Frontesk

Product
Industries
Pricing
Sign inGet started

Legal

Privacy Policy

This policy explains what personal data Frontesk collects, why, who we share it with, how long we keep it, and the rights you have over it — whether you run a business on Frontesk or you are one of its customers talking to an AI employee.

Effective: 16 September 2026

Operated by Novascape Technologies Ltd

Contents

  1. Who we are and what this policy covers
  2. Our role: controller or processor
  3. Personal data we collect
  4. How and why we use personal data
  5. How AI is involved
  6. Who we share data with
  7. International transfers
  8. How long we keep data
  9. How we protect data
  10. Cookies and similar technologies
  11. Your rights
  12. Children
  13. Marketing communications
  14. Changes to this policy
  15. Contact us

1. Who we are and what this policy covers

Frontesk is an AI employee platform operated by Novascape Technologies Ltd, a company incorporated in Kenya with its principal place of business in Nairobi (“Novascape Technologies Ltd”, “we”, “us”). Frontesk answers web chat, WhatsApp, Instagram, Messenger and phone calls on behalf of businesses, answers from the business’s own knowledge base, qualifies leads, books appointments, follows up and hands conversations to human teammates.

This Privacy Policy explains how we handle personal data when you:

  • visit frontesk.com or join a waitlist (“Visitors”);
  • create an account, run a workspace or are invited to one as a team member (“Customers” and their “Team Members”); or
  • chat with, call or message a business that uses Frontesk(“End Users” — a business’s customers, patients, leads and callers).

We are registered with, and process personal data in accordance with, the Kenya Data Protection Act, 2019 and its regulations, under the supervision of the Office of the Data Protection Commissioner (ODPC). Where we serve Customers in the European Economic Area, the United Kingdom or other jurisdictions, we also apply the GDPR, the UK GDPR and comparable laws to the extent they apply.

2. Our role: controller or processor

For Customer and Team Member data (your account, billing, workspace settings, usage and support history) we are the data controller: we decide why and how it is processed.

For End User data (the contacts, conversation transcripts, call recordings, appointments, lead notes and files that flow through a Customer’s workspace) the Customer is the data controller and Novascape Technologies Ltd is a data processor. We process that data only on the Customer’s documented instructions, as configured in the product and described in our Terms of Service. If you are an End User and want to access, correct or delete data about you, please contact the business you communicated with; we will help them respond, and you may also contact us directly.

3. Personal data we collect

Data you give us

  • Account data — name, email address, a salted password hash if you sign up with a password, profile image, time zone and locale, and whether you are the owner, admin or agent of a workspace. If you sign in with Google or Apple we receive the identifier, name, email and picture those providers share; we never see your password for those services.
  • Business profile — business name, industry (“vertical”), website, opening hours, services, pricing, locations and the persona you configure for your AI employee.
  • Knowledge base content — web pages you ask us to crawl, files you upload (PDF, DOCX, text, images, ZIP), Google Drive documents or Git repositories you connect. We split this content into chunks and generate vector embeddings so the AI can retrieve relevant answers.
  • Media library — brochures, price lists, photos and voice notes you upload for the AI or your team to send to End Users.
  • Integration credentials — WhatsApp, Meta, Twilio, Google Drive and other tokens, and any LLM API keys you bring (“BYO keys”). These are encrypted at rest with AES-256-GCM and never shown back in full.
  • Billing data — subscription tier, billing cycle, invoices, add-ons and the PayPal vault reference for a saved payment method. We do not store card numbers; payment details are entered directly with PayPal.
  • Support and marketing — messages you send to support@frontesk.com, waitlist entries (email, business name, industry) and referral codes.

Data about End Users (processed for Customers)

  • Contact details — name, phone number (stored in international digits-only form), email, channel of origin and the lead stage a business assigns.
  • Conversations — the full text of web chat, WhatsApp, Instagram and Messenger threads, attachments, tapped buttons, shared locations, delivery receipts and, for voice, the speech-to-text transcript of the call and any recording the Customer’s telephony provider makes.
  • Qualification and booking data — answers to qualification questions, estimated value, appointment date/time, notes, follow-up schedules and escalation reasons.
  • AI traces — for every AI reply we keep the reasoning trace: which tools were called, with what inputs and results, model used, tokens and latency. This lets the Customer audit what their AI employee did.

End User conversations may include sensitive or special-category data (for example a dental or medical concern described to a clinic). We do not use such data for any purpose other than providing the service to that Customer.

Data we collect automatically

  • Usage and metering — conversations, WhatsApp messages, voice minutes, LLM tokens, knowledge retrievals and storage, recorded per workspace to enforce plan allowances.
  • Product analytics — page views, feature usage and events captured through PostHog (see Cookies), associated with your user ID once you sign in.
  • Technical logs — IP address, browser and device type, referring URL, timestamps and error reports, used for security and debugging. Webhooks from Meta, Twilio and PayPal are logged with their event identifiers to prevent duplicate processing.

