Privacy Notice
Last updated: August 5, 2026 · Effective immediately
Compliant with Kenya Data Protection Act 2019, GDPR, and international standards
1. Scope & Controller Identity
This Privacy Notice explains how Guerison ("Ohala," "we," "our," or "us"), registered in the Republic of Kenya, collects, uses, discloses, retains, and protects personal information when you:
- Visit our website at guerison.website or any related subdomains
- Register for, access, or use the Ohala Business OS platform (the "Service")
- Communicate with us via email, phone, WhatsApp, or any other channel
- Interact with our marketing materials, social media, or advertisements
- Attend our events, webinars, or training sessions
We act as both a data controller (for our own business operations, marketing, and platform administration) and a data processor (when our customers process personal data of their own clients, employees, or suppliers through the Service).
Entity: Guerison (trading as Ohala Business OS)
Email: privacy@guerison.website
Data Protection Officer: Available at the email above
This Privacy Notice was last updated on August 5, 2026 and is effective immediately.
2. Our Privacy Commitments
We are committed to protecting your privacy and handling your personal data fairly, lawfully, and transparently. Our data protection practices are built around these core principles:
This Privacy Notice is designed to comply with the Kenya Data Protection Act, 2019 (No. 24 of 2019) ("DPA 2019"), the Data Protection (General) Regulations, 2021, the Data Protection (Complaints Handling and Enforcement Procedures) Regulations, 2021, and applicable guidance issued by the Office of the Data Protection Commissioner (ODPC). Where applicable, we also adhere to international standards including the EU General Data Protection Regulation (GDPR) for users in the European Economic Area.
3. What Information We Collect
3.1 Information You Provide Directly
3.2 Information Collected Automatically
3.3 Information From Third Parties
4. How We Use Your Information
We process personal data for the following purposes, each grounded in a valid legal basis under the DPA 2019:
Automated Decision-Making. Our AI-powered features (predictive analytics, inventory forecasting, automated insights) involve automated processing. These are assistive tools only — they do not produce legal effects or significantly affect you. All AI output requires human review before business decisions. You may request human intervention for any AI-generated output by contacting us.
6. Data Retention and Deletion
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, and reporting requirements. Our retention periods are:
When data is deleted, we use industry-standard methods to ensure it is irrecoverable, including cryptographic erasure where applicable. You may request earlier deletion of specific data by contacting us, subject to legal retention obligations.
7. Your Data Subject Rights (DPA 2019)
Under the Kenya Data Protection Act 2019 and its regulations, you have the following rights regarding your personal data. To exercise any right, contact us at privacy@guerison.website. We will respond within 14 days (as required under Kenyan regulations):
Verification. To protect your privacy, we will verify your identity before responding to rights requests. We may request additional information to confirm your identity. If you are making a request on behalf of another individual, you must provide proof of authorization.
9. AI Data Processing
Ohala includes AI-powered features (AI Assistant, predictive analytics, inventory forecasting, automated insights) that process data using third-party AI model providers (including OpenAI, among others):
- What We Send: When you use AI features, we send your prompt and relevant contextual business data (product names, sales figures, inventory levels) to the AI provider for processing. We do not send personal data unless it is part of your prompt.
- Training Opt-Out: By default, we have opted out of allowing AI providers to use your data for model training. Your data is processed for inference only and is not retained by AI providers beyond the brief period necessary to generate a response (typically seconds to minutes).
- Data Minimization: We minimize the data sent to AI providers to only what is necessary to fulfill your request. We do not send full databases — only the specific data context relevant to your query.
- Your Control: You control which AI features you use. You may disable AI features entirely from your Account Settings → AI Settings. Even when enabled, AI features are tools to assist your decision-making — you remain responsible for all business decisions.
- Accuracy: AI-generated output may contain errors. You should always verify critical information independently.
10. International Data Transfers
Your data is primarily stored and processed on servers located in Frankfurt, Germany (EU) and Nairobi, Kenya. Some of our service providers may process data in other jurisdictions.
Whenever we transfer personal data outside Kenya, we ensure appropriate safeguards are in place in compliance with the DPA 2019 and its regulations. These safeguards include:
- Adequacy: Transferring to countries that the ODPC has recognized as providing an adequate level of data protection (including EU member states where GDPR applies).
- Standard Contractual Clauses: Using ODPC-approved or GDPR-compliant Standard Contractual Clauses (SCCs) with all service providers.
- Binding Corporate Rules: Where applicable, requiring adherence to approved binding corporate rules for intra-group transfers.
- Data Processing Agreements: Executing comprehensive DPAs with all processors that include cross-border transfer provisions.
You may request details of the safeguards we use for international transfers by contacting privacy@guerison.website.
11. Security Measures
We implement and maintain industry-standard technical and organizational security measures designed to protect your data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access:
Data Breach Notification. In the unfortunate event of a personal data breach, we will notify the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware, as required by the DPA 2019 (Section 43). Where the breach is likely to result in high risk to your rights and freedoms, we will also notify you without undue delay, describing the nature of the breach, the likely consequences, and the measures taken or proposed.
12. Children's Data
The Service is not directed to or intended for individuals under 18 years of age — the age of digital consent under the Kenya Data Protection Act 2019. We do not knowingly collect, process, or solicit personal data from children under 18.
If we become aware that we have inadvertently collected personal data from a child under 18 without verified parental consent, we will take immediate steps to delete such data from our systems. If you believe a child under 18 has provided us with personal data, please contact us immediately at privacy@guerison.website.
If you are a parent or guardian and believe your child has used the Service, please contact us. We are committed to protecting children's privacy and complying with all applicable laws regarding minors' data.
13. Marketing Communications
We may send you marketing communications (product updates, newsletters, promotional offers, event invitations) only where:
- You have given us explicit consent (opt-in) to receive such communications, or
- We have an existing business relationship and are communicating about similar products or services (legitimate interest, subject to your right to object)
Opting Out. You may withdraw your consent or opt out of marketing communications at any time by:
- Clicking the "Unsubscribe" link at the bottom of any marketing email
- Adjusting your Notification Preferences in Account Settings → Security
- Contacting us at privacy@guerison.website
Opting out of marketing does not affect service-related communications (transactional emails, security alerts, billing notices, Terms updates) which we may still send as necessary for the operation of your Account.
14. Changes to This Privacy Notice
We may update this Privacy Notice from time to time to reflect changes in our practices, the Service, or applicable law. When we make changes:
- Material Changes: We will notify you via email at least 14 days before material changes take effect. The email will summarize the changes and their effective date.
- Non-Material Changes: Minor updates (clarifications, formatting, typo fixes) may be made without direct notification.
- Continued Use: Your continued use of the Service after the effective date of changes constitutes acceptance of the updated Privacy Notice. If you disagree, you may terminate your Account before the effective date.
- Version History: Previous versions of this Privacy Notice are available upon request.
15. Contact Us & Complaints
For any questions, concerns, or to exercise your data subject rights, please contact us:
We aim to acknowledge all privacy-related inquiries within 48 hours and resolve them within 14 days, as required under Kenyan data protection regulations.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC), the regulatory authority responsible for enforcing the Kenya Data Protection Act 2019:
Website: www.odpc.go.ke
Email: info@odpc.go.ke
Location: Nairobi, Kenya
We encourage you to contact us first so we can address your concerns directly before escalating to the ODPC.