Skip to content
Terms of Service

Terms of Service

The agreement between your business and the company behind Tephlo. It covers what you get, what you are responsible for, and what happens when either side wants to stop.

Last updated 26 September 2026Revision Draft 1.1 — factual content refreshVersion 3 · Effective 26 September 2026

In plain language

You get a workspace that answers your customers on WhatsApp, Telegram and your website using knowledge you upload, and hands conversations to your team when a person is needed. You keep ownership of everything you put in.

  • You are responsible for what your workspace says and does, for the accuracy of the knowledge you upload, and for your staff accounts.
  • The assistant can be wrong. It uses workspace knowledge, business facts and permitted capabilities, can ask for clarification, and brings in a person when required. You must not use it where a wrong answer causes serious harm.
  • We do not promise a specific uptime, and the service depends on WhatsApp, Telegram and an AI provider that can fail independently of us.
  • You can export or delete a customer’s data at any time, and deleting your workspace really deletes it — see section 11.
  • Either side can end the agreement; we can suspend a workspace immediately if it is causing harm or breaking a channel provider’s rules.

This summary is a reading aid. Where it differs from the text below, the text below is what applies.

1. The agreement

These terms are between TEPHLO AI VANGUARD SYSTEMS LTD, a private company limited by shares incorporated in the Federal Republic of Nigeria under the Companies and Allied Matters Act 2020 (registration number 9893569) with its registered office at 9A Kenneth Lekara Luka Street, Lokogoma, FCT, Nigeria (“we”, “us”), and the business that creates a Tephlo workspace (“you”). They take effect on 26 September 2026 or, if later, when you first create a workspace or accept them in the console.

They apply together with the Acceptable Use Policy, the Privacy Policy and, where you handle personal data through the service, the Data Processing Agreement. If you have signed a separate order form or written agreement with us, that document wins wherever it conflicts with these terms.

This is a business-to-business service. It is not offered to consumers, and you confirm you are entering this agreement in the course of a trade, business or profession.

2. What the service is

Tephlo is a hosted customer-support assistant. In summary, a workspace can:

  • receive and reply to messages on WhatsApp Business, Telegram and an embeddable web chat widget on your own site, and an enabled commercial API integration;
  • answer from a knowledge base you upload — documents and pasted text — and from your workspace profile and structured product catalogue, with source information where available;
  • escalate a conversation to your team, with its history and the reason, and let an agent take over on the same channel;
  • capture structured requests such as a callback, a complaint or a refund request for your team to action;
  • save carts and submit potential-order requests for your team to review; a request is not a placed, paid or shipped order, and this workflow does not collect card numbers or arrange fulfilment;
  • handle appointment requests and, where automatic confirmation is enabled, confirm a booking only after the selected time is reserved;
  • give you a console with conversations, knowledge, analytics, business hours, escalation review and privacy tooling.

Some capabilities are switched off by default and only work when both the platform and your workspace enable them — document reading, optical character recognition on scanned PDFs, image understanding, voice-note transcription and spoken replies are examples. Provider configuration, workspace settings and other capability controls also apply. Customer memory is enabled by default in the software, can be disabled by the workspace and is subject to sensitivity controls. The product documentation describes what is available; nothing in it forms part of this agreement, and we may change or withdraw individual features (see section 17).

Where Smart Updates is enabled, customers can consent to updates on a topic. The platform records that consent, checks send eligibility and includes a STOP instruction. Contacting your business alone does not subscribe someone. AI-generated answers and extracted facts may still contain errors; review your published information and action settings.

We provide the service as software you access over the internet. We do not provide contact-centre staffing, and we do not act as your agent in any conversation.

3. Accounts and access

Your workspace is isolated from every other workspace: data is stored against your workspace identifier and every request is scoped to the account that made it. Within your workspace, you decide who has an account and what role they hold.

You are responsible for:

  • keeping account credentials confidential, and for everything done through your accounts;
  • removing access promptly when someone leaves your team — the console lets you disable or delete an account, and a workspace must always keep at least one active administrator;
  • the channel credentials you connect (WhatsApp tokens, a Telegram bot token), which are stored encrypted and used only to operate your channels.

Multi-factor authentication is enforced for platform operator accounts in production and is available for your administrators. We strongly recommend enabling it: it is the single control that most reduces the damage of a stolen password.

You must not share one account between people, probe or test the security of the platform without our written permission, or attempt to reach another workspace’s data.

4. Data and roles

You own the content you put into the service: your knowledge base, your catalogue, your configuration, and the conversations your customers have with your workspace. We claim no ownership of it.

For personal data inside those conversations you are the controller and we are the processor: you decide why it is collected and we handle it on your instructions. Those instructions are given through how you configure and use the service. The Data Processing Agreement sets out the detail and forms part of this agreement.

We use your content to provide and maintain the service, and to diagnose faults. We do not sell it, and we do not use your customers’ conversations to train AI models. Aggregated, non-identifying operational statistics — message volumes, error rates, latency — are used to run and improve the platform.

