Legal
Privacy Policy
This policy explains what personal data Frontesk collects, why, who we share it with, how long we keep it, and the rights you have over it — whether you run a business on Frontesk or you are one of its customers talking to an AI employee.
Effective: 16 September 2026
Operated by Novascape Technologies Ltd
1. Who we are and what this policy covers
Frontesk is an AI employee platform operated by Novascape Technologies Ltd, a company incorporated in Kenya with its principal place of business in Nairobi (“Novascape Technologies Ltd”, “we”, “us”). Frontesk answers web chat, WhatsApp, Instagram, Messenger and phone calls on behalf of businesses, answers from the business’s own knowledge base, qualifies leads, books appointments, follows up and hands conversations to human teammates.
This Privacy Policy explains how we handle personal data when you:
- visit frontesk.com or join a waitlist (“Visitors”);
- create an account, run a workspace or are invited to one as a team member (“Customers” and their “Team Members”); or
- chat with, call or message a business that uses Frontesk(“End Users” — a business’s customers, patients, leads and callers).
We are registered with, and process personal data in accordance with, the Kenya Data Protection Act, 2019 and its regulations, under the supervision of the Office of the Data Protection Commissioner (ODPC). Where we serve Customers in the European Economic Area, the United Kingdom or other jurisdictions, we also apply the GDPR, the UK GDPR and comparable laws to the extent they apply.
2. Our role: controller or processor
For Customer and Team Member data (your account, billing, workspace settings, usage and support history) we are the data controller: we decide why and how it is processed.
For End User data (the contacts, conversation transcripts, call recordings, appointments, lead notes and files that flow through a Customer’s workspace) the Customer is the data controller and Novascape Technologies Ltd is a data processor. We process that data only on the Customer’s documented instructions, as configured in the product and described in our Terms of Service. If you are an End User and want to access, correct or delete data about you, please contact the business you communicated with; we will help them respond, and you may also contact us directly.
3. Personal data we collect
Data you give us
- Account data — name, email address, a salted password hash if you sign up with a password, profile image, time zone and locale, and whether you are the owner, admin or agent of a workspace. If you sign in with Google or Apple we receive the identifier, name, email and picture those providers share; we never see your password for those services.
- Business profile — business name, industry (“vertical”), website, opening hours, services, pricing, locations and the persona you configure for your AI employee.
- Knowledge base content — web pages you ask us to crawl, files you upload (PDF, DOCX, text, images, ZIP), Google Drive documents or Git repositories you connect. We split this content into chunks and generate vector embeddings so the AI can retrieve relevant answers.
- Media library — brochures, price lists, photos and voice notes you upload for the AI or your team to send to End Users.
- Integration credentials — WhatsApp, Meta, Twilio, Google Drive and other tokens, and any LLM API keys you bring (“BYO keys”). These are encrypted at rest with AES-256-GCM and never shown back in full.
- Billing data — subscription tier, billing cycle, invoices, add-ons and the PayPal vault reference for a saved payment method. We do not store card numbers; payment details are entered directly with PayPal.
- Support and marketing — messages you send to support@frontesk.com, waitlist entries (email, business name, industry) and referral codes.
Data about End Users (processed for Customers)
- Contact details — name, phone number (stored in international digits-only form), email, channel of origin and the lead stage a business assigns.
- Conversations — the full text of web chat, WhatsApp, Instagram and Messenger threads, attachments, tapped buttons, shared locations, delivery receipts and, for voice, the speech-to-text transcript of the call and any recording the Customer’s telephony provider makes.
- Qualification and booking data — answers to qualification questions, estimated value, appointment date/time, notes, follow-up schedules and escalation reasons.
- AI traces — for every AI reply we keep the reasoning trace: which tools were called, with what inputs and results, model used, tokens and latency. This lets the Customer audit what their AI employee did.
End User conversations may include sensitive or special-category data (for example a dental or medical concern described to a clinic). We do not use such data for any purpose other than providing the service to that Customer.
Data we collect automatically
- Usage and metering — conversations, WhatsApp messages, voice minutes, LLM tokens, knowledge retrievals and storage, recorded per workspace to enforce plan allowances.
- Product analytics — page views, feature usage and events captured through PostHog (see Cookies), associated with your user ID once you sign in.
- Technical logs — IP address, browser and device type, referring URL, timestamps and error reports, used for security and debugging. Webhooks from Meta, Twilio and PayPal are logged with their event identifiers to prevent duplicate processing.
4. How and why we use personal data
| Purpose | Legal basis (DPA 2019 / GDPR) |
|---|---|
| Creating and securing your account; authenticating you; running your workspaces. | Performance of a contract |
| Operating your AI employee: generating replies, retrieving knowledge, booking appointments, capturing leads, sending follow-ups, escalating to your team. | Performance of a contract; Customer’s instructions (as processor) |
| Billing, invoicing, metering usage, preventing fraud and collecting payment. | Performance of a contract; legal obligation; legitimate interests |
| Sending transactional email (verification, invites, receipts, reminders, incident notices). | Performance of a contract; legitimate interests |
| Product analytics, measuring feature adoption and improving reliability. | Legitimate interests; consent where required for cookies |
| Marketing our own services to Customers and waitlist subscribers. | Consent; legitimate interests (you can opt out at any time) |
| Security monitoring, abuse prevention, enforcing our Terms, defending legal claims. | Legitimate interests; legal obligation |
| Complying with law, regulators and lawful requests. | Legal obligation |
We do not sell personal data. We do not use Customer knowledge bases or End User conversations to train our own or any third party’s general-purpose AI models. Model providers we use are engaged under terms that prohibit training on API inputs.