4. How and why we use personal data

PurposeLegal basis (DPA 2019 / GDPR)
Creating and securing your account; authenticating you; running your workspaces.Performance of a contract
Operating your AI employee: generating replies, retrieving knowledge, booking appointments, capturing leads, sending follow-ups, escalating to your team.Performance of a contract; Customer’s instructions (as processor)
Billing, invoicing, metering usage, preventing fraud and collecting payment.Performance of a contract; legal obligation; legitimate interests
Sending transactional email (verification, invites, receipts, reminders, incident notices).Performance of a contract; legitimate interests
Product analytics, measuring feature adoption and improving reliability.Legitimate interests; consent where required for cookies
Marketing our own services to Customers and waitlist subscribers.Consent; legitimate interests (you can opt out at any time)
Security monitoring, abuse prevention, enforcing our Terms, defending legal claims.Legitimate interests; legal obligation
Complying with law, regulators and lawful requests.Legal obligation

We do not sell personal data. We do not use Customer knowledge bases or End User conversations to train our own or any third party’s general-purpose AI models. Model providers we use are engaged under terms that prohibit training on API inputs.

5. How AI is involved

Frontesk generates replies with large language models (LLMs) from third-party providers. To produce a reply, the relevant conversation, the matching knowledge chunks, the business profile and the configured persona are sent to the model provider over an encrypted connection. Providers we may use include Anthropic, OpenAI and Groq for chat models, and OpenAI or Voyage AI for embeddings. The provider for each workspace is chosen by the Customer or by us as a default. When a Customer supplies their own API key, requests go to that provider under the Customer’s own agreement with them.

For voice, speech is transcribed and synthesised by Twilio (and optionally Deepgram and ElevenLabs). For scanned PDFs and images added to a knowledge base, text is extracted by Google Cloud Vision or a configured OCR service.

Automated decisions. The AI may qualify a lead, propose appointment slots or decide to escalate to a human. These are assistive actions configured by the Customer; they do not produce legal or similarly significant effects on End Users without human involvement, and a business can always take over a conversation. If you believe an AI response about you was inaccurate, contact the business or us and we will help correct the record.

6. Who we share data with

We share personal data only with the categories of recipient below.

Sub-processors and service providers

ProviderPurposeLocation
Hetzner Online GmbHApplication hosting and primary databaseGermany / EU
Cloudflare, Inc. (R2)Object storage for uploaded files, media and attachmentsGlobal (EU-pinned where configured)
Anthropic, OpenAI, Groq, Voyage AILLM inference and embeddingsUnited States
Meta Platforms (WhatsApp, Instagram, Messenger)Message delivery on Meta channels; Embedded SignupUnited States / global
Twilio, Deepgram, ElevenLabsTelephony, speech-to-text and text-to-speechUnited States
PayPalSubscriptions, one-time payments, saved payment methods, refunds, payoutsUnited States / global
Google (Sign-in, Drive, Cloud Vision)OAuth login, Drive knowledge import, OCRUnited States / global
AppleSign in with Apple (where enabled)United States
ResendTransactional emailUnited States
PostHogProduct analyticsUnited States (or EU cloud where configured)

Each provider is bound by a written agreement that limits its use of the data to providing the service to us. We will update this list before adding a sub-processor that handles End User data, and Customers may object as described in the Terms.

Other recipients

  • The Customer you interact with. If you are an End User, everything you say to a business’s AI employee is visible to that business and its Team Members.
  • Team Members. Within a workspace, owners, admins and agents can see the workspace data their role permits.
  • Professional advisers, auditors and insurers under confidentiality obligations.
  • Regulators, courts and law enforcement where the law requires or permits, including the ODPC. We will notify the affected Customer unless legally prohibited.
  • A successor in a merger, acquisition or asset sale, subject to this policy.

7. International transfers

Novascape Technologies Ltd is based in Kenya. Our application and database are hosted in the European Union, and several sub-processors operate in the United States. Personal data therefore leaves Kenya, and may leave the EEA or UK, to be processed.

We transfer data outside Kenya only where permitted by section 48 of the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021 — relying on appropriate safeguards (binding contractual clauses with the recipient), a jurisdiction with adequate protection, or the data subject’s consent or the necessity of the transfer for a contract. For EEA/UK data we use the European Commission’s Standard Contractual Clauses and the UK Addendum, or the EU-US Data Privacy Framework where a recipient is certified. Copies of the relevant safeguards are available on request.

8. How long we keep data

  • Account and workspace data — for the life of the account and 30 days after deletion, to allow recovery from accidental deletion.
  • End User conversations, contacts, appointments and AI traces — for as long as the Customer keeps them. Customers can delete individual contacts, conversations and sources from the dashboard; deleting a workspace removes all of its data.
  • Knowledge base chunks and embeddings — until the source is removed or re-indexed.
  • Uploaded files and media — until deleted by the Customer; presigned download links expire within minutes.
  • Billing records — 7 years, as required by Kenyan tax and companies law.
  • Usage meters and webhook event logs — 24 months.
  • Analytics events — up to 12 months, then aggregated or deleted.
  • Encrypted database backups — taken nightly and rotated within 30 days; data deleted from the live system ages out of backups on that schedule.

