Legal

Privacy Policy

Tally AI Limited  ·  RC 9492510  ·  Effective: April 2026  ·  Version: 2.1  ·  Last updated: April 2026

Important: This Privacy Policy governs how Tally AI Limited collects, processes and protects your personal data. By using our Service, you agree to the practices described here. If you do not agree, please discontinue use of the Service.

Contents
  1. Introduction and Identity of Data Controller
  2. Data Protection Officer
  3. Scope of This Policy
  4. Information We Collect
  5. Lawful Bases for Processing
  6. How We Use Your Information
  7. Consent
  8. Data Retention
  9. Third-Party Service Providers
  10. Cross-Border Data Transfers
  11. Data Breach Notification
  12. Your Rights
  13. Data Security
  14. Cookies and Tracking
  15. Changes to This Policy
  16. Complaints
  17. Contact Us

1. Introduction and Identity of Data Controller

Tally AI is an artificial intelligence-powered financial management service delivered via WhatsApp and web platforms, operated by Tally AI Limited ("Company", "we", "us", or "our"), a company incorporated in Nigeria (RC 9492510).

As the operator of this Service, Tally AI Limited acts as the Data Controller in relation to personal data processed through Tally AI, in accordance with the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023.

Company
Tally AI Limited
RC Number
9492510
Service
Tally AI
Website
www.tallyai.ng

2. Data Protection Officer

In compliance with Section 32 of the Nigeria Data Protection Act (NDPA) 2023, Tally AI Limited has designated a Data Protection Contact responsible for overseeing compliance with applicable data protection laws and handling data subject requests.

All data protection queries, rights requests, and complaints should be directed to: [email protected]

3. Scope of This Policy

This Privacy Policy applies to all personal data collected and processed when you use the Tally AI WhatsApp bot, access the web dashboard at tallyai.ng, register for an account, subscribe to any plan, contact our support team, or otherwise interact with our Service.

4. Information We Collect

4.1 Information You Provide Directly

4.2 Voice Note Data

Important: When you send a voice note, we process audio data for transcription. See Section 7 on Consent and Section 9 on Third-Party Services for full details.

4.3 Information We Do NOT Collect

5. Lawful Bases for Processing

In accordance with Article 2.2 of the NDPR 2019, we process your personal data only where we have a lawful basis to do so:

Processing ActivityLawful BasisDetails
Account creation and managementContract (Art. 2.2(b) NDPR)Necessary to provide the Service
Transaction loggingContract (Art. 2.2(b) NDPR)Core service functionality
Sending notificationsLegitimate Interest (Art. 2.2(f) NDPR)Budget alerts and summaries you request
Voice note transcriptionConsent (Art. 2.2(a) NDPR)Explicit consent obtained at onboarding
AI-powered intent detectionContract (Art. 2.2(b) NDPR)Necessary to process natural language
Payment processingContract (Art. 2.2(b) NDPR)Necessary for subscription billing
Security and fraud preventionLegitimate Interest (Art. 2.2(f) NDPR)Protecting users and the platform
Legal complianceLegal Obligation (Art. 2.2(c) NDPR)Required by applicable Nigerian law

6. How We Use Your Information

We use your information solely to provide and operate the Tally AI Service, process and categorise financial transactions, generate financial reports and summaries, send budget alerts and notifications, personalise your experience in your preferred language, respond to support requests, maintain security and prevent fraud, comply with applicable Nigerian law, and improve the Service through aggregated anonymised analysis.

We do not use your personal data for advertising purposes. We do not sell your personal data to third parties.

7. Consent

7.1 Voice Note Consent

Before processing your first voice note, Tally AI will request your explicit consent to share audio content with Groq Inc. for transcription purposes. This consent is freely given, specific, informed, and unambiguous. You may continue using the Service via text without providing consent.

7.2 Withdrawal of Consent

You may withdraw consent at any time by sending "no voice notes" to the Tally AI bot, or by contacting [email protected]. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

7.3 Children

Our Service is not directed at persons under 18 years of age. We do not knowingly collect personal data from minors.

8. Data Retention

We retain your personal data in accordance with the NDPC General Application and Implementation Directive (GAID) 2025:

Data TypeRetention PeriodBasis
Transaction data6 months after account closureNDPC GAID 2025
Account information6 months after account closureNDPC GAID 2025
Voice note audioDeleted immediately after transcriptionData minimisation
Session data24 hours after inactivityOperational necessity
Audit logs12 monthsLegal obligation
Payment records7 yearsCAMA 2020 / FIRS requirements

9. Third-Party Service Providers

We share your data only with trusted third-party processors bound by Data Processing Agreements (DPAs) in accordance with Article 2.7 of the NDPR 2019:

ProviderPurposeData SharedLocationDPA
Twilio Inc.WhatsApp message deliveryPhone number, message contentUnited StatesYes
Anthropic PBCAI intent detectionMessage text onlyUnited StatesYes
Groq Inc.Voice note transcriptionAudio content (not stored)United StatesYes
Paystack Inc.Payment processingName, payment informationNigeriaYes

10. Cross-Border Data Transfers

Some of our processors are located in the United States. We safeguard cross-border transfers through Data Processing Agreements requiring processors to maintain data protection standards equivalent to Nigerian law, and by limiting data shared to the minimum necessary for the specific purpose.

11. Data Breach Notification

In compliance with Section 40 of the NDPA 2023, where a data breach is likely to result in risk to data subjects, we will notify the Nigeria Data Protection Bureau (NDPB) within 72 hours of becoming aware of the breach, and notify affected users directly without undue delay.

12. Your Rights

You have the following rights under the NDPR and NDPA. We will respond to all valid requests within 14 days of receipt:

RightDescription
AccessRequest a copy of the personal data we hold about you
RectificationRequest correction of inaccurate or incomplete data
ErasureRequest deletion of your personal data
PortabilityReceive your data in a machine-readable format
ObjectObject to processing based on legitimate interests
Withdraw ConsentWithdraw consent at any time for consent-based processing
ComplainLodge a complaint with the NDPB at www.ndpb.gov.ng

To exercise any right, contact [email protected] with your name, phone number, and description of your request.

13. Data Security

We implement appropriate technical and organisational security measures including encrypted data transmission via HTTPS/TLS, secure password hashing, JWT-based authentication, firewall protection, automated intrusion detection, and access controls. No method of electronic transmission is 100% secure, but we strive to use commercially acceptable means to protect your data.

14. Cookies and Tracking

Our WhatsApp bot does not use cookies. Our web dashboard uses only essential cookies required for authentication and session management, and Google Analytics for aggregated, anonymised traffic analysis. We do not use advertising or tracking cookies that identify individual users.

15. Changes to This Policy

This is a living document updated to reflect changes in our operations and legal requirements. When we make material changes, we will update the "Last Updated" date, notify active users via WhatsApp at least 14 days before changes take effect, and obtain fresh consent where required by law.

16. Complaints

If you are dissatisfied with how we have handled your personal data, you may contact our DPO at [email protected] or lodge a complaint with the Nigeria Data Protection Bureau (NDPB) at www.ndpb.gov.ng.

17. Contact Us

Data Protection
General Enquiries
Website
www.tallyai.ng
Regulator
Nigeria Data Protection Bureau — www.ndpb.gov.ng