Legal Document

Privacy Policy

Effective Date: July 21, 2026 · Last updated: July 21, 2026

Your privacy matters to us. This Policy explains what data we collect, how we use it, your rights, and the choices you have. We are committed to being transparent and complying with the Kenya Data Protection Act 2019, the EU General Data Protection Regulation (GDPR), and COPPA.

1. Who We Are and How to Contact Us

WinyMarket AI ("we", "us", or "our") operates the WinyMarket AI Marketing Operating System — an AI-powered platform for content creation, scheduling, and distribution, available at https://winymarket.com. We are the data controller in respect of personal data processed through this platform.

Data Controller: WinyMarket AI, Kenya
Privacy Contact: support@winymarket.com

We aim to respond to all privacy-related enquiries within 30 days of receipt. For urgent data breach concerns, please mark your email subject "URGENT — DATA BREACH".

2. Scope and Applicable Law

This Privacy Policy applies to all users of the WinyMarket AI platform and is written to comply with:

  • Kenya Data Protection Act 2019 (DPA 2019) — our primary applicable legislation as a Kenya-based operator
  • EU General Data Protection Regulation (GDPR) — to the extent we process personal data of individuals in the European Economic Area
  • UK GDPR — to the extent we process personal data of individuals in the United Kingdom
  • Children's Online Privacy Protection Act (COPPA) — governing our obligations in respect of children under 13 in the United States

3. Children's Privacy — COPPA Compliance

This service is strictly not for children under the age of 13.

In compliance with the Children's Online Privacy Protection Act (COPPA) and equivalent international child-protection legislation, WinyMarket AI does not knowingly collect, process, or retain any personal data from children under 13 years of age.

Additionally, our service is designed for business use and requires users to be at least 18 years old to create an account. By registering, you represent and warrant that you are 18 or older.

If you have reason to believe that a child under 13 has provided us with personal data, please contact us immediately at support@winymarket.com. We will delete such data promptly upon verification without requiring a formal written request.

We do not seek parental consent to collect data from children under 13 because our service is not directed at children and we actively prohibit their use of the platform.

4. Information We Collect

4.1 Information You Provide Directly

  • Account information: Name, email address, and hashed password when you register
  • Profile information: Brand voice guidelines, tone preferences, and other customisation settings you configure
  • Content data: URLs, text, uploaded files, images, and other material you add to the Content Brain
  • Support communications: Messages and attachments you send to our support team
  • Payment information: Billing details processed securely by PayPal — we never see or store your full card number or banking credentials

4.2 Information Collected Automatically

  • Usage data: Pages visited, features used, actions taken (e.g., content approval, scheduling), and time spent
  • Device information: Browser type, operating system, screen resolution, and IP address
  • Authentication logs: Login timestamps, session events, 2FA events, and failed login attempts
  • Performance metrics: Post analytics data you manually enter (likes, shares, reach, etc.)
  • Error data: Crash reports and error traces captured by Sentry to help us fix bugs

4.3 Data We Do Not Collect

  • We do not collect government IDs, passport numbers, or national identification numbers
  • We do not collect health or medical data
  • We do not collect biometric data
  • We do not build advertising profiles or sell your data to third parties

Important: Do not upload content containing sensitive personal data (health records, financial account details, government IDs) to the Content Brain. The platform is designed for marketing content only. If such data is inadvertently uploaded, contact us to request deletion.

5. Legal Bases for Processing (GDPR / Kenya DPA 2019)

We process your personal data only where we have a lawful basis to do so. The table below sets out our processing activities and the applicable legal basis:

Processing ActivityLegal BasisDetails
Creating and managing your accountContract performance (Art. 6(1)(b) GDPR; DPA 2019 s.30(a))Necessary to provide the service you signed up for
Processing payments via PayPalContract performanceNecessary to fulfil your subscription
AI content generation using your inputContract performanceThe core service you contracted for
Sending transactional emails (verification, password reset, billing)Contract performanceNecessary account operations
Detecting and preventing fraud or abuseLegitimate interests (Art. 6(1)(f) GDPR; DPA 2019 s.30(d))We have a legitimate interest in protecting our platform and users
Error monitoring via SentryLegitimate interestsNeeded to maintain service quality and fix bugs
Improving AI quality using your approval/rejection feedback (per-account only)Legitimate interestsWe do not use your data to train shared AI models
Sending product update emailsLegitimate interests / ConsentYou may opt out at any time
CAPTCHA verification (hCaptcha) on login / registrationLegitimate interestsNecessary to prevent automated bot abuse
Responding to legal requestsLegal obligation (Art. 6(1)(c) GDPR; DPA 2019 s.30(b))Required by applicable law
Aggregate platform usage analyticsLegitimate interestsNon-identifiable statistics to improve the product

6. AI Processing and Your Content

When you use AI generation features, your source content and preferences are transmitted to Anthropic's Claude API for processing. We recommend reviewing Anthropic's Privacy Policy.

