Legal

Privacy Policy

Effective date: [TODO: effective date]. This is a first-draft template pending legal review — see the notice in Section 1 before relying on it.

Draft notice. This page is a first-draft legal template prepared for Valkern OS. It is not a substitute for advice from qualified legal counsel in Rwanda and the United States, and every [TODO: placeholder] below must be completed before this document is published as final. The authoritative version of this document is the English version; any translation is provided for convenience.

1. Who we are

Valkern OS(“Valkern”, “we”, “us”) is operated by two affiliated companies, each responsible for the customers in its region:

  • Urugero & Family Ltd, registered in Rwanda (registration number [TODO: Urugero & Family Ltd RDB registration number], registered address [TODO: registered address, Rwanda]), contracts with and is the data controller for customers located in Rwanda and the rest of East Africa.
  • Fivorana LLC, a Wyoming, USA limited liability company (registration number [TODO: Fivorana LLC Wyoming registration number], registered address [TODO: registered address, Wyoming, USA]), contracts with and is the data controller for international customers (customers outside Rwanda and East Africa).

For privacy questions, data subject requests, or complaints, contact us at [TODO: DPO / privacy contact email], or via our general contact address [email protected].

2. Data we collect

We collect the following categories of data:

  • Account data— name, email address, phone number, organization name, role, and authentication data (e.g. hashed passwords, passkey public keys) for you and your organization’s users.
  • Business and operational data — the data your organization enters or generates while using Valkern OS: inventory and product records, sales and invoicing data, customer and supplier records, and, for pharmacy/clinic customers, patient records. Patient records may include health-related and other sensitive data (e.g. diagnoses, prescriptions, insurance details); we process this data strictly as directed by, and on behalf of, the customer organization that controls it.
  • Payment data — transaction metadata (amount, timestamp, status, payment method type). Card numbers, mobile-money PINs, and full payment credentials are collected and stored by our third-party payment providers (e.g. MTN Mobile Money, Flutterwave, Paystack, Stripe), not by us — we receive only confirmation and reference data needed to reconcile a transaction.
  • Usage, device, and analytics data — pages viewed, features used, timestamps, IP address, browser/device type, and similar diagnostic information, collected to operate and improve the service.
  • Cookies and similar technologies — used for authentication (session cookies), remembering preferences (e.g. language, theme), and basic analytics. See Section 3 for how we use them.

3. How we use it, and our legal bases

We use the data described in Section 2 to:

  • provide, operate, and maintain Valkern OS (contract performance);
  • authenticate users, secure accounts, and prevent fraud or abuse (contract performance and our legitimate interests);
  • process payments and reconcile transactions through our payment and fiscal-integration providers (contract performance and legal obligation, e.g. tax reporting);
  • communicate with you about your account, the service, and material changes to these terms (contract performance and legal obligation);
  • improve the product, diagnose issues, and understand feature usage (our legitimate interests, balanced against your rights); and
  • comply with applicable law, including tax, financial, and health-sector record-keeping obligations that apply to our customers (legal obligation).

Where we rely on your consent (for example, for optional analytics or marketing communications), you may withdraw it at any time as described in Section 6.

4. Data residency and applicable law

For customers contracting with Urugero & Family Ltd, personal data is collected, used, and protected in accordance with Rwanda Law N° 058/2021 of 13/10/2021 relating to the protection of personal data and privacy. Data for these customers is hosted in [TODO: hosting location / region for Rwanda / East Africa customers].

For customers contracting with Fivorana LLC, we apply the data protection principles described in this policy (purpose limitation, data minimization, security, and the rights in Section 6) regardless of the specific data-protection statute that may apply in the customer’s jurisdiction. Data for these customers is hosted in [TODO: hosting location / region for international customers].

5. Sharing and disclosure

We share personal data only with:

  • Service providers who process data on our behalf under contract — for example, cloud hosting and infrastructure providers, email and notification providers, and application-monitoring tools;
  • Payment processors (e.g. MTN Mobile Money, Flutterwave, Paystack, Stripe) to process transactions you or your customers initiate;
  • Tax and fiscal integrations your organization enables — for example, Rwanda Revenue Authority (RRA) EBM/VSDC fiscalization for Rwanda-based customers, to the extent required by law; and
  • Legal and regulatory authorities, where required to comply with a legal obligation, court order, or lawful request.

We do not sell personal data.

6. Your rights

Subject to applicable law, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure; request a portable copy of your data; object to certain processing; and withdraw consent where processing is based on consent. To exercise any of these rights, contact us using the details in Section 1. We may need to verify your identity before acting on a request, and some requests may be limited where the underlying data is controlled by the customer organization you interact with (e.g. a pharmacy or clinic using Valkern OS) rather than by us directly — in that case we will direct you to the relevant organization or assist it in responding.

7. International data transfers

Because Valkern OS is operated by two entities serving different regions, and because our service providers (hosting, payment, communications) may operate outside your country, personal data may be transferred to and processed in countries other than your own. Where we transfer personal data internationally, we use providers that apply appropriate contractual and technical safeguards for that transfer.

8. Retention

We retain personal data for as long as your organization’s account is active, and afterward for as long as needed to comply with legal, tax, and regulatory record-keeping obligations (which, for financial and health-related records, can be several years), resolve disputes, and enforce our agreements. When data is no longer needed for these purposes, we delete or anonymize it.

9. Security

We use technical and organizational measures designed to protect personal data against unauthorized access, loss, or misuse — including encryption in transit, access controls, and tenant-isolated data storage. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not currently hold formal third-party security certifications (e.g. ISO 27001, SOC 2); our practices are designed to align with recognized security principles, not certified against them.

10. Children’s data

Valkern OS is a business tool and is not directed at children. We do not knowingly collect personal data directly from children for account-registration purposes. Business or clinical records entered by a customer organization (for example, a clinic patient record) may relate to a minor; in that case the customer organization, as data controller for that record, is responsible for ensuring it has a lawful basis to process that data.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new effective date, and where changes are material, we will provide additional notice (e.g. by email or in-product notice). This policy was last updated on [TODO: effective date].

12. Contact and complaints

Questions, requests, or complaints about this policy or our data practices can be sent to [TODO: DPO / privacy contact email] or [email protected]. If you are in Rwanda and are not satisfied with our response, you have the right to lodge a complaint with the National Cyber Security Authority (NCSA), Rwanda’s data-protection supervisory authority. If you are in another jurisdiction, you may lodge a complaint with your local data-protection or consumer-protection authority.