Privacy Policy
Last updated: 24 April 2026. Effective date: 25 April 2026.
  1. Who we are
  1. This Privacy Policy explains how Gee Capital Holdings Limited, a company incorporated in the Republic of Kenya (company registration number: PVT-8LUYB7E), trading as Aqilee, collects, uses, stores, and protects personal data.
  1. In this Policy, "Aqilee", "we", "us", or "our" refers to Gee Capital Holdings Limited. "You" refers to any individual whose personal data we process, including visitors to our website, users of our platform, employees and representatives of our business customers, and end-customers of businesses that use our platform.
  1. Our registered office is at Westlands, Nairobi, Kenya. If you have any questions about this Policy, or want to exercise your privacy rights, contact us at support@aqilee.com.
  1. Our role under data protection law
  1. Aqilee operates in two capacities:
  1. As a data controller. When you visit our website, create an Aqilee account as a business customer, contact us, or interact with our marketing, we decide what data we collect and how it is used. In these cases, we are the data controller.
  1. As a data processor. When a business customer uses Aqilee to communicate with their own customers, the business customer is the data controller of those end-customers' personal data. We process that data on their behalf and under their instructions, as their data processor. Our business customers are responsible for the lawful basis, consent, and notices relating to their end-customers.
  1. This Policy primarily explains our role as a data controller. Section 11 explains our responsibilities as a data processor.
  1. Personal data we collect
  1. We collect different types of data depending on how you interact with us.
  1. Information you give us directly:
  1. Name, email address, and phone number
  1. Business name, business registration number, and business address
  1. Job title and role at your business
  1. Login credentials (email and hashed password)
  1. Payment information (processed by our payment partners; we do not store full card numbers)
  1. Content you upload, including product information, knowledge base documents, and message templates
  1. Communications with our support team
  1. Information we collect automatically when you use the platform:
  1. Device and browser information (type, operating system, browser version)
  1. IP address and approximate location
  1. Login times, pages visited, and features used
  1. Cookies and similar tracking technologies (see Section 9)
  1. Performance and error logs
  1. Information we receive from third parties:
  1. Authentication and account information from Meta (when you connect your WhatsApp Business Account, Instagram, or Facebook Messenger)
  1. Payment status information from M-PESA, Paystack, and other payment processors
  1. Information from identity verification services used during onboarding
  1. Information from referral partners or integrations you authorise
  1. Data from messaging channels (Meta-specific disclosure). When you connect your business messaging accounts to Aqilee, we access and process messages and associated metadata flowing through WhatsApp, Instagram, and Facebook Messenger, including:
  1. Customer phone numbers and profile names
  1. Message content, including text, voice notes, images, documents, and location data where shared
  1. Message timestamps and delivery status
  1. Interaction history between your business and your customers
  1. This data belongs to you (our business customer) as the data controller of your end-customers. We process it on your behalf only to provide the Aqilee platform. We do not use this data for our own purposes, do not sell it, and do not share it with Meta except as required to operate the messaging channel itself.
  1. Why we process your data
  1. We process personal data for the following purposes, each with a lawful basis under the Kenya Data Protection Act 2019 and other applicable laws.
  1. To provide the platform (contract performance):
  1. Create and manage your account
  1. Enable messaging, AI replies, payments, bookings, and other platform features
  1. Process transactions and calculate fees
  1. Provide customer support
  1. To operate our business (legitimate interest):
  1. Improve and develop new features
  1. Monitor platform performance, security, and uptime
  1. Detect, investigate, and prevent fraud, abuse, and security incidents
  1. Enforce our Terms and resolve disputes
  1. Conduct internal analytics
  1. To communicate with you (consent or legitimate interest):
  1. Send service notifications and security alerts
  1. Respond to your support requests
  1. Send onboarding and product education emails
  1. Send marketing communications (where you have consented)
  1. To comply with legal obligations (legal obligation):
  1. Respond to lawful requests from courts, regulators, and law enforcement
  1. Maintain records required by tax, anti-money laundering, and data protection law
  1. Cooperate with audits and investigations
  1. How we use AI and automated processing
  1. Our platform uses artificial intelligence and machine learning to provide core features. Specifically:
  1. Chatbot replies. AI models trained on your business's knowledge base generate suggested or automated replies to your customers.
