These drafts describe the implemented product and identify deployment details and legal decisions that still need confirmation. They have not yet been reviewed by a qualified lawyer in Nigeria and should not be treated as finalized agreements.
Nothing here is legal advice. Decisions still open — such as the transfer mechanism for data that leaves Nigeria, the audit terms in the Data Processing Agreement, and the effective dates of the disclosures — remain visibly marked for review. If you are evaluating Tephlo and need a signed agreement, contact us to confirm which reviewed documents are available.
Start with the Privacy Policy if you are a customer messaging a business, or the DPA if you are a business evaluating Tephlo.
The agreement for using the platform: accounts, acceptable use, availability, fees, liability, termination and governing law.
Updated 26 September 2026 · Draft 1.1 — factual content refreshHow to have data erased — different routes for someone who messaged a business and for someone who runs a workspace — what erasure removes, and what is deliberately kept.
Updated 6 September 2026 · Draft 1.1 — factual content refreshWhat personal data the platform handles — separately for the customers who message a business and for the staff who run a workspace — why, for how long, and what rights apply.
Updated 6 September 2026 · Draft 1.1 — factual content refreshThe processor terms for business customers: scope of processing, security measures, sub-processors, breach notification, audit, and deletion or return of data.
Updated 6 September 2026 · Draft 1.1 — factual content refreshProvider roles and data flows supported by the platform, with the actual provider, region and contractual details to confirm for the deployment.
Updated 6 September 2026 · Draft 1.1 — factual content refreshWhat a business may not use the assistant for, which limits are enforced in code rather than by policy alone, and what happens when a limit is crossed.
Updated 6 September 2026 · Draft 1.1 — factual content refreshSession cookies, currency and display preferences, and the widget’s pseudonymous conversation identifier — with no built-in advertising or analytics cookies.
Updated 6 September 2026 · Draft 1.1 — factual content refreshHow the platform protects data in plain language — isolation, encryption, authentication, audit trails and data lifecycle — plus what it deliberately does not claim.
Updated 6 September 2026 · Draft 1.1 — factual content refreshA policy that promises more protection than the software provides is worse than no policy, because it is relied on. So the following are stated here once, plainly, rather than being quietly absent:
Each document carries the date it was last updated. Material changes to the Terms, the Privacy Policy or the DPA will be notified to workspace administrators by email before they take effect, with the notice period stated in the Terms. New sub-processors are published on the sub-processor page before they start processing data.
Questions about any of this go to hello@tephlo.com, or through the contact page. Requests about personal data should reach the data protection contact at [DATA PROTECTION CONTACT] — until that address is published, the general address reaches the same team.