PRYSM AI TECHNOLOGIES
AboutContact

PRYSM AI TECHNOLOGIES LTD · RC 9444284

Privacy Policy

Effective 31 July 2026 · Last updated 31 July 2026

This Policy explains what personal data PRYSM AI TECHNOLOGIES LTD processes, why we process it, who receives it and the choices available to the people concerned. It reflects the services and production configuration reviewed on 31 July 2026.

1. Who is responsible

PRYSM AI TECHNOLOGIES LTD, RC 9444284, Nigeria (“PRYSM”, “we”, “us”) is responsible for the company website, VowLock and ShmuelOps. Contact us at info@prysmai.io or through the details on our Contact page.

Our role changes with the context. We are a data controller for the company website, VowLock customer and service records, ShmuelOps account administration, billing and security, and historical records from the former PrysmAI platform. A business using ShmuelOps normally decides why and how its customers' information is used. For that customer information, the business is the controller and PRYSM acts as its processor, following the business's lawful instructions.

This Policy is written with reference to the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Commission's General Application and Implementation Directive 2025.

2. The PRYSM company website

Information processed

The site is hosted by Vercel. When a page is requested, ordinary hosting and security logs can contain the IP address, request time, requested page, browser and device information, referrer, response status and security signals. We use these records to deliver the site, diagnose failures, prevent abuse and protect the service. Our lawful basis is our legitimate interest in operating a reliable and secure website.

The website currently has no contact form. If you email us, we process your address, message, attachments and our replies to answer you, take requested pre-contract steps, administer a contract, or handle a complaint. The lawful basis is contract where the communication is necessary for a service, and otherwise our legitimate interest in responding and keeping an appropriate business record.

Cookies and analytics

The company landing page does not use analytics, advertising pixels or non-essential cookies. It does not need a cookie banner. A hosting provider may still use strictly necessary technical mechanisms to route, secure or cache a request. If we add non-essential analytics or cookies, we will update this Policy and request consent where required before using them.

3. VowLock

VowLock is commitment software that applies a selected blocking boundary to an enrolled phone or computer. Treating the fact that a person bought or activated VowLock as confidential is important: it can reveal private circumstances even though it does not, by itself, establish any medical condition or reason for using the product.

Purchases and payment verification

For a paid VowLock purchase, we process:

  • the customer email address;
  • the payment reference, amount, currency, status, product code and relevant payment-provider response details;
  • the selected product, platform and commitment period; and
  • an activation-key identifier, purchase channel and whether the key or entitlement has been used.

We use this information to create checkout, verify payment with Flutterwave, prevent duplicate use and fraud, deliver the purchased entitlement, answer support and refund requests, and keep required financial records. The lawful bases are performance of the purchase contract, compliance with legal and accounting obligations, and our legitimate interest in transaction security. Payment-card details are entered on Flutterwave's checkout; VowLock does not receive or store the card number or security code.

Device enrolment and commitments

When a commitment is activated, we process:

  • a device-generated identifier, platform and public key;
  • the activation-key or payment-reference link needed to authorise that device;
  • a commitment ID, selected period, protection-pack identifiers, issue time, start time, end time and status; and
  • signed commitment and release records and activation or redemption timestamps.

Accountless activations use a non-routable technical customer record derived from the device ID; it is not an email address at which a person can be contacted. These records bind a commitment to the right device, calculate and prove its period, prevent key reuse and issue a signed release only when the selected period has ended. The lawful basis is performance of the VowLock contract and our legitimate interest in the integrity and security of the commitment system.

Downloads

VowLock records the product, download key, platform, protection variant, artifact version, artifact path and download time. Its application-level download record does not add an email address, IP address or user-agent. Separate Vercel security and access logs can still contain ordinary request information as described above.

What remains on the device

Blocking is performed locally by operating-system controls and the VowLock software. PRYSM does not receive visited URLs, browsing history, explicit-content activity, trading activity, X/Twitter activity or attempts to open a blocked page or application. A device contacts the VowLock service for activation, trusted-time or signed release checks using commitment identifiers; those requests do not contain the person's browsing activity. VowLock may create local operational logs on the device, but the reviewed clients do not upload those logs to PRYSM.

