Selwyze is built for Nigerian business owners who trust us with sensitive business data — their customers, their revenue, their orders. This policy explains exactly how we protect that data, the principles we operate by, and your rights under Nigerian and international data protection law.
1. Who This Policy Applies To
This policy applies to:
- Business owners who use Selwyze to analyse their sales data
- End customers whose data appears in chat exports uploaded by business owners
- Anyone who interacts with the Selwyze WhatsApp bot or website
Selwyze is the data processor for business owners (our direct users) and acts as a sub-processor for end customer data that owners upload. Business owners are the data controllers for their customers' information.
2. Legal Framework
Selwyze operates in compliance with the following data protection laws:
- Nigeria Data Protection Act 2023 (NDPA) — Nigeria's primary data protection legislation
- Nigeria Data Protection Regulation 2019 (NDPR) — issued by the National Information Technology Development Agency (NITDA)
- Meta / WhatsApp Business API Terms — governing how user data is handled via the WhatsApp platform
We are committed to full compliance with the NDPA 2023, which requires lawful, fair, and transparent processing of personal data of Nigerian residents.
3. Our Data Protection Principles
Everything we do with your data is governed by these eight principles:
01
Lawfulness & Fairness
We only process data with a valid legal basis — your consent or legitimate business purpose.
02
Purpose Limitation
Data collected for analytics is used only for analytics. Never for advertising or unrelated purposes.
03
Data Minimisation
We extract only what is necessary from your chat uploads. Nothing more.
04
Accuracy
We flag low-confidence extractions. You can correct inaccurate records at any time.
05
Storage Limitation
Raw chat files are deleted within 48 hours. Account data is deleted within 30 days of a deletion request.
06
Integrity & Confidentiality
All data is encrypted in transit and at rest. Access is restricted to authorised systems only.
07
Transparency
We tell you exactly what we collect, why, and how. No hidden processing.
08
Accountability
We take responsibility for data protection across all our systems and third-party processors.
4. What Data We Process
From business owners (direct users):
- WhatsApp phone number and business name
- WhatsApp chat exports (.txt files) uploaded for analysis
- Structured order submissions via the bot
- Bot usage history and command logs
From end customers (via uploaded chat data):
- Customer names as they appear in chats
- Phone numbers where present in chat history
- Order details — products, quantities, amounts, dates
We do not collect sensitive personal data such as financial account details, health information, or government identification numbers.
5. Legal Basis for Processing
We process personal data under the following lawful bases as defined by the NDPA 2023:
- Consent — business owners explicitly consent to data processing when they sign up and upload their chat history
- Contract performance — processing is necessary to deliver the analytics service you signed up for
- Legitimate interests — improving our service quality and preventing fraud, balanced against your privacy rights
6. How We Protect Your Data
We implement the following technical and organisational measures to protect your data:
- Encryption of all data in transit using TLS 1.2 or higher
- Encryption of all data at rest in our database
- Access controls ensuring only authorised systems can access production data
- Automatic deletion of raw chat files within 48 hours of processing
- Regular security reviews of our infrastructure and third-party processors
- No storage of WhatsApp API credentials in plain text
7. Third-Party Data Processors
We share data only with processors who are necessary to deliver the Selwyze service. Each is bound by a data processing agreement:
- Meta (WhatsApp Business API) — message delivery and receipt. Governed by Meta's Data Processing Terms.
- Anthropic (Claude API) — parsing of uploaded chat files. Data is processed and not retained for model training under our agreement.
- Cloud infrastructure provider — secure hosting and database storage with encryption at rest.
We do not sell data to any third party. We do not share data with advertisers.
8. Data Transfers
Some of our third-party processors operate outside Nigeria. Where data is transferred internationally, we ensure adequate protections are in place through contractual safeguards consistent with the NDPA 2023 requirements for cross-border data transfers.
9. Data Retention
- Raw chat files — deleted within 48 hours of processing (or 30 days if you reply KEEPDATA)
- Structured business data — retained for the duration of your active account
- Account data — deleted within 30 days of an account deletion request
- Bot interaction logs — retained for 90 days for debugging and service improvement, then deleted
10. Your Rights Under the NDPA 2023
As a data subject under Nigerian law, you have the following rights:
👁️
Right to Access
Request a copy of all personal data we hold about you and your business.
✏️
Right to Rectification
Request correction of any inaccurate data in your account.
🗑️
Right to Erasure
Request deletion of your data by sending DELETE MY DATA to the bot or emailing us. Processed within 30 days.
🚫
Right to Object
Object to processing of your data for any purpose beyond delivering the core service.
📦
Right to Data Portability
Request your business data in a machine-readable format (CSV) at any time.
⏸️
Right to Restrict Processing
Request that we restrict processing of your data while a complaint is being resolved.
To exercise any of these rights, message the bot with the relevant command or email info@selwyze.ai. We will respond within 30 days.
11. Data Breach Response
In the event of a data breach that poses a risk to your rights, we will:
- Notify affected users via WhatsApp within 72 hours of becoming aware
- Report to the Nigeria Data Protection Commission (NDPC) as required by the NDPA 2023
- Take immediate steps to contain the breach and prevent recurrence
- Provide a full incident report to affected users upon request
12. Children's Data
Selwyze is a business tool for adults. We do not knowingly process personal data of anyone under the age of 18. If you believe a minor's data has been submitted, contact us immediately at info@selwyze.ai and we will delete it promptly.
13. Complaints
If you believe we have not handled your data appropriately, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpb.gov.ng.
We ask that you contact us first at info@selwyze.ai so we can try to resolve your concern directly.
14. Changes to This Policy
We will notify you of any significant changes to this policy via WhatsApp message. The date at the top of this page reflects when it was last updated.
15. Contact
For any data protection questions or requests, contact us at info@selwyze.ai.