Skip to content

PadiDesk Legal

Privacy Policy

Last updated: August 15, 2026

This policy explains what information PadiDesk processes, why, and the choices available to merchants, their staff and the customers who message them.

1. Who PadiDesk is

PadiDesk is operated by PadiDesk Technologies Limited, a company registered in Nigeria with its business address at House No. 201D, Zone 2, Dantata Estate, Gwarinpa, Abuja, FCT, Nigeria.

PadiDesk provides business-management and conversational-commerce software to businesses. Depending on the plan, business type and integrations a business chooses to enable, the platform can include:

  • sales, inventory, customers and suppliers
  • expenses, purchases and supplier payments
  • invoices, receipts, receivables and payables
  • reports and business analytics
  • service jobs and hospitality operations
  • WhatsApp Business integration and human handoff
  • AI-assisted conversational features and voice-note transcription
  • payment-provider integrations, business notifications, and audit/security functionality

Not every business uses every feature. Some features only appear once a business enables the relevant integration or selects a matching business type.

2. Account and business information

When a business signs up and sets up PadiDesk, we may process:

  • name, email address and phone number of the account holder and invited team members
  • business name and business type
  • country, currency and timezone
  • role and team membership within a business
  • business settings and preferences
  • business logo and business contact details where supplied
  • authentication and security information (see section 9)

3. Business records

Merchants enter or generate operational records inside PadiDesk, which may include:

  • products, services and pricing
  • inventory records, adjustments and stock movements
  • sales, purchases and expenses
  • customers and suppliers
  • invoices, receipts, payments and payment status
  • returns, refunds and outstanding balances
  • reports, service jobs and appointments
  • hospitality bookings and related folio records
  • notes and other operational records

Most of this information is supplied by the merchant and relates to the merchant's own business operations. PadiDesk stores and processes it so the merchant can run their business.

4. Customer information

A merchant may record information about their own customers, such as:

  • customer name and phone number
  • transaction history and outstanding balances
  • invoices, receipts, bookings and service jobs
  • delivery or location details where the merchant enters them
  • conversation information needed to provide the merchant's service

PadiDesk does not sell merchant customer data and does not market its own products to a merchant's customers using that data. Messages sent to a customer come from the merchant's own business account.

5. WhatsApp data

When a business connects a WhatsApp Business account to PadiDesk, PadiDesk processes messages exchanged through that business account in order to:

  • receive messages from customers and from authorised business users
  • interpret merchant commands
  • respond to customers on the business's behalf
  • maintain conversation context across a conversation
  • create business actions that the business has authorised
  • support handoff to a human member of staff
  • display conversation history and status inside the app
  • process message delivery and status events

The information involved may include:

  • phone numbers
  • message text
  • message identifiers and timestamps
  • delivery and status metadata
  • structured conversation context derived from the conversation
  • media and voice metadata where media is sent

This processing is limited to the business WhatsApp integration a merchant has connected. PadiDesk does not access personal WhatsApp conversations that take place outside that connected business account, and the WhatsApp service itself is operated by Meta under its own terms and policies.

6. Voice notes and transcription

Where voice features are enabled, a voice note sent through a supported flow may be:

  • retrieved from the messaging provider using the business's own connection
  • stored temporarily in a private, business-scoped location
  • sent to a transcription service to be converted into text
  • passed through the same business-action and conversation logic as a text message

Stored audio is deleted after a short retention window — 24 hours by default, and configurable per business. The resulting transcript remains part of the conversation and business record so the merchant can see what was recorded and why an entry was created. Retention of the underlying media at the messaging provider is governed by that provider's own practices.

7. AI-assisted features

PadiDesk uses AI models, accessed through third-party model providers, to help with:

  • interpreting natural-language requests
  • classifying or understanding messages
  • generating conversational replies
  • summarising conversation context
  • extracting details such as quantities, amounts or product names where supported

Not every message is processed by an AI model. Many routine commands and lookups are handled by deterministic logic that does not call a model at all.

AI does not hold the authoritative record of a business. Changes to sales, stock, invoices, payments and other financial records are executed by PadiDesk's server-side routines and remain subject to the permissions configured for the account. AI output can be imperfect and should be reviewed. PadiDesk does not present AI output as legal, tax, accounting, medical or other professional advice, and does not use merchant business data to train its own models.

8. Payment data

Merchants connect their own payment-provider accounts (currently Paystack) to PadiDesk. Payments are processed by that provider, not by PadiDesk. In connection with those payments PadiDesk may process:

  • payment references and identifiers
  • amount, currency and payment status
  • transaction verification results returned by the provider
  • the merchant's payment-integration configuration and connection status

PadiDesk does not collect or store full card numbers, card PINs or CVV codes. Payment credentials supplied by a merchant to connect their provider account are stored in encrypted form and used only for that merchant's own transactions. Payment processing is also subject to the payment provider's terms and privacy practices.

9. Login and security data

To keep accounts secure, PadiDesk processes:

  • authentication information handled by our authentication infrastructure
  • session and security events, including sign-in and sign-out
  • multi-factor (authenticator app / TOTP) enrolment state
  • login and security logs
  • IP address, device and request metadata captured in server and webhook logs
  • audit and provenance records showing which account created or changed a record
  • logs of administrative or support access to internal tools

PadiDesk does not run advertising trackers or device-fingerprinting technology.

