1. Who we are
SIONA TECHNOLOGIES LIMITED ("Siona", "we", "us" or "our") is a Kenyan technology and intelligence company. Company No. PVT-YQ19MQ32. Our registered office is at Baraka, Building 5, Nanyuki, Laikipia County, Kenya.
This Privacy Notice explains how we handle personal data when you visit our corporate website, contact us, submit a project enquiry, interact with website security/verification functions, subscribe to communications where offered, or otherwise engage with a Siona-controlled public web property that links to this Notice.
This Privacy Notice also applies to Weza AI where Weza links to or relies on this Notice, including interactions through the WhatsApp Business Platform. Other Siona products, applications, marketplaces, AI services, SaaS platforms, client portals and sector-specific systems may provide additional or separate privacy notices. This Notice does not automatically govern every future Siona product or client system unless that product links to or expressly relies on this Notice.
2. Personal data we may collect through the website
- Project/contact enquiries: name, organisation, email, phone/WhatsApp number, website, solution required, budget range, expected timeline, project description and other information you choose to provide.
- Direct communications: email correspondence, WhatsApp/contact history, support/security reports and attachments you voluntarily send.
- Technical/security data: IP address, device/browser information, timestamps, request metadata, security/anti-abuse signals (including Cloudflare Turnstile verification), error logs and similar information used to operate and protect the website.
- Usage/analytics: pages viewed, referral source and approximate interaction information where an approved analytics tool is deployed. Siona currently operates an essential-first model and does not load non-essential marketing or advertising trackers by default.
- Preferences/consent: cookie choices, marketing preferences, consent/withdrawal records and suppression data where applicable.
Do not overshare. For an initial website enquiry, please do not send passwords, private keys, banking credentials, full identity documents, special-category data, confidential third-party datasets or production customer data unless Siona has specifically requested them through an approved secure channel.
3. Why we process website data
- Respond to enquiries and take steps toward a project or commercial relationship.
- Operate, secure and troubleshoot the website.
- Prevent spam, abuse, fraud and cyber threats.
- Maintain business records and defend legal claims.
- Website measurement and improvement, where approved tools are used.
- Direct marketing only with appropriate consent/opt-out; a project enquiry is not blanket marketing consent.
We do not treat submission of a website form as permission to use the information for any unrelated purpose. Website enquiry data is not automatically authorised for training a general/shared Siona AI model.
4. Legal bases
Depending on the activity and applicable law, Siona may process personal data on one or more of the following bases: performance of a contract or steps you request before entering a contract; legitimate interests that are not overridden by your interests or fundamental rights (for example, operating and securing our services, preventing abuse, and maintaining business records); compliance with legal obligations; and consent where consent is specifically required. This description is informational and does not constitute jurisdiction-specific legal advice beyond applicable law.
5. Weza AI and WhatsApp Business Services
Weza AI is operated by SIONA TECHNOLOGIES LIMITED. Weza is a WhatsApp-based AI/business assistant that may help users with business records, receipts, expenses, sales, summaries, categorisation, accounting-related workflows and related business interactions through messaging.
Weza may process both personal data and business/transaction information. Business records can still contain personal data depending on context (for example, names, phone numbers or identifiers appearing in messages, receipts or contact details).
5.1 Data Weza may process
Depending on how you interact with Weza, Siona may process some or all of the following categories of data:
- WhatsApp account and messaging identifiers: WhatsApp phone number; WhatsApp profile or display information; WhatsApp/Meta identifiers needed to route and respond to messages.
- Message content and metadata: incoming and outgoing message content; message timestamps; delivery/status metadata; commands and corrections you send.
- Business and accounting content you submit: business or account information; receipt images; invoice or document images; attachments; sales and expense records; transaction categories; merchant or supplier names; dates; amounts; currency; tax/VAT-related information where applicable; weekly or monthly summary data; and user corrections such as fix/review actions.
- Audio where used: voice notes or other audio you submit, and transcriptions generated to provide the requested functionality.
- Extracted structured fields: fields derived from receipts, invoices or messages (for example merchant/supplier, date, amount, currency, tax-related values and categories) to create or update business transaction records.
- Service integrity and security: usage and security metadata; technical logs; anti-abuse information; and related operational signals used to keep the service reliable and protected.
Siona processes the categories above only as needed for the Weza features you use. Weza does not intentionally collect data categories that are not used to provide, secure or support the service.
5.2 Purposes of Weza processing
Weza processing is directed at providing the requested WhatsApp assistant service, including to:
- receive and respond to user messages;
- extract information from receipts and documents;
- transcribe submitted voice notes where that feature is used;
- create and maintain business transaction records;
- categorise expenses and sales;
- calculate or assist with summaries and accounting-related workflows;
- apply user corrections;
- generate requested summaries;
- maintain message and transaction integrity and help prevent duplicate processing;
- support security, fraud prevention and abuse detection;
- provide support, troubleshooting and service reliability;
- retain records where required for legal or compliance purposes.
Data submitted to Weza is not automatically used for unrelated marketing. A Weza interaction is not treated as blanket consent for marketing communications.
5.3 AI processing
Weza may use third-party AI service providers—including OpenAI where applicable—to process user-submitted text, images, structured data and audio where required to provide the service (for example extraction, categorisation, summarisation, response generation or transcription).
