Pickovo Legal

Privacy Policy

Last updated: 18 July 2026

This policy explains how Pickovo Ltd handles personal data, in compliance with Rwanda's Law No. 058/2021 on the protection of personal data and privacy (and, where relevant to foreign users, GDPR principles). For your customers' data recorded on the platform, you are the data controller and Pickovo is the data processor acting on your instructions.

What we collect

Account data (name, email, phone, role, organization); business records you create (work orders, invoices, inventory, quotes, customer and vehicle details such as plate, make, model and service history); payment records (amounts, gateway references, mobile-money number used — we never store card numbers or Mobile Money PINs, which are handled by AzamPay and Centiwise); and technical logs (login times, IP address, device/browser) kept for security auditing.

How we use it

To provide and improve the service, process subscription payments, send service notifications (trial reminders, invoices, renewal and payment alerts), provide support, and meet legal obligations. Aggregated, de-identified statistics that never identify a person may be used to improve the platform.

Payment information

Online payments are processed by licensed gateways (AzamPay for Mobile Money, Centiwise for cards). We receive only transaction references and status — never full card details. Gateway callbacks are signature-verified.

Cookies & analytics

We use strictly necessary cookies for secure login sessions and preferences. We do not sell data to advertisers.

Sharing

Data is shared only with sub-processors needed to run the service (hosting, SMS gateway, payment providers), under confidentiality obligations; with authorities where the law requires; or at your documented instruction. We keep a current sub-processor list and give notice of changes.

Retention & deletion

Data is kept for the life of your account. After the account ends you may export your data for 30 days; it is then deleted from active systems within 30 days, except where law requires longer retention or it persists briefly in routine backups.

Your rights

Under Law No. 058/2021 you may request access, correction, deletion or portability of your personal data, and object to or restrict processing. Write to info@heptadev.com — we respond within the legally required timelines.

Security

Role-based access controls, encrypted transport (TLS), hashed passwords (bcrypt), login auditing, regular backups, and staff confidentiality obligations protect your data. We notify affected customers without undue delay after becoming aware of a personal-data breach.

Questions? Contact Pickovo Ltd — 1 KN 78 St, Kigali, Rwanda · info@heptadev.com · +250 788 701 902