Legal
Privacy policy
Afiaz is a growth and customer lifecycle platform. This policy explains what we collect, why we collect it, who we share it with, and how you stay in control of it.
- Last updated
- 22 July 2026
- Operated by
- Afiaz
The short version. We collect what we need to run your workspace and nothing we sell on. We never sell personal data or share it for advertising. Business data you bring into Afiaz — your contacts, conversations, and campaigns — belongs to you, and you can export or delete it at any time.
To delete your data, see Delete your data.
1. Who we are
Afiaz is operated by Afiaz ("Afiaz", "we", "us"), based in Lagos, Nigeria. We are the data controller for information about the people who hold Afiaz accounts.
When you use Afiaz to manage your own customers, you are the data controller for those customer records and we act as your data processor — we handle that data on your instructions and only to provide the service. If you are a customer of an Afiaz user and want your data removed, contact that business directly; we will assist them in honouring your request.
For any privacy question, write to afiaz.support@angelfss.com.
2. What we collect
Account and workspace information
- Your name and email address.
- Your workspace name, your role in it, and the other members you invite.
- Interface preferences, such as the shortcuts you pin to your navigation.
Afiaz signs you in with a one-time link sent to your email address, so we do not ask you to create or store a password with us.
Business Brain information
The description of your business you give us during onboarding: your products and services, who your customers are, your tone of voice, your goals, and the regions you sell into. This is what lets Afiaz draft relevant content for you.
Contact records you bring into Afiaz
- Contact name, email address, and phone number.
- Lifecycle stage, tags, and the channel a contact came from.
- Timestamps such as last interaction and last purchase, plus contact events you record.
You supply this data — by importing it, by adding it manually, or by connecting a channel through which customers contact you. You are responsible for having a lawful basis to process it.
Messages and conversations
When you connect a messaging channel, we store the conversations that flow through it: message content, subject lines, sender and participant identifiers, delivery status, and the provider's message and thread references. This is what makes the unified inbox work.
Connected account credentials
Access tokens, page identifiers, business account identifiers, and phone number identifiers for the accounts you connect. These are encrypted at rest and are used only to send and receive messages and posts on your behalf. Secret values are write-only in our interface — once saved, they are never displayed back to you or to anyone else.
Content, campaigns, and usage
The posts, emails, campaigns, automations, and ad configurations you create in Afiaz, along with the aggregate performance figures we calculate for your dashboards.
Billing information
Your plan, subscription status, renewal dates, invoice history, and the references our payment processor gives us. We never see or store your full card details — those go directly to Paystack, which is PCI-DSS compliant.
Technical and security records
We keep an audit log of significant account activity — sign-ins, permission changes, exports, and similar events — recording the event, the account involved, the IP address, and the browser user agent. We use it to investigate security incidents and to answer "who changed this?" for workspace owners.
3. Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Providing the workspace, inbox, campaigns, and publishing features you signed up for | Performance of our contract with you |
| Sending sign-in links, verification emails, and essential service notices | Performance of our contract with you |
| Taking payment and managing your subscription | Performance of our contract; legal obligation for tax records |
| Keeping accounts secure, preventing abuse, and investigating incidents | Our legitimate interest in a safe service |
| Diagnosing faults and improving reliability and features | Our legitimate interest in improving the product |
| Generating AI-assisted drafts from your Business Brain and prompts | Performance of our contract with you |
| Optional product or marketing emails | Your consent, withdrawable at any time |
4. How we use AI
Afiaz uses large language models to draft content, suggest replies, and summarise information. When you ask for a draft, the relevant context — typically your Business Brain profile and the prompt you wrote — is sent to our AI provider to generate a response.
- We do not use your data to train third-party AI models, and our providers are contractually bound not to train on it.
- AI output is a starting point, not a finished decision. Nothing in Afiaz makes a legally significant decision about a person automatically.
- You choose what to send. If you would rather not use these features, simply do not use the assistant.
5. Who we share data with
We do not sell personal data, and we do not share it with advertisers or data brokers. We share it only with service providers who help us run Afiaz, each bound by contract to protect it and to use it only for the service they provide us:
- Meta Platforms — to send and receive messages and publish posts through Facebook, Instagram, and the WhatsApp Business Cloud API, when you connect those accounts.
