Last updated: 30 July 2026
We wish to reiterate that HabariChat respects your privacy and are strongly committed to keeping secure any information we obtain from you or about you. This Privacy Policy describes our practices with respect to Personal Information we collect from or about you when you use our website, applications, and services (collectively, "Services"). Our use of that data is governed by our customer agreements covering access to and use of those offerings.
HabariChat is a product of Habari Labs Limited, a private limited company incorporated in the Republic of Kenya under the Companies Act, 2015, with company number PVT-BB1PA5W3 and registered office at P.O. Box 43529, 00100 G.P.O. Nairobi, Kenya. Habari Labs Limited is registered with the Office of the Data Protection Commissioner as both a data controller and a data processor, and is the entity responsible for the processing described in this Privacy Policy. In this Privacy Policy, "HabariChat", "we", "us", and "our" refer to Habari Labs Limited. Our registration details are set out in Section 10.
Two different kinds of data, two different roles. This Privacy Policy describes how we handle Personal Information for which we are the data controller: the account, billing, support and website data we collect to run our own business. It also explains, in Section 10 and Section 11, how we handle the messages, contact records and other personal data that our business customers and their end customers exchange through the platform. For that second category we act as a data processor on our customer's documented instructions, and the terms of our Data Processing Agreement govern that processing. Where a business customer has signed a Software Subscription and Services Agreement with us, its Data Processing Schedule prevails over this Privacy Policy in respect of that customer's data.
We collect personal information relating to you ("Personal Information") as follows:
Personal Information You Provide: We collect Personal Information if you create an account to use our Services or communicate with us as follows:
Account Information: When you create an account with us, we will collect information associated with your account, including your name, contact information, and authentication credentials.
User Content: When you use our Services, we collect Personal Information that is included in the input, file uploads, or feedback that you provide to our Services ("Content").
Communication Information: If you communicate with us, we collect your name, contact information, and the contents of any messages you send ("Communication Information").
Social Media Information: We have pages on social media sites like Instagram, Facebook, Medium, Twitter, YouTube and LinkedIn. When you interact with our social media pages, we will collect Personal Information that you elect to provide to us, such as your contact details (collectively, "Social Information"). In addition, the companies that host our social media pages may provide us with aggregate information and analytics about our social media activity.
Personal Information We Receive Automatically From Your Use of the Services: When you visit, use, or interact with the Services, we receive the following information about your visit, use, or interactions ("Technical Information"):
Log Data: Information that your browser automatically sends when you use our Services. Log data includes your Internet Protocol address, browser type and settings, the date and time of your request, and how you interact with our website.
Usage Data: We may automatically collect information about your use of the Services, such as the types of content that you view or engage with, the features you use and the actions you take, as well as your time zone, country, the dates and times of access, user agent and version, type of computer or mobile device, and your computer connection.
Device Information: Includes name of the device, operating system, device identifiers, and browser you are using. Information collected may depend on the type of device you use and its settings.
Cookies: We use cookies to operate and administer our Services, and improve your experience. A "cookie" is a piece of information sent to your browser by a website you visit. You can set your browser to accept all cookies, to reject all cookies, or to notify you whenever a cookie is offered so that you can decide each time whether to accept it. However, refusing a cookie may in some cases preclude you from using, or negatively affect the display or function of, a website or certain areas or features of a website.
Analytics: We may use a variety of online analytics products that use cookies to help us analyze how users use our Services and enhance your experience when you use the Services.
Third-Party Authentication: HabariChat respects the privacy and security of our users' data, including any information accessed through third-party OAuth providers such as Google, Microsoft, or other authentication services. We utilize third-party user data solely for the purpose of providing our services and enhancing the user experience. This may include accessing basic profile information to personalize the user experience and securely storing this data in accordance with industry standards. We do not share third-party user data with any external parties unless explicitly authorized by the user or required by law. Our privacy policy transparently outlines the specific ways in which we access, use, store, and potentially share third-party user data, ensuring clarity and accountability in our practices.
When you choose to sign in to HabariChat using your third-party account via OAuth, our application receives your email address, name, and profile picture from the authentication provider, as well as a unique identifier that allows you to log in. HabariChat uses this information to authenticate you and personalize your experience within the application. We securely store your unique identifier and email address to maintain your account and allow you to access your data across devices. HabariChat does not share your individual third-party user data with any external parties. We retain this data for as long as you maintain an active account with our service. If you wish to revoke HabariChat's access to your third-party account information, you may do so at any time through your respective account settings.
