This Privacy Policy explains how Ikofi App Ltd("we", "us", "our") processes personal data when you use the iKofi advertiser web portal (the "Portal"). It should be read together with our Terms of use.
This policy is designed to align with Rwanda's Law No. 058/2021 of 13 October 2021 relating to the protection of personal data and privacy ("Rwanda Data Protection Law"). Regulatory references and authority names may change; your counsel should confirm current filing or registration obligations and the correct complaint body.
1. Who we are (data controller)
Controller: Ikofi App Ltd
Address: Kigali, Rwanda
Contact (privacy): team@ikofi.app
If we appoint a Data Protection Officer (DPO), we will publish their contact details here. Until then, privacy requests may be sent to the email address above.
2. Scope
This policy covers personal data we process about advertiser account users(for example, individuals who register or log in on behalf of a business). It does not describe in detail how we process End Users' personal data in the consumer iKofi mobile application; that information should appear in the consumer-facing privacy notice for that app.
3. Personal data we collect
Depending on how you use the Portal, we may process:
- Account and identity data: business name, email address, password (stored using industry-standard hashing on our systems; we do not store your password in plain text), and similar profile fields you provide.
- Authentication and session data: security tokens and related identifiers used to keep you signed in. In your browser, session information for the Portal may be stored in local storage to maintain your login state.
- Advertising and wallet data: information you submit about campaigns, creatives, or offers; Wallet balance and top-up history in RWF; transaction references and statuses related to payments.
- Payment data: when you add funds, payment details are collected and processed by PawaPay using their Mobile Money checkout. We typically receive limited payment metadata (for example, confirmation status, amounts, timestamps, and identifiers needed for reconciliation) rather than your full Mobile Money credentials.
- Technical and usage data: IP address, device and browser type, dates/times of requests, diagnostic logs, and similar information generated when you interact with our servers or infrastructure. Exact fields depend on server configuration and should be confirmed internally.
- UI preference cookie: the Portal may store a cookie named
sidebar_stateto remember dashboard sidebar layout. This cookie is not used for third-party advertising analytics in the Portal code we operate today.
4. Why we process personal data (purposes)
We process personal data to:
- create and administer advertiser accounts;
- authenticate users and secure the Portal;
- provide Wallet functionality, record top-ups, and prevent fraud;
- deliver, measure, and improve advertising services and placements;
- comply with legal obligations (including tax, accounting, and regulatory requests);
- enforce our Terms of use and defend legal claims.
5. Legal bases (Rwanda Data Protection Law)
We rely on one or more of the following, as applicable to the specific processing activity: performance of a contract (providing the Services you request); legal obligation; legitimate interests (for example, securing our systems, preventing abuse, and improving the Services), where those interests are not overridden by your fundamental rights and freedoms; and consent, where we expressly request it (for example, certain optional communications if we add them). Where consent is the basis, you may withdraw it without affecting processing that occurred before withdrawal.
6. Sharing and processors
We may share personal data with:
- PawaPay and other payment service providers, strictly as needed to process payments you initiate.
- Hosting, infrastructure, and communications providers that help us operate the Portal and store data.
- Professional advisers (lawyers, auditors) where required.
- Authorities when we believe disclosure is required by law or is necessary to protect rights, safety, and security.
We require processors to implement appropriate confidentiality and security measures and to process personal data only on our instructions, except where law requires otherwise.
7. International transfers
Some service providers may process data in countries other than Rwanda. Where Rwanda Data Protection Law requires safeguards for such transfers, we will implement appropriate measures (such as contractual clauses or other mechanisms recognised by law). Details can be provided on request where we are permitted to disclose them.
8. Retention
We retain personal data only as long as necessary for the purposes described in this policy, including to satisfy legal, accounting, or reporting requirements. For example:
- Account data is kept while your account is active and for a reasonable period afterwards to resolve disputes and enforce terms.
- Financial records may be retained for longer periods where required by tax or commercial law.
- Security logs may be retained for a limited period consistent with security needs and legal obligations.
9. Security
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. No method of transmission over the Internet is completely secure; we cannot guarantee absolute security.
10. Your rights
Subject to Rwanda Data Protection Law and applicable exceptions, you may have rights to request access to your personal data, rectification of inaccuracies, erasure, restriction of processing, objection to certain processing, and data portability where applicable. You may also have the right to lodge a complaint with the competent supervisory authority in Rwanda.
To exercise rights, contact team@ikofi.app. We may need to verify your identity before responding. We will respond within timelines required by law where applicable.
11. Children
The Portal is intended for business users and is not directed to children. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us and we will take appropriate steps to delete it.
12. Automated decision-making
We do not use solely automated decision-making that produces legal or similarly significant effects concerning you as described in the Portal today. If that changes, we will update this policy and provide information required by law.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will revise the "Last updated" date at the top of this page and, where changes are material, provide additional notice as required by law (which may include email or an in-Portal notification).
Effective date: 14 May 2026. For the previous version history, retain internally or publish an archive if your counsel recommends it.