Pickovo Legal
Last updated: 18 July 2026
This policy explains how Pickovo Ltd handles personal data, in compliance with Rwanda's Law No. 058/2021 on the protection of personal data and privacy (and, where relevant to foreign users, GDPR principles). For your customers' data recorded on the platform, you are the data controller and Pickovo is the data processor acting on your instructions.
Account data (name, email, phone, role, organization); business records you create (work orders, invoices, inventory, quotes, customer and vehicle details such as plate, make, model and service history); payment records (amounts, gateway references, mobile-money number used — we never store card numbers or Mobile Money PINs, which are handled by AzamPay and Centiwise); and technical logs (login times, IP address, device/browser) kept for security auditing.
To provide and improve the service, process subscription payments, send service notifications (trial reminders, invoices, renewal and payment alerts), provide support, and meet legal obligations. Aggregated, de-identified statistics that never identify a person may be used to improve the platform.
Online payments are processed by licensed gateways (AzamPay for Mobile Money, Centiwise for cards). We receive only transaction references and status — never full card details. Gateway callbacks are signature-verified.
We use strictly necessary cookies for secure login sessions and preferences. We do not sell data to advertisers.
Data is shared only with sub-processors needed to run the service (hosting, SMS gateway, payment providers), under confidentiality obligations; with authorities where the law requires; or at your documented instruction. We keep a current sub-processor list and give notice of changes.
Data is kept for the life of your account. After the account ends you may export your data for 30 days; it is then deleted from active systems within 30 days, except where law requires longer retention or it persists briefly in routine backups.
Under Law No. 058/2021 you may request access, correction, deletion or portability of your personal data, and object to or restrict processing. Write to info@heptadev.com — we respond within the legally required timelines.
Role-based access controls, encrypted transport (TLS), hashed passwords (bcrypt), login auditing, regular backups, and staff confidentiality obligations protect your data. We notify affected customers without undue delay after becoming aware of a personal-data breach.
Questions? Contact Pickovo Ltd — 1 KN 78 St, Kigali, Rwanda · info@heptadev.com · +250 788 701 902