Skip to main content

Privacy Policy

Last updated: July 23, 2026

1. Data Controller

Rainlight Automation, business number BN-55S9QVEM, trading as Rainlight AI (“we,” “us,” or “our”), is the data controller responsible for processing your personal data. We are based in Nairobi, Kenya, postal address 19275, 00100 G.P.O Nairobi. If you have questions or wish to exercise a data-protection right, contact us at [email protected].

2. Information We Collect

We collect the following categories of personal information:

  • Identifiers: Name, email address, phone number, and IP address.
  • Commercial Information: Records of services purchased or considered, inquiry details, and project scope information.
  • Internet/Network Activity: Browsing history on our site, pages visited, referral URLs, and interactions with our website.
  • Device Information: Browser type, operating system, device identifiers, and screen resolution.
  • Communication Data: SMS messages, WhatsApp messages, email correspondence, and call scheduling information processed through our automation platforms.

We collect this information when you fill out our contact form, book a call, submit a request through our services, opt into SMS or WhatsApp communications, or interact with our website.

3. Legal Basis for Processing

In Kenya, we process personal data under the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021. We identify one lawful basis for each purpose before processing. The bases we use are:

  • Consent: For WhatsApp marketing, ad-audience use, and WhatsApp booking reminders where requested. Consent is voluntary, specific, informed, recorded, and withdrawable.
  • Steps requested before a contract or performance of a contract: To answer an inquiry, prepare a proposal, schedule a requested call, and deliver services.
  • Legitimate interests: For security, fraud prevention, service improvement, and responding to an inbound message where our interests do not override your rights.
  • Legal obligation: For tax, accounting, regulatory, and lawful disclosure requirements.

For people in the EEA or United Kingdom, the equivalent GDPR bases apply under Article 6.

4. How We Use Your Information

We use your personal information for the following purposes:

  • To provide, maintain, and improve our AI automation consulting and implementation services.
  • To communicate with you about our solutions and respond to your inquiries.
  • To answer inbound questions and share relevant guides or case studies in the active conversation.
  • To send WhatsApp booking reminders or marketing only where the separate consent for that purpose is recorded.
  • To schedule and manage calls and consultations.
  • To use AI to classify an inquiry, select a relevant resource, draft a reply, and route a conversation. We do not use this system to make a solely automated decision with legal or similarly significant effects.
  • To analyze website usage and improve user experience.
  • To comply with legal obligations.

We do not sell your personal information to third parties.

No mobile information - including SMS opt-in data and consent - will be sold, shared with, or disclosed to third parties or affiliates for marketing or promotional purposes. If you have opted into SMS communications, we may use your phone number to send transactional or informational messages about our services. You can opt out at any time by replying STOP to any SMS message you receive from us.

5. SMS Communications (A2P Messaging)

If you provide your phone number and consent to receive text messages, you agree to receive automated promotional and transactional SMS messages from Rainlight AI via Rainlight AI's authorized communication platforms, including Twilio.

  • Message frequency varies depending on your engagement and the services you have signed up for.
  • Message and data rates may apply.
  • Reply HELP for help or STOP to opt out at any time.
  • You may receive a confirmation message after opting in.
  • SMS opt-in data and consent will not be sold or shared with third parties for their marketing or promotional purposes.

Consent to SMS messaging is not a condition of purchase. Opting in is voluntary and you may withdraw consent at any time by replying STOP. After opting out, you will receive one final confirmation message and no further SMS messages will be sent.

All SMS campaigns are registered in compliance with applicable carrier requirements, CTIA Messaging Principles and Best Practices, TCPA regulations, and 10DLC registration requirements.

6. WhatsApp Business Communications

We may use WhatsApp Business API to communicate with you for the purpose of providing customer support, sending service updates, delivering automation notifications, and facilitating project communication. WhatsApp messages are processed in accordance with Meta's Platform Terms and WhatsApp Business Policy. AI-powered responses on WhatsApp are used only for specific, purpose-driven business tasks (e.g., lead qualification, support routing) and are not open-ended general-purpose chatbots.

At booking, WhatsApp reminders and marketing follow-ups use separate optional checkboxes. Agreeing to reminders does not agree to marketing. Marketing consent permits useful follow-ups and offers after the call, including verified no-show follow-up.

You can opt out of WhatsApp communications at any time by sending “STOP” or contacting us at [email protected].

7. Meta Direct Messages and Resource Follow-Up

When you message us on Instagram or Facebook Messenger, we use your Meta account identifier, message history, inquiry details, and engagement timestamps to answer your inquiry, qualify the request, and share relevant information within the active conversation.

We do not place legal notices or consent questionnaires into ordinary Meta chats. You can reply “STOP” to end automated follow-up. Separate WhatsApp marketing consent is collected only at booking.

