Kairos Privacy Policy

Kairos Privacy Policy as of 24 June 2026

Introduction

Kairos is an AI chatbot and digital ministry support service owned by Witbank SDA Church, a local church within the Northern Conference of South Africa, and managed by the Mission Impact Fund GenZ chatbot team.

This Privacy Policy explains how personal information may be collected, used, disclosed, transferred, stored, and protected when individuals interact with Kairos through WhatsApp and other approved channels such as Telegram, websites, custom applications, or related digital interfaces.

This is a draft for legal review. It should be finalised only after confirmation of the correct responsible party, Information Officer, data flow, operator agreements, retention schedule, children’s-use framework, and cross-border transfer position.

Who We Are and Legal Roles

For purposes of applicable privacy law, including the Protection of Personal Information Act, 2013, the final approved version of this document must identify the correct Responsible Party and the correct Information Officer.

Based on the current project description, Kairos involves multiple entities with potentially different legal roles, including the owner, project management structure, API developer, messaging platform providers, language-model provider, and live-agent handover provider. The final version should clearly identify which entities are operators, independent service providers, or third-party platform environments.

Scope

This Policy applies to personal information processed through Kairos, including information processed when a user sends a message, receives a response, submits a request, is handed over to a live agent, or generates technical logs, support records, or follow-up notes.

Personal Information We May Collect

Depending on the way Kairos is used, the project may collect or process information such as:

  • name or profile name;
  • mobile number or other platform identifier;
  • contact details voluntarily provided by the user;
  • conversation content and user messages;
  • preferences, interests, ministry interests, and follow-up history;
  • prayer requests and spiritual questions;
  • records of interactions, including handover notes and follow-up records;
  • technical information such as timestamps, device or browser-related information, channel source, and system logs;
  • user-submitted content, attachments, or media where enabled;
  • any information voluntarily disclosed by the user in conversation.

Special Personal Information

Kairos operates in a faith-based setting and may process information that could amount to sensitive or special personal information, including information concerning religious or spiritual beliefs. Users may also disclose health, family, emotional, or crisis-related information during interactions.

Such information must be handled with additional care, limited access, and clear purpose justification. Users should be encouraged not to disclose unnecessary sensitive information.

Children and Young Persons

Because Kairos is linked to a GenZ-focused initiative, the final deployment must clearly state whether the service knowingly engages persons under 18. If so, additional controls may be required, including age-appropriate notices, parental or guardian involvement where required by law, restricted functionality, and enhanced moderation or escalation procedures.

How Information Is Collected

We may collect information in the following ways:

  • directly from users when they message or interact with Kairos;
  • through the digital platform used to access Kairos;
  • through system logs, access logs, and related technical records;
  • through records created during support, follow-up, or escalation processes;
  • from authorised project users who record handover or follow-up information;
  • from integrated third-party systems where a handover or continuation of service is required.

Purposes of Processing

Personal information may be processed for purposes including:

  • responding to messages and questions;
  • providing ministry support, information, and engagement;
  • facilitating Bible-study, pastoral, follow-up, or discipleship-related interaction;
  • referring or escalating a conversation to an authorised human agent where appropriate;
  • maintaining continuity in support and communication;
  • monitoring service quality, safety, and platform performance;
  • protecting users, staff, and systems from misuse or abuse;
  • meeting legal, regulatory, governance, security, and reporting obligations;
  • improving workflows, safety measures, moderation, and operational processes;
  • generating de-identified or aggregated reporting where appropriate.

Lawful Grounds for Processing

Personal information may be processed on one or more lawful grounds, including consent, provision of a requested response or support pathway, legitimate and lawful ministry or operational purposes, compliance with law, protection of lawful interests, or another ground recognised by applicable law. The final version should be reviewed by legal counsel to ensure that each stated ground properly matches the actual processing activities.

AI Processing and Automated Responses

Kairos uses artificial intelligence technologies, including language-model services supplied by OpenAI, to generate responses and support conversations. AI-generated outputs may at times be incomplete, inaccurate, unsuitable, or require human review.

Kairos should not be relied upon as a substitute for emergency support, legal advice, medical advice, mental-health treatment, or other regulated professional services.

Third-Party Platforms and Service Providers

Kairos may rely on third-party platforms and service providers, including Meta / WhatsApp, OpenAI, Desgn, Thrive by Adventist Technology, and other approved service providers involved in hosting, analytics, security, maintenance, or operational support.

While the project may implement reasonable safeguards within systems it controls, it does not control every third-party platform environment through which data may pass.

Cross-Border Transfers

Because Kairos uses digital platforms and service providers that may operate in multiple jurisdictions, personal information may be stored, accessed, routed, or processed outside South Africa. The final version of this Policy must be aligned with the project’s verified transfer mechanisms, contracts, and safeguards.

Sharing of Personal Information

Personal information may be shared only where reasonably necessary and lawful, including with authorised project administrators, pastors, chaplains, ministry leaders, approved live agents, contracted operators, service providers, regulators, or safeguarding responders where legally justified. Kairos does not sell personal information.

Data Minimisation and Accuracy

The project should limit collection and use of personal information to what is reasonably necessary for the intended purpose. Reasonable steps should also be taken to keep personal information accurate, relevant, and not misleading.

Security Safeguards

Reasonable technical and organisational measures should be implemented to protect personal information against loss, misuse, unauthorised access, alteration, or disclosure. These may include access control, administrative permissions, logging, contractual confidentiality obligations, secure transmission controls, incident handling procedures, and staff or volunteer training.

Retention and Deletion

Personal information should not be kept longer than necessary for the lawful purpose for which it was collected, subject to legal, safeguarding, dispute, audit, or security requirements. Specific retention periods should be inserted once approved internally and by legal counsel.

User Rights

Subject to applicable law, users may have rights to request access, correction, objection, deletion, restriction, or withdrawal of consent in relevant circumstances. This section should be aligned with the final POPIA process and the project’s operational capacity to receive and respond to such requests.

Direct Marketing and Follow-up Communications

If Kairos or affiliated ministry teams use information for follow-up messages, invitations, campaign messaging, or similar communications, this must be reviewed against applicable legal requirements, including any consent or opt-out rules.

Data Breaches and Incidents

If a security compromise or data incident occurs that creates a risk to personal information, the project should respond in accordance with applicable law, internal procedures, and contractual obligations, including notification where legally required.

Contact Details and Complaints

Questions, objections, access requests, corrections, withdrawal notices, and complaints regarding privacy should be directed to genzbot@nc.adventist.org. Users may also have the right to complain to the Information Regulator of South Africa.