GDPR Compliance & Your Rights

Last Updated: January 15, 2025

1. GDPR Compliance Overview

eSwipe is fully compliant with the General Data Protection Regulation (GDPR) and Rwanda's Data Protection and Privacy Law. We are committed to protecting your personal data and ensuring your privacy rights are respected.

This page outlines your rights under GDPR and how you can exercise them with eSwipe.

2. Your GDPR Rights

Right to Information

You have the right to be informed about how we collect, use, and process your personal data.

  • Clear information about data collection purposes
  • Legal basis for processing your data
  • Data retention periods
  • Your rights and how to exercise them

Right of Access

You can request access to all personal data we hold about you, including:

  • Account information and transaction history
  • Data categories and processing purposes
  • Recipients of your data
  • Retention periods and data sources

How to exercise: Settings → Privacy → Download My Data or email privacy@eswipe.rw

Right to Rectification

Correct inaccurate or incomplete personal information at any time.

How to exercise: Update information in app settings or contact support for assistance

Right to Erasure (Right to be Forgotten)

Request deletion of your personal data, subject to legal retention requirements.

Important limitations:

  • Financial records must be retained for 7 years per Rwanda law
  • Fraud investigation data may be retained longer
  • Backup copies may persist for up to 90 days

How to exercise: Settings → Privacy → Delete Account or email privacy@eswipe.rw

Right to Data Portability

Receive your data in a structured, machine-readable format (CSV, JSON) for transfer to another service.

How to exercise: Settings → Privacy → Export Data

Right to Restrict Processing

Limit how we process your data in certain circumstances, such as during accuracy verification or when contesting processing legality.

How to exercise: Email privacy@eswipe.rw with your request

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes.

How to exercise: Settings → Notifications → Manage Preferences

Right to Withdraw Consent

Withdraw consent for processing activities at any time. This does not affect the lawfulness of processing before withdrawal.

How to exercise: Settings → Privacy → Manage Consents

3. Automated Decision-Making

eSwipe uses automated systems for certain decisions. You have the right to:

  • Know when automated decisions significantly affect you
  • Obtain human intervention for important decisions
  • Contest automated decisions
  • Receive an explanation of the logic involved

Examples of Automated Decisions:

  • Fraud Detection: Transactions flagged as potentially fraudulent
  • Credit Scoring: Creditworthiness assessments for financial services
  • Spending Classification: Automatic categorization of transactions
  • Risk Assessment: Account security risk levels

To request human review: Contact support@eswipe.rw within 30 days of the decision

4. Data Processing Legal Basis

We process your personal data based on the following legal grounds:

Contractual Necessity

Processing is necessary to fulfill our contract with you, including account management and payment processing.

Legal Obligations

We must process certain data to comply with legal requirements like KYC, AML, and tax reporting.

Legitimate Interests

We process data for legitimate business purposes like fraud detection and service improvement.

Consent

For certain processing activities, we obtain your explicit consent, such as biometric authentication and marketing.

5. Data Breach Notification

In the unlikely event of a data breach, we will:

Immediate Response

Notify affected users within 72 hours via email and in-app alert

Regulatory Reporting

Report to relevant authorities as required by law

Investigation

Thorough investigation to determine cause and prevent recurrence

Support

Dedicated support team to assist affected users

6. International Data Transfers

eSwipe does not sell, rent, or transfer your personal data to third parties for commercial purposes. When data is shared with service providers, we ensure adequate protection through:

🔒

Standard Contractual Clauses

EU-approved contractual terms ensuring data protection compliance

Adequacy Decisions

Transfers to countries recognized as providing adequate data protection

🛡️

Security Safeguards

Technical and organizational measures equivalent to those in Rwanda

7. Contact & Complaints

Data Protection Officer

Email: dpo@eswipe.app

Phone: +250791700692

Address: Kimironko, Kigali, Rwanda

Office Hours: Mon-Fri, 8AM-6PM EAT

Regulatory Authority

Authority: Rwanda Utilities Regulatory Authority

Email: info@rura.rw

Website: www.rura.rw

Phone: +250 788 126 200

Address: Airport Road, Kigali

Response Times: We respond to GDPR requests within 5 business days and complete requests within 30 days, as required by law.

Your Rights, Our Commitment

At eSwipe, we believe your privacy rights are fundamental. We're committed to transparency, security, and respecting your GDPR rights. If you have any questions about your data rights or need to exercise them, please don't hesitate to contact us.