Privacy Policy
How we collect, process, secure and retain personal data — and the enforceable rights you hold over it under Rwandan law.
Last updated: 17 August 2026
Registration context
On 17 August 2026 Ai7 OPTIVARO submitted its application for registration as both a Data Controller and a Data Processor to the Data Protection and Privacy Office of the National Cyber Security Authority (NCSA), under Law N° 058/2021 of 13/10/2021 relating to the protection of personal data and privacy. This policy reflects the processing activities declared in that application.
1. Introduction & scope
Ai7 OPTIVARO ("we", "us" or "our") is committed to the fair, lawful and transparent processing of personal data in strict compliance with the Rwandan Law N° 058/2021 of 13/10/2021 relating to the Protection of Personal Data and Privacy.
This Privacy Policy details how we handle personal data collected from prospective business clients, website users, partners and systems users when acting in our capacity as a Data Controller. Where we build, host or operate automation systems on behalf of a client, that client is the controller and we act as a Data Processor under a written data processing contract, processing personal data only on their documented instructions.
This policy applies to this website, our enquiry forms, our client onboarding and billing operations, and the automation systems we operate.
2. Controller identity and Data Protection Officer
The data controller is Ai7 OPTIVARO, a public company limited by shares registered in Rwanda on 2 March 2026 — RDB Registration No. 260611043184510, TIN 155865378 — with its registered office at Nyabisindu, Remera, Gasabo, City of Kigali. Our declared sector is Information & Communication Technology (ICT) / data processing activities. We also operate from KG 313 St, Kibagabaga, Kigali and 50 KK 15 Rd, Sonatube, Kicukiro, Kigali. General company enquiries: info@ai7optivaro.com.
We have designated a Data Protection Officer responsible for overseeing compliance with Law N° 058/2021, handling data subject requests and acting as the contact point for the supervisory authority. The Data Protection Officer can be reached at:
- Email: eddie@ai7optivaro.com(mark your message “Data Protection Officer”)
- Telephone: +250 783 282 759
- Post: The Data Protection Officer, Ai7 OPTIVARO, Nyabisindu, Remera, Gasabo, City of Kigali, Rwanda
3. Categories of data subjects and personal data we collect
We process data obtained directly from you or through automated interactions. We limit our data collection strictly to what is necessary for the purposes set out in this policy.
Categories of data subjects: prospective business clients, website users, invoiced partners, and the end-users of systems we operate on behalf of our clients.
- Source of collection: data is gathered directly when you input details into our enquiry forms, when you contact us by email, phone or WhatsApp, or through your direct system integrations.
- Identity & corporate data: full names, company name, corporate role/title and organisational operational profiles.
- Contact information: business email addresses and operational mobile phone numbers.
- Technical pipeline identifiers: system API access tokens, IP addresses, browser configurations and diagnostic integration logs.
Sensitive personal data:we do not collect, store or process any categories of sensitive personal data as defined under Article 3 of Law N° 058/2021 — this was declared “not applicable” in our registration application. Please do not include such data in enquiry forms or messages. If sensitive data reaches us unsolicited, we delete it promptly unless we are legally required to retain it.
We do not collect payment card details through this website.
4. Purpose and legal grounds for processing
In strict accordance with Article 4 and Article 5 of Law N° 058/2021, your personal data is processed exclusively under the three legal bases declared in our registration application:
- Consent: when you voluntarily input your details via our online forms to request a free business AI workflow audit, and for non-essential analytics cookies. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Contractual necessity: to execute service agreements, client onboarding, service delivery scoping, billing and invoicing, and service-level tracking.
- Legitimate interest: for B2B lead generation, website auditing, corporate communication management, verifying secure platform traffic and maintaining overall platform stability — balanced against your rights and freedoms, and subject at all times to your right to object.
Where Rwandan law separately requires us to keep records — principally tax and company records — we retain them for that period only, as described in section 9.
We do not sell, rent or trade personal data, and we do not share it with advertising networks or data brokers.
5. Automated decision-making and AI profiling
As an artificial intelligence automation agency, we utilise algorithmic workflows to score business readiness for AI tool integration. However, Ai7 OPTIVARO does not engage in automated decision-making that produces adverse legal effects, or that significantly affects individuals, without active human intervention, strictly upholding data subject rights under Law N° 058/2021.
Every material outcome affecting a person or a business is reviewed and approved by a member of our team before it is acted upon. You may at any time request human review of, or contest, any output that concerns you by contacting our Data Protection Officer.
6. Who we disclose data to
We disclose personal data only to the following categories of recipient, and only so far as each disclosure is necessary:
- Regulators and supervisory authorities — including the Rwanda Revenue Authority (RRA) and the National Cyber Security Authority (NCSA), where disclosure is required by law or requested under a lawful power.
- Internal auditors — for statutory audit and financial control purposes.
- Cloud infrastructure and service providers — acting strictly as processors on our documented instructions (see section 7).
- Our clients — where we process data as their processor, the data belongs to them and is returned or deleted on their instruction.
We do not disclose personal data to any other party without your instruction or a legal requirement to do so.
7. Service providers and subprocessors
We engage a limited number of service providers strictly as processors acting on our documented instructions. They are bound by written data processing contracts, may not use your data for their own purposes, and are subject to due-diligence review before engagement:
- Hosting and content delivery — for serving this website.
- Database and authentication — for securely storing enquiries and client records.
- Form delivery and enquiry notification — a third-party form service that relays your enquiry to our inbox so nothing is missed.