  1. Voice note understanding. Audio messages are transcribed and interpreted by speech-to-text and language models.
  1. Semantic search and recommendations. Content is converted into embeddings to enable intelligent search across your knowledge base.
  1. Language detection. The platform automatically detects English, Swahili, Sheng, and other supported languages.
  1. These AI features use third-party model providers, including Anthropic, OpenAI, and other providers we may engage from time to time. Your data is processed under contractual terms that prohibit the provider from using your content to train their foundation models or for purposes beyond serving the platform. Inputs and outputs may be temporarily retained by these providers for abuse monitoring and service reliability, typically for up to 30 days, before being deleted.
  1. We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing without human involvement.
  1. How we share data
  1. We do not sell your personal data. We share data only in the following circumstances:
  1. Service providers. We work with trusted third parties who help us run the platform. These include:
  1. Cloud hosting and infrastructure: Contabo (Germany), Cloudflare (global), and others
  1. Messaging channels: Meta Platforms (WhatsApp Business Platform, Instagram Messaging API, Messenger Platform)
  1. Payment processing: Safaricom (M-PESA), Paystack
  1. AI and machine learning: Anthropic, OpenAI
  1. Logistics: Leta (for customers who enable logistics features)
  1. Email and communications: Zoho Mail
  1. Analytics and error monitoring: providers we engage to monitor platform performance
  1. Each service provider processes data only under contractual obligations that restrict use to the purposes we specify.
  1. Business customers. If you are an end-customer of a business using Aqilee, your data is shared with that business, which is the data controller. You should consult that business's own privacy policy for how they use your data.
  1. Legal and safety. We may disclose data when required by law, court order, or a lawful request from a regulator, or when we believe in good faith that disclosure is necessary to protect our rights, the safety of users, or the public.
  1. Corporate transactions. If we are involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction. We will notify you before data is transferred and becomes subject to a different privacy policy.
  1. With your consent. In any other case, we share data only with your explicit consent.
  1. International data transfers
  1. Aqilee operates in Kenya, but some of our service providers are based outside Kenya. This means your data may be transferred to, stored in, or processed in countries including Germany, the United States, and others. Where we transfer personal data outside Kenya, we rely on one or more of the following safeguards as required by Section 48 of the Kenya Data Protection Act 2019:
  1. The receiving country has been assessed as providing adequate protection
  1. Contractual clauses that require the recipient to protect your data to a standard equivalent to Kenyan law
  1. Your explicit consent, where applicable
  1. The transfer is necessary to perform the contract you have with us
  1. In line with the Data Protection (General) Regulations 2021, we maintain at least one serving copy of personal data to which the Act applies on a server located in Kenya.
  1. Data retention
  1. We retain personal data only for as long as necessary to fulfil the purposes described in this Policy or to meet legal, regulatory, or contractual obligations.
  1. Account information: Duration of your subscription, plus 7 years for tax and audit records
  1. Messages and conversation history: Duration of your subscription, plus 30 days after termination for export
  1. Payment records: 7 years, as required by Kenyan tax law
  1. Support correspondence: 3 years from last contact
  1. Website analytics: 14 months
  1. Marketing contact data: Until you unsubscribe, plus a reasonable suppression period
  1. Security and audit logs: 12 months
  1. After the retention period ends, we securely delete or irreversibly anonymise the data.
  1. You can request earlier deletion at any time, subject to any legal obligations that require us to retain the data.
  1. To request deletion of your personal data, email support@aqilee.com with the subject 'Data Deletion Request'. We will verify your identity and respond within 30 days. See Section 7 on Data Retention for information on retention obligations that may delay or prevent immediate deletion.
  1. Cookies and tracking technologies
  1. Our website and platform use cookies and similar technologies to:
  1. Keep you logged in securely
  1. Remember your preferences
  1. Measure site performance and fix errors
  1. Understand how our platform is used, so we can improve it
  1. You can control cookies through your browser settings. If you disable essential cookies, some parts of the platform may not work.