10. Contact form and support

If you use the contact form or email support, we process the name, email address, optional business name and phone number, and the message you send, together with any diagnostic details you choose to include. Submitting the form sends a confirmation email to the address you provide and a notification to PadiDesk support so we can respond.

11. Why we use information

  • to provide, operate and maintain PadiDesk
  • to authenticate users and protect accounts
  • to run the business-management features a merchant uses
  • to process WhatsApp conversations and execute authorised merchant commands
  • to generate invoices, receipts and reports
  • to initiate and verify payments through a merchant's connected provider
  • to provide customer support and troubleshoot problems
  • to detect, investigate and prevent misuse, fraud and abuse
  • to maintain audit and security records
  • to improve reliability and product quality
  • to send operational notifications and messages you or the merchant request
  • to comply with applicable legal obligations

We do not use this information for advertising profiling or for sale to third parties.

12. Our role in the data

PadiDesk's role differs depending on the information concerned, and a single blanket classification would not be accurate:

  • For account registration, authentication, billing where applicable, platform security, audit logs and support communications, PadiDesk determines the purposes and means of processing.
  • For business records and customer information that a merchant enters or generates in their own workspace, PadiDesk generally processes that information on the merchant's instructions in order to provide the service to that merchant. The merchant decides what to collect and why.

The precise legal characterisation under the Nigeria Data Protection Act 2023 and any other applicable law depends on the specific processing activity, and this section is kept deliberately factual rather than asserting a single legal conclusion.

13. Service providers

PadiDesk relies on the following categories of providers:

  • cloud hosting, database and file storage infrastructure (Supabase, Cloudflare)
  • authentication infrastructure (Supabase Auth)
  • Meta Platforms — WhatsApp Business Platform, for connected business messaging
  • payment processing — Paystack, through each merchant's own connected account
  • transactional email delivery for account, receipt and support emails
  • AI model processing and voice transcription, accessed through the Lovable AI gateway
  • logging and monitoring used to operate and secure the platform

These providers may process information only as needed to supply their services to PadiDesk or to the merchant, subject to their own terms and to the contractual arrangements in place. Providers may change over time; material changes will be reflected here.

14. Cross-border processing

PadiDesk runs on internet infrastructure and uses external providers, so information may be processed or stored in countries other than the country you are in, including outside Nigeria. Where information is transferred across borders, we seek to rely on the safeguards and legal bases available under applicable law, including the Nigeria Data Protection Act 2023, and on the contractual terms offered by our providers. We do not claim that all data remains within Nigeria.

15. Security

Security measures used across the platform include:

  • authenticated access with role and permission controls
  • tenant isolation so a business only sees its own records
  • server-side authorisation for business-changing actions
  • multi-factor authentication for privileged and internal access
  • encryption in transit, and encrypted storage of integration credentials
  • audit logging of sensitive and administrative actions
  • authentication of inbound webhooks and verification of payment callbacks

No online service can be completely secure. We work to protect information but cannot guarantee absolute security, and we ask users to protect their own credentials and devices.

16. Data retention

We retain information for as long as reasonably necessary to provide the service, maintain business and account records, comply with legal obligations, resolve disputes, prevent abuse and keep appropriate security and audit records. Retention differs by category. Specific periods currently applied by the platform include:

  • voice-note audio: deleted after 24 hours by default, configurable per business
  • raw messaging webhook events: deleted after 30 days
  • WhatsApp message content and media references: cleared after 90 days, while the summary record of the conversation remains

Business records such as sales, invoices and payments are retained while the account is active and afterwards where needed for accounting, audit, dispute or legal reasons. Where no fixed period is stated, retention is assessed against the purposes above.

17. Your rights

Depending on your location and applicable law, including the Nigeria Data Protection Act 2023, you may have the right to request:

  • access to the personal information we hold about you
  • correction of inaccurate or incomplete information
  • deletion of personal information
  • objection to, or restriction of, certain processing
  • portability of information you provided, where applicable
  • withdrawal of consent, where processing is based on consent
  • to lodge a complaint with the Nigeria Data Protection Commission or another competent authority

These rights are not absolute. We may need to keep certain information where law, an ongoing dispute, security, fraud prevention or accounting obligations require it, and we will explain the reason where we cannot fully action a request. If the information relates to a business you dealt with through PadiDesk, that business may also need to be involved — see our data deletion page.

Send privacy requests to support@padidesk.com.

18. Merchant responsibilities

Businesses using PadiDesk are responsible for:

  • having a lawful basis to collect and use their customers' information
  • providing any privacy notice their own business is required to give
  • managing staff access and permissions within their workspace
  • not uploading data they are not permitted to process
  • complying with the sector and business rules that apply to them

This does not remove PadiDesk's own obligations for the platform, its security and the information we determine the purposes for.

19. Children

PadiDesk is a business platform intended for businesses and their authorised representatives. It is not directed at children, and we do not knowingly create accounts for or knowingly collect personal information directly from children. If you believe a child's information has been provided to us, contact support@padidesk.com and we will review it.

20. Changes to this policy

We may update this policy as the product, our providers or the law change. When we make material changes we will update the “Last updated” date above and, where appropriate, notify account holders in the app or by email.

Contact

PadiDesk Technologies Limited
House No. 201D, Zone 2, Dantata Estate,
Gwarinpa, Abuja, FCT, Nigeria

WhatsApp support: +2349138086662 (voice calls to this number are not monitored)

Email: support@padidesk.com