Data Protection & Privacy
When you send messages through AfriRoute you are processing personal data β phone numbers, names, and sometimes financial or health details inside message bodies. African data protection laws, alongside the EU GDPR for any EU residents you contact, impose specific obligations on how that data is collected, stored, and used. This page explains how AfriRoute helps you meet them.
Applicable Lawsβ
| Jurisdiction | Law | Regulator | Key Obligations |
|---|---|---|---|
| π³π¬ Nigeria | NDPR / NDPA 2023 | NDPC | Lawful basis, consent records, breach notification (72h) |
| π°πͺ Kenya | Data Protection Act 2019 | ODPC | Registration as data controller, consent, data subject rights |
| πΏπ¦ South Africa | POPIA | Information Regulator | Purpose limitation, opt-out, cross-border transfer rules |
| π¬π Ghana | Data Protection Act 2012 | DPC | Controller registration, consent |
| πͺπΊ EU residents | GDPR | National DPAs | Full GDPR regime β see GDPR |
AfriRoute's Roleβ
AfriRoute is a data processor: we process recipient data on your instructions to deliver messages and payments. You are the data controller, responsible for the lawful basis (usually consent) of the contacts you upload. Our Data Processing Addendum sets out these responsibilities and is available to all customers.
Data Residencyβ
| Region | Primary Data Region | Notes |
|---|---|---|
| East Africa | Nairobi, Kenya | Default for KE/TZ/UG/RW traffic |
| West Africa | Lagos, Nigeria | Default for NG/GH traffic |
| EU residents | Frankfurt, Germany | GDPR-aligned storage |
You can request region pinning so that PII for a given market never leaves that region.
Consent Managementβ
Maintain a verifiable record of consent for every contact. AfriRoute can store consent metadata alongside contacts and enforce it at send time:
curl -X POST https://api.afriroute.ai/api/v1/contacts \
-H "Authorization: Bearer $AFRIROUTE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"phone": "+254712345678",
"consent": {
"marketing": true,
"source": "web_signup_form",
"captured_at": "2026-05-20T09:00:00Z",
"ip_address": "102.89.x.x"
}
}'
When you send a promotional message, AfriRoute checks the stored marketing consent and rejects the send if consent is absent or withdrawn.
Opt-Out Handlingβ
Opt-out must be free and honored promptly (within 10 days under POPIA, immediately in practice). AfriRoute automatically suppresses any recipient who replies STOP and exposes the suppression list:
curl https://api.afriroute.ai/api/v1/contacts/suppressions \
-H "Authorization: Bearer $AFRIROUTE_API_KEY"
Data Subject Rightsβ
Recipients can request access to, correction of, or deletion of their data. To erase a contact and all associated message history:
curl -X DELETE https://api.afriroute.ai/api/v1/contacts/+254712345678/data \
-H "Authorization: Bearer $AFRIROUTE_API_KEY"
This performs a hard delete of PII while retaining anonymized, aggregate billing records as permitted by law.
Security Measuresβ
- TLS 1.2+ in transit; AES-256 at rest
- API keys scoped and rotatable; webhook payloads HMAC-signed
- Role-based dashboard access with audit logging
- Independent assessments: ISO 27001 and SOC 2 Type II
Your Compliance Checklistβ
- Identify your lawful basis for each contact and record it.
- Register as a data controller where required (Kenya, Ghana, others).
- Provide a clear privacy notice at the point of collection.
- Honor opt-outs and data subject requests promptly.
- Sign the AfriRoute DPA and configure data residency.
Relatedβ
Privacy questions? [email protected]
Last Updated: May 2026