8. Cookies and Tracking Technologies

We use essential cookies to ensure our website functions properly. We may also use analytics tools (such as Google Analytics) to understand how visitors interact with our site, including pages visited, time spent, and referral sources.

You can control cookie settings through your browser preferences. Most browsers allow you to refuse cookies or alert you when cookies are being sent. Please note that disabling cookies may affect the functionality of our website.

For users in the EEA: non-essential cookies are only placed with your consent. You may withdraw your consent at any time by adjusting your browser settings or contacting us.

9. Third-Party Services and Data Processors

Our website and services may use the following third-party services, each acting as a data processor on our behalf:

  • Cal.com - for scheduling consultations and calls.
  • Twilio - for SMS communications and A2P messaging.
  • Meta - for Instagram, Facebook Messenger, WhatsApp messaging, and platform attribution.
  • Supabase - for secure database and server-side workflow functions.
  • OpenRouter and selected AI model providers - for limited-purpose message classification and reply drafting.
  • Google Analytics - for website analytics and usage insights.
  • Vercel - for website hosting and delivery.
  • n8n - for workflow automation (self-hosted).

These providers have their own privacy terms. We limit the data sent to what is needed for the stated purpose, apply access controls, and assess contractual and transfer safeguards. Contact us for current processor and transfer information.

10. International Data Transfers

Some processors operate outside Kenya, including in the United States and other jurisdictions. Before a transfer, we assess the destination, purpose, data category, processor terms, security controls, and safeguards required by sections 48 and 49 of Kenya's Data Protection Act. Where consent is the transfer basis, the notice identifies the possible transfer risks.

  • Contractual data-protection and confidentiality obligations.
  • Encryption in transit, access controls, minimisation, and purpose restrictions.
  • Additional consent or another lawful transfer basis where required.

You may request a copy of the safeguards in place by contacting us at [email protected].

11. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Specifically:

  • Unsuccessful inquiries and direct-message history: Up to 24 months after the last interaction.
  • Consent, withdrawal, and suppression evidence: While relevant communications continue and for 36 months afterward solely to demonstrate consent or honour an opt-out.
  • Client and project records: For the relationship and up to 7 years where needed for tax, accounting, contracts, or legal claims.
  • Operational message and error logs: Up to 90 days unless needed to investigate security, fraud, delivery, or a legal claim.
  • Analytics data: Retained for up to 26 months (per Google Analytics defaults) and then automatically deleted.
  • Financial and contractual records: Retained for 7 years as required by tax and accounting obligations.

12. Data Security

We implement appropriate technical and organizational measures to protect the security of your personal information, including encryption in transit (TLS/SSL), secure hosting infrastructure, access controls, and regular security reviews. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

13. Your Rights

For people in Kenya

You may ask us to access, correct, restrict, erase, or port your personal data, object to processing, or withdraw consent. Objection to direct marketing is absolute and the affected data will not be used for that purpose again.

  • Access requests: normally within 7 days.
  • Restriction, objection, rectification, and erasure requests: normally within 14 days.
  • Portability requests: normally within 30 days.

You may complain to Kenya's Office of the Data Protection Commissioner at odpc.go.ke.

For EEA and UK Residents (GDPR)

Under the General Data Protection Regulation, you have the following rights:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your personal data (“right to be forgotten”).
  • Right to Restrict Processing: Request that we limit how we use your data.
  • Right to Data Portability: Request a machine-readable copy of your data for transfer to another service.
  • Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated.

For California Residents (CCPA/CPRA)

Under the California Consumer Privacy Act and the California Privacy Rights Act, you have the following rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: Request deletion of your personal information.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out: We do not sell or share your personal information for cross-context behavioral advertising. If this changes, we will provide a “Do Not Sell or Share My Personal Information” link.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

Exercising Your Rights

To exercise any of the above rights, contact us at [email protected]. We will verify identity proportionately and respond within the applicable statutory period listed above or required by your local law. Rights requests are free unless the law permits a reasonable charge.

14. Data Deletion

You may request deletion of your personal information at any time. To submit a data deletion request, contact us at [email protected] with the subject line “Data Deletion Request” and include the identifier needed to find the record. For requests governed by Kenyan law, we respond within 14 days. We also notify relevant processors where required, subject to lawful retention exceptions.

For more detailed instructions, visit our Data Deletion Instructions page.

15. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal data from a child under the age of 18, we will take steps to delete that information promptly.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. When we make material changes, we will update the “Last updated” date at the top of this page. We encourage you to review this page periodically.

17. Contact Us

If you have any questions about this Privacy Policy, including regarding your data protection rights, SMS communications, WhatsApp data, or data deletion, please contact us at:

Rainlight Automation, trading as Rainlight AI

Business number: BN-55S9QVEM

Address: 19275, 00100 G.P.O Nairobi, Nairobi, Kenya

Phone: +254 786 307 831

Email: [email protected]

Website: www.rainlightai.com