5. How AI is involved
Frontesk generates replies with large language models (LLMs) from third-party providers. To produce a reply, the relevant conversation, the matching knowledge chunks, the business profile and the configured persona are sent to the model provider over an encrypted connection. Providers we may use include Anthropic, OpenAI and Groq for chat models, and OpenAI or Voyage AI for embeddings. The provider for each workspace is chosen by the Customer or by us as a default. When a Customer supplies their own API key, requests go to that provider under the Customer’s own agreement with them.
For voice, speech is transcribed and synthesised by Twilio (and optionally Deepgram and ElevenLabs). For scanned PDFs and images added to a knowledge base, text is extracted by Google Cloud Vision or a configured OCR service.
Automated decisions. The AI may qualify a lead, propose appointment slots or decide to escalate to a human. These are assistive actions configured by the Customer; they do not produce legal or similarly significant effects on End Users without human involvement, and a business can always take over a conversation. If you believe an AI response about you was inaccurate, contact the business or us and we will help correct the record.
7. International transfers
Novascape Technologies Ltd is based in Kenya. Our application and database are hosted in the European Union, and several sub-processors operate in the United States. Personal data therefore leaves Kenya, and may leave the EEA or UK, to be processed.
We transfer data outside Kenya only where permitted by section 48 of the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021 — relying on appropriate safeguards (binding contractual clauses with the recipient), a jurisdiction with adequate protection, or the data subject’s consent or the necessity of the transfer for a contract. For EEA/UK data we use the European Commission’s Standard Contractual Clauses and the UK Addendum, or the EU-US Data Privacy Framework where a recipient is certified. Copies of the relevant safeguards are available on request.
8. How long we keep data
- Account and workspace data — for the life of the account and 30 days after deletion, to allow recovery from accidental deletion.
- End User conversations, contacts, appointments and AI traces — for as long as the Customer keeps them. Customers can delete individual contacts, conversations and sources from the dashboard; deleting a workspace removes all of its data.
- Knowledge base chunks and embeddings — until the source is removed or re-indexed.
- Uploaded files and media — until deleted by the Customer; presigned download links expire within minutes.
- Billing records — 7 years, as required by Kenyan tax and companies law.
- Usage meters and webhook event logs — 24 months.
- Analytics events — up to 12 months, then aggregated or deleted.
- Encrypted database backups — taken nightly and rotated within 30 days; data deleted from the live system ages out of backups on that schedule.
When a subscription lapses we keep the workspace in a read-only state for 60 days and then delete it, unless you ask us to delete it sooner or a legal hold applies.
9. How we protect data
- All traffic is encrypted in transit with TLS 1.2 or higher.
- Integration tokens, API keys and channel secrets are encrypted at rest with AES-256-GCM under a key held separately from the database.
- Passwords are stored only as salted bcrypt hashes.
- Every workspace is isolated: each request re-checks that the signed-in user is a member of the workspace it is reading, and provider identifiers (for example a WhatsApp number) can belong to only one workspace.
- Inbound webhooks from Meta, Twilio and PayPal are verified by signature before they are processed.
- Role-based access (owner / admin / agent) limits what each Team Member can see and do.
- Nightly encrypted backups and a documented restore procedure.
No system is perfectly secure. If we discover a personal data breach that is likely to harm you, we will notify the ODPC within 72 hours and affected Customers without undue delay, as the Data Protection Act requires, and support Customers in notifying their End Users.
11. Your rights
Under the Data Protection Act, 2019 (and the GDPR/UK GDPR where applicable) you have the right to:
- be informed about how your data is used (this policy);
- access the personal data we hold about you and receive a copy;
- have inaccurate or incomplete data corrected;
- have your data deleted where there is no lawful reason to keep it;
- object to, or ask us to restrict, processing — including direct marketing at any time;
- receive your data in a portable, machine-readable format;
- withdraw consent where consent is the legal basis, without affecting prior processing;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you.
Customers can export and delete contacts, conversations and knowledge sources from the dashboard, and delete a workspace or account from Settings. End Users should first contact the business they interacted with, as that business controls the data; if you cannot reach them, email us at privacy@frontesk.com and we will forward your request and assist.
We respond to requests within 30 days and may ask you to verify your identity. There is no fee unless a request is manifestly unfounded or excessive. If you are not satisfied you may lodge a complaint with the Office of the Data Protection Commissioner (odpc.go.ke) or, in the EEA/UK, with your local supervisory authority.
12. Children
Frontesk is a business tool. You must be at least 16 years old to create an account, and we do not knowingly collect personal data from children under 18 as Customers. Businesses that use Frontesk to communicate with minors (for example a paediatric dental clinic) are responsible for obtaining parental or guardian consent as the Data Protection Act requires. If you believe a child has provided us data without consent, contact us and we will delete it.
13. Marketing communications
We may email Customers and waitlist subscribers about product updates, new industries and offers. Every marketing email includes an unsubscribe link, and you can also opt out by emailing us. Transactional messages (invites, receipts, security notices, appointment reminders sent on a Customer’s behalf) are not marketing and will continue while you use the service. We never send marketing to End Users on our own behalf.
14. Changes to this policy
We may update this policy as the product and the law change. We will post the revised version at this address with a new effective date and, for material changes, notify Customers by email or an in-app notice at least 14 days before they take effect. Continued use of Frontesk after that date means you accept the revised policy.
15. Contact us
Novascape Technologies Ltd
Nairobi, Kenya
Privacy enquiries: privacy@frontesk.com
General support: support@frontesk.com
Our Data Protection Officer can be reached at the privacy address above. Please include “Data request” in the subject line so we can route it quickly.