Privacy Notice

Last updated: August 5, 2026 · Effective immediately

Compliant with Kenya Data Protection Act 2019, GDPR, and international standards

1. Scope & Controller Identity

This Privacy Notice explains how Guerison ("Ohala," "we," "our," or "us"), registered in the Republic of Kenya, collects, uses, discloses, retains, and protects personal information when you:

  • Visit our website at guerison.website or any related subdomains
  • Register for, access, or use the Ohala Business OS platform (the "Service")
  • Communicate with us via email, phone, WhatsApp, or any other channel
  • Interact with our marketing materials, social media, or advertisements
  • Attend our events, webinars, or training sessions

We act as both a data controller (for our own business operations, marketing, and platform administration) and a data processor (when our customers process personal data of their own clients, employees, or suppliers through the Service).

Data Controller Details:

Entity: Guerison (trading as Ohala Business OS)

Email: privacy@guerison.website

Data Protection Officer: Available at the email above

This Privacy Notice was last updated on August 5, 2026 and is effective immediately.

2. Our Privacy Commitments

We are committed to protecting your privacy and handling your personal data fairly, lawfully, and transparently. Our data protection practices are built around these core principles:

Lawfulness: We process personal data only where we have a valid legal basis, as required by the Kenya Data Protection Act 2019.
Transparency: We tell you exactly what data we collect, why we collect it, how we use it, and who we share it with.
Purpose Limitation: We collect data for specified, explicit, and legitimate purposes and do not process it in ways incompatible with those purposes.
Data Minimization: We collect only the minimum personal data necessary for the stated purposes.
Accuracy: We take reasonable steps to ensure personal data is accurate and up to date.
Storage Limitation: We retain personal data only for as long as necessary to fulfill the purposes for which it was collected.
Security: We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or damage.
Accountability: We take responsibility for our data processing activities and can demonstrate compliance with data protection principles.

This Privacy Notice is designed to comply with the Kenya Data Protection Act, 2019 (No. 24 of 2019) ("DPA 2019"), the Data Protection (General) Regulations, 2021, the Data Protection (Complaints Handling and Enforcement Procedures) Regulations, 2021, and applicable guidance issued by the Office of the Data Protection Commissioner (ODPC). Where applicable, we also adhere to international standards including the EU General Data Protection Regulation (GDPR) for users in the European Economic Area.

3. What Information We Collect

3.1 Information You Provide Directly

Account Registration:Full name, email address, phone number, business name, password (hashed), and billing address.
Profile Information:Profile photo, job title, department, and communication preferences.
Payment Information:Billing details, payment method information. Full card numbers are processed exclusively by our PCI-DSS compliant payment partners (Paystack, Stripe) and are never stored on our servers.
Customer Data:Any data you upload, store, or process through the Service, including inventory records, sales transactions, customer contact details, employee records, financial data, and business documents.
Communications:Content of emails, support tickets, chat messages, WhatsApp conversations, and feedback you send us.
Marketing Preferences:Your consent choices for receiving marketing communications, newsletters, and promotional offers.

3.2 Information Collected Automatically

Usage Data:Features accessed, pages visited, actions performed, time spent, clicks, and navigation patterns within the Service.
Device Information:IP address, browser type and version, operating system, device type, screen resolution, and language settings.
Location Data:Approximate geographic location derived from your IP address (city/country level only).
Cookies & Similar Technologies:Session cookies, authentication tokens, preference cookies, and analytics identifiers. See our Cookie Policy (Section 8) for details.
Log Data:Server logs including access timestamps, API requests, error logs, and performance metrics.

3.3 Information From Third Parties

Payment Processors:Payment confirmation, transaction IDs, and payment status from Paystack, M-Pesa, Stripe, or PesaPal.
Auth Providers:If you use social login or SSO, we receive authentication tokens and basic profile information from the identity provider.
Integration Partners:If you connect third-party services (Shopify, QuickBooks, etc.), we receive data per your authorization from those platforms.

