← Back to Rasazu

Privacy Policy

Effective date: 21 August 2026  ·  Operated by Seer Group Inc.

This Privacy Policy explains how Seer Group Inc. ("we", "us", "our") collects, uses, and protects information when you use the Rasazu WhatsApp commerce platform at rasazu.com. Please read it carefully. By using Rasazu you agree to this policy.

01

Who We Are

Rasazu is a product of Seer Group Inc., a company that builds commerce and lead-generation technology for African businesses. In Nigeria, Rasazu is operated through Seer Group Inc.'s affiliate, Seer Global Solutions Limited.

For data-protection purposes, the data controller for merchant accounts is Seer Group Inc. The data controller for end-customer data processed through the WhatsApp Business API on a merchant's behalf is the merchant themselves; Rasazu acts as a data processor in that context.

Contact: privacy@rasazu.com

02

Data We Collect

Merchant account data

  • Business name, email address, phone number, and password (bcrypt-hashed — we never store your plain password)
  • Business category, description, support contact, and profile image
  • WhatsApp Business Account (WABA) credentials and phone number ID (stored encrypted at rest)
  • Bank account details for payouts (stored with field-level AES-128 encryption)
  • KYC documents — business registration certificate, director ID, proof of address (stored securely, accessible only to authorised Seer Group Inc. staff)
  • Subscription plan, billing history, and payment references

Customer data (collected on merchants' behalf)

  • WhatsApp phone number or Business-Scoped User ID (BSUID) of customers who message a merchant's bot
  • Message content — text, images, voice notes, documents, and location messages sent by customers
  • Cart contents, order details, and delivery addresses entered during checkout
  • Post-order feedback submitted through WhatsApp Flow forms

Platform usage data

  • IP addresses, browser type, and session logs for security and debugging
  • AI token usage per merchant for billing and quota management
  • Webhook events from Meta (WhatsApp) and Paystack
03

How We Use Your Data

  • Service delivery — running the AI shopping assistant, processing orders, syncing product catalogs to WhatsApp Shop, and managing delivery zones
  • Payments and payouts — verifying payments via Paystack, managing subscription billing, and processing merchant withdrawal requests
  • Account management — authentication, password reset, email verification, and team role management
  • Notifications — transactional alerts via email, SMS (Termii), and WhatsApp for orders, billing events, and inventory warnings
  • KYC review — verifying merchant identity and business registration to comply with Nigerian financial regulations
  • Platform improvement — aggregate, anonymised usage metrics to improve the AI model and product features
  • Security — fraud detection, rate limiting, and audit logging of all platform-admin actions
  • Legal compliance — retaining records as required by Nigerian tax, financial, and data protection regulations

We do not sell your data to third parties. We do not use your customers' message content for advertising.

04

Data Sharing

We share data only with the following categories of recipients and only to the extent necessary:

  • Meta Platforms, Inc. — messages are transmitted via the WhatsApp Business API. Meta acts as a data processor for message transmission. See Meta's WhatsApp Privacy Policy.
  • Anthropic, Inc. — message content is sent to Claude (Anthropic's AI) to generate shopping assistant responses. Anthropic does not use this data to train its models under our enterprise agreement. See Anthropic's Privacy Policy.
  • Paystack Payments Limited — payment card and bank account information is processed by Paystack. We do not store full card numbers. See Paystack's Privacy Policy.
  • Termii Inc. — transactional SMS and WhatsApp notification messages are delivered via Termii. Termii receives merchant phone numbers for delivery purposes only.
  • 360dialog GmbH — some merchants are onboarded through 360dialog's WhatsApp partner infrastructure. 360dialog receives WABA credentials for those merchants.
  • Legal authorities — we may disclose information if required by law, court order, or regulation in Nigeria or any jurisdiction where Seer Group Inc. operates.
05

Data Retention

  • WhatsApp messages — retained for 12 months from receipt, then permanently deleted
  • Order records — retained for 7 years to comply with Nigerian tax and financial record-keeping requirements
  • KYC documents — retained for the duration of the merchant account and for 5 years after account closure, as required by Nigerian AML regulations
  • AI token usage logs — retained for 24 months for billing audit purposes
  • Merchant account data — retained for the lifetime of the account and deleted within 30 days of verified account closure request
  • Security and audit logs — retained for 12 months
06

Security

We implement technical and organisational measures to protect your data:

  • All data in transit is encrypted via TLS 1.2 or TLS 1.3
  • Sensitive database fields (WhatsApp credentials, bank details, payment codes) are encrypted at rest using AES-128-CBC with HMAC-SHA256 integrity (Fernet)
  • Passwords are stored as bcrypt hashes — never in recoverable form
  • PostgreSQL Row-Level Security (RLS) enforced at the database engine level prevents any merchant accessing another merchant's data
  • KYC documents are served only through an authenticated, tenant-scoped proxy — they are never exposed on a public URL
  • All admin actions are recorded in an immutable audit log
  • Rate limiting and multi-layer authentication protect all account endpoints

Despite these measures, no system is entirely risk-free. Please notify us immediately at privacy@rasazu.com if you suspect a security issue.

