Effective Date: 1 January 2026 | Last Updated: August 2026
IndustryAI ("we", "us", or "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights.
1. Information We Collect
- Account Data: Name, email address, password (hashed), and organisation details provided during registration.
- Usage Data: Pages visited, features used, AI job history, and session timestamps collected automatically.
- Uploaded Content: Documents, images, or files you submit to our AI tools (e.g. electricity bills, house photos, receipts, invoices, quotations and contracts). These are processed to deliver results and not shared with third parties.
- Payment Data: Billing name, card last 4 digits, and transaction IDs. Full card details are handled by PCI-DSS-compliant processors (Pesapal, PayPal, M-Pesa) and never stored on our servers.
- Device & Browser Data: IP address, browser type, operating system, and referral URLs collected via server logs and analytics.
2. How We Use Your Information
- Deliver and improve our AI-powered services (house design, solar planning, business tools).
- Process subscriptions, payments, and send service-related communications.
- Personalise your experience and surface relevant features.
- Detect fraud, enforce our Terms of Service, and maintain platform security.
- Comply with applicable laws and respond to lawful requests.
3. Data Sharing
We do not sell your personal data. We share information only with:
- Service Providers: vendors that run parts of the service for us, under data-processing terms:
- Amazon Web Services (AWS S3) — storage of files you upload and documents we generate;
- Resend — sending account, receipt and newsletter emails;
- Google Analytics — aggregate statistics on how the website is used;
- Cloudflare Turnstile — telling people from bots on some free tools;
- an SMS provider (Africa's Talking or Twilio) — only if you reset your password by SMS;
- our hosting provider, which runs the servers the platform operates on.
- AI Providers: Content you submit is sent to third-party AI APIs (e.g. Anthropic, OpenAI, Groq, Stability AI) solely to generate the output you requested. These providers process it as our sub-processors and do not use it to train their models.
- Legal Authorities: When required by law or to protect rights and safety.
4. Data Retention
Account data is retained for the duration of your subscription. Uploaded files and AI outputs are retained for 12 months then purged unless you delete them earlier from your dashboard — except where a product keeps records for a legal period, as the Document Review Portal does (§8).
When you request deletion, we run a two-stage process so that an accidental or disputed request can still be undone:
- Day 30 — deactivation. Your organisation is disabled and personal details (name, email, profile photo) are anonymised. Your content is retained but inaccessible.
- Day 120 — erasure. Your database schema is dropped and all remaining data is permanently deleted. Recovery is no longer possible after this point.
You can cancel the request yourself before deactivation, and ask support to restore the account between deactivation and erasure.
5. Your Rights
Depending on your jurisdiction — including under the EU/UK GDPR and the Kenya Data Protection Act 2019 — you have the right to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing.
- Export: Download a machine-readable copy of your personal data at any time from your Privacy & Data settings.
- Deletion: Organisation owners can request erasure from the same page; the timeline is set out in §4. Other members should email the address below and we will remove their membership and personal data within 30 days. In both cases we retain records we are legally required to keep, such as tax records of completed payments.
- Other rights: Contact privacy@industryai.africa. We respond within 30 days.
You also have the right to lodge a complaint with your local supervisory authority — in Kenya, the Office of the Data Protection Commissioner.
6. Security
We use TLS encryption in transit, encryption at rest for stored files, role-based access controls, tenant-level database isolation, and malware scanning of uploaded files. No system is perfectly secure; please use a strong, unique password and enable two-factor authentication.
7. International Transfers
Our infrastructure and some sub-processors (notably AI and email providers) are located outside Kenya, including in the United States and the European Union. Where personal data is transferred internationally, we rely on the sub-processor's standard contractual clauses or an equivalent safeguard.
8. Document Review Portal
The Document Review Portal reads business documents — receipts, invoices, quotations, contracts and supplier certificates — so that you can check and file them. In addition to the rest of this policy:
- What it holds: the files you upload or scan, the pages we make from them, and what is read off them: supplier and customer names, KRA PINs, phone numbers, amounts, VAT, eTIMS numbers, M-Pesa codes, contract terms and dates. It also holds what you and your colleagues change, approve or note, with who did it and when.
- Other people's details: your documents often name other people and businesses (a supplier, a contractor, a director). For those details your organisation decides why they are processed and is responsible for having a lawful reason; we process them on your behalf, only to provide the portal.
- AI reading, and where it happens: AI reading is off until an owner or admin of your workspace turns it on and accepts a notice; the date and version of that acceptance are recorded. With it on, the page images and text of each document are sent to Anthropic, our AI provider, which processes them outside Kenya (in the United States) to read them, and does not use them to train its models. With it off, documents are read on our own servers with text recognition, and nothing is sent to an AI provider. Contract review needs AI reading.
- Checks are suggestions: the checks the portal makes — on KRA PINs, VAT, eTIMS details, contract terms and supplier certificates — are produced automatically to help you and your accountant. They are not tax or legal advice, a KRA verification, or a decision about anyone. A person in your workspace confirms every document before it is filed.
- Sanctions screening: if you use supplier checks, a supplier's name is compared, on our servers, with the public sanctions lists published by the United Nations, the United States (OFAC), the European Union and the United Kingdom. A similar name is shown to you as a possible match for you to review; it is never treated as a finding that someone is sanctioned, and nothing is sent to those authorities or anyone else.
- How long it is kept: documents are kept for the period your workspace sets — seven years unless an owner or admin changes it, and never less than five, the period Kenya's Tax Procedures Act requires for tax records — counted from the document's date, then deleted. Documents under a legal hold are kept until the hold is lifted. Deleting your account (§4) deletes them sooner, except records we must keep by law.
- On your phone: in the IndustryAI apps, a scan that hasn't been sent yet waits on your phone, encrypted with a key held in the phone's secure storage, and is deleted from the phone once our servers have it.
9. Changes to This Policy
Material changes will be communicated by email and/or an in-app notice at least 14 days before taking effect. Continued use of the platform constitutes acceptance.
10. Contact
IndustryAI — Privacy Team
Email: privacy@industryai.africa
Registered in Kenya.