1. Who is responsible for your data
Azizi Africa, Nairobi, Kenya is the data controller for personal data described here. Contact us at info@aziziafrica.com or +254 768 227585.
Where we process data on behalf of an organisation that deploys Azizi AI to its own customers, that organisation is the controller and we act as its processor under a written agreement.
2. What we collect
- Call data — your phone number, the time and duration of the call, audio recordings, and transcripts of what was said.
- What you tell the agent — anything you say during a call, which may include your name, location, business details or other personal information you choose to share.
- Marketplace data — listings, enquiries and the contact details you publish or exchange.
- Console and API data — account name, email, role, and audit records of actions taken.
- Technical data — IP address, device and browser information, and log data when you use the console or APIs.
We do not deliberately collect sensitive personal data. Please do not share health, financial account credentials, or similar details with the agent unless a service you are using specifically asks for them.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Answering your call and responding to your request | Performance of a contract; your consent |
| Recording and transcribing calls so the agent can operate | Consent, given at the start of the call |
| Running the marketplace and connecting buyers with sellers | Performance of a contract |
| Improving accuracy, safety and language coverage | Legitimate interest, using de-identified data where practicable |
| Security, fraud prevention and abuse detection | Legitimate interest; legal obligation |
| Meeting legal, regulatory and reporting duties | Legal obligation |
4. Automated processing
Conversations are handled by an automated AI agent. We do not make decisions producing legal or similarly significant effects about you by automated means alone. Where an organisation uses our platform to screen or score activity, that organisation is responsible for its own decision-making and for telling you about it.
5. Who we share it with
We share personal data only as needed to run the service:
- Telecommunications operators that carry the call;
- Cloud hosting and infrastructure providers that host the platform;
- Speech and language model providers that convert speech to text and generate responses;
- The organisation whose service you called, where you called a number they operate;
- Authorities, where we are legally required to disclose.
We do not sell personal data.
6. Transfers outside Kenya
Some providers process data outside Kenya. Where that happens we rely on the safeguards permitted by the Data Protection Act, 2019 — including appropriate contractual protections — and transfer only what is necessary.
7. How long we keep it
We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it. Indicative periods — confirm these against your operational requirements before publishing:
- Call recordings and transcripts — retained for the period needed to deliver and support the service;
- Marketplace listings and enquiries — retained while your listing is active and for a period afterwards;
- Console accounts and audit logs — retained for the life of the account and as required for security and regulatory purposes;
- Records we must keep by law — retained for the statutory period.
8. Your rights
Under the Data Protection Act, 2019 you have the right to be informed; to access your data; to correct data that is inaccurate; to have data deleted where the law allows; to object to or restrict processing; to data portability; and to withdraw consent at any time — withdrawal does not affect processing already carried out.
To exercise any of these, write to info@aziziafrica.com. We will respond within the timeframe set by the Act. You may also complain to the Office of the Data Protection Commissioner in Kenya.
9. How we protect it
We use encryption in transit, access controls and role separation, tenant isolation, audit logging of console and API activity, and least-privilege access for staff. No system is perfectly secure; where a breach is likely to cause real risk to you, we will notify you and the ODPC as the Act requires.
10. Children
The service is not directed at children under 18. We do not knowingly collect their data without appropriate consent. If you believe a child's data has been collected, contact us and we will delete it.
11. Cookies
The public website uses only what is needed to serve pages. The client console uses strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not use advertising cookies.
12. Changes
We may update this policy. The "last updated" date will change, and we will give notice of material changes through the console or by email.
13. Contact
Azizi Africa, Nairobi, Kenya · info@aziziafrica.com · +254 768 227585
Data Protection Officer: to be named before publication.