07

WhatsApp & Meta

Rasazu operates as a WhatsApp Business API Tech Provider. When merchants connect their WhatsApp Business Account to Rasazu via our Embedded Signup flow:

  • The merchant grants Rasazu access to their WABA to send and receive messages on their behalf
  • Messages are processed through Meta's Cloud API. Meta's infrastructure handles transmission; Rasazu handles the AI response generation and order logic
  • Customers who message a Rasazu-powered WhatsApp number can opt out at any time by replying STOP. Opt-outs are honoured immediately and automatically
  • Customers who have opted out can re-subscribe at any time by replying START
  • Rasazu complies with Meta's WhatsApp Business Policy, including the prohibition on unsolicited bulk messaging
08

AI Processing

Rasazu uses Claude, developed by Anthropic, Inc., to power its AI shopping assistant. When a customer sends a message to a merchant's WhatsApp bot:

  • The message content, relevant conversation history, and the merchant's product catalog are sent to Anthropic's API to generate a response
  • Voice notes are transcribed locally using an open-source Whisper model before being sent to the AI. Audio files are not stored after transcription
  • Images and documents sent by customers are processed for content understanding and are not stored beyond the standard message retention period
  • Anthropic does not use your data to train its models under our commercial agreement
  • Merchant-supplied AI instructions (custom tone, FAQs, policies) are injected into the AI context. We sanitise this input to prevent prompt injection attacks
  • Bank account numbers and payment details are never sent to the AI — they are delivered directly to customers as a separate, non-AI message
09

Payments

All payment processing is handled by Paystack Payments Limited, a PCI-DSS compliant payment gateway licensed by the Central Bank of Nigeria. Rasazu does not store full card numbers. We store only:

  • Paystack customer codes (a reference, not payment credentials)
  • Paystack sub-account codes and transfer recipient codes (stored encrypted) for merchant payouts
  • Payment reference numbers and status for order and subscription verification

Merchant payouts are processed via Paystack's transfer API directly to the merchant's registered Nigerian bank account. Withdrawal requests are logged with a full audit trail.

10

KYC & Identity Verification

To comply with Nigerian financial regulations and Meta's WhatsApp Business verification requirements, Rasazu collects Know Your Customer (KYC) information from merchants:

  • Business registration number, registration type (CAC, sole proprietorship, LLC, etc.), and business address
  • Director or business owner name and National ID / Passport / Driver's Licence number
  • Scanned copies of the CAC certificate, government-issued ID, and proof of address

KYC documents are reviewed by authorised Seer Group Inc. staff only. They are stored with access controls and served exclusively through an authenticated, encrypted proxy — they cannot be accessed without a valid merchant or admin session.

KYC status (Unverified / Pending / Verified / Rejected) affects platform access. Merchants with Rejected KYC may appeal by contacting support@rasazu.com.

11

Your Rights (NDPR / GDPR)

Under the Nigeria Data Protection Regulation (NDPR) 2019 and, where applicable, the EU General Data Protection Regulation (GDPR), you have the following rights:

  • Right of access — request a copy of all personal data we hold about you
  • Right to rectification — request correction of inaccurate data
  • Right to erasure — request deletion of your personal data, subject to legal retention obligations
  • Right to restrict processing — request that we limit how we process your data in certain circumstances
  • Right to data portability — request your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests

For merchants: submit requests via the dashboard (Settings → Account) or email privacy@rasazu.com.

For end customers (individuals who messaged a merchant's WhatsApp bot): contact the merchant directly or email us and we will coordinate with the merchant. Customers can also exercise their right to erasure by sending their WhatsApp number to privacy@rasazu.com — we will anonymise all stored records within 30 days.

We will respond to all rights requests within 30 days.

12

Cookies

The Rasazu merchant dashboard uses the following cookies:

  • auth_session (HttpOnly, Secure) — your authentication token. Required for the dashboard to function. Expires in 15 minutes and is automatically refreshed
  • refresh_session (HttpOnly, Secure, path-scoped) — used to obtain a new auth token. Expires in 7 days

We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies. The public marketing site (rasazu.com) may use essential session cookies only.

13

Children

Rasazu is a business platform and is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact privacy@rasazu.com and we will delete it promptly.

14

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page and, for material changes, notify registered merchants by email at least 14 days before the change takes effect. Continued use of the platform after the effective date constitutes acceptance of the revised policy.

15

Contact Us

For all privacy-related enquiries:

Seer Group Inc.

Operating entity for the Rasazu platform

Privacy: privacy@rasazu.com

Support: support@rasazu.com

Lagos, Nigeria

You also have the right to lodge a complaint with the National Information Technology Development Agency (NITDA), which oversees NDPR compliance in Nigeria.

Terms of Service·Back to Rasazu·© 2026 Seer Group Inc.