N Nsesa Contact us

Privacy Policy

Last updated 5 August 2026

Nsesa provides an AI knowledge base and meeting intelligence platform to organisations. This policy explains what personal data we handle, why, and what rights you have. It covers our website and the Nsesa application.

1. Who is responsible for your data

We act in two different roles, and which one applies changes who you should contact:

  • As a data controller — for visitors to our website and people who contact us about buying Nsesa. We decide how that data is used.
  • As a data processor — for everything inside a customer's workspace (documents, meetings, chats, user accounts). Your employer is the controller; we only process that data on their instructions under our agreement with them. If you are an employee of a Nsesa customer and want your data corrected or deleted, contact your own organisation's administrator first.

2. Data we collect

From website visitors

  • Enquiry details you submit through the “request a quote” or “request a meeting” form: your name, work email, company, optional phone number, and whatever you write in the message field.
  • Basic technical data needed to serve and protect the site, including your IP address, which we use for rate limiting to stop abuse.

The public website does not use advertising or analytics cookies, and we do not track you across other sites.

Inside a customer workspace

  • Account data: name, work email, role, department, seniority level, and authentication data (password hashes are held by our authentication provider; we never see your password). If you enable two-factor authentication, we store the authenticator secret needed to verify your codes.
  • Content your organisation uploads: documents, meeting recordings and transcripts, and anything personal contained within them.
  • Usage records: your chat conversations, the questions you search for, action items assigned to you, an audit log of administrative changes, and error reports used to keep the service working.

3. Why we use it, and our lawful basis

PurposeLawful basis
Responding to a sales enquiry you sent usSteps taken at your request before entering a contract
Providing the application to our customerPerformance of our contract with that customer
Security, rate limiting, fraud and abuse preventionOur legitimate interest in keeping the service safe
Meeting recording and transcriptionOur customer's chosen basis — they are responsible for informing participants and obtaining consent where the law requires it
Complying with legal obligationsLegal obligation

We do not sell personal data, and we do not use customer content to train AI models.

4. Who we share it with

We use a small number of service providers to run Nsesa. Each is bound by contract to protect the data and to process it only on our instructions. The current list, including what each one receives and where it is located, is published at our subprocessors page.

Customers who need data to remain in their own infrastructure can deploy Nsesa against a database they control, or fully on-premises with local AI models, in which case no document content reaches any third-party AI provider at all.

5. International transfers

Our managed cloud stores data in the regions offered by our hosting provider, which may be outside your country. Where personal data leaves its country of origin, we rely on the transfer mechanisms required by applicable law, including standard contractual clauses. Customers with strict data-residency requirements should ask us about a dedicated or on-premises deployment.

6. How long we keep it

  • Sales enquiries — kept while we are in contact with you and for a reasonable period afterwards, then deleted.
  • Workspace content — kept for as long as the customer's subscription is active. On termination it is deleted or returned as agreed with the customer.
  • Error logs — 90 days. Search and chat query logs — 180 days. Administrative audit log — 365 days. These are purged automatically.
  • When a member is offboarded — their account, sign-in access, private chat history and personal dashboard are deleted immediately; documents and meetings they contributed remain with the organisation, with their authorship reference cleared.

7. How we protect it

Each customer's data is isolated at the database level, enforced by the database itself rather than by application code alone. Connections are encrypted in transit, files are stored in private buckets, and third-party access credentials are encrypted at rest. Two-factor authentication is available to every member and can be made mandatory by an administrator. Details are on our security page.

8. Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to its processing, withdraw consent, receive it in a portable format, and lodge a complaint with your data protection authority. In Ghana, that is the Data Protection Commission; in the EU or UK, your national supervisory authority.

To exercise these rights over data held in a customer workspace, contact that organisation's administrator — we will assist them promptly. For data we hold as a controller, contact us directly.

9. Children

Nsesa is a workplace product and is not directed at children. We do not knowingly collect data from anyone under 18.

10. Changes

If we make a material change to this policy we will update the date at the top and notify customers through the application or by email.

11. Contact

Questions, requests, or complaints: privacy@nsesa.space. Security reports: security@nsesa.space.

Privacy Terms Subprocessors Security © 2026 Nsesa