Privacy Policy

Last Updated: November 06, 2025

Gephra Ltd ("we," "us," "our") operates Gephra Trade (the "Platform"). We are committed to protecting your personal information and your right to privacy.

1. Introduction

This Privacy Policy explains:

  • What information we collect
  • How we use and share it
  • Your rights and choices
  • How we protect your data

By using the Platform, you consent to the practices described in this Privacy Policy.

2. Information We Collect

2.1 Information You Provide

Account Registration:

  • Full name
  • Email address
  • Phone number
  • Company/business name
  • Country and city/region

Assessment Data:

  • Product categories and descriptions
  • Destination countries
  • Certifications and permits
  • Production capacity details
  • Quality control practices
  • Financial readiness information
  • Documentation status
  • Export experience

Market Explorer:

  • Email address
  • Company name (optional)
  • Product and destination queries

Communications:

  • Support inquiries and correspondence
  • Feedback and survey responses
  • Feature requests

2.2 Information Collected Automatically

Technical Data:

  • IP address
  • Browser type and version
  • Device information
  • Operating system
  • Referring URLs
  • Pages viewed and time spent
  • Clickstream data

Cookies and Tracking:

We use cookies and similar technologies to:

  • Maintain your session
  • Remember your preferences
  • Analyze Platform usage
  • Improve user experience

You can control cookies through your browser settings.

2.3 Payment Information

Payment details (card numbers, mobile money accounts) are collected and processed by our payment partners:

  • Dodo Payments
  • Mobile Money operators (MTN, Airtel)
  • PESAPAL

We do not store complete payment credentials on our servers. We receive only:

  • Transaction confirmation
  • Payment amount and date
  • Payment method used (card/mobile money)

3. How We Use Your Information

3.1 To Provide Services:

  • Create and manage your account
  • Process and deliver assessments
  • Generate personalized reports
  • Provide customer support
  • Send transactional emails (receipts, report delivery)

3.2 To Improve the Platform:

  • Analyze usage patterns and trends
  • Identify popular features and pain points
  • Develop new features based on demand
  • Test and optimize user experience

3.3 To Communicate:

  • Respond to your inquiries
  • Send service announcements
  • Notify you of regulatory changes affecting your assessments
  • Request feedback (you may opt out)

3.4 Marketing (With Consent):

  • Send promotional emails about new features
  • Share export tips and trade insights
  • Announce partnerships or special offers

You can unsubscribe from marketing emails at any time via the link in each message.

3.5 For Legal and Security Purposes:

  • Prevent fraud and abuse
  • Comply with legal obligations
  • Enforce our Terms of Service
  • Protect our rights and safety

4. How We Share Your Information

4.1 We Do NOT Sell Your Data

We never sell, rent, or trade your personal information to third parties.

4.2 Service Providers

We share data with trusted third parties who help us operate the Platform:

Hosting and Infrastructure:

  • Supabase (database hosting - see Supabase privacy policy)
  • Vercel (application hosting)

Payment Processing:

  • Dodo Payments
  • Mobile Money operators
  • PESAPAL

Email Services:

  • Resend (transactional emails)

Analytics:

  • Google Analytics or similar (anonymized usage data)

All service providers are contractually obligated to protect your data and use it only as instructed.

4.3 Legal Requirements

We may disclose information if required by:

  • Court orders or legal process
  • Government or regulatory requests
  • Law enforcement investigations
  • Protection of our legal rights

4.4 Business Transfers

If Gephra Ltd is acquired, merged, or undergoes restructuring, your information may be transferred to the successor entity. You will be notified of any such change.

4.5 With Your Consent

We may share information in other circumstances with your explicit permission.

5. Data Retention

5.1 Active Accounts

We retain your information as long as your account is active or as needed to provide services.

5.2 After Account Deletion

When you delete your account:

  • Personal information is deleted within 30 days
  • Assessment reports are anonymized and retained for 90 days (for support purposes)
  • Aggregated, anonymized data may be retained indefinitely for analytics

5.3 Legal Obligations

We may retain data longer if required by law, to resolve disputes, or enforce agreements.

6. Data Security

6.1 Security Measures

We implement industry-standard security practices:

  • HTTPS encryption for all data transmission
  • Encrypted data storage
  • Secure authentication (hashed passwords)
  • Regular security audits
  • Access controls and monitoring
  • Payment data handled by PCI-compliant processors

6.2 No Absolute Security

While we take reasonable precautions, no internet transmission or electronic storage is 100% secure. You use the Platform at your own risk.

6.3 Your Responsibility

You are responsible for:

  • Maintaining password confidentiality
  • Logging out of shared devices
  • Reporting suspected security breaches

7. Your Privacy Rights

7.1 Access and Correction

You may access and update your account information anytime from your dashboard settings.

7.2 Data Portability

You may request a copy of your assessment data in a machine-readable format.

7.3 Deletion

You may request deletion of your account and personal data by:

We will process deletion requests within 30 days, subject to legal retention requirements.

7.4 Marketing Opt-Out

You may opt out of marketing emails via:

You cannot opt out of essential service communications (receipts, security alerts).

7.5 Cookie Management

You can disable cookies through your browser settings, though some Platform features may not function properly.

7.6 Data Protection Laws

If you are located in a jurisdiction with specific data protection laws (e.g., GDPR, Rwanda Data Protection Law), you may have additional rights. Contact us to exercise these rights.

8. Children's Privacy

The Platform is not intended for individuals under 18 years of age. We do not knowingly collect information from minors. If we discover we have collected data from a minor, we will delete it promptly.

9. International Data Transfers

Your information may be transferred to and processed in countries outside Rwanda, including where our service providers operate. These countries may have different data protection laws.

We take steps to ensure adequate protection through:

  • Standard contractual clauses
  • Service provider agreements
  • Compliance with applicable transfer mechanisms

10. Third-Party Links

The Platform may link to external websites (regulatory bodies, service providers). We are not responsible for their privacy practices. Review their privacy policies before providing information.

11. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • Changes in our practices
  • New legal requirements
  • Platform enhancements

Material changes will be communicated via:

  • Email notification to registered users
  • Prominent notice on the Platform

Continued use after changes constitutes acceptance.

12. Contact Us About Privacy

Privacy Questions or Requests:

Mailing Address:

Gephra Ltd
KG 65 ST
Kigali, Rwanda

Your Privacy Matters to Us

Have questions about how we protect your data? We're here to help.