Privacy Policy
Last updated: 28 September 2026
1. Who this policy is from
This policy explains how Datalyst Africa ("we") handles personal data in the course of operating the Datalyst Africa AI HR and onboarding assistant platform. Our contact point for privacy questions is munyaradzi@datalystafrica.com, and our registered address is Corner Rotten Row & Pennefather Road, Harare City Library, Harare, Zimbabwe. We do not currently have a dedicated Data Protection Officer — a business of our size and processing scope is not required to appoint one under Zimbabwean law. Direct any data protection query to the email above.
2. Two different relationships
This distinction matters, because our obligations differ in each case:
- Our customers (the companies who buy the platform) — for their own account data we are the controller. This policy describes what we do with it.
- Our customers' employees, new hires and job applicants (people who talk to the HR assistant, or whose details the company loads into it) — for that data we are a processor acting on the company's instructions. The company is the employer and decides what is collected and why; its own privacy notice to its staff governs it.
If you are an employee and want to see, correct or remove your data, contact your employer's HR team first. They can action it in their dashboard, and we support them doing so. HR records are personal data that many employers are legally required to keep for a set period, so an employer may lawfully decline to erase some of them.
3. What we collect about our customers
- Account data: name, email address, hashed password, role, and an optional phone number for alerts.
- Business data: your company name, plan, billing state, and branding you upload.
- Content you supply: documents, website content and FAQs you add to your knowledge base, and the instructions you give your Agent.
- Configuration: the tools, channels and integrations you connect. Credentials for those are encrypted at rest and never shown back to you or anyone else.
- Usage and billing records: request counts, token volumes, cost estimates, payment references and invoices.
- Audit records: who did what in your account, including anything our setup staff did on your behalf.
- Support correspondence: tickets you raise with us and our replies.
4. What is stored on behalf of the employer
To operate the HR assistant we store, on behalf of the company that deployed it:
- The employee directory the company loads: name, work email, job title, department, location, manager, employment type, start date and status. It is what the assistant checks when it verifies who it is talking to.
- Onboarding records: each new hire's checklist, task status, due dates and who completed what.
- Leave records: requests (dates, type, working days, status and decision) and balances the company supplies. A free-text reason is stored only if the person volunteers one, is hidden from lists and notifications, and is opened only through a logged action.
- Policy acknowledgements: which policy version a person accepted, and when.
- Documents an employee uploads through a private, one-time link — for example a signed contract or identity copy. They are stored privately and opened only through short-lived, logged links. People are asked never to type such details into the chat.
- The conversation itself — the messages exchanged, and metadata such as channel, outcome and sentiment trend.
- Confidential cases: where someone raises a sensitive matter (for example harassment, a grievance, or a wellbeing concern) the assistant opens a case for the company's HR team. Cases and their conversations are visible only to the account owner and people the owner assigns, and every access is logged. They are excluded from general conversation lists, exports and analytics samples, and nothing from them is saved as a remembered fact.
- Identity checks: a one-time code sent to the work email on file, stored only as a hash and valid for a short time.
- Where an employee messages from WhatsApp or Telegram, the channel-specific address needed to send a reply, stored encrypted and decrypted only to deliver a message.
- Facts a person has stated across conversations, where the company has enabled longer-term memory — for example how they like to be addressed. Not full transcripts by default, and never anything from a sensitive case.
The assistant is designed not to present something as a fact a person stated unless they actually stated it, not to claim an action succeeded unless it was confirmed, and never to approve leave or make or recommend decisions about individual people. Those decisions are made by people at the employer.
5. Why we process it
- To provide the service — answering questions, running onboarding, routing requests and cases to the right person, and recognising a returning employee.
- To bill accurately, and to show usage against a plan allowance.
- To keep the platform secure, including detecting attempts to manipulate an Agent's instructions.
- To support you, investigate faults, and improve reliability.
- To meet legal and accounting obligations.
Where the law requires a lawful basis, ours is performance of our contract with you, our legitimate interest in operating and securing the platform, and compliance with legal obligations. Your own basis for your customers' data is yours to determine.
