Privacy Policy
Last updated: 23 April 2026
- We process your customers' data as your processor, on your instructions — never for ourselves.
- We don't sell your data, and we don't use it to train AI models without explicit consent.
- Disconnect an integration and its tokens are revoked immediately; cancelled-account data is deleted within 30 days.
This summary is for convenience only — the full text below is what's binding.
This Policy explains how we collect, use, and protect your personal data when you use the Hamla platform (hamla.io) and our related services. We comply with the Republic of Rwanda Law N° 058/2021 on the Protection of Personal Data and Privacy, and we handle your data in line with internationally recognized privacy principles (including the EU GDPR where applicable).
1. Data Controller
The controller of your personal data is:
- ALIENZHOUSE LTD — a private limited company registered in Rwanda
- TIN: 155603688
- Address: Westerwelle Startup Haus, Gasabo, Kigali, Rwanda
- Data Protection Officer (DPO): Yassin Hussein Ahmed Abdalla — dpo@hamla.io
2. Who This Applies To
This Policy applies to: (a) Hamla account holders (Customers); (b) visitors to hamla.io; (c) individuals whose contact details our Customers process through our platform to send marketing (for this category we act as a processor on behalf of the Customer).
3. Data We Collect
3.1 Account Data
Name, email address, password (stored hashed), or third-party authentication identifiers (e.g. Google OAuth), and your business name and industry.
3.2 Integration Data
When you connect your account to a third-party service (e.g. Salla, Zid, TikTok, WhatsApp/Meta, Polar, etc.), we store the OAuth access tokens issued by that platform and read the data you have authorized us to access within each integration's scope (for example, activity records, item or product lists, account statistics, public content). The exact data depends on your business and the platform you connect.
3.3 Contact Data
When you import or sync your contacts from your systems, we store the information you provide: name, email address, phone number, behavioral identifiers (engagement history, cities, browsing events), and platform-specific identifiers. We process this data as a processor on your behalf.
3.4 Usage Data
Logs of your interaction with the dashboard, campaign performance (open rates, click rates, conversions), server logs (IP address, browser type, request timestamps), and technical performance signals that help us improve the Service.
3.5 AI Chat Data
Messages you send to the Hamla AI assistant are transmitted to our AI providers (Anthropic, OpenAI, Google) to generate a response. We store the conversation log in your account so you can refer back to it unless you delete it.
3.6 Payment Data
All payments are processed via Polar.sh. We do not store your credit card data. From Polar we only receive subscription identifiers, payment status, and invoice metadata.
4. Legal Basis for Processing
- Contract: to deliver the Service you subscribed to (running your account, executing campaigns, billing).
- Legitimate interests: to secure the platform, detect fraud, improve features, and run limited anonymized analytics.
- Consent: for our own marketing communications to you (e.g. the Hamla newsletter); you can withdraw consent at any time.
- Legal obligation: to keep financial and tax records as required by Rwandan law.
5. How We Use Data
- Operate your account and deliver platform features.
- Execute marketing campaigns on your behalf via the channels you choose.
- Generate AI-powered recommendations and analytics.
- Collect payments and manage your subscription.
- Respond to support requests.
- Secure the platform and prevent abuse.
We do not sell your personal data. We do not use Customer data to train our own AI models without explicit consent.
6. Who We Share Data With
We only share data with trusted service providers we rely on to operate Hamla, and only to the extent necessary:
- Infrastructure: Amazon Web Services (USA), Vercel (USA), Neon (USA), Upstash, Cloudflare R2.
- Message delivery: Resend (email), Twilio (SMS, WhatsApp), Meta WhatsApp Business API.
- Payment processor: Polar.sh.
- AI providers: Anthropic, OpenAI, Google (Gemini).
- Monitoring and logging: Sentry, Better Stack.
- Platforms you connect: Salla, Zid, TikTok, Meta/WhatsApp, Google, and any third party you authorize to connect with your account.
We may disclose your data if required by law (court order, criminal investigation, regulatory obligation). We will notify you where legally permissible.
7. International Data Transfers
Most of our infrastructure is located in the United States of America (AWS, Vercel, Neon). We have obtained authorization from Rwanda's National Cyber Security Authority (NCSA) to transfer personal data outside Rwanda for the operational purposes described in this Policy. We rely on contractual safeguards and the privacy policies of our service providers for these transfers.