  1. We do not use cookies for third-party advertising or cross-site tracking.
  1. Your rights
  1. Under the Kenya Data Protection Act 2019, you have the following rights:
  1. Right to be informed. To know how your data is being used (this Policy).
  1. Right of access. To request a copy of the personal data we hold about you.
  1. Right to rectification. To request correction of inaccurate or incomplete data.
  1. Right to erasure. To request deletion of your data, subject to our legal and contractual obligations.
  1. Right to restrict processing. To ask us to pause processing in certain circumstances.
  1. Right to data portability. To receive your data in a structured, commonly used format.
  1. Right to object. To object to processing based on legitimate interest, including direct marketing.
  1. Right to withdraw consent. Where we rely on consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
  1. Right to complain. To lodge a complaint with the Office of the Data Protection Commissioner (ODPC) in Kenya.
  1. To exercise any of these rights, email support@aqilee.com. We will respond within 30 days. We may ask you to verify your identity before acting on your request.
  1. If you are unsatisfied with our response, you may contact the ODPC:
  1. Our obligations as a data processor
  1. When our business customers use Aqilee to communicate with their own customers, those business customers are the data controllers of their end-customers' personal data, and we act as their data processor. In that role:
  1. We process personal data only on the documented instructions of the business customer
  1. We implement appropriate technical and organisational security measures
  1. We require our sub-processors to meet equivalent data protection standards
  1. We assist the business customer in responding to data subject requests
  1. We notify the business customer of any personal data breach affecting their data within 48 hours of becoming aware of it
  1. We return or delete personal data at the end of the contract, subject to any legal obligations requiring retention
  1. Business customers are responsible for:
  1. Obtaining a lawful basis to process their end-customers' data
  1. Providing their own privacy notices to their end-customers
  1. Obtaining opt-in consent where required by WhatsApp and Meta policies for marketing messages
  1. Registering with the ODPC where required
  1. Honouring data subject requests from their own end-customers
  1. Security
  1. We implement industry-standard technical and organisational measures to protect personal data, including:
  1. Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  1. Role-based access controls and least-privilege permissions
  1. Multi-factor authentication for administrative access
  1. Regular security reviews and penetration testing
  1. Incident response procedures
  1. Secure software development practices
  1. Continuous monitoring of infrastructure and logs
  1. No system is 100% secure. If you suspect a security issue with your account, contact us immediately at support@aqilee.com.
  1. Data breach notification
  1. In the event of a personal data breach that is likely to result in risk to the rights and freedoms of affected individuals, we will:
  1. Notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of the breach, as required by the Kenya Data Protection Act 2019
  1. Notify affected individuals without undue delay where the breach is likely to result in high risk
  1. Notify our business customers within 48 hours where their data is affected, in our role as their data processor
  1. Take immediate steps to contain the breach and prevent recurrence
  1. Children
  1. The Aqilee platform is intended for use by businesses and adults aged 18 or over. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, contact us at support@aqilee.com and we will delete it.
  1. Business customers who use Aqilee to communicate with end-customers are responsible for ensuring they do not process children's data in a manner that violates applicable law.
  1. Third-party links and services
  1. Our platform may contain links to third-party websites or integrate with third-party services (including Meta's messaging channels, payment providers, and logistics partners). We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies before sharing data with them.
  1. Specifically, when you use WhatsApp, Instagram, or Facebook Messenger through the Aqilee platform, Meta's own privacy practices apply to your use of those channels. See:
  1. Changes to this Policy
  1. We may update this Privacy Policy from time to time. Material changes will be communicated to you by email or in-platform notification at least 30 days before they take effect, except where shorter notice is required by law. The "Last updated" date at the top of this page indicates when the Policy was most recently revised.
  1. Your continued use of the platform after a change takes effect constitutes acceptance of the updated Policy.
  1. Contact
  1. Gee Capital Holdings Limited (trading as Aqilee) Westlands, Nairobi, Kenya
  1. Data Protection Officer / Privacy contact: support@aqilee.com
  1. Regulator
  1. If you believe we have not handled your personal data properly, you have the right to complain to the Kenyan data protection authority:
  1. Office of the Data Protection Commissioner (ODPC) Website: www.odpc.go.ke Email: info@odpc.go.ke
This Privacy Policy was last updated on 24 April 2026.
Book a Call Now!