← Back to Gephra Ltd

Legal

Privacy Policy

How Gephra Ltd collects, uses, stores, shares, and protects Personal Data.

Effective date22 August 2026
Last updated22 August 2026

1.Introduction

GEPHRA LTD (“Gephra,” “we,” “us,” or “our”) develops and operates digital products, platforms, websites, applications, and related technology services.

This Privacy Policy explains how Gephra collects, uses, stores, shares, and protects Personal Data when individuals interact with:

  • gephra.com
  • Gephra HOPILLA
  • Gephra Sustaina
  • Gephra business communications, support, recruitment, and commercial activities
  • any other Gephra product, website, application, or service that references this Privacy Policy

This Privacy Policy may be supplemented by product-specific notices, contractual terms, or Data Processing Agreements where additional information is required for a particular Service. Gephra processes Personal Data in accordance with applicable data protection and privacy laws.

2.Definitions

Customer means any business, organization, institution, property, or other legal entity that uses a Gephra Service.

Customer Data means Personal Data submitted to, stored in, transmitted through, or otherwise processed through a Gephra Service by or on behalf of a Customer.

Personal Data means information relating to an identified or identifiable individual.

Services means Gephra’s websites, applications, platforms, products, and related services that reference this Privacy Policy.

3.Gephra’s Role

Gephra may process Personal Data either as a data controller or as a data processor, depending on the relevant Service and processing activity.

3.1 Where Gephra Acts as a Data Controller

Gephra generally acts as a data controller for Personal Data processed in connection with:

  • corporate website activity
  • business enquiries
  • account administration
  • customer and commercial relationships
  • billing and subscriptions
  • security and fraud prevention
  • service administration and customer support
  • recruitment and marketing communications
  • legal, regulatory, accounting, and compliance requirements

3.2 Where Gephra Acts as a Data Processor

Gephra may act as a data processor where a Customer uses a Gephra Service to process Personal Data relating to its guests, customers, employees, suppliers, partners, or other individuals. In those circumstances, the Customer determines the purposes and means of processing and Gephra processes Customer Data on the Customer’s behalf in accordance with the applicable agreement and documented instructions.

For example, where a hospitality business uses Gephra HOPILLA to manage guest or operational information, that business may act as the data controller and Gephra may act as its data processor.

4.Personal Data We May Collect

The Personal Data Gephra processes depends on how an individual interacts with Gephra and which Services are used.

4.1 Identity and Contact Information

  • name
  • email address
  • telephone number
  • business or postal address
  • country or location
  • organization
  • job title or role

4.2 Account and Access Information

  • account identifiers and user identifiers
  • authentication records and access permissions
  • account settings and security events
  • device registration and account recovery information

4.3 Business and Customer Information

  • company, organization, property, or business-unit information
  • subscription, contractual, billing, and invoice information
  • customer support history and authorized representative details

4.4 HOPILLA Data

Where Gephra HOPILLA is used, Personal Data may include:

  • guest and customer information
  • reservations, bookings, arrival and departure information
  • stay, occupancy, accommodation, and service-request records
  • guest communications and preferences
  • staff and authorized-user information
  • invoice and transaction references
  • operational records containing Personal Data
  • information received from authorized integrations

Where such data is processed on behalf of a Customer, the Customer remains responsible for determining the lawful purposes for which it is used.

4.5 Sustaina Data

  • profile and account information
  • business or organizational information
  • buyer, supplier, producer, or partner information
  • product or service listing information
  • enquiries and communications
  • verification or credential-related information
  • commercial or transaction-related records

4.6 Transaction and Billing Information

  • billing name and address
  • invoice information
  • transaction amount, currency, and payment status
  • payment-provider reference
  • refund, settlement, tax, or accounting records

Where payments are processed through a third-party payment provider, payment credentials may be collected directly by that provider rather than by Gephra.

