Privacy Policy
This Privacy Policy governs your use of Lacesse products and services.
Introduction & Scope
General Provisions
Welcome to Lacesse Ventures. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our products and services, including Lacesse Workspace, Lacesse Intelligence, Baze, and associated platforms.
We are committed to protecting your privacy in compliance with the Kenya Data Protection Act, 2019 and the EU General Data Protection Regulation (GDPR) where applicable.
Data We Collect
Data Collection
Account Data
- Name, email address, phone number
- Encrypted passwords (we never store passwords in plain text)
Business & Workspace Data
- Website content created through Lacesse Workspace
- Inventory lists and customer data you manage
- AI employee profiles (Lumi, Mark, Akia, etc.)
Financial Data
- We do not store full credit card details
- Payment processing is handled by Paystack
- We store transaction IDs and payment status only
Usage & Device Data
- IP addresses, browser type, device type
- Collected via Cloudflare and Google Analytics
AI Interaction Data
- Prompts and inputs to Lacesse Intelligence models (Fikra series)
- Conversations with AI assistants (Akia, Lumi)
- Note: Training data and user data are handled under separate policies
Data Storage & International Transfers
Data Storage & Processing
Primary Jurisdiction: Kenya
Data protection governed by Kenya Data Protection Act, 2019
Current Infrastructure
- Application Hosting: Frankfurt, Germany (Render)
- Database: Frankfurt, Germany (Neon Inc.)
- Media Storage: US West (Backblaze B2)
- Email: All @lacesse.app emails are rerouted and stored in Gmail (Google Workspace)
🎯 Long-Term Goal
We are actively working to migrate data residency to Kenya (via HostAfrica) to ensure complete data sovereignty within our primary jurisdiction.
Third-Party Data Processors
Third-Party Processors
We work with trusted third-party service providers who process data on our behalf:
Infrastructure & Security
- Cloudflare - DDoS protection, CDN, edge security
- Microsoft - VSCode telemetry (if applicable)
AI & Machine Learning
- HuggingFace, Groq, Fal.ai - Model hosting and inference
- Kaggle - Datasets and training environments
- Nvidia & Meta - Source of open-source model weights (subject to their licenses)
Analytics & Marketing
- Google - Search Console, Trends, Google Analytics
Payments
- Paystack - Payment processing and tokenization
Note: All third-party processors are required to maintain adequate security standards and comply with applicable data protection laws.
How We Use Your Data
Data Collection
We use your data for the following purposes:
- •Service Delivery: To provide, maintain, and improve Lacesse products
- •AI Processing: To power AI employees, generate content, and provide intelligent features
- •Payment Processing: To process transactions via Paystack
- •Security: To detect fraud, prevent abuse, and protect our systems
- •Analytics: To understand usage patterns and improve user experience
- •Communications: To send service updates, support messages, and (with consent) marketing materials
Your Rights (GDPR & Kenya DPA)
User Rights
Under Kenya Data Protection Act, 2019 and GDPR, you have the following rights:
✓ Right to Access
Request a copy of your personal data
✓ Right to Rectification
Correct inaccurate data
✓ Right to Erasure
Delete your data ("right to be forgotten")
✓ Right to Portability
Export your data in a machine-readable format
✓ Right to Restrict Processing
Limit how we use your data
✓ Right to Object
Opt out of specific data uses
To exercise any of these rights, contact us at legal@lacesse.app
Data Retention
Data Storage & Processing
We retain your data as follows:
- Active Accounts: Until account deletion or 5 years of inactivity
- Deleted Accounts: We permanently delete data within 30 days of account deletion, except where required by law
- Payment Records: Retained for 7 years for tax and compliance purposes
- AI Training Data: Anonymized and aggregated data may be retained indefinitely for model improvement
Security Measures
Security Measures
We implement industry-standard security measures:
- 🔒Encryption in Transit:
TLS/SSL (via Cloudflare & Render)
- 🔐Encryption at Rest:
AES-256 (Neon & Backblaze standards)
- 👥Access Control:
Strict internal access policies; minimal personnel access
- 🏠Local Option:
Users concerned about data sovereignty can opt for Lacesse Box (hardware) to keep data within their physical premises
Cookies & Tracking
Cookies & Tracking
Essential Cookies
Required for basic functionality (session management, authentication). These cannot be disabled.
Analytics Cookies
Google Analytics trackers for usage insights. You can opt out via browser settings.
Affiliate Tracking Cookies
Critical for our marketing program: We use cookies to track referrals for the Lacesse Starter Kit.
- Duration: 90 days
- Purpose: Attribute sales and calculate KES 120 commission
Privacy Note: Affiliate cookies do not track personal browsing behavior outside Lacesse domains.
Contact & Data Protection Officer
General Provisions
For privacy inquiries, data requests, or to exercise your rights:
We will respond to all requests within 30 days as required by Kenya Data Protection Act, 2019.
Document Integrity Signature
0816f008e4d3c8c63c74488c758cc1b4cafc9412e3e6ceccfa84d589c3561d4f58c25010120687f756cf4b86291b79c1605bd3b0616ce54e7b7588f989425777
This cryptographic signature verifies document authenticity and prevents tampering.