When a subscription lapses we keep the workspace in a read-only state for 60 days and then delete it, unless you ask us to delete it sooner or a legal hold applies.

9. How we protect data

  • All traffic is encrypted in transit with TLS 1.2 or higher.
  • Integration tokens, API keys and channel secrets are encrypted at rest with AES-256-GCM under a key held separately from the database.
  • Passwords are stored only as salted bcrypt hashes.
  • Every workspace is isolated: each request re-checks that the signed-in user is a member of the workspace it is reading, and provider identifiers (for example a WhatsApp number) can belong to only one workspace.
  • Inbound webhooks from Meta, Twilio and PayPal are verified by signature before they are processed.
  • Role-based access (owner / admin / agent) limits what each Team Member can see and do.
  • Nightly encrypted backups and a documented restore procedure.

No system is perfectly secure. If we discover a personal data breach that is likely to harm you, we will notify the ODPC within 72 hours and affected Customers without undue delay, as the Data Protection Act requires, and support Customers in notifying their End Users.

10. Cookies and similar technologies

We use a small number of first-party cookies and local storage keys:

NamePurposeType / duration
next-auth.session-tokenKeeps you signed in (signed JWT)Strictly necessary · session, up to 30 days
next-auth.csrf-token, next-auth.callback-urlProtects sign-in forms from cross-site request forgeryStrictly necessary · session
fx_wsRemembers which of your workspaces is activeFunctional · 1 year
fx_railRemembers whether the sidebar is collapsedFunctional · 1 year
bm_refAttributes a sign-up to the referral link that brought you hereFunctional · 30 days
ph_* (PostHog)Product analytics — page views, feature events, session identifierAnalytics · up to 1 year

The embedded chat widget a business places on its own website stores a conversation identifier in the visitor’s browser so the thread continues across page loads. It sets no advertising cookies and does not track visitors across other sites.

You can block or delete cookies in your browser settings; strictly necessary cookies are required for the dashboard to work. We honour the Global Privacy Control signal for analytics where supported.

11. Your rights

Under the Data Protection Act, 2019 (and the GDPR/UK GDPR where applicable) you have the right to:

  • be informed about how your data is used (this policy);
  • access the personal data we hold about you and receive a copy;
  • have inaccurate or incomplete data corrected;
  • have your data deleted where there is no lawful reason to keep it;
  • object to, or ask us to restrict, processing — including direct marketing at any time;
  • receive your data in a portable, machine-readable format;
  • withdraw consent where consent is the legal basis, without affecting prior processing;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you.

Customers can export and delete contacts, conversations and knowledge sources from the dashboard, and delete a workspace or account from Settings. End Users should first contact the business they interacted with, as that business controls the data; if you cannot reach them, email us at privacy@frontesk.com and we will forward your request and assist.

We respond to requests within 30 days and may ask you to verify your identity. There is no fee unless a request is manifestly unfounded or excessive. If you are not satisfied you may lodge a complaint with the Office of the Data Protection Commissioner (odpc.go.ke) or, in the EEA/UK, with your local supervisory authority.

12. Children

Frontesk is a business tool. You must be at least 16 years old to create an account, and we do not knowingly collect personal data from children under 18 as Customers. Businesses that use Frontesk to communicate with minors (for example a paediatric dental clinic) are responsible for obtaining parental or guardian consent as the Data Protection Act requires. If you believe a child has provided us data without consent, contact us and we will delete it.

13. Marketing communications

We may email Customers and waitlist subscribers about product updates, new industries and offers. Every marketing email includes an unsubscribe link, and you can also opt out by emailing us. Transactional messages (invites, receipts, security notices, appointment reminders sent on a Customer’s behalf) are not marketing and will continue while you use the service. We never send marketing to End Users on our own behalf.

14. Changes to this policy

We may update this policy as the product and the law change. We will post the revised version at this address with a new effective date and, for material changes, notify Customers by email or an in-app notice at least 14 days before they take effect. Continued use of Frontesk after that date means you accept the revised policy.

15. Contact us

Novascape Technologies Ltd
Nairobi, Kenya
Privacy enquiries: privacy@frontesk.com
General support: support@frontesk.com

Our Data Protection Officer can be reached at the privacy address above. Please include “Data request” in the subject line so we can route it quickly.

See also: Terms of Service

Frontesk

Frontesk — AI employees that answer your website, WhatsApp and phone, qualify leads and book appointments 24/7.

Product

How it works

Pricing

Get started

Industries

Dental clinics

Med spas

All industries

Company

About

Contact

Legal

Terms

Privacy

© 2026 Frontesk. frontesk.com

Never miss a customer.