4.7 Communications

  • emails
  • contact forms
  • customer support requests
  • messaging communications
  • feedback
  • surveys
  • service-related communications

4.8 Technical and Usage Information

  • IP address, device type, browser type, and operating system
  • session information and timestamps
  • server and application logs
  • authentication, diagnostic, and security events
  • usage and performance information
  • cookie or similar technology identifiers

4.9 Recruitment Information

  • contact information
  • curriculum vitae or résumé
  • education and qualifications
  • employment history and references
  • interview records and application correspondence

5.How We Collect Personal Data

  • directly from the individual
  • from Customers and their authorized users
  • through the use of the Services
  • from authorized integrations
  • from payment, communications, security, hosting, and infrastructure providers
  • from business partners
  • from publicly available sources where appropriate
  • automatically through browsers, devices, logs, cookies, and similar technologies

6.How We Use Personal Data

  • provide and operate the Services
  • create and administer accounts
  • authenticate users and manage access permissions
  • configure Services and manage customer relationships
  • process subscriptions, invoices, and payments
  • respond to enquiries and provide customer support
  • send operational, billing, security, and service communications
  • monitor system performance and availability
  • detect and prevent fraud, misuse, and unauthorized access
  • investigate and respond to security incidents
  • maintain logs and audit records
  • diagnose technical issues and improve existing products and services
  • develop new capabilities and generate aggregated or de-identified analytics
  • manage recruitment and conduct business administration
  • send marketing communications where permitted
  • comply with legal and regulatory obligations
  • establish, exercise, or defend legal claims

Gephra will not use Personal Data for materially incompatible purposes unless permitted by applicable law.

7.Legal Basis for Processing

Where required by applicable law, Gephra relies on an appropriate lawful basis for processing Personal Data. Depending on the circumstances, this may include:

  • performance of a contract
  • compliance with a legal obligation
  • legitimate business interests
  • consent
  • protection of vital interests
  • another lawful basis recognized under applicable law

Where processing is based on consent, consent may be withdrawn at any time, subject to applicable law. Where Gephra processes Customer Data solely on behalf of a Customer, the Customer is responsible for establishing the appropriate lawful basis for that processing.

8.How We Share Personal Data

Gephra may share Personal Data with the following categories of recipients.

8.1 Customers and Authorized Users

Customer Data may be made available to the relevant Customer and its authorized users in accordance with configured permissions and contractual arrangements.

8.2 Service Providers and Subprocessors

We may engage service providers for cloud hosting, data storage, authentication, communications, payment processing, security, monitoring, analytics, customer support, infrastructure operations, and professional services. Such providers may process Personal Data only as necessary to provide services to Gephra and subject to appropriate contractual and security requirements.

8.3 Third-Party Integrations

Where a Customer or user enables an integration with a third-party service, Personal Data may be transmitted to that service as necessary to provide the requested functionality. The third party’s own privacy terms may apply to its independent processing.

8.4 Professional Advisers

Gephra may share Personal Data with legal advisers, accountants, auditors, insurers, consultants, and other professional advisers where reasonably necessary.

8.5 Public Authorities

Gephra may disclose Personal Data where required by law, court order, regulatory requirement, or another lawful process.

8.6 Corporate Transactions

Personal Data may be disclosed or transferred in connection with a merger, acquisition, restructuring, financing, sale of assets, or similar corporate transaction. Gephra does not sell Personal Data as a business model.

9.Customer Data

Where Gephra acts as a data processor, Customer Data is processed in accordance with the applicable customer agreement and, where relevant, a Data Processing Agreement.

Customers remain responsible for:

  • determining why Personal Data is processed
  • ensuring that processing is lawful
  • providing required privacy notices
  • obtaining required consent where applicable
  • managing user access and permissions
  • determining appropriate retention periods
  • responding to individuals exercising their privacy rights

Gephra will provide reasonable assistance to Customers in meeting applicable privacy obligations where required by law or contract.

10.International Data Transfers

Gephra may use infrastructure, service providers, or business partners located in jurisdictions other than the country in which Personal Data was originally collected. Where Personal Data is transferred internationally, Gephra will use appropriate safeguards and comply with applicable legal requirements governing such transfers. Where Gephra processes Customer Data on behalf of a Customer, international transfers may also be governed by the applicable customer agreement and Data Processing Agreement.

11.Data Retention

Gephra retains Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy or as required for legal, regulatory, contractual, tax, accounting, security, or dispute-resolution purposes.

