The data controller for account, billing and website data is M-Office Portal Limited, registered in the Federal Republic of Nigeria, with its registered office at 7A Olaniji Street, Oregun, Lagos State, Nigeria. For privacy questions or to exercise your rights, use our Contact page or email privacy@temira.net. Step-by-step deletion instructions are on our Data Deletion page. If we have appointed a representative or data-protection officer for a region, their contact details will be made available on request.
This policy covers personal data we handle as a controller. Where you use the Service to process your End Users' personal data inside your Workspace, you are the controller of that data and this policy does not govern your own privacy practices toward your End Users โ your privacy notice and the Terms/DPA do.
| Data | Our role | What it means |
|---|---|---|
| Your account, billing, support, website & app usage | Controller | We decide how and why it's processed, under this policy. |
| Workspace content, conversations, leads, tickets and other End-User personal data you put into the Service | Processor (service provider) | We process it only on your instructions to run the Service. You are the controller; our Terms and DPA govern. |
To provide, secure and operate the Service and your account; to process payments; to send service, security and transactional messages; to provide support and respond to enquiries; to detect, prevent and investigate fraud, abuse and security incidents; to analyse and improve the Service and develop new features (using aggregated or de-identified data where practicable); to comply with legal obligations; and to enforce our Terms and protect our rights. We do not sell personal data, and we do not use one Workspace's content to answer another business's assistant.
Where these laws apply, we rely on: performance of a contract (to provide the Service you signed up for); legitimate interests (to secure, improve and market the Service, and prevent abuse, balanced against your rights); consent (for optional cookies/marketing where required, which you can withdraw); and legal obligation (for tax, accounting and lawful requests). For Workspace/End-User data we process as processor, your instructions and your lawful basis apply.
To generate answers and assist your team, relevant excerpts of your content and the visitor's or customer's messages are sent to the AI provider configured for your Workspace to produce a reply and, for tickets, a short summary, tags, a draft reply and a suggested knowledge-base entry (AI-suggested knowledge-base answers are added only after a person in your Workspace approves them). If you bring your own key, your chosen provider processes that data under your agreement with them. AI features are assistive; see Section 16.
We share personal data only as needed to run the Service and as described here: with subprocessors that host or power the Service under contract; with payment processors to take payment; with messaging providers you connect, to deliver messages you send; with professional advisers; to comply with law or lawful requests, or to protect rights and safety; and in connection with a merger, acquisition or asset sale (with continued protection). Current categories of subprocessors:
| Category | Examples | Purpose |
|---|---|---|
| AI model providers | Anthropic, OpenAI, Google, and others you or we enable (or your own key) | Generate assistant answers & ticket assistance |
| Payment processing | Paystack, Stripe | Billing & receipts (they handle card data) |
| Messaging channels | Meta (WhatsApp, Instagram, Messenger), Telegram, email/SMS providers you connect | Deliver messages you choose to send |
| Push notifications | Google Firebase Cloud Messaging | Deliver mobile-app alerts |
| Infrastructure | Our hosting & delivery providers | Run, store and secure the Service |
A current subprocessor list is available on request via the Contact page.
We and our subprocessors may process personal data in countries other than yours, including outside your region. Where we transfer personal data across borders, we use appropriate safeguards recognised by applicable law โ such as the European Commission's Standard Contractual Clauses (and the UK Addendum), adequacy decisions where available, or your consent/necessity for the contract โ to protect it. You may request more information via the Contact page.
We keep personal data for as long as needed to provide the Service and your account, then for as long as necessary to meet legal, tax, accounting, dispute-resolution and security obligations, after which we delete or de-identify it. You control retention of Workspace conversations and tickets and can erase them at any time. Security logs are kept for a limited period for account protection and abuse-prevention. After account closure we delete or de-identify Customer Content within a reasonable period, except where retention is legally required.
We use administrative, technical and organisational measures to protect personal data, including encryption in transit, per-Workspace isolation, salted password hashing, optional two-factor authentication, role-limited operator access, audit logging, and rate limiting. See our Security statement. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Depending on your location, you may have rights to: access a copy of your personal data; correct or update it; delete it; restrict or object to processing; withdraw consent; data portability; and to not be subject to solely automated decisions with legal or similarly significant effects. To exercise these rights for data we control, use the Contact page or email privacy@temira.net; we will verify your request and respond within the time the law requires. For data we process on a business's behalf (End-User data in a Workspace), please contact that business (the controller); we will assist them as their processor. We will not discriminate against you for exercising your rights.
If you are a resident of California or another US state with a privacy law (for example the CCPA as amended by the CPRA, and comparable laws in Virginia, Colorado, Connecticut and elsewhere), you may have rights to know/access, delete, correct, and to opt out of the "sale" or "sharing" of personal information and of targeted advertising. We do not sell your personal information and do not share it for cross-context behavioural advertising. We do not knowingly process sensitive personal information for purposes requiring an opt-out. To exercise your rights, use the Contact page; you may use an authorised agent, and we will verify the request. We honour applicable opt-out preference signals where required.
We use strictly necessary cookies and local storage to sign you in, keep your session, and remember preferences (such as light/dark theme). We keep non-essential tracking to a minimum; where required by law we seek consent for any optional analytics or marketing cookies. You can control cookies through your browser settings; blocking essential cookies may break sign-in.
The Service is for business use and is not directed to children under 16 (or the age set by local law). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
The Service uses AI to draft answers, summaries, tags and suggestions. These are assistive tools for you and your team to review; they are not used by us to make decisions that produce legal or similarly significant effects about an individual without human involvement. You are responsible for how you use AI Output in your own decisions.
We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice. Your continued use after the effective date constitutes acceptance.
If you have a concern, please contact us first via the Contact page and we will try to resolve it. You also have the right to lodge a complaint with your local data-protection or privacy authority โ for example, in Nigeria the Nigeria Data Protection Commission (NDPC); in the EU/UK your national supervisory authority or the UK ICO; and comparable regulators elsewhere.