Teja

Privacy Policy

Effective date: 26 June 2026 · Last updated: 26 June 2026

This Privacy Policy explains how Teja (“Teja,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you interact with our service through WhatsApp, our supplier and operations dashboard, or any related channel. Teja is operated from the Republic of Kenya and processes personal data in accordance with the Kenya Data Protection Act, 2019 and applicable WhatsApp and Meta platform policies.

By messaging Teja on WhatsApp or otherwise using our service, you confirm that you have read, understood, and consented to the practices described in this Policy.

1. Who we are

Teja is a pre-purchase intelligence and order-routing service. Buyers send a product request on WhatsApp; our system returns price and value options sourced from verified suppliers, processes payment through licensed payment providers, and coordinates delivery. The data controller for personal data described in this Policy is Teja, contactable at privacy@teja.ke.

2. The personal data we collect

We only collect what we need to deliver the service. The categories are:

  • WhatsApp profile data. Your WhatsApp phone number, WhatsApp display name, and the message content you send to us. This is provided to us by Meta Platforms, Inc. through the WhatsApp Business Platform when you initiate a conversation with Teja.
  • Order and delivery details. The product or service you are requesting, quantity, delivery address or pickup location, and any notes you share to help us fulfil the order.
  • Payment data. When you pay via M-Pesa or another supported payment channel, we receive the M-Pesa receipt number, the paying phone number, the amount, and the transaction status from the payment provider. We do not see or store your M-Pesa PIN or any bank/card credentials.
  • Conversation history. A record of messages exchanged with Teja, used to maintain conversation state (WhatsApp itself is stateless across sessions) and to improve the accuracy of our automated responses.
  • Operational metadata. Timestamps, message identifiers, delivery status, and technical logs needed to debug and monitor the service.
  • Supplier and ops user data. If you are a supplier or a member of the ops team using our dashboard, we additionally hold your name, username, role, contact details, and a salted hash of your password.

We do not intentionally collect special categories of personal data (health, biometric, religious, sexual orientation, political views, etc.). Please do not send such information to Teja.

3. How we use your data

We process the data above for the following purposes and legal bases:

  • Performance of a contract — to understand your request, present options, place and fulfil orders, take payment, coordinate delivery, and respond to queries and complaints.
  • Automated message understanding — message content is sent to a third-party large language model provider (currently Anthropic) under a no-training data-processing arrangement, strictly to extract the product, quantity, and location from your message and to draft responses.
  • Legitimate interests — fraud prevention, abuse detection, reliability scoring of suppliers, aggregate demand analytics (which use de-identified data only), service security, and internal record-keeping.
  • Legal obligations — tax records, accounting, responding to lawful requests from regulators or law enforcement.
  • Consent — for any optional communications (e.g. promotional broadcasts). You can withdraw consent at any time by replying STOP on WhatsApp or emailing us.

We do not sell your personal data, and we do not use your conversations to train third-party AI models.

4. Who we share data with

We share the minimum data necessary with the following categories of recipients, each of whom acts as either a data processor or an independent controller under their own policies:

  • Meta Platforms, Inc. (WhatsApp Business Platform)— for message delivery between you and Teja. Meta's handling of your data is governed by the WhatsApp Privacy Policy.
  • Anthropic, PBC — provider of the language model used to understand your messages. Anthropic processes the message content only to return a response and does not use it to train its models under our enterprise terms.
  • Payment providers — Safaricom PLC (M-Pesa / Daraja) and/or PayHero, for processing payments. They receive the phone number, amount, and reference needed to complete the transaction.
  • Suppliers and dispatch partners — the supplier fulfilling your order receives your delivery details (name or alias, delivery address, phone number, and the order itself). They are contractually required to use this information solely to fulfil and support your order.
  • Infrastructure providers — cloud hosting (DigitalOcean) and transactional email/SMS providers, who store data on our behalf under contractual data processing terms.
  • Authorities — when required by law, court order, or to protect the rights, property, or safety of Teja, our users, or others.

5. International data transfers

Some of our processors (notably Meta and Anthropic) are based outside Kenya. Where data is transferred outside Kenya, we rely on the safeguards permitted under section 48 of the Kenya Data Protection Act — including the recipient's adherence to substantially similar data protection standards and contractual data protection clauses — to ensure your data remains protected.

6. How long we keep data

We retain personal data only for as long as is reasonably necessary for the purpose for which it was collected, after which it is deleted or anonymised:

  • Order records: kept for at least seven (7) years to meet tax and accounting obligations under Kenyan law.
  • WhatsApp conversation history: kept for up to twenty-four (24) months to support quality, dispute resolution, and service improvements; older messages are purged or anonymised.
  • Payment transaction metadata: kept in line with the retention requirements of the payment provider and Kenyan financial regulations.
  • Dashboard user accounts: kept while the account is active; password hashes and session data are removed within thirty (30) days of account deactivation.

7. How we protect your data

We apply administrative, technical, and physical safeguards proportionate to the sensitivity of the data we hold. These include encrypted connections (TLS) for all data in transit, encryption at rest for our databases and backups, parameterised database queries to prevent injection attacks, signed and short-lived authentication tokens for the operations dashboard, role-based access controls, audit logging of administrative actions, regular dependency vulnerability scanning, and the principle of least privilege for all staff and processors.

No internet-connected system is ever completely secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Office of the Data Protection Commissioner and, where required, you directly, in line with the timelines under the Kenya Data Protection Act.

8. Your rights

Under the Kenya Data Protection Act, 2019, you have the right to:

  • be informed of the use of your personal data;
  • access the personal data we hold about you;
  • object to or restrict processing of your personal data;
  • have inaccurate or incomplete personal data corrected;
  • have your personal data deleted, where retention is no longer justified;
  • withdraw consent at any time for processing based on consent, without affecting the lawfulness of processing carried out before withdrawal; and
  • lodge a complaint with the Office of the Data Protection Commissioner (www.odpc.go.ke).

To exercise any of these rights, email us at privacy@teja.ke from the address or phone number associated with your account. We will respond within the timelines set by the Act (typically within seven days, and in any event within thirty days). We may need to verify your identity before acting on a request.

9. Opting out of WhatsApp messages

You can stop receiving WhatsApp messages from Teja at any time by replying STOP, UNSUBSCRIBE, or CANCELto any of our messages. You can also block the Teja number using WhatsApp's built-in controls. Opting out will end transactional and promotional messages; if you have an order in progress, we may still need to contact you to complete or refund it.

10. Children

Teja's service is intended for users aged eighteen (18) and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Cookies and the operations dashboard

Our public website does not use tracking or advertising cookies. The operations dashboard at this domain is for authenticated staff and supplier users only and uses a single HMAC-signed, HTTP-only session cookie strictly to keep you logged in. This cookie is essential to the service and cannot be disabled separately from sign-in.

12. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date at the top of the page indicates when the most recent changes were made. Material changes will be communicated through a notice on WhatsApp or via the dashboard before they take effect.

13. Contact us

For any privacy questions, complaints, or data subject requests, contact:

Teja — Privacy Office
Email: privacy@teja.ke
General support: ops@teja.ke