Privacy Policy
Last updated : July 10, 2026
Drwintech LTD is committed to protecting the personal data of individuals who use the Zana platform. This policy describes the data we process, the purposes, the legal bases, the recipients, the retention periods and the rights of data subjects, pursuant to Law N°058/2021 of 13/10/2021 relating to the protection of personal data and privacy.
1. Data controller and Data Protection Officer
The data controller is Drwintech LTD, a company registered with the Rwanda Development Board under number 260120815153760 (TIN 155067359), with its registered office at Gasabo, Kigali, République du Rwanda. A Data Protection Officer (DPO) can be reached at dpo@getzana.africa for any question relating to the processing of your personal data.
2. Data we process
Identification and contact: name, contact details (phone, email), address, company;
Identity verification (KYC): identity documents and supporting documents required by applicable regulations;
Account and authentication: identifiers, password (hashed), session tokens, access logs;
Transactional and operational data: orders, deliveries, trips, support interactions;
Financial data: payment metadata (tokenised), billing history; card data are processed exclusively by PCI-DSS certified providers and are never stored by Zana;
Location data: the client's GPS coordinates where consent is given, solely for delivery purposes, as well as position data from GPS trackers installed on fleet vehicles;
Technical data: IP address, device identifiers, app version, preferences;
Communications and support: interactions with our customer service, complaints, feedback.
3. Purposes and legal bases
Provision of the service (accounts, orders, deliveries, payments, fleet management) — performance of the contract;
Authentication, security and fraud prevention — legitimate interests and performance of the contract;
Identity verification (KYC), anti-money-laundering and counter-terrorism-financing (AML-CFT) obligations, regulatory reporting — legal obligation;
Support, complaints and dispute handling — performance of the contract and legitimate interests;
Service improvement and statistics, based on aggregated or pseudonymised data — legitimate interests;
Commercial communications — consent, withdrawable at any time.
4. Payments
Mobile Money payments and refunds are executed via the pawaPay payment aggregator and/or directly via the MTN Mobile Money and Airtel Money operators. Card payments are processed by Stripe, a PCI-DSS certified provider. Only the metadata strictly necessary to execute and reconcile transactions (reference, phone number, status) are processed by Zana; card data are never stored by Drwintech LTD.
5. Recipients and processors
Data are accessible to authorised Drwintech LTD personnel and, on a need-to-know basis, to the following processors, each acting on instructions under a data-processing agreement (DPA):
Supabase — database hosting, authentication and file storage — European Union (Ireland) — data-processing agreement (DPA) and NCSA authorisation under Article 48;
Vercel — web application hosting — European Union / United States — data-processing agreement (DPA);
pawaPay — mobile money payment aggregator (collections and disbursements) — United Kingdom / European Union — data-processing agreement (DPA);
MTN Mobile Money Rwanda and Airtel Money Rwanda — mobile money payment operators — Rwanda;
Stripe — card payment processing (PCI-DSS certified) — United States / European Union — data-processing agreement (DPA);
Africa's Talking — sending of transactional SMS and WhatsApp messages — data-processing agreement;
Twilio — messaging and SMS services — United States — data-processing agreement (DPA);
Resend — sending of transactional emails — United States — data-processing agreement (DPA);
Google Maps and OpenStreetMap / Nominatim — mapping and address geocoding;
Mapbox — mapping, where applicable — data-processing agreement (DPA);
Traccar (self-hosted on Hetzner infrastructure, European Union) and Flespi — reception and gateway of data from GPS trackers installed on vehicles;
Contentful — content management system for the public legal pages (public, non-nominative content);
OpenSanctions — sanctions and politically exposed persons (PEP) list screening for anti-money-laundering purposes, self-hosted solution.
Data may also be disclosed to competent authorities — the National Cyber Security Authority (NCSA), the National Bank of Rwanda (BNR), the Rwanda Utilities Regulatory Authority (RURA), the Rwanda Revenue Authority (RRA), the Rwanda Development Board (RDB), and judicial authorities — upon valid legal request.
6. Transfers outside Rwanda
Some of the processors listed in Section 5 are established outside Rwanda, notably in the European Union and the United States. Such transfers are framed by appropriate safeguards: standard contractual clauses or equivalent, data-processing agreements (DPAs), and, where required, an authorisation from the National Cyber Security Authority (NCSA) under Article 48 of Law N°058/2021.
7. Automated processing — fraud prevention and anti-money-laundering
Drwintech LTD implements automated fraud-detection processing as well as anti-money-laundering screening measures (sanctions lists, politically exposed persons, transaction monitoring), for security reasons and in performance of its legal obligations. These processes may result in a temporary restriction of access to the service. Any person affected by such a decision may request a human review from the DPO at dpo@getzana.africa.
8. Retention periods
Account data: for the lifetime of the account, then a limited period after closure;
Transactional and financial data: statutory period (accounting, tax, anti-money-laundering), typically ten years;
KYC data: period required by anti-money-laundering regulations;
Security logs: limited period for security purposes.
Upon expiry of these periods, data are securely deleted or anonymised.
9. Your rights
Subject to the conditions laid down by law, you have the rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and the right not to be subject to a fully automated decision.
To exercise these rights, contact the DPO at dpo@getzana.africa. You also have the right to lodge a complaint with the National Cyber Security Authority — Data Protection & Privacy Office (Kigali).
10. Security
Drwintech LTD implements technical and organisational measures proportionate to the risk: role-based access control, multi-factor authentication for administrative accounts, encryption at rest (AES-256) and in transit (TLS 1.3), audit logs, encrypted backups, regular processor assessments and incident-management procedures.
11. Data breach notification
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, Drwintech LTD notifies the National Cyber Security Authority (NCSA) and, where applicable, the affected individuals, in accordance with Law N°058/2021.
12. Minimum age
The Zana service is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors.
13. Cookies
The use of cookies and similar technologies is described in our Cookie Policy.
14. Contact and updates
Data Protection Officer — Drwintech LTD, Nyarugenge 583, Kigali, Rwanda, dpo@getzana.africa. This policy may be updated; the version in force is published on getzana.africa.
This document is provided for information purposes. In case of conflict, the mandatory provisions of Rwandan law prevail.