- Corporate email and document storage — for replying to you and holding correspondence.
- Invoicing and payment processing — for billing clients. Card details are handled by the payment provider, never stored by us.
- Workflow automation — operated on infrastructure under our own administrative control, for routing enquiries to a human responder.
- Website analytics — activated only where you have given consent (see section 12).
A current, itemised list of subprocessors — including entity names and processing locations — is available to clients and to the supervisory authority on request from our Data Protection Officer. We notify clients in advance of any change to subprocessors that affects their data.
8. Security, storage and cross-border transfers
We utilise the technical and organisational measures declared in our registration application to ensure your data remains confidential and structurally resilient:
- Encryption: Transport Layer Security (TLS 1.3) in transit and Advanced Encryption Standard (AES-256) at rest.
- Authentication: multi-factor authentication (MFA) on corporate accounts, and secure management of API tokens.
- Access control: role-based operational access privileges, row-level access control in our database, and staff access granted on a least-privilege, need-to-know basis. Credentials are never exposed in the browser.
- Platform hardening: this website is served exclusively over HTTPS with HTTP Strict Transport Security, a strict Content Security Policy, MIME-sniffing and clickjacking protections, and a restrictive permissions policy that disables camera, microphone and location access. Access to production systems is logged.
Cross-border storage and transfer. For cloud architecture and corporate messaging, personal data may be stored or processed by cloud providers located in the United States and European Union countries. This was declared in our registration application, and we maintain written data processing contracts with those providers. Law N° 058/2021 requires a separate authorisation from the NCSA to store or transfer personal data outside Rwanda: that authorisation application is being prepared for submission, and we will operate in line with the conditions attached to it once issued.
9. Data retention
Personal data collected for B2B prospecting or operations is retained only for as long as necessary to fulfil the business profiling purpose. Client operational data is systematically purged within ninety (90) days of contract termination, unless extended retention is legally mandated — principally by the Rwanda Revenue Authority (RRA) for statutory audit tracking, and by company law for annual returns and accounts.
Retention periods are reviewed periodically, and data that no longer serves a lawful purpose is securely deleted. You may request earlier deletion at any time under section 10.
10. Statutory rights of the data subject
Under Chapter V of Law N° 058/2021, you possess enforceable legal rights regarding your data:
- Right of access: you may request written confirmation of the specific items of data we hold about you, and obtain a copy.
- Right to rectification: you may demand immediate updates to inaccurate or outdated personal data.
- Right to erasure (“right to be forgotten”): you may demand the permanent deletion of your data from our systems.
- Right to object / withdraw consent: you may opt out of our business marketing pipelines at any time.
- Right to restriction: you may ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Right to data portability: you may request the data you provided to us in a structured, commonly used, machine-readable format.
- Right to human review: you may contest any automated output concerning you and request review by a member of our team.
How to exercise these rights. File a formal request with our designated Data Protection Officer at eddie@ai7optivaro.com. We acknowledge requests promptly and respond within thirty (30) days of receipt, free of charge. Where a request is complex we may extend this period once, and will tell you why before the initial period expires. To protect your data we may ask for reasonable proof of identity before acting on a request, and we will use that proof for no other purpose.
11. Security breaches and incident notification
In the event of a data security incident or unauthorised access, Ai7 OPTIVARO maintains an active Incident Response Framework covering the risks declared in our registration application — unauthorised access, data leakage, malicious credential exploitation and theft. We log every incident in an internal breach register and notify affected data subjects and the NCSA within forty-eight (48) hours of discovery, as required by Law N° 058/2021.
Our notification will describe the nature of the incident, the categories of data concerned, the likely consequences, and the remedial measures taken or proposed. If you believe your data has been affected, contact our Data Protection Officer immediately at eddie@ai7optivaro.com.
12. Cookies and website analytics
Analytics only run if you say yes.When you first visit, we ask. Until you choose “Accept”, the Google Analytics script is never loaded at all — Google is not contacted, no analytics cookies are set, and nothing about you is collected. As a second layer, a consent signal defaulting to deniedis set in the page head before any tag could run. If you choose “Decline”, we remember that and never ask again.
If you accept, we use Google Analytics to see which pages are useful — page views, roughly where visitors come from, and which buttons get clicked. We do not use advertising cookies, ad personalisation or cross-site tracking pixels for profiling. Those are switched off explicitly, not merely left unused.
Changed your mind? Clear this site's data in your browser settings and we'll ask again on your next visit. The site works exactly the same either way — declining costs you no functionality.
13. Children's data
Our services are directed at businesses and organisations, not at children. We do not knowingly collect personal data from anyone under the age of eighteen (18). If we become aware that we hold such data without the consent required by law, we delete it without undue delay.
14. Complaints and the supervisory authority
If you are concerned about how we handle your data, contact our Data Protection Officer first at eddie@ai7optivaro.com — we investigate every complaint and aim to resolve it within thirty (30) days.
You do not have to come to us first. For any unresolved complaint regarding our processing methods, you have the right to lodge a formal complaint with the Data Protection and Privacy Office under the National Cyber Security Authority (NCSA) via their official channels: complaint@dpo.gov.rw.
15. Changes to this policy
We review this policy at least annually, whenever our processing activities change materially, and whenever our registration status with the NCSA changes. If we change it, we will update the “last updated” date at the top of this page. Material changes affecting existing clients or requiring fresh consent will be communicated directly before they take effect.