Last Updated: January 15, 2025
At eSwipe, protecting your personal data is fundamental to our operations. We recognize that you trust us with sensitive financial information, and we take this responsibility seriously. This document outlines our comprehensive approach to data protection and your rights as a user.
We comply with international data protection standards including GDPR, Rwanda's Data Protection and Privacy Law, and industry-specific regulations for financial services.
We process your personal data based on the following legal grounds:
Processing is necessary to fulfill our contract with you, including:
We must process certain data to comply with legal requirements:
We process data for legitimate business purposes:
For certain processing activities, we obtain your explicit consent:
Our data protection practices are guided by internationally recognized principles:
We process data legally, fairly, and transparently. You always know what data we collect and why.
Data is collected for specific, explicit, and legitimate purposes and not processed in ways incompatible with those purposes.
We only collect data that is adequate, relevant, and limited to what is necessary for the stated purposes.
We take reasonable steps to ensure personal data is accurate and up-to-date. You can correct inaccuracies at any time.
Data is retained only as long as necessary for the purposes for which it was collected, or as required by law.
We implement appropriate security measures to protect against unauthorized access, loss, destruction, or damage.
We demonstrate compliance with data protection principles through documentation, policies, and regular audits.
As an eSwipe user, you have comprehensive rights regarding your personal data:
You can request access to all personal data we hold about you. This includes:
How to exercise: Navigate to Settings → Privacy → Download My Data or email privacy@eswipe.app
Correct inaccurate or incomplete personal information at any time.
How to exercise: Update information in app settings or contact support for assistance
Request deletion of your personal data, subject to legal retention requirements.
Important limitations:
How to exercise: Settings → Privacy → Delete Account or email privacy@eswipe.rw
Receive your data in a structured, machine-readable format (CSV, JSON) for transfer to another service.
How to exercise: Settings → Privacy → Export Data
Limit how we process your data in certain circumstances, such as during accuracy verification or when contesting processing legality.
How to exercise: Email privacy@eswipe.rw with your request
Object to processing based on legitimate interests or for direct marketing purposes.
How to exercise: Settings → Notifications → Manage Preferences
Withdraw consent for processing activities at any time. This does not affect the lawfulness of processing before withdrawal.
How to exercise: Settings → Privacy → Manage Consents
File a complaint with the Rwanda Utilities Regulatory Authority (RURA) if you believe your rights have been violated.
Contact RURA: info@rura.rw or visit www.rura.rw
We process certain sensitive data categories with enhanced protections:
Fingerprints and facial recognition data are processed only with your explicit consent and stored with additional encryption. You can disable biometric authentication at any time.
Payment credentials and transaction data are encrypted using AES-256 and stored in PCI DSS compliant systems.
Precise location is collected only when necessary for fraud detection and only with your permission. You control location access through device settings.
We implement data protection from the earliest stages of system design:
In the unlikely event of a data breach, we have established procedures to:
Immediate identification and impact assessment of the breach
Swift action to contain and mitigate the breach
Affected users notified within 72 hours via email and in-app alert
Notification to relevant authorities as required by law
Thorough investigation to determine cause and prevent recurrence
Dedicated support team to assist affected users
When transferring data internationally, we ensure adequate protection through:
EU-approved contractual terms ensuring data protection compliance
Transfers to countries recognized as providing adequate data protection
Technical and organizational measures equivalent to those in Rwanda
eSwipe uses automated systems for certain decisions. You have the right to:
To request human review: Contact support@ within 30 days of the decision
Name: Jean Paul Mugisha
Email: dpo@eswipe.rw
Phone: +250791700692
Address: KG 123 St, Kigali, Rwanda
Office Hours: Mon-Fri, 8AM-6PM EAT
Authority: Rwanda Utilities Regulatory Authority
Email: info@rura.rw
Website: www.rura.rw
Phone: +250 788 126 200
Address: Airport Road, Kigali
Response Times: We respond to data protection inquiries within 5 business days and complete requests within 30 days, as required by law.
At eSwipe, we believe you should always have control over your personal data. We're committed to transparency, security, and respecting your privacy rights. If you have any questions about how we protect your data, please don't hesitate to contact us.