4. How We Use Your Information

We process personal data for the following purposes, each grounded in a valid legal basis under the DPA 2019:

Service Provision:To create and manage your Account, authenticate you, provide the features you request, process payments, and deliver the Service. (Legal basis: Contractual necessity)
Customer Support:To respond to inquiries, troubleshoot issues, provide technical support, and send service-related communications. (Legal basis: Contractual necessity; Legitimate interest)
Security & Fraud Prevention:To monitor for and prevent fraud, unauthorized access, security incidents, and abuse; to enforce our Terms of Service. (Legal basis: Legitimate interest; Legal obligation)
Product Improvement:To analyze usage patterns, identify bugs, develop new features, and improve the Service experience. (Legal basis: Legitimate interest)
Marketing (with consent):To send you newsletters, product updates, promotional offers, event invitations, and other marketing communications. You may opt out at any time. (Legal basis: Consent)
Legal Compliance:To comply with applicable laws (DPA 2019, KRA requirements, AML/CTF obligations), respond to lawful requests from authorities, and establish or defend legal claims. (Legal basis: Legal obligation; Legitimate interest)
Business Operations:To conduct analytics, generate aggregated insights, manage our business relationship with you, and for internal reporting and planning. (Legal basis: Legitimate interest)

Automated Decision-Making. Our AI-powered features (predictive analytics, inventory forecasting, automated insights) involve automated processing. These are assistive tools only — they do not produce legal effects or significantly affect you. All AI output requires human review before business decisions. You may request human intervention for any AI-generated output by contacting us.

5. How We Share Information

We do not and will never sell, rent, or trade your personal data. We share data only in the following limited circumstances:

Service Providers:With trusted third-party vendors who help us deliver the Service (infrastructure, payment processing, email delivery, AI model inference, analytics). These providers are bound by data processing agreements and confidentiality obligations.
Payment Partners:Paystack, Safaricom (M-Pesa Daraja API), PesaPal, and Stripe receive transaction data necessary to process your payments. Each partner maintains independent PCI-DSS compliance.
Infrastructure Partners:Supabase (database and authentication), DigitalOcean (server hosting), Resend (email delivery) receive data necessary to operate the technical infrastructure.
AI Providers:OpenAI and other AI model providers receive prompt data to generate AI responses. Such data is not used to train their models by default. See Section 9 for details.
At Your Direction:When you connect third-party integrations (Shopify, QuickBooks, etc.), we share data per your explicit authorization and configuration.
Legal Obligations:When required by Kenyan law, court order, or governmental authority with proper jurisdiction. We will notify you of such disclosure unless legally prohibited.
Business Transfers:In connection with a merger, acquisition, reorganization, or sale of assets, your data may be transferred as a business asset, subject to the same privacy commitments.
With Your Consent:In any other circumstances with your explicit prior consent.

6. Data Retention and Deletion

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, and reporting requirements. Our retention periods are:

Account Data:Retained for the duration of your Account plus 90 days after termination, after which it is permanently and irretrievably deleted from active systems.
Customer Data:Retained for the duration of your Account. Upon termination, we provide a 30-day export window. Data is permanently deleted thereafter. Backups are purged within 90 days.
Payment Records:Retained for 7 years as required by Kenyan tax law (KRA) and financial regulations.
Support Communications:Retained for 3 years from last interaction for quality assurance and reference.
Marketing Consent:Retained until you withdraw consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
Server Logs:Retained for 90 days for security monitoring, then automatically purged.
Backups:Encrypted backups are retained for 30-90 days on a rotating schedule, after which they are securely overwritten.

When data is deleted, we use industry-standard methods to ensure it is irrecoverable, including cryptographic erasure where applicable. You may request earlier deletion of specific data by contacting us, subject to legal retention obligations.