Who receives VowLock information

Vercel hosts the web and activation service; Turso stores the customer, purchase, device and commitment records; Flutterwave hosts checkout and verifies payment. We also disclose information where required by law, to protect a person or the service, or to professional advisers who are bound to protect it.

4. ShmuelOps

ShmuelOps is a controlled pilot that helps businesses handle customer enquiries and orders through WhatsApp while keeping consequential decisions with people.

Business account and operating information

We process information supplied by an owner or operator, including:

  • name, email address, verification records, account and session information;
  • business name, account settings, team roles, WhatsApp line and connection identifiers;
  • product names, descriptions, images, prices, variants, stock levels, verification times and sources;
  • business rules, reply style, escalation rules, delivery information and owner-approved bank-transfer instructions; and
  • billing references, amounts, currency and status where the business buys an optional paid feature.

We use this data to create and secure the account, deliver access codes, configure the business workflow, ground replies in approved information, administer the pilot, provide support and verify our own charges. The lawful bases are contract, steps requested before a contract, legal obligation for financial records, and legitimate interests in service security and support.

Customer conversations and orders

Depending on what the business and its customers send through the connected line, ShmuelOps processes:

  • WhatsApp account identifiers, customer names and phone numbers;
  • incoming and outgoing message text, reply relationships and delivery status;
  • supported images, documents, voice notes, video or other media and their metadata;
  • requested products, quantities, prices, delivery area or other delivery information, and order status;
  • payment receipts or screenshots where a customer sends them, and the owner's payment-review status; and
  • reply approvals, rejections, human takeovers, failures, retries and operational audit records.

The business using ShmuelOps is responsible for having a lawful basis for this customer processing, giving its customers an appropriate privacy notice and limiting collection to its real sales workflow. PRYSM processes the information to provide ShmuelOps under the business's instructions and contract. We separately control the limited records needed for platform security, billing, abuse prevention and administration.

ShmuelOps is not designed to receive banking passwords, card numbers, card security codes, banking login information, identity documents or unrelated customer chat histories. Businesses and customers must not send them. A bank-transfer receipt can contain personal information; the business should request only what is necessary to verify the relevant order.

AI processing and human review

ShmuelOps sends relevant business setup, inventory, approved payment instructions, order context, recent conversation text and supported product images to Groq for AI generation, image matching and a second review of proposed replies. The system can extract order details and prepare a reply. New live lines begin with supervised controls; a business may later enable guarded sending for a routine reply that passes the product's checks. AI and automated checks can still be wrong.

A person can approve or reject a draft, take over a conversation and correct business information. ShmuelOps does not confirm a customer's bank transfer from a message or receipt alone. Payment confirmation, unusual cases and consequential customer commitments remain with the business owner or a verified payment-provider event.

Who receives ShmuelOps information

Vercel hosts the control plane; Turso stores account, business, conversation, inventory, order and audit state; Resend sends account access emails; Groq performs the AI processing described above; Flutterwave handles PRYSM's optional paid-feature checkout; and the connected WhatsApp service and its controlled linked-device runtime carry messages. Meta/WhatsApp also processes the messages under its relationship with the business and the people using WhatsApp.

5. Former PrysmAI developer platform

The former human-facing product and authentication routes on prysmai.io have been retired. The legacy API domain and known service did not respond during the 31 July 2026 service audit, and PRYSM is not inviting new use of those endpoints. Blocking the old website did not itself erase historical platform records.

Historical records from that platform include account identifiers and email addresses; sessions and chat messages; connected repository names and access permissions; audit requests, reports, traces and source-code excerpts included in those records; usage and security events; API-key hashes; encrypted provider credentials; and GitHub or Google integration tokens. They are used only to secure and decommission the former service, answer a user's request, resolve a dispute, meet a legal obligation or complete an authorised migration. The lawful bases are the former contract, legal obligation and our legitimate interest in secure decommissioning and record integrity.