Quality features are opt-in. Features that keep customer content for review or reuse — escalation review excerpts, approved answer suggestions, response caching, customer memory — are controlled per workspace and default to off, apart from customer memory. See the Privacy Policy for what each one stores.

5. Acceptable use

The Acceptable Use Policy forms part of these terms and lists what a workspace may not be used for. In short: nothing illegal, nothing designed to deceive, no unsolicited bulk messaging, no collecting card numbers or one-time codes through chat, no use as a substitute for emergency services or regulated professional advice, and nothing that breaks the rules of the messaging channel you are using.

You are responsible for your customers’ experience of your workspace, including the instructions you give the assistant and the accuracy of the knowledge you upload. Incorrect material can lead to incorrect answers, and generated replies can still contain errors.

6. Messaging channels and other third parties

WhatsApp and Telegram are operated by third parties on their own terms. Where you connect your own WhatsApp Business account or Telegram bot, your relationship with that provider is yours, and their policies — including messaging limits, template rules and account bans — apply to you directly. We cannot restore access that a channel provider withdraws.

Two consequences are worth stating plainly. WhatsApp only allows free-form replies within 24 hours of a customer’s last message; outside that window an approved template is required, so a delayed reply may not be deliverable. Channel readiness and health checks can block delivery or disable an affected connection, depending on the channel ownership and failure type.

The service also depends on the providers listed on the sub-processor page, including an AI provider that generates answers. We choose these providers carefully and remain responsible to you for the service, but we do not control their availability.

7. What the AI assistant does and does not do

The assistant answers from material you supply. It is built to say it is unsure and hand off to a person rather than invent an answer, and several limits are enforced in code rather than merely requested of the model: it will not ask a customer for a card number, PIN, one-time code or similar credential; it will not report an action as completed unless the underlying step actually completed; and phrases you add to a “never say” list are checked before a reply is sent, with the conversation escalated to a person instead.

Those are real safeguards, and they are not a guarantee of correctness. Language models make mistakes, retrieval can surface the wrong passage, and your own documents may be out of date. You must:

  • review the knowledge you upload, and keep it current;
  • test your workspace before pointing customers at it, and monitor the conversations it handles;
  • not use the service to give medical, legal or financial advice that a qualified professional should give, to make decisions with legal or similarly significant effects about a person, or in any setting where a wrong answer risks physical harm.
Not an emergency service. The assistant must never be presented to customers as a route to emergency help. It replies only when the platform is running and a channel is working, and it is not monitored for emergencies.

8. Availability, maintenance and support

We aim to keep the service available and we monitor it, but we do not offer a service level agreement, an uptime percentage, or service credits. Anyone telling you otherwise is mistaken.

We may take the platform into maintenance mode for planned work, which shows a notice to signed-in users and can pause AI replies. We will give reasonable notice of planned maintenance where we can, and we may act without notice where there is a security or stability risk.

Support is provided by email at hello@tephlo.com during business hours in West Africa Time (WAT). Response targets, if any, are those in your order form; there are none by default.

9. Fees

Plans and prices are published on our pricing page and may be set out in an order form. Available billing behavior depends on the deployment:

  • Workspace plan payments. Where Paystack billing is enabled, the console can open a hosted checkout for a workspace plan. Payment details are entered on the provider’s page. The platform stores transaction records and, where supplied for renewal, a reusable authorization reference and limited payment-method display details; it does not receive full card numbers through that checkout flow. Payment and renewal terms remain those presented to you and agreed in your order form.
  • Usage and limits. The platform meters usage and can enforce plan allowances when the relevant platform and entitlement controls are enabled. Hard caps, grace units and any permitted overage depend on the active plan and configuration. A usage counter alone is not proof that a payment was taken.

Paying for your workspace plan is separate from a customer submitting a saved cart to your business. A potential-order request does not take payment for that cart or confirm an order.

Fees are exclusive of taxes, which you pay in addition where they apply. Late payment terms, currency and payment method are as stated in your order form; unless it says otherwise, all payments are due upfront in Nigerian Naira (NGN), by recurring debit-card authorization, bank transfer or an electronic payment gateway. We may change prices for a renewal term on 30 days’ notice.

10. Term, suspension and termination

The agreement runs from when you accept it until it is ended. Unless your order form says otherwise, either side may end it for convenience on 30 days’ written notice, and fees already paid for a period are not refunded for the unused part of it.

Either side may end the agreement immediately if the other:

  • materially breaches it and does not fix the breach within 30 days of being asked to; or
  • becomes insolvent or stops trading.

We may suspend a workspace immediately — including disabling its channels — where we reasonably believe it is being used in breach of the Acceptable Use Policy, is putting the platform or other customers at risk, is breaching a channel provider’s rules, or where a channel provider requires it. We will tell you why, and lift the suspension when the cause is resolved. Suspension is also a technical prerequisite for deleting a workspace, so that a deletion cannot race live traffic.

11. What happens to your data when the agreement ends

Before the end, you can export your data through the console and the API, including a full export of an individual customer’s conversations.