7. Your Data Subject Rights (DPA 2019)

Under the Kenya Data Protection Act 2019 and its regulations, you have the following rights regarding your personal data. To exercise any right, contact us at privacy@guerison.website. We will respond within 14 days (as required under Kenyan regulations):

Right to be Informed:You have the right to know what personal data we collect, why we collect it, how we use it, and who we share it with (this Privacy Notice fulfills this obligation).
Right of Access (Section 26):You may request a copy of all personal data we hold about you, free of charge once per year. Additional copies may incur a reasonable administrative fee.
Right to Rectification (Section 27):You may request correction of inaccurate or incomplete personal data. You can also update most information directly through your Account Settings.
Right to Erasure (Section 28):You may request deletion of your personal data where: (a) it is no longer necessary; (b) you withdraw consent; (c) you object to processing; (d) processing was unlawful; or (e) erasure is required by law. This right is subject to legal retention obligations.
Right to Restrict Processing (Section 29):You may request restriction of processing where: (a) accuracy is contested; (b) processing is unlawful but you oppose erasure; (c) we no longer need the data but you need it for legal claims; or (d) you have objected to processing pending verification.
Right to Data Portability (Section 30):You may request your personal data in a structured, commonly used, machine-readable format (CSV, JSON, Excel) and have it transmitted directly to another controller where technically feasible.
Right to Object (Section 31):You may object to processing based on legitimate interests or for direct marketing purposes. We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests.
Rights Regarding Automated Decisions (Section 35):You have the right not to be subject to decisions based solely on automated processing that produce legal effects or significantly affect you. Our AI features are assistive — they do not make legally binding decisions.
Right to Withdraw Consent:Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of prior processing.
Right to Lodge a Complaint:You have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) if you believe your data protection rights have been violated. Contact: info@odpc.go.ke or visit www.odpc.go.ke.

Verification. To protect your privacy, we will verify your identity before responding to rights requests. We may request additional information to confirm your identity. If you are making a request on behalf of another individual, you must provide proof of authorization.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies (local storage, session storage, pixels) for the following purposes:

Essential (Required):Authentication tokens, session management, CSRF protection, and security features. These are necessary for the Service to function and cannot be disabled.
Functional:Language preferences, theme settings (light/dark mode), sidebar mode, and UI customization. These enhance your experience but are not essential.
Analytics:Anonymous usage analytics (page views, feature usage, error tracking) to improve the Service. We use self-hosted or privacy-respecting analytics.
Marketing (Opt-in Only):With your consent, we may use cookies to track the effectiveness of our marketing campaigns and to deliver relevant advertisements.

Managing Cookies. You can control and delete cookies through your browser settings. Disabling essential cookies will prevent the Service from functioning. Most browsers allow you to block third-party cookies specifically while allowing first-party cookies. For more information, visit www.allaboutcookies.org.

Do Not Track. We honor "Do Not Track" (DNT) signals from browsers that support them. When DNT is enabled, we disable all non-essential tracking.

9. AI Data Processing

Ohala includes AI-powered features (AI Assistant, predictive analytics, inventory forecasting, automated insights) that process data using third-party AI model providers (including OpenAI, among others):

  • What We Send: When you use AI features, we send your prompt and relevant contextual business data (product names, sales figures, inventory levels) to the AI provider for processing. We do not send personal data unless it is part of your prompt.
  • Training Opt-Out: By default, we have opted out of allowing AI providers to use your data for model training. Your data is processed for inference only and is not retained by AI providers beyond the brief period necessary to generate a response (typically seconds to minutes).
  • Data Minimization: We minimize the data sent to AI providers to only what is necessary to fulfill your request. We do not send full databases — only the specific data context relevant to your query.
  • Your Control: You control which AI features you use. You may disable AI features entirely from your Account Settings → AI Settings. Even when enabled, AI features are tools to assist your decision-making — you remain responsible for all business decisions.
  • Accuracy: AI-generated output may contain errors. You should always verify critical information independently.

10. International Data Transfers

Your data is primarily stored and processed on servers located in Frankfurt, Germany (EU) and Nairobi, Kenya. Some of our service providers may process data in other jurisdictions.

