Privacy
What personal data Sema holds, why, for how long, and how to get it back or deleted. Written to be checkable against what the software actually does.
Last updated 23 August 2026
Draft pending legal review. This document describes how Sema actually handles data today, but it has not been reviewed by a lawyer. Do not rely on it as final terms, and do not launch on it without review under Kenya's Data Protection Act 2019 and, where relevant, the GDPR.
Who is responsible for what
Two different roles matter here, and they are not interchangeable.
The business using Sema is the data controller for its own customers' information. It decides who to message, why, and on what basis. Sema is the data processor: we store and transmit that information on the business's instructions and do not use it for our own purposes.
For the accounts of the people who log in to Sema — names, emails, passwords — Sema is the controller.
If you are a customer of a business that uses Sema and want your data removed, contact that business. They control it; we act on their instruction.
What we hold
Conversations. The messages sent to and from a business's WhatsApp number, including text, images, documents, voice notes and delivery status. Attachments are downloaded from WhatsApp and stored, because WhatsApp's own links expire within minutes.
Contacts. Phone number, the WhatsApp profile name, any name or tags the business adds, and the record of whether that person agreed to receive messages.
Consent history. Every time someone agrees to or withdraws from messaging, we record when it happened and how — a replied STOP, an import, a note by a team member. This record is append-only and never edited, because being able to demonstrate consent is the point of keeping it.
Account and billing. The email and name of each person who logs in, the workspace they belong to, message costs, and payment references. M-Pesa transactions store the receipt number and the paying phone number.
We do not hold card numbers. Payments go through M-Pesa or a payment processor and we only ever see their reference.
How it is kept separate
Each workspace's data is isolated in the database itself, not merely in the interface. Every table enforces row-level security keyed to workspace membership, so a query from one business physically cannot return another business's rows — including over the realtime connection the inbox uses.
Within a workspace, access follows role. An agent can read conversations but not billing; a billing contact can see invoices but not conversations. These limits are enforced by the database, so they hold even for someone bypassing the interface.
WhatsApp access tokens are encrypted at rest and never returned to a browser.
How long we keep it
Conversations and attachments are kept for as long as the workspace is active, because they are the business's record of what it promised its customers. A business can delete individual conversations or contacts at any time.
Consent records outlive the contact they describe. If a contact is deleted, the fact that they once objected is retained — otherwise a re-import could quietly resurrect someone who asked to be left alone.
Billing records are kept for seven years, as Kenyan tax law requires.
When a workspace closes, its conversations, contacts and attachments are deleted within 30 days. Billing and consent records are retained as above.
Who else processes it
These are the only third parties involved in running the service:
- Meta Platforms — delivers every WhatsApp message. Messages necessarily pass through WhatsApp; that is what the product is.
- Supabase — database, file storage and authentication.
- Safaricom — M-Pesa payments, for Kenyan customers topping up.
We do not sell data, and we do not share it with advertisers or data brokers.
Where it is stored
Data is stored on infrastructure that may be outside Kenya. Under section 48 of the Data Protection Act, transfers abroad require appropriate safeguards; we rely on contractual protections with our processors. Where a business requires Kenyan residency specifically, contact us before signing up — we would rather say no than say yes and be wrong.
Your rights
Under the Data Protection Act 2019 and, where it applies, the GDPR, you can ask to see the data held about you, correct it, have it deleted, object to it being used, or receive a copy in a portable form.
People with a Sema login can export or delete their workspace's data from Settings. If you are a customer of a business using Sema, ask that business — and if they do not respond, you may complain to the Office of the Data Protection Commissioner.
Anyone receiving WhatsApp messages through Sema can stop them at any time by replying STOP. That is honoured automatically and immediately, and the business cannot override it.
Breaches
If personal data is compromised in a way that risks harm, we will notify the Office of the Data Protection Commissioner within 72 hours and tell affected businesses without undue delay, per section 43 of the Act.