When you connect your Facebook Page to HabariChat, we access limited data from your Facebook account in order to deliver our messaging and customer support services. This access is granted through Facebook’s authorized login process and is subject to your explicit consent.
Permissions and Data Accessed:
Through the Facebook login process, HabariChat may request the following permissions:
These permissions allow us to:
We do not access your personal Facebook profile data beyond what is necessary for Page authorization. HabariChat does not publish to your Pages, nor do we post or take any actions on your behalf without your explicit action or instruction.
Use of Facebook Data:
Any data accessed through Facebook is used solely for the purpose of enabling you to respond to messages, track conversations, and manage interactions within your Facebook Page’s inbox through the HabariChat platform. We do not sell, share, or use this data for any other purpose.
Data Retention and Revocation:
We retain Facebook Page-related access data only for as long as your account is connected to HabariChat or until you revoke access. You may disconnect your Facebook Page at any time through your HabariChat account settings or directly via your Facebook account's Business Integrations settings.
Compliance with Facebook Platform Policies:
HabariChat complies with Meta’s Platform Terms and Developer Policies, including requirements around user transparency and data security. For more information about how Facebook handles your data, please review Meta’s Data Policy.
We may use Personal Information for the following purposes:
Aggregated or De-Identified Information: We may aggregate or de-identify Personal Information so that it may no longer be used to identify you and use such information to analyze the effectiveness of our Services, to improve and add features to our Services, to conduct research and for other similar purposes.
AI Model Training: We do not use identifiable customer data, including the messages, contact records, knowledge-base content and customer conversations processed through the platform on behalf of a business customer, to train a general-purpose model or a model made available to other customers, unless that customer has given written consent. We may use anonymous and combined service information to operate, secure and improve HabariChat, provided that the information does not identify the customer or any individual.
In certain circumstances we may provide your Personal Information to third parties:
Vendors and Service Providers: To assist us in meeting business operations needs and to perform certain services and functions, we may provide Personal Information to vendors and service providers, including providers of hosting services, cloud services, and other information technology services providers, email communication software, and web analytics services, among others. Pursuant to our instructions, these parties will access, process, or store Personal Information only in the course of performing their duties to us.
Subprocessors of Business Customer Data: Where we act as a data processor for a business customer, we use only the subprocessors required to provide the Services. Each subprocessor is bound by appropriate written data-protection obligations and we remain responsible for its performance. We maintain a current subprocessor list, which is available to business customers on request at [email protected], and we give reasonable notice before appointing a material new subprocessor. A business customer may object to a new subprocessor within ten business days on reasonable data-protection grounds, and we will work with them to find a reasonable alternative.
Business Transfers: If we are involved in strategic transactions, reorganization, bankruptcy, receivership, or transition of service to another provider (collectively, a "Transaction"), your Personal Information and other information may be disclosed in the diligence process with counterparties and others assisting with the Transaction and transferred to a successor or affiliate as part of that Transaction along with other assets.
Legal Requirements: We may share your Personal Information, including information about your interaction with our Services, with government authorities, industry peers, or other third parties (i) if required to do so by law or in the good faith belief that such action is necessary to comply with a legal obligation, (ii) to protect and defend our rights or property, (iii) if we determine, in our sole discretion, that there is a violation of our terms, policies, or the law; (iv) to detect or prevent fraud or other illegal activity; (v) to protect the safety, security, and integrity of our products, employees, or users, or the public, or (vi) to protect against legal liability.
As a user, you have a right to:
To the extent provided for by local law and subject to applicable exceptions, individuals may have the following privacy rights in relation to their Personal Information:
We don't "sell" Personal Information or "share" Personal Information for cross-contextual behavioral advertising (as those terms are defined under applicable local law). We also don't process sensitive Personal Information for the purposes of inferring characteristics about a consumer.
Exercising Your Rights: To the extent applicable under local law, you can exercise privacy rights described in this section by submitting a request to [email protected]
Verification: In order to protect your Personal Information from unauthorized access, change, or deletion, we may require you to verify your credentials before you can submit a request to know, correct, or delete Personal Information. If you do not have an account with us, or if we suspect fraudulent or malicious activity, we may ask you to provide additional Personal Information and proof of residency for verification. If we cannot verify your identity, we will not be able to honor your request.
Our Service is not directed to children under the age of 18. HabariChat does not knowingly collect Personal Information from children under the age of 18, and accounts may not be created or used by persons under 18.