Whenever we transfer personal data outside Kenya, we ensure appropriate safeguards are in place in compliance with the DPA 2019 and its regulations. These safeguards include:

  • Adequacy: Transferring to countries that the ODPC has recognized as providing an adequate level of data protection (including EU member states where GDPR applies).
  • Standard Contractual Clauses: Using ODPC-approved or GDPR-compliant Standard Contractual Clauses (SCCs) with all service providers.
  • Binding Corporate Rules: Where applicable, requiring adherence to approved binding corporate rules for intra-group transfers.
  • Data Processing Agreements: Executing comprehensive DPAs with all processors that include cross-border transfer provisions.

You may request details of the safeguards we use for international transfers by contacting privacy@guerison.website.

11. Security Measures

We implement and maintain industry-standard technical and organizational security measures designed to protect your data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access:

TLS 1.3 encryption for all data in transit
AES-256 encryption for all data at rest
PostgreSQL Row-Level Security for multi-tenant isolation
Multi-factor authentication (MFA) support
Role-based access controls with audit logging
Regular automated vulnerability scanning
Annual third-party penetration testing
24/7 security monitoring and intrusion detection
Encrypted daily backups with geo-redundancy
Secure SDLC with code review and dependency scanning
Strict access controls — production access limited to essential personnel only
Security awareness training for all personnel

Data Breach Notification. In the unfortunate event of a personal data breach, we will notify the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware, as required by the DPA 2019 (Section 43). Where the breach is likely to result in high risk to your rights and freedoms, we will also notify you without undue delay, describing the nature of the breach, the likely consequences, and the measures taken or proposed.

12. Children's Data

The Service is not directed to or intended for individuals under 18 years of age — the age of digital consent under the Kenya Data Protection Act 2019. We do not knowingly collect, process, or solicit personal data from children under 18.

If we become aware that we have inadvertently collected personal data from a child under 18 without verified parental consent, we will take immediate steps to delete such data from our systems. If you believe a child under 18 has provided us with personal data, please contact us immediately at privacy@guerison.website.

If you are a parent or guardian and believe your child has used the Service, please contact us. We are committed to protecting children's privacy and complying with all applicable laws regarding minors' data.

13. Marketing Communications

We may send you marketing communications (product updates, newsletters, promotional offers, event invitations) only where:

  • You have given us explicit consent (opt-in) to receive such communications, or
  • We have an existing business relationship and are communicating about similar products or services (legitimate interest, subject to your right to object)

Opting Out. You may withdraw your consent or opt out of marketing communications at any time by:

  • Clicking the "Unsubscribe" link at the bottom of any marketing email
  • Adjusting your Notification Preferences in Account Settings → Security
  • Contacting us at privacy@guerison.website

Opting out of marketing does not affect service-related communications (transactional emails, security alerts, billing notices, Terms updates) which we may still send as necessary for the operation of your Account.

14. Changes to This Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our practices, the Service, or applicable law. When we make changes:

  • Material Changes: We will notify you via email at least 14 days before material changes take effect. The email will summarize the changes and their effective date.
  • Non-Material Changes: Minor updates (clarifications, formatting, typo fixes) may be made without direct notification.
  • Continued Use: Your continued use of the Service after the effective date of changes constitutes acceptance of the updated Privacy Notice. If you disagree, you may terminate your Account before the effective date.
  • Version History: Previous versions of this Privacy Notice are available upon request.

15. Contact Us & Complaints

For any questions, concerns, or to exercise your data subject rights, please contact us:

General Support: support@guerison.website
Security Incidents: security@guerison.website

We aim to acknowledge all privacy-related inquiries within 48 hours and resolve them within 14 days, as required under Kenyan data protection regulations.

Right to Complain.

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC), the regulatory authority responsible for enforcing the Kenya Data Protection Act 2019:

Website: www.odpc.go.ke

Email: info@odpc.go.ke

Location: Nairobi, Kenya

We encourage you to contact us first so we can address your concerns directly before escalating to the ODPC.