Legal · For sellers
Seller Data Processing Terms
Last updated 23 August 2026 · Exeli Digital Limited (RC 9669496), Port Harcourt, Rivers State, Nigeria
In short
When your customers message you, their messages are their personal data. You decide what happens to it — we only act on your instructions. In the language of the NDPA, you are the data controller and Exeli is your data processor.
These terms set out what we will and will not do with your customers' data, who else touches it, how quickly we tell you if something goes wrong, and how you get it all back or deleted when you leave.
They apply automatically to every business using Exeli — you do not need to sign anything, though we will sign a copy if your own compliance requires it.
1. Parties and scope
These terms are between Exeli Digital Limited(RC 9669496) (“Exeli”, “Processor”) and the business using the Exeli service (“you”, “Seller”, “Controller”). They form part of your agreement with us and govern our processing of personal data relating to your customers under the Nigeria Data Protection Act 2023.
Our handling of your own account data is covered by the Privacy Policy, where we act as controller.
2. What we process, and why
| Item | Detail |
|---|---|
| Subject matter | Drafting, approving and sending WhatsApp replies on your behalf, and logging the resulting leads |
| Duration | For as long as your account is open, plus the deletion window in §9 |
| Nature and purpose | Receiving, storing, transcribing, analysing and transmitting customer messages so you can respond to them |
| Categories of data | Phone number, WhatsApp profile name, message content (text, images, documents, voice notes and their transcriptions, location pins, reactions), timestamps, delivery status |
| Categories of data subject | Your customers and prospective customers |
Do not use Exeli to process sensitive personal data — health information, financial account credentials, biometric data, or data revealing religious or political beliefs — unless we have agreed that in writing first. Some businesses (for example diagnostic labs) will need that conversation before going live, and we would rather have it early.
3. Your obligations as controller
You are responsible for:
- Having a lawful basis to process your customers' data, and telling them how you use it
- Making it clear to your customers that replies may be assisted by AI — we give you wording for this if you want it
- The accuracy of the business information you configure (prices, stock, hours). Exeli drafts from what you give it
- Reviewing replies before they are sent, unless you deliberately switch on auto mode
- Handling requests from your own customers to see, correct or delete their data — we will help you do it
- Keeping your account credentials secure and telling us promptly if they are compromised
4. Our obligations as processor
We will:
- Process only on your instructions.Using Exeli as intended is your instruction. We will not process your customers' data for our own purposes.
- Never sell your customers' data, and never share it with another seller.
- Not permit it to be used to train third-party AI models. Message content goes to our AI provider only to draft that reply.
- Keep it confidential. Anyone with access is bound by confidentiality obligations and gets least-privilege access only.
- Apply the security measures in §7 and keep them under review.
- Tell you about breaches on the timeline in §8.
- Help you meet your own obligations — data subject requests, impact assessments, and regulator queries.
- Delete or return the data when you leave, per §9.
- Give you the information you need to verify this, including reasonable audit support (§10).
5. Sub-processors
We use the following sub-processors. Each is bound by data protection obligations no less protective than these terms.
| Sub-processor | Purpose | Location |
|---|---|---|
| Meta Platforms, Inc. | WhatsApp Business Cloud API — message delivery | United States / global |
| Anthropic, PBC | AI model that drafts replies | United States |
| Amazon Web Services, Inc. | Voice note transcription | United States (us-east-1) |
| Supabase, Inc. | Database — accounts, conversations, leads | Ireland (eu-west-1) |
| Vercel, Inc. | Application hosting | United States (iad1) |
| Resend, Inc. | Transactional email notifications | United States |
If we add or replace a sub-processor we will update this page and notify active sellers at least 14 days beforehand. If you object on reasonable data-protection grounds, tell us within those 14 days — if we cannot resolve it, you may close your account and we will refund any unused prepaid period.
6. International transfers
As the table above shows, data is processed outside Nigeria. Part IX of the NDPA permits this where adequate protection exists. We rely on the contractual data-protection commitments we hold with each sub-processor. We will provide details of the safeguards for any specific provider on request.
7. Security measures
- TLS encryption for all data in transit
- Encryption at rest through our database and storage providers
- Row Level Security enabled on the database, with no public read or write policies — the application server is the only path in
- HMAC-SHA256 signature verification on every inbound WhatsApp webhook, so forged or replayed requests are rejected
- Token-authenticated access to the seller inbox
- Least-privilege credentials — for example our transcription key is restricted to a single API action
- Segregation of each seller's data by account
- Deduplication of retried webhooks to prevent double handling
8. Breach notification
If we become aware of a personal data breach affecting your customers' data, we will notify you without undue delay and within 48 hours of becoming aware — deliberately inside the 72-hour window the NDPA gives you to notify the NDPC, so you have time to act.
We will tell you what we know: what happened, which categories and roughly how many records are affected, the likely consequences, and what we are doing about it. Where the full picture is not yet available we will send what we have and follow up rather than wait.
9. Deletion and return
You can export your lead book and conversation history at any time while your account is open — just ask.
When your account closes, we delete your customers' data within 30 days, unless a law requires us to keep something (financial records, for example). Ask us to delete it sooner and we will. Backups age out on a rolling cycle and are deleted no later than 90 days after account closure.
10. Audit
On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will provide the information you reasonably need to confirm we are meeting these terms. We will cooperate with the NDPC in relation to your data.
11. Liability and changes
Each party is responsible for its own compliance with the NDPA. Nothing here limits any right your customers have against either of us under Nigerian law.
If we change these terms we will update the date at the top and notify active sellers before the change takes effect.
12. Honest note on where we are
Exeli is an early-stage Nigerian company. These terms are written to be accurate about what we actually do today, rather than to copy a template from a larger company and promise things we have not built. As we grow — and as our NDPC obligations step up with volume — we will strengthen both the controls and this document, and we will tell you when we do.
Questions about this document? Email hello@exelidigital.com. We answer in plain language — if anything here is unclear, that is our problem to fix, not yours to decode.