Data protection policy

Version 1.0, effective 1 October 2026. Zafrionet Ltd, Kigali, Rwanda. Reviewed annually.

This policy sets out how Zafrionet Ltd handles personal data in SwiftPass. The privacy policy tells users what we do with their information; this document sets the internal standard we hold ourselves to, and is written to be read by staff, partners and regulators alike.

Scope

This policy applies to all personal data processed through SwiftPass and to everyone who handles it: employees, contractors, and anyone given access to production systems. It covers the attendee app, the seller and organiser apps, the gate app and the platform console.

Zafrionet Ltd is the data controller. Centrika Ltd is an independent controller for payment data it processes under its own licence from the National Bank of Rwanda.

Principles

Every decision about personal data in SwiftPass is measured against the principles in Law No. 058/2021:

  • Collect for a stated purpose. If we cannot name the purpose in one sentence, we do not collect the field.
  • Collect the least that works. A field that is merely useful is not a field we are entitled to.
  • Keep it accurate. Users can correct their own profile, and we correct anything reported to us.
  • Keep it only as long as needed. Retention periods are written down, not left to habit.
  • Keep it secure. Set out in section 6.
  • Be able to show all of the above. Section 12.

Lawful basis

ProcessingBasis
Running the wallet and settling payments Performance of a contract
Verifying identity, retaining transaction records Legal obligation
Fraud detection, service security Legitimate interest
Product announcements by email Consent, withdrawable at any time

Where we rely on legitimate interest, we record the balancing assessment that led to it and review it when the processing changes.

What we do not collect

Stating the absences is as useful as listing the presences, because an absence is a decision someone could quietly reverse.

  • No location data. The app requests no location permission on either platform.
  • No contacts. Recipients are found by SwiftPass handle, typed or scanned, never by reading an address book.
  • No advertising identifiers and no third-party advertising or analytics SDKs.
  • No readable PIN. Stored as a one-way hash. Nobody at Zafrionet can recover it.
  • No card numbers. Card payments happen entirely on the payment provider's page; card details never reach our systems.
  • No biometric or identity-document data in the current version of the service.

Who can see what

RoleCan see
The user Their own profile, balance, transactions, bands and tickets. Nothing belonging to anyone else.
A seller Their own takings and sales. For each sale: the amount and enough to identify the payer for a refund. Not the payer's balance, contact details or other transactions.
An organiser Their own events, ticket sales and admissions. Not the attendee's wallet.
Zafrionet support What is needed to answer a specific query, on a request-by- request basis. Access is recorded.
Zafrionet engineering Production access limited to named individuals, used for incident response rather than routine work.

Separation of duties applies to money: the people who can approve a payout are not the people who reconcile it.

Technical controls

  • Server-authoritative balances. No client can write to a wallet or a ledger. Database rules deny it outright, so a modified app can display a wrong number but cannot make one true.
  • Field-level rules. Sensitive fields — the PIN hash, attempt counters, business grants, payout details — are server-owned and denied to clients even on the user's own record.
  • Encryption in transit and at rest.
  • Secrets management. Payment API keys live in a managed secret store, are never in source control, and are never sent to a client.
  • Double-entry ledger. Every balance change writes a matching record, so an unexplained balance is detectable rather than invisible.
  • Own-number withdrawals. Money can only leave a wallet to the account holder's own registered mobile money number.
  • Rate limiting and lockout on PIN attempts and on payment initiation.

Processors

ProcessorPurposeData
Google (Firebase / Google Cloud) Hosting, database, authentication, notifications All service data
Centrika Ltd (XentriPay) Collecting and disbursing payments Name, phone, email, amount, reference

Each has a written agreement covering confidentiality, security and the return or deletion of data. We assess a new processor before engaging it and record that assessment.

Transfers abroad

Some data is stored on Google Cloud infrastructure outside Rwanda. We rely on the safeguards permitted under Law No. 058/2021 and require equivalent protection by contract. We review this arrangement annually and whenever the residency requirements applying to financial data in Rwanda change.

Retention and disposal

CategoryPeriodThen
Account profileLife of the account Deleted on closure
Transaction and ledger records10 years Deleted
Payment intents and payout records10 years Deleted
Band assignment history10 years Deleted
Support correspondence3 years Deleted
Technical and security logs12 months Deleted

On account closure, profile data is deleted and retained financial records are decoupled from it so far as the law permits.

Handling data subject requests

  1. Received By email to info@zafrionet.com, or in the app. Logged on arrival.
  2. Identity verified We confirm the requester controls the account. We do not act on unverified requests — doing so would be the breach.
  3. Assessed We establish what is held, and what must be retained by law regardless of the request.
  4. Answered within 30 days With the data, the correction, or a written reason if we cannot comply in full.

Where we refuse in part, we say which part and why, and we tell the person they may complain to the National Cyber Security Authority.

Breaches

A personal data breach means any unauthorised access to, disclosure of, alteration of, or loss of personal data.

  • Contain — revoke access, rotate credentials, stop the bleeding, before anything else.
  • Assess — what data, how many people, what harm is plausible.
  • Notify the supervisory authority within the period required by Rwandan law.
  • Notify affected users in plain language where there is a risk to them, saying what happened, what it means for them, and what to do.
  • Record every breach, including ones we decide not to notify, with the reasoning.
  • Fix — a written remediation with an owner and a date.

Suspected breaches go to info@zafrionet.com immediately. Reporting early and being wrong costs an hour. Reporting late and being right costs considerably more.

Accountability

  • A named person at Zafrionet is responsible for data protection and is the contact point for users and for the supervisory authority.
  • We maintain a record of processing activities: what we hold, why, on what basis, who it goes to and for how long.
  • New features that introduce a new category of personal data get an impact assessment before they ship, not after.
  • Everyone with production access is briefed on this policy on joining and annually.
  • This policy is reviewed every year and whenever the law, our processors, or the product change materially.

Data protection contact

Zafrionet Ltd, Kigali, Rwanda
info@zafrionet.com

Supervisory authority: National Cyber Security Authority, Rwanda.