Skip to content
Legal

Terms, privacy and how your data is handled.

8 documents covering the agreement to use Tephlo, what happens to personal data, who else touches it, and how the platform is secured. Each one describes what the software actually does today.

Latest content review 23 September 2026Revision Draft 1.1 — factual content refresh

Download all documents as PDF or Word.

These are drafts, pending review by a lawyer

These drafts describe the implemented product and identify deployment details and legal decisions that still need confirmation. They have not yet been reviewed by a qualified lawyer in Nigeria and should not be treated as finalized agreements.

Nothing here is legal advice. Decisions still open — such as the transfer mechanism for data that leaves Nigeria, the audit terms in the Data Processing Agreement, and the effective dates of the disclosures — remain visibly marked for review. If you are evaluating Tephlo and need a signed agreement, contact us to confirm which reviewed documents are available.

The documents

What each one covers

Start with the Privacy Policy if you are a customer messaging a business, or the DPA if you are a business evaluating Tephlo.

Terms of Service

The agreement for using the platform: accounts, acceptable use, availability, fees, liability, termination and governing law.

Updated 26 September 2026 · Draft 1.1 — factual content refresh

Deleting your data

How to have data erased — different routes for someone who messaged a business and for someone who runs a workspace — what erasure removes, and what is deliberately kept.

Updated 6 September 2026 · Draft 1.1 — factual content refresh

Privacy Policy

What personal data the platform handles — separately for the customers who message a business and for the staff who run a workspace — why, for how long, and what rights apply.

Updated 6 September 2026 · Draft 1.1 — factual content refresh

Data Processing Agreement

The processor terms for business customers: scope of processing, security measures, sub-processors, breach notification, audit, and deletion or return of data.

Updated 6 September 2026 · Draft 1.1 — factual content refresh

Sub-processors

Provider roles and data flows supported by the platform, with the actual provider, region and contractual details to confirm for the deployment.

Updated 6 September 2026 · Draft 1.1 — factual content refresh

Acceptable Use Policy

What a business may not use the assistant for, which limits are enforced in code rather than by policy alone, and what happens when a limit is crossed.

Updated 6 September 2026 · Draft 1.1 — factual content refresh

Cookies & Local Storage

Session cookies, currency and display preferences, and the widget’s pseudonymous conversation identifier — with no built-in advertising or analytics cookies.

Updated 6 September 2026 · Draft 1.1 — factual content refresh

Security Overview

How the platform protects data in plain language — isolation, encryption, authentication, audit trails and data lifecycle — plus what it deliberately does not claim.

Updated 6 September 2026 · Draft 1.1 — factual content refresh

What these documents deliberately do not claim

A policy that promises more protection than the software provides is worse than no policy, because it is relied on. So the following are stated here once, plainly, rather than being quietly absent:

  • No security certification. Tephlo holds no SOC 2 report and no ISO 27001 certificate. The Security Overview describes real, implemented controls, and an independent audit has not assessed them.
  • No uptime guarantee. There is no service level agreement with credits attached. The platform depends on WhatsApp, Telegram, an AI provider and a hosting provider, any of which can fail independently of us.
  • No data residency guarantee. Messages are processed by an AI provider and delivered by messaging providers that operate internationally. We cannot promise data stays within one country or region — the sub-processor list says where each one operates.
  • No end-to-end encryption of message content. To answer a customer’s question, the platform has to read it. Message content is encrypted in transit and stored in an access-controlled database, not sealed from us.
  • No claim that AI answers are always right. The assistant answers from a business’s own knowledge and refuses to guess, but it can still be wrong. It is not a substitute for professional advice, and never confirms a payment or an identity.

Who these documents are for

People messaging a business that uses Tephlo
The Privacy Policy explains what happens to your messages. The business you contacted decides what is collected and why; Tephlo handles it on their instructions, and requests about your data are answered fastest by that business.
Businesses running a workspace
The Terms of Service is the agreement, the DPA covers your customers’ personal data, and the Acceptable Use Policy sets the limits. The sub-processor list is the one to send to your own compliance reviewer.
Security and procurement reviewers
The Security Overview and the DPA security annex are the technical answer, and the product documentation covers how the controls appear in the console.

Changes to these documents

Each document carries the date it was last updated. Material changes to the Terms, the Privacy Policy or the DPA will be notified to workspace administrators by email before they take effect, with the notice period stated in the Terms. New sub-processors are published on the sub-processor page before they start processing data.

Contact

Questions about any of this go to hello@tephlo.com, or through the contact page. Requests about personal data should reach the data protection contact at [DATA PROTECTION CONTACT] — until that address is published, the general address reaches the same team.

Reporting a security problem. If you have found a vulnerability, write to [SECURITY CONTACT] (or the general address above) with enough detail to reproduce it. We do not run a paid bug bounty, and we will not pursue anyone who reports a genuine issue in good faith.