DRAFT · UNDER LEGAL REVIEWLAST UPDATED · 24 JULY 2026
Privacy

What we collect, why, and what we never do.

CogniChat handles business and customer information on behalf of merchants in Ghana. This page explains what data we touch, who else sees it, and the choices you have. We follow Ghana's Data Protection Act, 2012 (Act 843).

01

Who we are.

CogniChat is operated by Vendyi Stores Ltd, a private company limited by shares, incorporated in Ghana under the Companies Act, 2019 (Act 992), registration number CS219480925, TIN C0066213495, with its registered office at House No. OKE 25, Chanatta Street, Suhum, Eastern Region, Ghana (GhanaPost GPS ES-0008-8206; P.O. Box 345, Suhum). In this policy “we”, “us” and “CogniChat” mean Vendyi Stores Ltd.

For your own account, billing and verification data we are the data controller. For the messages and details of your customers that flow through your workspace, we act as a data processor on your behalf, handling that data on your instructions to run the service; you remain the controller for it.

We follow Ghana's Data Protection Act, 2012 (Act 843) and are completing our registration with the Data Protection Commission. Our data-protection contact is samuel@vendyi.com.

02

The data we collect.

When you sign up, we collect your name, business name, email, phone number, country and currency. When your customers chat with your WhatsApp line, we receive their phone number, the messages they send, and any media attached to those messages.

Identity & business verification (KYC). Before a workspace can connect WhatsApp and go live, we verify the business and the person running it, a requirement of our payment and WhatsApp Business partners and of Ghanaian regulation. For this we collect your business's legal name and registration number and a copy of your business registration document, and the owner's or authorised representative's full name, ID type and number. We do not store a photograph of a Ghana Card: Ghanaian law does not permit it, so we record the card number and the card itself is checked by a licensed verification partner. You may also confirm a WhatsApp number by sending us a code.

For payments processed through Paystack, we receive transaction metadata (amount, status, reference), not the underlying card numbers, which Paystack handles directly.

Cookies & local storage. The app keeps a sign-in token in your browser's local storage so you stay logged in, plus the essential cookies needed to run the dashboard. We don't use third-party advertising cookies. CogniChat isn't directed at children, and you must not use it to collect a child's data without the consent the law requires.

03

Why we have it.

To run the service you signed up for: routing chats to your team board, generating AI replies, tracking inventory, settling payments, and giving your team a customer list that's useful next time the same person reaches out.

We also use aggregated, anonymous usage data, counts of messages, response times, uptime, to make the product better. We do not sell your data, your customers' data, or any of their chat content to third parties.

Verification documents (IDs and business registration) are used only to confirm your identity and that your business is genuine, to prevent fraud and impersonation, and to meet our legal and partner obligations. They are never sent to the AI, shown to other merchants, used for marketing, or sold.

Our legal basis. We process data to perform our contract with you (running the service and billing), to meet legal obligations (identity and anti-fraud verification, tax and accounting records), for our legitimate interests (preventing abuse and improving the product), and with your consent where it applies (for example, optional marketing). Your customers' data is processed on your instructions, as your processor.

04

Who else sees it.

A short list, by design:

  • Meta / Kapso (WhatsApp Business Platform), the transport for messages between you and your customers.
  • OpenAI and Google , the AI providers that draft replies. Message text forwarded to them is processed to generate the response and is not retained for model training under their API terms.
  • Paystack , card and Mobile Money payment processing.
  • DigitalOcean and Cloudflare, the cloud infrastructure and network providers that host and protect the service, under data processing agreements.
  • Sentry , error monitoring, so we find out about faults before you have to report them.
05

International transfers.

Some of these providers process data outside Ghana, for example Google (Gemini) and our cloud and payment partners. Where personal data leaves Ghana, we rely on the provider's contractual data-protection commitments and only share the minimum needed to run the service, as permitted by the Data Protection Act, 2012. Your verification documents are stored in our private, access-controlled bucket and are not sent to the AI.

06

How long we keep it.

Chat history and order/booking records are kept for as long as your workspace is active, plus a reasonable retention window after you close it so you can export records for tax or dispute reasons. After that, data is deleted from our active systems within 90 days.

Verification documents are treated as sensitive. They are held in a private, access-controlled store, never in the public app, and only a small number of vetted staff can view them, through short-lived links, to make a verification decision. We do not hold Ghana Card images at all. If we reject an application we delete any documents promptly, keeping only the dossier record (the decision and reason), not the images; for approved workspaces we keep them only as long as needed to meet our verification and legal obligations.

07

Government and legal requests.

If a government, law-enforcement agency, or regulator asks us for personal data, we follow a written internal policy before anything is disclosed:

  • We review every request for legal validity under Ghanaian law before responding, and act only on properly served, verifiable requests.
  • We challenge requests we believe are unlawful or overbroad, and ask for them to be narrowed or withdrawn.
  • When a request is valid, we disclose the minimum necessary to satisfy it, never open-ended access.
  • We document every request, our legal reasoning, and exactly what was disclosed, and where the law permits we notify the affected business.
08

Your rights.

Under Ghana's Data Protection Act, 2012, you can ask us to:

  • Show you what we hold about you or your business.
  • Correct anything that's wrong.
  • Delete it, subject to legal or accounting retention duties.
  • Export it in a portable format.

Email samuel@vendyi.com with the request. We respond within 30 days as the law requires. You can also lodge a complaint with Ghana's Data Protection Commission if you believe we have mishandled your data.

09

Contact + changes.

Questions about this policy: email samuel@vendyi.com. When we make material changes, we'll notify active workspaces by email and update the “last updated” date at the top.

THIS DOCUMENT IS A WORKING DRAFT. FORMAL LEGAL REVIEW IS UNDERWAY.

Questions about your data?

Reach our privacy team directly. We answer every request inside 30 days.