The Moozy platform and Botswana’s Data Protection Act, 2024
How Moozy processes customer data on behalf of the businesses that use it, where that data lives, and how the platform meets the Data Protection Act, 2024 (Act No. 18 of 2024).
Your customers, Botswana
- Write on WhatsApp, SMS, USSD or web chat, identified by their number or chat ID
Moozy platform, EU
- Holds the conversation in the business’s own isolated tenant
- Drafts replies from the business’s documents, with personal details masked first if chosen
- Every system in a country with an adequacy decision (s. 75)
Partner services, Botswana
- Identity checks and payments run through the customer’s mobile operator, so no transfer arises
The bottom line
- The business that collected the data is the data controller. Moozy is the data processor and acts only on its instructions, under a written agreement (ss. 55, 58).
- Every Moozy system runs in a country that holds an adequacy decision, so each transfer is permitted under s. 75. Partner services stay in Botswana, so no transfer arises there.
- Every record, export and setting is scoped to one business. Nothing one business sees, exports or configures can reach another.
- Customer data never trains a model. Personal details can be masked before a message reaches the AI model, if the business chooses.
- Consent is recorded in the conversation, withdrawal stops the uses that depended on it, and retention is set by the business.
- Audit logs, this note and the records of processing let a business demonstrate compliance to the Commissioner (s. 25).
Summary. The five sections below set out the detail.
The platform and the roles
A business runs its customer service on Moozy. Its customers reach it on WhatsApp, SMS, USSD or the web; Moozy holds the conversation, answers from the business’s own documents and transacts through partners in Botswana.
- The customer writes on WhatsApp, SMS, USSD or web chat, identified by their number or chat ID.
- Moozy holds the conversation in the business’s own isolated tenant, apart from every other business.
- The assistant answers from the business’s documents. An AI model in the EU drafts the reply; personal details can be masked first.
- Transactions run through partners. Identity checks and payments run through the customer’s mobile operator, in Botswana.
- The customer is served without leaving the channel: cover in force, loan applied, question answered.
Who is responsible for what
| Party | Role under the Act |
|---|---|
| The business | Data controller. Decides why customer data is collected and how it is used. First point of contact for access, correction and deletion. |
| Moozy | Data processor. Processes only on the business’s instructions, under a written agreement (ss. 55, 58), and helps it act on every customer request. |
| Our suppliers | Sub-processors. Microsoft (AI model), Hetzner (hosting) and MongoDB (database), each bound by a written data processing agreement. |
Tenant truth is absolute. Every record, export and setting is scoped to one business. Nothing a business sees, exports or configures can reach another.
The data, and where it lives
Section 74 prohibits transferring personal data out of Botswana except where the Act allows it. Section 75 allows transfer to a country that holds an adequacy decision. Every Moozy system sits in such a country, so each transfer is permitted under s. 75, and partner services stay in Botswana, where no transfer arises.
What Moozy processes for a business
| Category | What it holds |
|---|---|
| Identifiers | Phone number, chat ID, name and e-mail where the customer gave them. |
| Conversations and forms | What the customer wrote and the answers they gave, kept for the period the business sets. |
| Identity check results | The outcome returned by the verification provider. Where a check runs through the customer’s mobile operator, Moozy holds the outcome, not the operator’s underlying records. |
| Payments and policies | Mandates, payments, policies and loans, shown exactly as the systems of record hold them. |
| The business’s documents | Product guides and FAQs the business uploads so the assistant can answer from them. |
Where it is processed
| System | What runs there | Country | Basis (ss. 74–75) |
|---|---|---|---|
| Platform servers | Channels, conversations, forms and payment services | Germany | Compliant: s. 75 adequacy |
| Databases | Tenant records and conversation history | South Africa and Germany | Compliant: s. 75 adequacy |
| AI model | Microsoft Azure OpenAI, West Europe. Processed only inside the EU and not used to train models | Netherlands, EU | Compliant: s. 75 adequacy |
| Mobile money and identity checks | Mobile money operators, operator identity checks and airtime | Botswana | Compliant: no transfer |
Built into the platform: protection by design and by default (s. 52)
These controls are how Moozy is built, not options a business has to remember to switch on.
| Control | What Moozy does | Sections |
|---|---|---|
| Tenant isolation at every layer | Every request carries the business’s tenant identity. Records, exports, analytics and settings are separated at the application, service and database level. | ss. 24, 62 |
| Role-based access, fully audited | Staff sign in through single sign-on and see only the modules their role allows. Every access and change is written to an audit log the business can review. | ss. 25, 60 |
| Classified exports | Every report and export carries a classification: Public, Confidential or Restricted. Restricted data leaves the platform only to roles cleared for it. | s. 24 |
| Consent recorded, withdrawal honoured | A customer’s consent is captured in the conversation and stored with their record. When they withdraw it, the uses that depended on it stop. | ss. 27, 28 |
| Masking before AI, if a business wants it | Not required, because the AI model runs in the EU under s. 75. A business can still choose to mask or replace names, numbers and IDs before a message reaches the model, with the reply restored afterwards. | s. 21, optional |
| Retention the business sets | Conversations are kept for the period the business chooses, then deleted. Deleted records pass through a recycle bin before they are purged for good. | s. 23 |
- Encrypted in transit on every link, using TLS.
