The Moozy platform and Botswana’s Data Protection Act, 2024

How Moozy processes customer data on behalf of the businesses that use it, where that data lives, and how the platform meets the Data Protection Act, 2024 (Act No. 18 of 2024).

Compliance note: September 2026     Prepared for: partners, tenants and regulators     Applicable law: Data Protection Act, 2024

Your customers, Botswana

  • Write on WhatsApp, SMS, USSD or web chat, identified by their number or chat ID

Moozy platform, EU

  • Holds the conversation in the business’s own isolated tenant
  • Drafts replies from the business’s documents, with personal details masked first if chosen
  • Every system in a country with an adequacy decision (s. 75)

Partner services, Botswana

  • Identity checks and payments run through the customer’s mobile operator, so no transfer arises

Questions from data protection officers, risk and IT

Is Moozy a data controller or a data processor?

A data processor. The business that collected the customer data is the controller and decides why it is collected and how it is used. Moozy processes it only on that business’s instructions, under a written agreement, and helps it act on every customer request.

Where is customer data stored and processed?

Platform servers run in Germany, databases in South Africa and Germany, and the AI model in the Netherlands. Each is a country with an adequacy decision, so the transfer is permitted under section 75 of Botswana’s Data Protection Act, 2024. Mobile money and identity checks run through partners in Botswana, so no transfer arises.

Does Moozy transfer personal data out of Botswana lawfully?

Yes. Section 74 prohibits transfers except where the Act allows them, and section 75 allows transfer to a country that holds an adequacy decision. Every Moozy system sits in such a country. No transfer relies on a safeguard under section 76 or a derogation under section 78.

Is customer data used to train AI models?

No. The AI model is processed only inside the EU and customer data is never used to train a model.

Can we mask personal details before AI processing?

Yes, as an option. A business can choose to mask or replace names, numbers and IDs before a message reaches the model, with the reply restored afterwards. It is not required, because the model runs in the EU under section 75, but it is available to any business that wants it.

What happens if there is a data breach?

Moozy notifies the affected business without delay with what happened, which records were involved and what has been done, so the business can notify the Commissioner and its customers as section 63 requires. Sub-processors are bound to notify Moozy on the same terms.

Which sub-processors does Moozy use?

Microsoft Azure OpenAI for the AI model in the Netherlands, Hetzner Online for hosting in Germany, and MongoDB Atlas for the database in South Africa and Germany. Each is bound by a written data processing agreement.

Can we get a data processing agreement?

Yes. Moozy processes under a written agreement with each business, as sections 55 and 58 require. Request the full compliance note and the agreement from info@moozy.ai, and bring your data protection officer to the demo.

Bring your data protection questions to the demo

We will walk through where each kind of data lives, the controls around it and the records you would show the Commissioner, against one of your own journeys.