- Paystack — to take subscription payments and manage renewals.
- Our AI provider — to generate the drafts and suggestions described above.
- Our email delivery provider — to send sign-in links, service notices, and the bulk email campaigns you create.
- Our hosting and infrastructure providers — to store and serve the application.
We may also disclose data where the law requires it, to establish or defend legal claims, or to protect the rights and safety of our users. If Afiaz is ever involved in a merger or acquisition, we will tell you before your data becomes subject to a different privacy policy.
6. Data from connected Meta accounts
If you connect a Facebook Page, Instagram professional account, or WhatsApp Business number, you authorise Afiaz to act on your behalf on that account. We request only the access needed to do so, and we use it only for the features you asked for:
- Page and account identifiers — so we know which account to publish to or reply from.
- Access tokens — stored encrypted, used solely to call the relevant Meta API on your behalf.
- Messages and conversations — retrieved so they appear in your Afiaz inbox and so your replies reach the right thread.
- Post and message performance figures — retrieved to populate your dashboards.
We do not use Meta data for advertising, we do not sell it, and we do not transfer it to any party other than the service providers listed above. Disconnecting an account in Afiaz immediately revokes our stored tokens and stops all further access. You can also revoke Afiaz from your Facebook settings under Settings & Privacy → Settings → Business Integrations.
7. How long we keep data
- While your account is active — we keep your workspace data so the service works.
- Contacts, conversations, and content — kept until you delete them or close your workspace.
- Connected account credentials — deleted as soon as you disconnect the account.
- Audit and security logs — kept for up to 12 months.
- Billing and tax records — kept for as long as tax law in Nigeria requires, typically six years.
- Encrypted backups — rotated out within 90 days, after which deleted data is gone from backups too.
8. How we protect data
- All traffic to Afiaz is encrypted in transit with TLS.
- Third-party credentials and access tokens are encrypted at rest.
- Every workspace is isolated — queries are scoped to a single tenant, and we test that isolation on every change.
- Access is role-based, and sensitive actions are recorded in an audit log.
- Inbound webhooks are signature-verified so we only accept genuine provider traffic.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant regulator without undue delay.
9. Your rights
Depending on where you live, you have the right to:
- Access a copy of the personal data we hold about you.
- Correct anything inaccurate or incomplete.
- Delete your data — see Delete your data.
- Export your data in a portable, machine-readable format.
- Object to or restrict processing based on our legitimate interests.
- Withdraw consent at any time, where we relied on it.
- Complain to a data protection authority.
Email afiaz.support@angelfss.com from your account address and we will respond within 30 days. We may ask you to verify your identity first. Exercising these rights is free, and we will never treat you differently for doing so.
Afiaz processes personal data in line with the Nigeria Data Protection Act 2023. If you are in Nigeria and are unhappy with our response, you may complain to the Nigeria Data Protection Commission. If you are in the European Economic Area or the United Kingdom, the GDPR applies to our processing of your data and you may complain to your local supervisory authority.
10. International transfers
Afiaz is operated from Nigeria, and some of our service providers process data in other countries, including the United States and the European Union. Where we transfer personal data across borders, we rely on appropriate safeguards — such as standard contractual clauses or an adequacy determination — to keep it protected to the same standard.
11. Children
Afiaz is a business tool and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us data, email afiaz.support@angelfss.com and we will delete it.
12. Cookies
We use only the cookies Afiaz needs to function: a session cookie to keep you signed in and a security token to protect forms against cross-site request forgery. We also store your light or dark theme preference in your browser. We do not use advertising or third-party tracking cookies, so there is nothing here for you to opt out of.
13. Changes to this policy
We will update this page when our practices change and revise the "last updated" date at the top. If a change materially affects your rights, we will email account holders before it takes effect.
14. Contact us
Afiaz
Lagos, Nigeria
Privacy enquiries: afiaz.support@angelfss.com
Data deletion: afiaz.angelfss.com/user-data-deletion