The verified legacy configuration used Auth0 for identity, Turso for storage, Groq for AI inference, E2B for isolated code-audit execution, GitHub or Google when a user connected those accounts, and Resend for service email. Restoring any legacy processing or moving it to api.prysmai.io requires a fresh operational and privacy review before public use.

6. Retention

We do not apply one invented period to every record. We use the following criteria and delete or anonymise information when the relevant reason ends, subject to a legal hold or a request we are entitled or required to preserve:

  • website security logs follow the hosting and security lifecycle needed to investigate incidents and keep the site reliable;
  • correspondence is kept while the enquiry, transaction or complaint remains active and for the period needed to establish what was agreed;
  • VowLock commitment data is kept through activation and release, then only as needed for transaction records, support, fraud prevention, disputes and legal obligations;
  • payment records are kept for accounting, tax, reconciliation, refunds, charge disputes and other applicable legal duties;
  • ShmuelOps customer content is kept while the business account or controlled pilot needs it and is then deleted or returned according to the business's lawful instructions, except for limited security, billing or dispute records PRYSM must control; and
  • former PrysmAI records are kept only for secure decommissioning, migration, rights requests, disputes or legal obligations.

7. International processing

Some listed providers operate infrastructure outside Nigeria, so personal data can be processed in another country. We limit each transfer to what the service requires, review the recipient and its safeguards, and use the provider's contractual and security commitments. A transfer must have a basis allowed by sections 41–43 of the Nigeria Data Protection Act, such as an applicable adequacy basis, an approved transfer instrument, contractual necessity or another lawful exception. Consent is used only where the law genuinely requires it and the person can make an informed choice.

8. Your rights

Subject to the conditions and exceptions in applicable law, you can ask us to:

  • confirm whether we process your personal data and give you access;
  • correct incomplete or inaccurate information;
  • delete information that no longer has a lawful reason to be kept;
  • restrict processing while an issue is considered;
  • object to processing based on legitimate interests;
  • provide eligible information in a portable, commonly used format;
  • withdraw consent for future processing where consent is the basis; and
  • obtain human intervention and contest a qualifying decision made solely by automated processing.

Email info@prysmai.io. Tell us which service and account, device, order or conversation is involved. We may request proportionate information to confirm identity and authority, particularly where a response could disclose another person's data. A ShmuelOps customer should normally contact the business first; we will assist that business with a valid request.

You can complain to us at the same address. You also have the right to complain to the Nigeria Data Protection Commission, including at info@ndpc.gov.ng.

9. Security

We use measures proportionate to the service, including HTTPS, access-controlled production systems, protected provider credentials, signed and device-bound VowLock commitment records, hashed session or verification secrets where implemented, webhook signature checks, tenant-scoped ShmuelOps records and human approval controls for sensitive operational actions. We restrict production access to people and systems that need it and review unusual failures and abuse.

No internet service is perfectly secure. If a personal-data breach occurs, we will contain and investigate it, preserve an appropriate record, and notify the Nigeria Data Protection Commission and affected people when and within the time required by law.

10. Children and legal capacity

The company website and ShmuelOps business accounts are intended for people and organisations able to enter a binding service agreement. A business must not use ShmuelOps to collect a child's information unless it has a lawful basis, gives the required notice and obtains valid parent or guardian authorisation where required.

VowLock must be installed by the device owner or a person authorised to control the device. Where the intended user lacks legal capacity, a parent or guardian must make the decision and provide any consent required by law. We do not ask a child to make a paid commitment contract independently.

11. Changes and contact

We will revise this Policy when a product, processor or legal duty changes materially. The date at the top will change, and where a change materially affects an active service we will give notice through that service or the relevant business account before the new use begins where practicable.

PRYSM AI TECHNOLOGIES LTD
RC 9444284
Plot M 105, Ewet Housing
By Police Station Division B
Uyo, Akwa Ibom State, Nigeria
info@prysmai.io
+234 816 810 4194

PRYSM AI TECHNOLOGIES LTD · RC 9444284

HomeAbout UsContactRefund PolicyPrivacy PolicyTerms & Conditions