  • Your content is sent to Anthropic solely to generate the requested output — not for general model training
  • Generated outputs and your approval or rejection decisions are stored in your account to improve future content quality for your brand voice specifically
  • We do not use your content to train shared or public AI models
  • You retain ownership of all content you upload and all AI-generated outputs produced from your inputs

7. Third-Party Data Processors

We do not sell your personal data. We share your information with the following sub-processors, all of whom are bound by appropriate data processing agreements:

ProcessorPurposeData SharedLocation
Vercel Inc.Hosting and serving the web applicationAll platform data (encrypted at rest and in transit)USA (EU SCCs in place)
Railway Corp.PostgreSQL database hostingAll structured user and content dataUSA (EU SCCs in place)
Anthropic PBCAI content generation via Claude APIContent you submit for generation + brand preferencesUSA (EU SCCs in place)
PayPal Holdings Inc.Payment processing and subscription billingEmail, subscription plan, billing confirmationUSA (EU SCCs in place)
Resend Inc.Transactional email deliveryYour email address + email contentUSA (EU SCCs in place)
Upstash Inc.Redis rate limiting and cachingIP addresses, request identifiers (ephemeral, auto-expires)USA (EU SCCs in place)
Sentry Inc.Error monitoring and crash reportingError traces, session IDs, anonymised IP addressesUSA (EU SCCs in place)
Intuition Machines (hCaptcha)CAPTCHA verification to prevent bot sign-upsBrowser fingerprint, CAPTCHA response tokenUSA (EU SCCs in place)

Social media platforms: When you use scheduling and publishing features, approved content is sent to the relevant platform (Facebook, Instagram, Twitter/X, LinkedIn, TikTok, YouTube) via their official APIs. Each platform's own privacy policy governs their processing.

We review our sub-processor list regularly and will update this policy when processors change. We will notify you of significant processor changes by email.

8. International Data Transfers

WinyMarket AI is operated from Kenya. Most of our sub-processors are located in the United States. When we transfer personal data internationally, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs): For transfers from the EEA/UK, we use the European Commission's approved SCCs incorporated into our Data Processing Agreements with each sub-processor
  • Kenya DPA 2019 cross-border compliance: We assess each sub-processor's data protection standards under DPA 2019 Section 48 before transferring data to them, and ensure they provide an adequate level of protection
  • Data minimisation: We transfer only the minimum data necessary for the specific processing purpose

You may request a copy of the relevant transfer safeguards by contacting support@winymarket.com.

9. Data Retention

We retain your data only as long as necessary for the stated purpose or as required by law:

Data CategoryRetention PeriodReason
Account profile dataDuration of account + 90 days after deletionRecovery window; then permanently deleted
Content Brain itemsUntil you archive or delete themAdmin/Staff can delete; persists otherwise
Generated posts and draftsDuration of account, or until you deleteRequired for analytics and AI learning
Approval / rejection decisionsDuration of accountPowers per-account AI personalisation
Post analytics data24 monthsTrend analysis; then anonymised
Authentication and login logs90 daysSecurity and fraud investigation
Payment transaction records7 yearsLegal / tax obligation (Kenya Revenue Authority)
Support email correspondence3 yearsDispute resolution
Error logs (Sentry)90 daysBug investigation; automatically purged by Sentry
Upstash rate-limit records24 hours (ephemeral)Security; automatically expires in Redis TTL

When your account is deleted, we will permanently delete or irreversibly anonymise all personal data within 30 days, except where retention is required by law. You will receive a deletion confirmation by email.

