Privacy Policy
Last updated: September 4, 2026
This Privacy Policy explains how KhaelSolution Enterprise ("we", "us", "our") collects, uses, and protects information through KSE AI Assistant ("the Service") — an AI-powered customer support platform that businesses ("Organizations") embed on their websites and, optionally, connect to WhatsApp Business to answer customer questions automatically.
If you have any questions about this policy, contact us at info@khaels.org.
1. Who This Policy Covers
This policy applies to three groups of people:
- Organization accounts — the businesses that sign up for KSE AI Assistant and manage a dashboard.
- Website visitors — people who chat with an Organization's embedded AI widget.
- WhatsApp users — people who message an Organization's WhatsApp Business number, where that Organization has connected WhatsApp to the Service.
2. Information We Collect
2.1 Organization account data
- Name, email address, and password (stored as a salted hash — we never see or store your plaintext password).
- Organization details: business name, description, logo, website, and knowledge base content you upload (documents, URLs, text, PDFs).
- Billing information processed via Paystack — we do not receive or store your card number.
2.2 Conversation data (website widget & WhatsApp)
- The messages exchanged between a visitor/WhatsApp user and the AI assistant, including timestamps.
- For WhatsApp: the sender's WhatsApp phone number (WhatsApp ID), used to route replies back to the correct conversation.
- For the website widget: a visitor identifier generated by the widget and, where a lead form is submitted, the contact details the visitor chooses to provide.
- Metadata such as response confidence scores and which knowledge base content was used to answer a question.
2.3 Usage & analytics data
- Aggregate metrics such as number of questions asked, responses given, and live-agent takeovers, used to power the Organization's analytics dashboard.
3. How We Use Information
- To generate AI responses to visitor/customer questions, using the Organization's own knowledge base as context.
- To deliver and receive messages over WhatsApp on behalf of a connected Organization.
- To calculate usage-based billing (pay-as-you-go plans).
- To detect gaps in an Organization's knowledge base (questions the AI could not answer) so the business can improve it.
- To provide analytics to the Organization about their own conversations.
- To maintain security, prevent abuse, and comply with legal obligations.
We do not sell personal data, and we do not use conversation content for advertising.
4. Third-Party Service Providers
We rely on the following processors to operate the Service. Each only receives the data necessary to perform its function:
- OpenAI — processes message text and knowledge base content to generate AI responses and text embeddings. See OpenAI's Privacy Policy.
- Qdrant — stores numeric vector representations (embeddings) of knowledge base content, used to retrieve relevant context for each question.
- Meta / WhatsApp Business Platform — for Organizations that connect WhatsApp, message delivery is routed through Meta's infrastructure and is also subject to WhatsApp's Business Policy and Meta's Privacy Policy.
- Paystack — processes payments for pay-as-you-go billing. See Paystack's Privacy Policy.
5. WhatsApp-Specific Data Practices
When an Organization connects a WhatsApp Business number to the Service, and a customer messages that number, we process:
- The customer's WhatsApp phone number.
- The text content of messages sent to and received from that number.
- Message timestamps and delivery status.
This data is used solely to generate and deliver an automated AI response on behalf of the Organization the customer is messaging, and to let the Organization view that conversation in their dashboard (including handing it to a human agent when requested). We do not use WhatsApp message content for advertising, and we do not share it with any Organization other than the one the customer contacted.
Conversation data is retained for as long as the Organization's account remains active, or until a deletion request is processed — see our Data Deletion Instructions.
6. Data Security
- All traffic to and from the Service is encrypted in transit via HTTPS.
- WhatsApp API credentials (access tokens, app secrets) are encrypted at rest.
- Incoming WhatsApp webhook requests are verified using Meta's signature scheme before being processed.
- Each Organization's knowledge base and conversation data is isolated from other Organizations.
7. Data Retention
We retain account, knowledge base, and conversation data for as long as an Organization's account is active. If an Organization closes its account, or a data subject requests deletion, we delete the associated data within 30 days, except where retention is required by law (e.g. financial records related to payments).
8. Your Rights
Depending on your location, you may have the right to access, correct, or request deletion of your personal data. To exercise these rights, or to request deletion of your data, see our Data Deletion Instructions or email info@khaels.org.
9. Children's Privacy
The Service is intended for business use and is not directed at children under 13. We do not knowingly collect personal data from children.
10. International Data Transfers
Some of our service providers (OpenAI, Qdrant Cloud, Meta) may process data outside Ghana, including in the United States and the European Union. We rely on our providers' own safeguards for cross-border data transfers.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
12. Contact Us
KhaelSolution Enterprise · info@khaels.org · +233 500 670 020 · khaels.org