On termination we delete your workspace. That deletion is real and irreversible: it removes conversations and message history, escalations, captured tickets, knowledge sources and their indexed chunks, product catalogue, customer memory, channel configuration and encrypted credentials, staff accounts, usage records, uploaded media and their extracted text, and the queued work belonging to the workspace. Files in object storage are removed by a job that commits with the deletion, so a crash cannot leave them orphaned.

Two things deliberately survive, and you should know about both:

  • Platform audit records. A small number of audit tables record that an administrative action happened — a deletion, a channel credential change, a routing change — with who did it and why. They hold no message content, and two of them cannot be modified even by us, because the database itself refuses. They are the evidence that the platform was operated correctly.
  • Backups. Encrypted database backups are kept on a rolling schedule and are not individually edited. Deleted data disappears from backups as those backups age out and are pruned, not at the moment of deletion.

Unless you ask us to delete sooner, we will delete a terminated workspace within 30 days of the end of the agreement, so that a mistaken termination can be reversed.

12. Confidentiality

Each side may receive information from the other that is marked confidential or that a reasonable person would treat as confidential. Each will use it only to perform this agreement, protect it with at least reasonable care, and disclose it only to people who need it and are under similar obligations. This does not apply to information that is public through no fault of the receiver, was already known, is independently developed, or must be disclosed by law — in which case the receiver gives notice where it lawfully can.

13. Intellectual property

We own the platform, its software, and everything we supply with it. You get a non-exclusive, non-transferable right to use it during the term for your own business. You own your content, and you grant us the licence needed to host, process and display it in order to run the service for you.

You may not copy, reverse engineer, resell or offer the platform as your own service, or use it to build a competing product, unless a separate written agreement says you may. Feedback you give us can be used freely.

14. Warranties and disclaimers

Each side warrants that it has the authority to enter this agreement. We warrant that we will provide the service with reasonable skill and care.

Beyond that, and to the extent the law allows, the service is provided “as is”. We do not warrant that it will be uninterrupted or error-free, that AI-generated answers will be accurate or complete, or that it will meet any particular regulatory requirement that applies to your business. Nothing in this section limits rights that cannot be limited under the law of the Federal Republic of Nigeria.

You warrant that you have the right to upload the content you upload and to have the personal data in it processed as described in the DPA.

15. Liability

Neither side excludes liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot lawfully be excluded.

Subject to that, neither side is liable for loss of profit, revenue, goodwill, anticipated savings, or for indirect or consequential loss. Each side’s total liability arising out of this agreement is capped at the total amounts actually paid by you to us in the six (6) months immediately preceding the event giving rise to the liability.

Given what the service does, one allocation is stated explicitly: you are responsible for the content of your knowledge base and for reviewing what your workspace tells your customers, and we are not liable for the consequences of an answer that faithfully reflects inaccurate material you supplied.

16. Indemnity

You will defend and indemnify us against third-party claims arising from your use of the service in breach of this agreement or the Acceptable Use Policy, or from content you uploaded. We will defend and indemnify you against third-party claims that the platform itself infringes their intellectual property rights, provided you tell us promptly and let us run the defence.

17. Changes

We may change the service, and we may change these terms. For material changes to these terms we will give workspace administrators 30 days’ notice by email before they take effect; if you do not accept a material change, you may end the agreement before it applies. Changes required by law or to address a security risk may take effect immediately.

We may add, change or withdraw individual features. We will not remove a feature you rely on without notice unless a provider or a security issue forces it.

18. Governing law and disputes

This agreement is governed by the laws of the Federal Republic of Nigeria. Any dispute, controversy or claim arising out of or relating to it is referred to and finally resolved by binding private arbitration in Abuja, Federal Capital Territory, administered by a single arbitrator in accordance with the Arbitration and Mediation Act of Nigeria. The costs of the arbitration, including the arbitrator’s fees and the venue, are borne as the arbitrator determines or otherwise shared equally by the parties, and each side bears its own legal representation fees. Before starting arbitration, each side agrees to raise the issue in writing and to try in good faith to resolve it for 30 days.

19. General

  • Assignment. Neither side may assign this agreement without the other’s consent, except to a successor of its business.
  • Notices. Notices to you go to the email addresses of your workspace administrators; notices to us go to hello@tephlo.com and to the registered address above.
  • Force majeure. Neither side is liable for failure caused by events outside its reasonable control, including provider outages, network failures and government action.
  • Severability. If a provision is unenforceable, the rest continues in force.
  • No waiver. Not enforcing a right once does not waive it.
  • No partnership. Nothing here creates a partnership, agency or employment relationship.

Contact

General questions about this document go to hello@tephlo.com. Questions about personal data, including requests from individuals, should go to the data protection contact at hello@tephlo.com. A request about your own data — access, erasure, correction, objection or a complaint — can also be sent through the privacy request form, which puts it in front of the team as a tracked request rather than a message in a mailbox.

Postal address: TEPHLO AI VANGUARD SYSTEMS LTD, 9A Kenneth Lekara Luka Street, Lokogoma, FCT, Nigeria.