Skip to main content

Data Protection & Privacy

When you send messages through AfriRoute you are processing personal data β€” phone numbers, names, and sometimes financial or health details inside message bodies. African data protection laws, alongside the EU GDPR for any EU residents you contact, impose specific obligations on how that data is collected, stored, and used. This page explains how AfriRoute helps you meet them.

Applicable Laws​

JurisdictionLawRegulatorKey Obligations
πŸ‡³πŸ‡¬ NigeriaNDPR / NDPA 2023NDPCLawful basis, consent records, breach notification (72h)
πŸ‡°πŸ‡ͺ KenyaData Protection Act 2019ODPCRegistration as data controller, consent, data subject rights
πŸ‡ΏπŸ‡¦ South AfricaPOPIAInformation RegulatorPurpose limitation, opt-out, cross-border transfer rules
πŸ‡¬πŸ‡­ GhanaData Protection Act 2012DPCController registration, consent
πŸ‡ͺπŸ‡Ί EU residentsGDPRNational DPAsFull GDPR regime β€” see GDPR

AfriRoute's Role​

AfriRoute is a data processor: we process recipient data on your instructions to deliver messages and payments. You are the data controller, responsible for the lawful basis (usually consent) of the contacts you upload. Our Data Processing Addendum sets out these responsibilities and is available to all customers.

Data Residency​

RegionPrimary Data RegionNotes
East AfricaNairobi, KenyaDefault for KE/TZ/UG/RW traffic
West AfricaLagos, NigeriaDefault for NG/GH traffic
EU residentsFrankfurt, GermanyGDPR-aligned storage

You can request region pinning so that PII for a given market never leaves that region.

Maintain a verifiable record of consent for every contact. AfriRoute can store consent metadata alongside contacts and enforce it at send time:

curl -X POST https://api.afriroute.ai/api/v1/contacts \
-H "Authorization: Bearer $AFRIROUTE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"phone": "+254712345678",
"consent": {
"marketing": true,
"source": "web_signup_form",
"captured_at": "2026-05-20T09:00:00Z",
"ip_address": "102.89.x.x"
}
}'

When you send a promotional message, AfriRoute checks the stored marketing consent and rejects the send if consent is absent or withdrawn.

Opt-Out Handling​

Opt-out must be free and honored promptly (within 10 days under POPIA, immediately in practice). AfriRoute automatically suppresses any recipient who replies STOP and exposes the suppression list:

curl https://api.afriroute.ai/api/v1/contacts/suppressions \
-H "Authorization: Bearer $AFRIROUTE_API_KEY"

Data Subject Rights​

Recipients can request access to, correction of, or deletion of their data. To erase a contact and all associated message history:

curl -X DELETE https://api.afriroute.ai/api/v1/contacts/+254712345678/data \
-H "Authorization: Bearer $AFRIROUTE_API_KEY"

This performs a hard delete of PII while retaining anonymized, aggregate billing records as permitted by law.

Security Measures​

  • TLS 1.2+ in transit; AES-256 at rest
  • API keys scoped and rotatable; webhook payloads HMAC-signed
  • Role-based dashboard access with audit logging
  • Independent assessments: ISO 27001 and SOC 2 Type II

Your Compliance Checklist​

  1. Identify your lawful basis for each contact and record it.
  2. Register as a data controller where required (Kenya, Ghana, others).
  3. Provide a clear privacy notice at the point of collection.
  4. Honor opt-outs and data subject requests promptly.
  5. Sign the AfriRoute DPA and configure data residency.

Privacy questions? [email protected]

Last Updated: May 2026