Retention periods may vary depending on:

  • the nature of the Personal Data
  • the purpose of processing
  • the duration of the customer or user relationship
  • contractual and statutory requirements
  • security requirements and applicable limitation periods

Where Gephra acts as a data processor, Customer Data is retained in accordance with the applicable agreement, Customer instructions, and legal requirements. When Personal Data is no longer required, it may be deleted, anonymized, or otherwise securely disposed of.

12.Information Security

Gephra uses technical and organizational measures designed to protect Personal Data against unauthorized access, disclosure, alteration, loss, destruction, or misuse. Depending on the Service and level of risk, these measures may include:

  • identity and access controls
  • strong authentication and least-privilege permissions
  • encryption and tenant or data isolation
  • logging and monitoring
  • secure software-development practices and vulnerability management
  • backup, recovery, and incident-response procedures
  • confidentiality obligations and service-provider security controls

No electronic system or method of data transmission can be guaranteed to be completely secure.

13.Personal Data Breaches

Gephra maintains procedures for identifying, assessing, containing, investigating, and responding to Personal Data breaches. Where required by applicable law or contract, Gephra will notify the relevant Customer, supervisory authority, affected individual, or other appropriate party.

14.Cookies and Similar Technologies

Gephra may use cookies and similar technologies for:

  • authentication
  • session management
  • security
  • user preferences
  • service functionality
  • analytics
  • performance monitoring

Where required, non-essential cookies will be used only after obtaining appropriate consent. Additional information may be provided through a cookie notice or consent interface.

15.Analytics and De-Identified Information

Gephra may use usage, device, and service information to measure performance, diagnose technical issues, understand product usage, improve the Services, support capacity planning, and develop new capabilities. Where appropriate, Gephra may aggregate or de-identify information so that it no longer identifies an individual.

16.Marketing Communications

Gephra may send information about its company, products, or services where permitted by applicable law. Recipients may opt out of marketing communications using the unsubscribe mechanism provided or by contacting Gephra. Opting out does not affect necessary service, security, billing, legal, or transactional communications.

17.Automated Processing

Gephra may use automated systems to support the operation, security, administration, or functionality of the Services. Where automated processing produces legal or similarly significant effects for an individual, Gephra will apply appropriate safeguards and provide additional information where required by law.

18.Children’s Personal Data

Gephra’s Services are primarily intended for businesses, organizations, and authorized users and are not directed to children for independent use.

A Customer may process Personal Data relating to minors where necessary for a legitimate business purpose, including hospitality services. Where Gephra processes such information on behalf of a Customer, the Customer is responsible for ensuring that the processing is lawful and appropriately authorized.

19.Privacy Rights

Subject to applicable law, individuals may have rights relating to their Personal Data, including the right to:

  • request access
  • request correction
  • request deletion
  • request restriction of processing
  • object to certain processing
  • withdraw consent
  • request data portability
  • object to direct marketing
  • exercise rights relating to certain automated decisions
  • lodge a complaint with a competent supervisory authority

These rights may be subject to legal limitations or exceptions.

20.Exercising Privacy Rights

Requests relating to Personal Data for which Gephra acts as data controller may be submitted to privacy@gephra.com.

Gephra may request information reasonably necessary to verify the identity and authority of the requester and to protect Personal Data against unauthorized access or disclosure. Where a request relates to Customer Data for which a Customer acts as data controller, the request should generally be directed to that Customer. Gephra will assist the relevant Customer where required by law or contract.

21.Third-Party Services

The Services may contain links to or integrate with websites, platforms, payment providers, communications providers, and other services operated by third parties. Where a third party independently determines how Personal Data is processed, that third party’s own privacy policy applies. Gephra is not responsible for the independent privacy practices of third parties.

22.Changes to this Privacy Policy

Gephra may update this Privacy Policy from time to time to reflect changes to the Services, processing activities, operations or security, and legal or regulatory requirements. The revised Privacy Policy will indicate the date it was last updated. Where appropriate, Gephra may provide additional notice of material changes.

23.Contact Us

GEPHRA LTD

KG 65 STREET
Kigali, Rwanda

Privacy: privacy@gephra.com
General enquiries: info@gephra.com

Individuals may also have the right to lodge a complaint with the competent data protection supervisory authority.

© Gephra Ltd. All rights reserved.