Data may be transmitted to approved AI service providers for inference or transcription solely as necessary to provide the requested functionality, subject to Siona's vendor controls and applicable contractual/privacy safeguards. This Notice does not claim that such providers store or train on Weza customer data beyond what is verified under those vendor arrangements.
Weza customer data is not used to train a shared/general Siona AI model unless a separate lawful basis and explicit arrangement applies.
5.4 WhatsApp / Meta processing
Weza operates through the WhatsApp Business Platform provided by Meta Platforms. WhatsApp/Meta may process messages, identifiers, delivery/status metadata and related communication information under Meta's own terms and privacy policies. Siona receives WhatsApp webhook and message data necessary to provide Weza. Siona does not control Meta's independent processing of WhatsApp communications.
5.5 Infrastructure and service providers for Weza
To operate Weza, Siona uses vetted processors and service providers. At a high level these may include:
- Meta / WhatsApp Business Platform — messaging delivery and related communication services.
- Cloudflare — hosting/runtime, security, queues, private object/media storage and network protection for Weza infrastructure.
- OpenAI — AI inference and related processing where used to provide Weza features.
- Neon / PostgreSQL infrastructure — application and database storage for Weza operational and business records.
- Email/communications providers — where used for support, notices or related communications.
Providers receive only the access reasonably necessary for their approved role. This Notice does not disclose credentials, private infrastructure endpoints, internal system identifiers or other sensitive operational details.
5.6 Media, receipts and document storage
User-submitted receipts, documents and other media may be stored privately to deliver the service, maintain accounting history, support correction/review workflows, provide support, meet audit needs or satisfy retention requirements. Siona uses access controls and private storage rather than intentionally publishing customer receipts publicly. No internet-connected system can be guaranteed absolutely secure.
5.7 Automated processing
Weza may use automated processing and AI to extract receipt fields, categorise transactions, interpret commands, generate summaries, transcribe audio and provide suggested classifications or responses. Where the product supports correction or review functionality, users can correct outputs. Weza is designed to assist business recordkeeping; it does not claim to make fully autonomous, legally binding decisions about individuals without appropriate human involvement where required by law.
5.8 Data minimisation for Weza
Please limit submissions to what is needed for the intended Weza function. Do not submit passwords, private keys, full payment card details, bank login credentials, government IDs, special-category data or confidential third-party information unless specifically requested through a secure approved workflow.
6. Sharing and service providers
We may disclose personal data to authorised Siona personnel and vetted service providers that support hosting, security, email, communications, analytics, CRM, messaging, AI inference, databases, object storage or similar functions, only where access is necessary for an approved purpose. Current website operations commonly involve Cloudflare (hosting, CDN, security and Turnstile verification) and email/communications providers used to receive and respond to enquiries. Weza-related providers are described in section 5.5.
Siona does not sell website visitors' or Weza users' personal data as a data-brokerage business.
7. International processing
Some hosting, security, communications, AI, database or other service providers—including providers used for Weza—may process data outside Kenya. Siona assesses relevant processing locations and applies transfer safeguards required by applicable law.
8. Retention
We keep personal data only as long as reasonably necessary for the purpose, contractual/legal obligations, security, dispute prevention and documented retention requirements.
Website enquiries that do not lead to an ongoing commercial relationship should ordinarily be reviewed for deletion or minimisation within twenty-four (24) months after the last substantive interaction, unless a longer period is justified.
Weza operational and business records may be retained for different periods depending on the active customer relationship, business/accounting record requirements, contractual obligations, legal or tax obligations, dispute resolution, security/audit requirements and customer deletion requests. Website enquiry data and Weza business/accounting records may therefore have different retention schedules. Siona does not publish a single universal retention period for all accounting records in this Notice.
9. Security
Siona uses risk-based technical and organisational measures intended to protect personal data. For Weza, these measures may include access controls, encrypted transport, private object storage, database access controls, webhook verification, anti-abuse protections and least-privilege service access, as appropriate to the system. No internet transmission or online service can be guaranteed absolutely secure. Security vulnerabilities should be reported through our published security channel.
10. Your rights
Subject to applicable law, you may have rights to be informed, access your personal data, object to processing, request correction, request deletion or restriction, obtain portability where applicable, withdraw consent, object to direct marketing, and seek human review in relevant automated-decision contexts.
For Weza, users and business customers may—subject to applicable law—request access, correction, deletion, restriction, objection, export/portability where applicable, and withdrawal of consent where consent is the basis for processing.
Users and business customers may request deletion of personal data associated with their Weza account or WhatsApp interactions. Where deletion is legally and technically permitted, Siona will delete or anonymise relevant data from active systems and allow backup copies to expire according to applicable retention schedules. Immediate deletion cannot be promised where legal, tax, accounting or dispute-related retention obligations apply.
Privacy requests: office@sionaglobal.com. For step-by-step deletion instructions, including Weza AI, see Data Deletion & Privacy Requests. You may also lodge a complaint with the Office of the Data Protection Commissioner in Kenya where applicable.
11. Cookies and similar technologies
Our website may use cookies, local storage, security tokens or similar technologies. Categories and controls are explained in our Cookie & Tracking Notice.
12. Changes and contact
We may update this Notice as our website, services (including Weza), vendors, law or data practices change. The published version shows its effective date and version.
Privacy/legal: office@sionaglobal.com
SIONA TECHNOLOGIES LIMITED, Company No. PVT-YQ19MQ32, Baraka, Building 5, Nanyuki, Laikipia County, Kenya.
