1. Introduction
Kongko Inspira Ltd ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our WhatsApp AI assistant service ("Service") and website qenn.ai.
This policy complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
2. Data Controller
Kongko Inspira Ltd is the data controller for the personal data we collect.
- Address: 5 South Charlotte Street, Edinburgh, Scotland, EH2 4AN.
- Company Number: SC823803.
3. Data We Collect
3.1 Information You Provide
- Account Data: Name, email address, WhatsApp phone number, business name, and trade.
- Payment Data: Billing address and transaction records (processed by Stripe; we do not store card details).
- Communications: Messages you send to our support channels.
3.2 Content and Usage Data
- Messages: Text, images, and documents sent via WhatsApp to Qenn for processing.
- Voice Data: Audio recordings and transcripts of calls handled by our AI Receptionist feature.
- Generated Documents: Quotes, invoices, and schedules created by Qenn on your behalf.
- Integration Data: When you connect third-party services (e.g., Google Calendar, QuickBooks), we access and process data necessary to provide the Service (contacts, events, invoices) strictly per your authorization.
3.3 Automatically Collected Data
- Usage Data: Timestamps, interaction logs, error reports, and feature usage statistics.
- Device Data: IP address, browser type, and device information for security and analytics.
4. How We Use Your Data
- Service Provision: To process your messages, generate quotes/invoices, and manage your CRM.
- AI Processing: To analyze your requests using Large Language Models (LLMs).
- Billing: To manage subscriptions and process payments.
- Support: To provide customer support and troubleshooting.
- Security: To detect fraud, abuse, and security incidents.
- Legal Compliance: To meet tax, regulatory, and legal obligations (e.g., HMRC record keeping).
5. Legal Basis for Processing
- Contractual Necessity: Processing required to fulfill your subscription contract and provide the Service.
- Legitimate Interest: Service improvement, security, fraud prevention, and analytics.
- Consent: For marketing communications and non-essential cookies (where applicable).
- Legal Obligation: Compliance with tax and regulatory laws.
6. Data Sharing and Sub-processors
We do not sell your personal data. We share data only with trusted sub-processors who assist us in operating the Service:
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Meta Platforms (WhatsApp Cloud API) | WhatsApp message content & metadata (messaging transport) | Global (incl. US) | Meta Cloud API Data Processing Terms; UK IDTA / SCCs |
| OpenAI | AI processing (chat: understanding your messages and drafting replies; and transcribing voice notes) | United States | OpenAI DPA (executed 27 August 2026); EU Standard Contractual Clauses as amended by the UK Addendum; API data is not used to train their models |
| Mistral AI (La Plateforme) | AI processing (photo analysis; searching your past conversations so Qenn can find what was said before; and chat if OpenAI is unavailable) | France (EU) | GDPR DPA |
| Twilio / Vapi | Voice routing & voice AI (telephony only) | US | UK IDTA / SCCs |
| Resend | Transactional email: quote/invoice delivery when no Gmail/Outlook is connected, and beta signup confirmations | EU (eu-west-1) | GDPR DPA |
| Stripe | Payment processing | US / EU | UK IDTA / SCCs |
| Sentry | Error monitoring & diagnostics | US | UK IDTA / SCCs |
| Supabase / Railway | Database & hosting | UK / EU | Standard Contractual Clauses |
| Google / Microsoft / Xero / Intuit | Integrations (OAuth) | Global | User authorisation & SCCs |
7. Google API Services & Limited Use
When you connect a Google account (e.g., Google Calendar), Qenn requests access only to the data needed to provide the features you enable. Qenn's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained from Google Workspace APIs:
- Is used only to provide or improve user-facing features that are prominent in Qenn's requesting interface;
- Is not transferred to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior user consent;
- Is not used or transferred for serving advertisements, including retargeting, personalised, or interest-based advertising;
- Is not read by humans unless we first obtain your affirmative agreement, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or for internal operations where the data has been aggregated and anonymised.
Qenn does not use Google Workspace API data to develop, improve, or train generalised or non-personalised artificial intelligence or machine learning models.
8. International Transfers
Your account details, your message history and our backups are stored in the United Kingdom and the European Union.
Some of the services we depend on process data in the United States, and the largest of them is the AI processing at the centre of the Service. Understanding your messages, drafting replies and transcribing your voice notes are all carried out by OpenAI in the United States. This happens every time you use Qenn, so we set it out here as well as in the table in section 6. Photo analysis is carried out by Mistral AI in France.
Data also leaves the UK and EU for WhatsApp messaging through Meta, voice telephony through Twilio and Vapi, payment processing through Stripe, and error monitoring through Sentry.
Every transfer outside the UK and EU is covered by a contract that gives your data the protection UK law requires. For OpenAI we rely on EU Standard Contractual Clauses as amended by the UK Addendum, under a data processing agreement signed on 27 August 2026. For the other providers we rely on the UK International Data Transfer Agreement (IDTA) or on Standard Contractual Clauses with the UK Addendum. The table in section 6 shows which safeguard applies to each provider.
9. Data Retention
- Active Accounts: Data is retained for the duration of your subscription.
- Account Deletion: Personal data is deleted or anonymized within 30 days of account closure, subject to legal retention requirements.
- Financial Records: Invoices and transaction data are retained for 6 years to comply with HMRC regulations.
- Conversation Search Index: The search index of a message (a list of numbers, not its text) is kept only as long as the message itself and is deleted with it.
10. Your Rights
Under the UK GDPR, you have the following rights:
- Right to Access: Request a copy of your personal data.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data ("Right to be Forgotten").
- Right to Restrict Processing: Limit how we use your data in certain circumstances.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interest.
- Right to Withdraw Consent: Withdraw consent at any time (where processing is consent-based).
- Right to Complain to Us: Make a complaint directly to us if you think we have handled your personal data in breach of data protection law. This is separate from your right to complain to the Information Commissioner, and both are set out in section 14.
To exercise your rights, contact us at [email protected]. We will respond within 30 days. If we tell you we are not going to act on your request, we will explain why, and we will tell you that you can complain to us, complain to the Information Commissioner, and seek a remedy through the courts.
11. Security
We implement industry-standard security measures to protect your data:
- Encryption: Data encrypted at rest (AES-128) and in transit (HTTPS/TLS 1.3).
- Access Control: Strict role-based access controls and authentication.
- Monitoring: Regular security audits and vulnerability assessments.
12. Children's Privacy
Our Service is intended for business use by individuals aged 18 and over. We do not knowingly collect data from children. If we become aware that we have collected data from a child, we will delete it immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. Your continued use of the Service constitutes acceptance of the updated policy.
14. Contact Us
If you have questions or complaints about this Privacy Policy or our data practices, please contact:
- Email: [email protected]
- Post: Data Protection Officer, Kongko Inspira Ltd, 5 South Charlotte Street, Edinburgh, EH2 4AN, Scotland.
If you think we have handled your personal data in breach of data protection law, you have two separate rights of complaint.
- Complain to us. You can complain directly to Kongko Inspira Ltd by emailing [email protected] with the word "complaint" in the subject line, or by writing to us at the address above. We will acknowledge your complaint within 30 days of receiving it, look into it, keep you posted on progress, and tell you the outcome.
- Complain to the Information Commissioner. You can make a complaint to the Information Commissioner, the UK's data protection regulator, at https://ico.org.uk/make-a-complaint/.