Where HabariChat is used by educational institutions or other business customers to communicate with or about minors, such processing is subject to the enhanced protections for children's personal data under the Kenya Data Protection Act, 2019, and is governed by Section 11(c) of this Privacy Policy. In those contexts, the educational institution acts as the data controller and is responsible for obtaining and maintaining valid parental or guardian consent in accordance with applicable law.
We implement commercially reasonable technical, administrative, and organizational measures to protect Personal Information both online and offline from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. These measures are appropriate to the nature of the Services and include access limited according to role and business need, password and authentication controls, encryption of data in transit and, where supported by the hosting service, at rest, reasonable software testing and vulnerability management, security and operational logging, backups and recovery procedures, confidentiality and security training for authorised personnel, written security obligations for material service providers, and incident response and secure deletion procedures. We may update these measures provided that the overall level of protection is not materially reduced.
However, no Internet or email transmission is ever fully secure or error free. In particular, email sent to or from us may not be secure. Therefore, you should take special care in deciding what information you send to us via the Service or email. In addition, we are not responsible for circumvention of any privacy settings or security measures contained on the Service, or third-party websites.
Personal Data Breach Notification: Where we act as a data processor for a business customer, we will notify that customer without undue delay and, where reasonably possible, within twenty-four hours after confirming a personal data breach affecting their data. The notice will set out the available details of the nature of the breach, the information and persons affected, the likely consequences, and the steps taken or proposed. We will investigate, contain and remedy the breach and provide reasonable assistance with any notification required by law, including any notification to the Office of the Data Protection Commissioner or to affected data subjects. Where we act as a data controller in our own right, we will notify affected data subjects and the ODPC as required by the Kenya Data Protection Act, 2019.
Audit: A business customer may, once in any twelve-month period and on at least fifteen business days' notice, request information or conduct a reasonable audit of our compliance with our data-protection obligations. An audit must protect other customers' information and avoid unreasonable disruption. An additional audit may be conducted following a material breach or where required by a regulator.
We'll retain your Personal Information for only as long as we need in order to provide our Service to you, or for other legitimate business purposes such as resolving disputes, safety and security reasons, or complying with our legal obligations. How long we retain Personal Information will depend on a number of factors, such as the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, our purpose for processing the information, and any legal requirements.
Export and Deletion at the End of a Subscription: When a business customer's subscription ends, we make their data available for export in a standard format for thirty days after termination, subject to payment of undisputed amounts. After that period we may delete the data unless the law requires it to be retained, and we will otherwise return or delete personal data as the customer directs. Data held in secure backups may remain until it is deleted through the normal backup cycle.
By using our Service, you understand and acknowledge that your Personal Information will be processed and stored in our facilities and servers and may be disclosed to our service providers and affiliates in other jurisdictions.
Legal Basis for Processing: Our legal bases for processing your Personal Information include:
We may update this Privacy Policy from time to time. When we do, we will post an updated version on this page, unless another type of notice is required by applicable law.
Please contact us at [email protected] if you have any questions or concerns not already addressed in this Privacy Policy.
HabariChat is subject to and complies with the Kenya Data Protection Act, 2019 (No. 24 of 2019) ("KDPA") and its subsidiary regulations, including the Data Protection (General) Regulations, 2021, the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, and the Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021. As a data controller and, where applicable, a data processor operating within the Republic of Kenya and processing the Personal Information of Kenyan data subjects, we are committed to processing your Personal Information lawfully, fairly, and transparently in full accordance with the KDPA's requirements.
Our Role Under the KDPA:
HabariChat acts as a data controller when we determine the purposes and means of processing your Personal Information in connection with our Services, for example when managing your account, communicating with you, or improving our platform. Where we process Personal Information on behalf of our business customers (for example, when a business uses HabariChat to communicate with its own end customers), we act as a data processor, operating solely under the lawful instructions of that business as the data controller. We maintain the registrations and internal records required of data controllers and data processors under the KDPA and its subsidiary regulations.
Our ODPC Registrations:
Because we act in both capacities, Habari Labs Limited holds a separate registration with the Office of the Data Protection Commissioner for each. Both were issued under the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 and share a single ODPC registration identification:
These registrations may be verified against the public register maintained by the Office of the Data Protection Commissioner. Copies of both certificates are available on request at [email protected], together with our standard Data Processing Agreement for business customers who require one.
Lawful Basis for Processing Under the KDPA:
We process your Personal Information only where we have a valid and documented lawful basis to do so. Under the KDPA, the lawful bases on which we may rely include:
Your Rights Under the KDPA:
In addition to the rights described in Section 4 of this Privacy Policy, the KDPA specifically guarantees Kenyan data subjects the following rights. These rights may be exercised at no charge by submitting a request to [email protected], and we will respond within the timelines prescribed by the KDPA and its subsidiary regulations.
