Legal
Privacy Policy
Agent Kesh is a WhatsApp AI sales agent operated by Kesh Business Hub (Pvt) Ltd. This policy explains what data we handle, why, who we share it with, and how you get it deleted.
Last updated: 10 August 2026
1. Two different people are covered by this policy
Agent Kesh sits between a shop and the shop's customers, so it handles data about two groups. Your rights differ depending on which one you are.
| Who you are | Our role | What that means |
|---|---|---|
| Shop owner | We are the controller | You signed up for Agent Kesh. We decide how your account data is handled and you deal directly with us. |
| Customer of a shop | We are a processor | You messaged a shop on WhatsApp. The shop decides what happens to your data; we only process it on the shop’s instructions. Contact the shop first — or us, and we will pass it on. |
2. What we collect
| Data | Where it comes from | Why we have it |
|---|---|---|
| Name, email, password | Shop owner at sign-up | To create and secure the account |
| Business name, WhatsApp number, plan | Shop owner during setup | To run the service and bill correctly |
| Store connection credentials and product catalog (titles, descriptions, prices, stock, images) | The shop’s own e-commerce store | So the agent answers from real products instead of guessing |
| Knowledge documents and website content the shop uploads or points us at | Shop owner | So the agent can answer questions about policies, delivery and hours |
| Customer WhatsApp number, message text, voice notes, images | The shop’s customers, via WhatsApp | To read the question and generate a reply |
| Order details — items, quantities, total, and delivery name, address, phone and landmarks | The shop’s customers, during the chat | So the shop can fulfil and deliver the order |
| Usage records — conversation counts, tokens, model used, cost | Generated automatically | To meter your plan, bill accurately and monitor quality |
| Payment records | PayHere | To manage your subscription. We never see or store your card number. |
| Technical logs — IP address, timestamps, errors | Generated automatically | Security, debugging and abuse prevention |
3. How we use it
- To run the agent — read an incoming message, find the right products, and generate a reply in the customer’s language.
- To show the shop owner their inbox, orders and usage.
- To meter conversations against the plan cap and bill the subscription.
- To keep the service working and secure — monitoring, error alerts, fraud and abuse prevention.
- To support you when you ask for help.
- To meet legal and tax obligations in Sri Lanka.
We do not sell your data, and we do not use it for advertising. We do not use the content of customer conversations to train AI models, and the AI providers we use are on API terms that do not permit training on the content we send them.
4. Who we share it with
Agent Kesh is built on third-party infrastructure. These are our sub-processors — each receives only what it needs to do its job.
| Provider | What it does | What it receives |
|---|---|---|
| Meta Platforms (WhatsApp Business Platform) | Delivers WhatsApp messages | Messages to and from customers |
| Green API | Alternative WhatsApp connection used by some accounts | Messages to and from customers |
| Anthropic (Claude) | Generates English replies and catalog search terms | Message text and product context |
| Google (Gemini), routed via OpenRouter | Generates Sinhala and Tamil replies | Message text and product context |
| OpenAI | Transcribes voice notes and creates search embeddings | Voice note audio, message and product text |
| Supabase | Hosts the database | All stored account, catalog, conversation and order data |
| Hetzner Online GmbH | Hosts the application servers | Data in transit while being processed |
| Cloudflare | DNS, security and content delivery | Network traffic metadata |
| PayHere | Processes subscription payments in LKR | Billing details you enter on their checkout |
| Telegram | Delivers operational alerts to our team | System health and error information — no customer messages |
We may also disclose data where the law requires it, or to protect our rights, users or the safety of others. If Kesh Business Hub is ever sold or reorganised, data may transfer with the business — you will be told before that happens.
5. WhatsApp and Meta
When a shop connects its WhatsApp number, we receive access to that WhatsApp Business Account through Meta's official platform. We commit that:
- We access WhatsApp data only to provide Agent Kesh to the shop that authorised it.
- We never sell, rent or share WhatsApp data with data brokers, advertisers or anyone building profiles of people.
- We never use WhatsApp data for advertising or for training AI models.
- One shop can never see another shop’s conversations — every record is locked to its own workspace at the database level.
- We follow Meta’s Platform Terms and the WhatsApp Business Messaging Policy, and we delete WhatsApp data when the shop disconnects or asks us to.
Messages sent over WhatsApp are also governed by WhatsApp's own privacy policy.
6. How the AI is used, and how you know
Replies are generated by an AI assistant, not a person. Every shop's agent carries an AI disclosure and will say it is an AI when asked. A customer can ask for a human at any time and the shop owner can take over the conversation.
The agent answers only from the shop's own catalog and uploaded knowledge. It is not permitted to invent products, prices or promises — but it is software, and a shop should check anything that matters before acting on it.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account and workspace records | While the account is open, then 90 days after closure |
| Conversations and messages | While the account is open, then 90 days after closure |
| Orders and delivery details | While the account is open, then 90 days after closure |
| Billing and tax records | As long as Sri Lankan law requires, typically 6 years |
| Technical logs | 30 days |
| Deleted-on-request data | Removed within 30 days — see the data deletion page |
8. How we protect it
- Every row of shop data is tagged to its workspace and protected by database-level row-level security, so a query can never reach another shop’s data.
- Store and WhatsApp credentials are encrypted at rest.
- Traffic is encrypted in transit over HTTPS.
- Staff access to the admin panel is role-based, and every action taken on a shop’s account is written to an audit log.
- No system is perfectly secure. If a breach affects your data, we will tell you promptly.
9. Where your data is
Our database, servers and AI providers are located outside Sri Lanka, principally in the European Union and the United States. By using Agent Kesh you agree to your data being processed in those locations. We can confirm the exact regions on request.
10. Your rights
You can ask us to:
- Show you a copy of the data we hold about you.
- Correct anything that is wrong.
- Delete your data — see the data deletion page.
- Export your conversations and orders.
- Stop processing your data, which for a shop owner means closing the account.
Email [email protected] and we will respond within 30 days. If you are a customer of a shop rather than a shop owner, we will pass your request to that shop, because the data is theirs.
11. Children
Agent Kesh is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has reached us, tell us and we will delete it.
12. Changes to this policy
We will update this page when the service changes and move the “last updated” date. If a change materially affects how we handle your data, we will email account holders before it takes effect.
Contact us
Kesh Business Hub (Pvt) Ltd, Sri Lanka — the company behind Agent Kesh.
- Email: [email protected]
- WhatsApp: +94 77 500 2841
- Web: agentkesh.com