or out of date.
- Delete it, or block a particular use of it, where we have no lasting reason or legal duty to keep it.
- Stop using it for a purpose you object to, including any marketing.
- Withdraw a consent you gave, which does not undo what was lawfully done before you withdrew it.
How to ask
Sellers can export a whole workspace, or one buyer's data, from the dashboard at any time, and can erase a buyer from there too. For anything else, write to support@kasarm.com. We will confirm we received it, check that the request really comes from you, and answer within 7 business days. If a request is complicated we will tell you and finish it within 30 days.
Asking is free. We only charge where a request is repeated or clearly excessive, and we say so before doing any work.
If you are a buyer
Ask the shop you messaged first, because they hold the relationship and the tools. If they do not resolve it, write to us at support@kasarm.com naming the shop, and we will act on their behalf.
If we get it wrong
Tell us and we will try to put it right. You can also complain to the Data Protection Commission of Ghana, which supervises the use of personal data in Ghana and publishes its contact details on its own website. You do not have to come to us first, but it is usually quicker.
12.Children
Kasa is a business tool for adults. You must be at least 18 to open an account, and the service is not directed at children. If we learn that we hold the personal data of a child who has no business being on the platform, we remove it.
13.Changes to this policy
As Kasa grows, this policy will change with it. Every version carries a number and a date at the top of the page. When a change materially affects you we will tell you by email or in the dashboard before it takes effect, rather than quietly replacing the text.
14.Contact
Write to support@kasarm.com with Data protection in the subject, or use any of the ways listed on our contact page. We reply within one business day.