8. Data Retention
- Active account data: for as long as you use the Service.
- Cancelled account data: deleted within 30 days of termination, except financial records which we retain for 5 years.
- Support tickets: 2 years from last ticket.
- Analytics data: up to 12 months in identifiable form.
- OAuth tokens: deleted immediately when you disconnect the integration.
9. Data Security
We apply commercially reasonable security controls including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, OAuth 2.1 authentication, continuous monitoring, and regular security audits. No system can be guaranteed 100% secure; in the event of a breach affecting your data, we commit to notifying you without undue delay (within 48 hours to NCSA and 72 hours with full report).
10. Your Rights
As a data subject, you have the following rights:
- Access: obtain a copy of the personal data we process about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of your data (subject to legal retention obligations).
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to certain processing based on our legitimate interests.
- Restriction: request temporary restriction of processing.
- Withdraw consent: withdraw any consent you previously granted, without affecting past processing.
To exercise any of these rights, contact dpo@hamla.io. We typically respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with Rwanda's National Cyber Security Authority (NCSA) at registration@dpo.gov.rw, or with the data protection authority in your jurisdiction.
11. Hamla's Role for Contact Data
When you use Hamla to send messages to your contacts, the Customer acts as the data controller and Hamla acts as the processor. You are responsible for obtaining recipient consent and for complying with privacy laws in their jurisdictions. We provide a Data Processing Addendum (DPA) on request to support your obligations.
12. Children
The Service is directed at adult business owners. We do not knowingly collect data from children under 16. If you become aware that a child has provided data, contact us and we will delete it promptly.
13. Cookies
We use strictly necessary cookies to operate the Service (session, authentication), and optional cookies for analytics and performance. You can manage cookie preferences from the dashboard or your browser. More detail is available in our Cookie Policy.
14. Policy Updates
We may update this Policy from time to time. We will notify you of material changes at least 30 days before they take effect, by email or in the dashboard. The latest version is always available at hamla.io/privacy.
15. WhatsApp & Meta Data Processing
When you connect your WhatsApp Business Account to Hamla via Meta's Embedded Signup, the following data handling applies:
Data we receive from Meta:
- WhatsApp Business Account (WABA) identifier.
- Phone number identifier for the number you connect.
- A scoped OAuth access token that lets Hamla call the WhatsApp Cloud API on your behalf.
- Business profile metadata (display name, verification status, quality rating).
Data we send through the WhatsApp Cloud API on your behalf:
- Marketing, transactional, and service messages you compose or schedule inside Hamla.
- Message template submissions for Meta approval.
Data we receive via Meta webhooks:
- Message delivery, read, and reply events.
- Template status changes.
- Account-level notifications Meta issues about your WABA.
What Hamla does NOT do:
- We do not read or store the content of incoming replies beyond what's necessary to deliver them to your inbox or trigger automations you configured.
- We do not share your WhatsApp data with any third party.
- We do not use your WhatsApp data to train machine-learning models.
- We do not sell your WhatsApp data.
Who else receives this data: Only Meta (WhatsApp LLC / WhatsApp Ireland Ltd) and our core infrastructure providers (listed in section 6 "Who We Share Data With"). Meta's handling is governed by their own terms at business.whatsapp.com/policy and facebook.com/privacy/policy.
Retention: We keep your WABA connection data and access tokens for as long as the connection is active. When you disconnect in the Hamla dashboard, we revoke the token, delete the connection record, and stop receiving webhook events within 24 hours.
Your control: You can disconnect WhatsApp from Hamla at any time via Settings → Integrations → WhatsApp. You can also revoke Hamla's access directly from Meta Business Suite → Settings → Apps. Disconnection is immediate and non-reversible for that connection (you can reconnect fresh later).
Pricing: Meta bills you directly for WhatsApp message costs — those charges go to the payment method on your WABA, not to Hamla.
16. Contact
For any question about privacy or your data: dpo@hamla.io. General support: support@hamla.io. Mail: ALIENZHOUSE LTD, Westerwelle Startup Haus, Gasabo, Kigali, Rwanda.