6. AI processing
To generate a reply, the relevant conversation content and the retrieved extract of your knowledge base are sent to a third-party AI provider. We route across more than one provider for reliability. These providers process the content to return a response and are contractually restricted from using it to train their models.
We do not use your content, or your employees' conversations, to train general-purpose AI models.
7. Who else sees the data
We share data only with service providers that make the platform work:
- AI model providers, to generate replies.
- Cloud hosting and database providers, to run and store the service.
- The messaging platforms you choose to connect, to deliver messages on those channels.
- Our payment provider, to take payment. We never see or store your full card details.
- Email and SMS providers, to send the notifications you have enabled.
- Error monitoring, to detect faults.
Our current sub-processors:
- Railway Corporation — application, database and cache hosting (EU West, Amsterdam).
- Cloudflare, Inc. — encrypted document, file and backup storage, and bot-verification on our sign-in forms (global network, United States-headquartered).
- Anthropic PBC, OpenAI, L.L.C. and Google LLC — AI model providers used to generate replies (United States).
- Google LLC — additionally used for platform email delivery (sign-in codes, verification codes, alerts) and, where a person uses it, "Sign in with Google" (United States).
- Meta Platforms, Inc. — WhatsApp Business Platform, only for companies who connect that channel (United States).
- Telegram — bot messaging, only for companies who connect that channel.
- Twilio Inc. — SMS alert delivery, only for customers who enable that channel (United States).
- Paynow (Zimbabwe) — payment processing, only for customers on a paid plan (Zimbabwe).
- Sentry (Functional Software, Inc.) — error monitoring (United States).
We do not sell personal data, and we do not share it for advertising.
8. Where data is held
The application and database run in the EU (Amsterdam). AI model providers process reply content in the United States, and Cloudflare's global network stores files and may cache static assets closer to you. If you have a regulatory requirement for data to stay in a particular region, tell us before you go live — we record that requirement against your account, but you should not assume data is physically relocated unless we have confirmed that in writing.
Where data crosses a border, we rely on the standard contractual data-processing safeguards each provider listed above already has in place, rather than a bespoke agreement of our own.
9. How we protect it
- Each business's data is isolated at the database level, not only by application code, so one business cannot read another's.
- Credentials and channel access tokens are encrypted at rest.
- Passwords are stored only as salted hashes.
- Access to production data is limited to staff who need it, and staff actions inside a customer's account are logged and attributable.
- Traffic is encrypted in transit.
No system is perfectly secure. If a breach affects your data we will notify you without undue delay, and regulators where required.
10. How long we keep it
Conversation and memory data is kept for the retention period configured on your account, then deleted automatically. The default is 365 days. The employer decides how long employment records are kept and is responsible for any legal duty to keep them; confidential cases are never deleted automatically.
Account, billing and audit records are kept for as long as you are a customer and then for as long as we are legally required to keep them — typically 6 years for accounting records, in line with Zimbabwean tax record-keeping requirements. Audit logs are kept deliberately, because they are the record of who changed what.
11. Your rights
Depending on where you are, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to complain to a regulator. To exercise any of these, contact munyaradzi@datalystafrica.com. We will respond within 30 days.
You can delete a specific person's stored memory from your dashboard at any time; that action is recorded in your audit log.
If you have chatted with one of these assistants, our data deletion page explains what is held about you and the three ways to have it erased.
The regulator for our jurisdiction is the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), the Data Protection Authority under Zimbabwe's Cyber and Data Protection Act.
12. Cookies
The dashboard stores a session token in your browser so you stay signed in, and remembers small interface preferences. The chat widget stores an identifier so a returning visitor's conversation can continue. We do not use advertising or cross-site tracking cookies.
13. Children
The platform is sold to employers and is not intended for children. We do not knowingly collect data from children. Employing young people is your responsibility to handle lawfully.
14. Changes
If we change this policy in a way that materially affects how we handle your data, we will tell you before it takes effect. The date at the top always reflects the current version.