- No training. Customer data never trains a model.
- White label. Public pages carry the business’s name.
How Moozy meets the Act
Sections 19 to 25 set the principles every controller must be able to demonstrate. As processor, Moozy gives each business the means to do so.
| Principle | On Moozy | Section |
|---|---|---|
| Lawful and transparent | Each business states its purpose and lawful basis in its channel terms and opt-in messages. Moozy records the opt-in and honours opt-out on every channel. | s. 19 |
| Purpose limitation | Data collected for a service is used for that service. Any further use needs the customer’s explicit consent, captured on the platform (s. 27). | s. 20 |
| Data minimisation | Forms ask only what the product needs. Identity checks return an outcome, not documents. Personal details can be masked before AI processing. | s. 21 |
| Accuracy | Payments, policies and mandates are shown exactly as the systems of record hold them. Customers can correct their details through the business. | s. 22 |
| Storage limitation | Retention periods are set per business. Expired records are deleted through a two-stage recycle bin. | s. 23 |
| Integrity and confidentiality | Tenant isolation, role-based access, classified exports and encryption in transit (s. 62). Breaches are notified to the business without delay (s. 63). | s. 24 |
| Accountability | Audit logs, this note and the records of processing (s. 60) let a business demonstrate compliance to the Commissioner. | s. 25 |
Transfers. Every Moozy system is in a country with an adequacy decision (s. 75), and partner services run in Botswana, so no transfer relies on a safeguard (s. 76) or a derogation (s. 78).
People, incidents and contacts
The business a customer dealt with is their first point of contact. Moozy helps that business act on every request and never leaves a customer without an answer.
- Step 1. The customer asks for access, correction, deletion or to stop messages, on the channel they used or by contacting the business.
- Step 2. The business decides. As controller it verifies the request and instructs Moozy. Opt-outs take effect immediately on every channel.
- Step 3. Moozy acts. It exports, corrects or deletes the record and confirms. Deletion requests sent to Moozy directly are acknowledged and routed to the business. Data deletion requests
If something goes wrong
Moozy notifies the affected business without delay with what happened, which records were involved and what has been done, so the business can notify the Commissioner and its customers as s. 63 requires. Sub-processors are bound to notify Moozy on the same terms.
Sub-processors
| Sub-processor | Role | Country |
|---|---|---|
| Microsoft Azure OpenAI | AI model | Netherlands |
| Hetzner Online | Hosting | Germany |
| MongoDB Atlas | Database | South Africa, Germany |
Contact
- Aga Intelligence (Pty) Ltd — Gaborone, Botswana
- Email — info@moozy.ai
- Deletion requests — subject line “Data Deletion Request”
About this note
This note describes how the platform is built and operated as at September 2026. It is not legal advice, and no certification is claimed. Each business remains responsible for its own obligations as controller; Moozy provides the controls and the evidence, and configures journeys to fit them.
Partners, tenants and regulators can request the full compliance note and a data processing agreement from info@moozy.ai. Related reading: Trust and governance Privacy Statement
Questions from data protection officers, risk and IT
Is Moozy a data controller or a data processor?
A data processor. The business that collected the customer data is the controller and decides why it is collected and how it is used. Moozy processes it only on that business’s instructions, under a written agreement, and helps it act on every customer request.
Where is customer data stored and processed?
Platform servers run in Germany, databases in South Africa and Germany, and the AI model in the Netherlands. Each is a country with an adequacy decision, so the transfer is permitted under section 75 of Botswana’s Data Protection Act, 2024. Mobile money and identity checks run through partners in Botswana, so no transfer arises.
Does Moozy transfer personal data out of Botswana lawfully?
Yes. Section 74 prohibits transfers except where the Act allows them, and section 75 allows transfer to a country that holds an adequacy decision. Every Moozy system sits in such a country. No transfer relies on a safeguard under section 76 or a derogation under section 78.
Is customer data used to train AI models?
No. The AI model is processed only inside the EU and customer data is never used to train a model.
Can we mask personal details before AI processing?
Yes, as an option. A business can choose to mask or replace names, numbers and IDs before a message reaches the model, with the reply restored afterwards. It is not required, because the model runs in the EU under section 75, but it is available to any business that wants it.
What happens if there is a data breach?
Moozy notifies the affected business without delay with what happened, which records were involved and what has been done, so the business can notify the Commissioner and its customers as section 63 requires. Sub-processors are bound to notify Moozy on the same terms.
Which sub-processors does Moozy use?
Microsoft Azure OpenAI for the AI model in the Netherlands, Hetzner Online for hosting in Germany, and MongoDB Atlas for the database in South Africa and Germany. Each is bound by a written data processing agreement.
Can we get a data processing agreement?
Yes. Moozy processes under a written agreement with each business, as sections 55 and 58 require. Request the full compliance note and the agreement from info@moozy.ai, and bring your data protection officer to the demo.
Bring your data protection questions to the demo
We will walk through where each kind of data lives, the controls around it and the records you would show the Commissioner, against one of your own journeys.