We will not discriminate against you for exercising any of the rights listed above. We may, however, need to verify your identity before processing a rights request, and we may decline requests that are manifestly unfounded, excessive, or that conflict with our obligations under applicable law.
Cross-Border Data Transfers:
The KDPA restricts the transfer of Personal Information outside Kenya to jurisdictions that do not provide a level of data protection that is at least equivalent to that afforded under the KDPA. Where we transfer your Personal Information to countries, territories, or international organisations outside Kenya (for example, to cloud infrastructure providers, analytics platforms, or other service providers), we take steps to ensure that such transfers comply with the KDPA. Where we act as a data processor for a business customer, we transfer personal data outside Kenya only where the transfer is required to provide the Services, the business customer has been informed, and the safeguards required by law are in place. Any agreed hosting or data-location requirement is recorded in that customer's Order Form. Safeguards we may rely on include: (i) a determination by the relevant Kenyan authority that the recipient jurisdiction provides an adequate level of protection; (ii) the use of standard contractual clauses or data transfer agreements incorporating appropriate technical and organisational protections; or (iii) where required, your explicit and informed consent to the specific transfer after being made aware of the possible risks. You may request details of the specific safeguards applicable to any international transfer of your Personal Information by contacting us at [email protected].
Data Protection Officer:
HabariChat has designated a Data Protection Officer ("DPO") responsible for overseeing our compliance with the KDPA and its subsidiary regulations, and for serving as the primary point of contact for data subjects and the Office of the Data Protection Commissioner on all matters relating to data protection. You may contact our DPO at [email protected] with the subject line "Attention: Data Protection Officer."
Sensitive Personal Data:
The KDPA affords heightened protection to certain categories of Personal Information classified as sensitive, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person's sex life or sexual orientation. HabariChat does not intentionally collect sensitive Personal Data from users of our general Services. Where any such data is processed in connection with a specific use case (for example, health-related information shared by a clinic using our platform), processing will be subject to explicit consent or another lawful basis permitted under the KDPA, and will be subject to enhanced security and access controls.
Data Retention Under the KDPA:
Consistent with our obligations under the KDPA, we retain your Personal Information only for as long as is necessary to fulfil the purpose for which it was collected, or for such longer period as may be required or permitted under applicable Kenyan law or other legal obligations. Once Personal Information is no longer required for any lawful purpose, we will securely delete, destroy, or anonymise it in a manner that prevents reconstruction or re-identification. Where immediate deletion is not possible (for example, because data is temporarily held in encrypted backup archives), we will isolate it from further active processing until secure deletion can be completed.
Supervisory Authority (Office of the Data Protection Commissioner):
The KDPA established the Office of the Data Protection Commissioner (ODPC) as the independent supervisory authority responsible for regulating the processing of Personal Information in Kenya, registering data controllers and data processors, investigating complaints, and enforcing data subjects' rights. If you are a Kenyan data subject and believe that HabariChat has processed your Personal Information in a manner inconsistent with the KDPA, you have the right to lodge a complaint with the ODPC. We encourage you to contact us first at [email protected] so that we may work to resolve your concern directly and promptly; however, this does not affect your right to approach the ODPC at any time without prior notice to us. The ODPC may be reached at:
HabariChat's platform is used by businesses operating in regulated industries in Kenya. The following describes how we handle data in those specific contexts. In all cases, the business customer remains the data controller and HabariChat acts solely as a data processor under their instructions. The business customer is responsible for ensuring their use of HabariChat complies with all sector-specific regulations applicable to them, and must inform us before using the Services to process sensitive or regulated information so that we can confirm whether additional safeguards are required.
When a financial institution uses HabariChat to communicate with its customers:
When a healthcare facility uses HabariChat to communicate with patients:
When an educational institution uses HabariChat to communicate with parents, guardians, or students:
HabariChat generates automated replies, summaries and recommendations using the information a business customer supplies and the settings selected for their account. AI-generated content may be incomplete or inaccurate, and our business customers are contractually required to review it to the extent appropriate to the risk involved.
Our business customers must not rely solely on an automated response to make a decision that significantly affects a person's health, finances, employment, legal rights or access to an essential service, and where required by law they must inform affected persons that AI is being used and provide access to human review. If you are an end customer interacting with a business through HabariChat and you wish to have a decision reviewed by a person, or to understand the logic involved, contact that business as the data controller in the first instance. You may also contact us at [email protected] and we will refer your request to them and assist them in responding.