10. Security Measures (SOC 2 Alignment)

We implement the following technical and organisational security measures, aligned with SOC 2 Trust Service Criteria:

Confidentiality

  • All data in transit is encrypted using TLS 1.2 or higher (HTTPS enforced via HSTS preload)
  • Passwords are hashed using bcrypt with a minimum of 12 salt rounds — we never store or transmit plain-text passwords
  • Authentication tokens are cryptographically signed JWTs with rolling expiry and token-version invalidation on logout or password change
  • Database access is restricted to authorised systems via network-level access controls
  • API keys and secrets are stored as encrypted environment variables in Vercel — never committed to source code

Availability

  • Platform is hosted on Vercel's global edge network with automatic failover
  • Database is hosted on Railway with automatic daily backups
  • Uptime monitoring is active with immediate alerting on downtime
  • We target 99.5% monthly uptime, excluding planned maintenance windows

Processing Integrity

  • All API routes include input validation and schema enforcement
  • Rate limiting is enforced via Upstash Redis sliding-window algorithm to prevent abuse
  • Role-based access control prevents users from accessing data beyond their permissions
  • A human-in-the-loop content approval workflow runs before any AI-generated content is published

Incident Response and Breach Notification

  • Security incidents are monitored continuously via Sentry error tracking
  • In the event of a personal data breach, we will notify affected individuals and relevant supervisory authorities within 72 hours of becoming aware, as required by GDPR Article 33
  • Breach notifications will include: nature of the breach, categories and approximate number of affected individuals, likely consequences, and remediation measures taken
  • For Kenya DPA 2019 notifications, we will comply with the procedures prescribed by the Office of the Data Protection Commissioner (ODPC)

11. Cookies and Tracking

We use only essential and functional cookies. See our full Cookie Policy for complete details. In summary:

  • Essential cookies: Authentication session (HttpOnly, Secure, SameSite=Lax) and CSRF protection — cannot be disabled without breaking the service
  • Functional storage: UI preferences in localStorage — never transmitted to third parties
  • No advertising cookies: We use zero third-party advertising, retargeting, or cross-site tracking cookies

12. Your Rights Under GDPR and Kenya DPA 2019

You have the following rights in respect of your personal data. We will respond to all valid requests within 30 days (extendable by a further 60 days for complex requests, with advance notice):

RightWhat It MeansHow to Exercise
Right of Access (Art. 15 GDPR; DPA 2019 s.26)Receive a copy of the personal data we hold about youEmail support@winymarket.com — subject: "Data Access Request"
Right to Rectification (Art. 16; DPA 2019 s.35)Correct inaccurate or incomplete dataUpdate in account Settings, or email us
Right to Erasure (Art. 17; DPA 2019 s.36)Have your data deleted, subject to legal retention obligationsUse Delete Account in Settings or email support@winymarket.com
Right to Data Portability (Art. 20; DPA 2019 s.38)Receive your data in a structured, machine-readable format (JSON/CSV)Email support@winymarket.com — subject: "Data Portability Request"
Right to Restriction (Art. 18; DPA 2019 s.37)Limit how we process your data in certain circumstancesEmail support@winymarket.com
Right to Object (Art. 21; DPA 2019 s.39)Object to processing based on legitimate interestsEmail support@winymarket.com
Right to Withdraw ConsentWithdraw consent at any time where processing is consent-basedEmail us or use account settings
Right to Lodge a ComplaintComplain to a supervisory authority if you believe we have breached applicable lawKenya: ODPC (odpc.go.ke) | EU: your local DPA | UK: ICO (ico.org.uk)

We will not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive. We may need to verify your identity before processing a request.

Kenya Supervisory Authority: You have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at odpc.go.ke.

13. Marketing Communications

We may send you product updates and feature announcements by email. You may opt out at any time by:

  • Clicking the unsubscribe link in any marketing email
  • Emailing support@winymarket.com with subject "Unsubscribe"

Opting out of marketing emails will not affect transactional emails (account verification, password reset, billing notifications) which are necessary for the service.

14. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable legal requirements. We will notify you of material changes by:

  • Updating the effective date at the top of this page
  • Sending an email notification to your registered address, at least 14 days before significant changes take effect
  • Displaying an in-platform notice

For changes that materially affect your rights or how we use your data, we will seek fresh consent where required by law.

15. Contact Our Privacy Team

For any privacy questions, data requests, complaints, or concerns, please contact us:

WinyMarket AI

Email: support@winymarket.com

Website: https://winymarket.com

We aim to respond to all privacy requests within 30 days as required by the Kenya DPA 2019 and GDPR.

Kenya Supervisory Authority

Office of the Data Protection Commissioner (ODPC)

odpc.go.ke

© 2026 WinyMarket AI. All rights reserved.