Privacy Policy
Effective September 4, 2026 · Last updated September 4, 2026
1. Who we are
beoneofus ("we", "our", "us") operates the education-and-career ecosystem at beoneofus.work, connecting students, mentors, schools, and institutions. For the purposes of Rwanda's data protection law, beoneofus acts as the data controller for personal data processed on the platform.
2. Legal framework
This Privacy Policy is issued in accordance with Law N° 058/2021 of 13/10/2021 relating to the protection of personal data and privacy of the Republic of Rwanda ("the Data Protection Law"), and its implementing regulations. Where our processors or infrastructure sit outside Rwanda, we also align our practices with recognised international standards (such as the EU GDPR) so that your data is never protected to a lower standard than Rwandan law requires.
The supervisory authority for data protection in Rwanda is the National Cyber Security Authority (NCSA), through its Data Protection and Privacy Office.
3. Data we collect
- Account data: name, email address, password (hashed), profile photo, bio, skills, and career information you provide on sign-up or in your profile.
- Institutional data: for students, mentors, and staff onboarded through a school or organization, the enrolment, role, and academic/mentorship records that institution provides or that you generate on the platform.
- Usage data: pages visited, features used, session timestamps, and device/browser metadata collected automatically to improve the platform.
- Content: posts, messages, comments, uploaded files, credentials, and any other content you create on the platform.
- Payment data: if you purchase a premium plan, payment is handled by Paystack. We do not store full card details.
- Communications: emails or messages you send to our support team.
4. Legal basis for processing
Under the Data Protection Law, we only process your personal data where we have a valid legal basis, namely:
- Consent — for example, when you opt in to optional communications.
- Performance of a contract — to create and operate your account and deliver the platform's core features.
- Legitimate interest — to secure the platform, prevent fraud, and improve our services, balanced against your rights.
- Legal obligation — to comply with Rwandan law, regulatory requests, or a valid court order.
5. How we use your data
- To provide, maintain, and improve the platform and its features.
- To send you transactional emails (account verification, password reset, notifications).
- To personalise your experience and surface relevant content, mentorship matches, and opportunities.
- To detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations under Rwandan and, where applicable, other law.
We do not sell your personal data to third parties. We do not use your data for advertising profiling.
6. Data sharing & processors
We share data only with:
- Supabase — our database and authentication provider.
- Paystack — payment processing for premium subscriptions.
- Resend / email providers — transactional email delivery.
- Vercel — application hosting and edge delivery.
- Your school or institution admin — limited to the records relevant to your enrolment or role there.
- Rwandan law enforcement, NCSA, or another competent regulator when required by applicable law.
Every processor we use is bound by a data processing agreement requiring them to protect your data to at least the standard this policy describes.
7. International transfers
Some of our processors host data outside Rwanda. The Data Protection Law restricts transferring personal data outside Rwanda unless the destination provides an adequate level of protection, or another safeguard applies (such as your explicit consent, standard contractual clauses, or the transfer being necessary to perform our contract with you). Where we transfer data internationally, we rely on one of these safeguards and limit the transfer to what is necessary to operate the platform.
8. Data retention
We retain your account data for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required by Rwandan law (or another applicable law) to retain certain records for longer — for example, academic or credentialing records an institution is required to keep.
9. Your rights
Under the Data Protection Law, you have the right to:
- Be informed about how your data is processed (this policy).
- Access a copy of the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erasure — request deletion of your data, subject to our retention obligations above.
- Object to or restrict certain processing.
- Data portability — receive your data in a machine-readable format.
- Withdraw consent at any time where processing is based on consent.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you.
- Lodge a complaint with the National Cyber Security Authority (NCSA) if you believe we have not handled your data lawfully.
To exercise any of these rights, contact us at privacy@beoneofus.work. We will respond within the timeframe required by Rwandan law.
10. Data Protection Officer
In line with the Data Protection Law's requirements for data controllers of our kind, we have designated a contact point for data protection matters:
11. Cookies
We use strictly necessary cookies for session management and authentication. We do not use third-party advertising cookies. You can clear cookies via your browser settings at any time.
12. Security & breach notice
We implement industry-standard security measures including HTTPS encryption, hashed passwords, row-level security on our database, and access controls. However, no system is completely secure — please protect your account with a strong password.
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the National Cyber Security Authority and affected users without undue delay, as required by the Data Protection Law.
13. Children
Where beoneofus is used by school-age students, their accounts are created and managed through their school or a parent/guardian, consistent with the Data Protection Law's protections for children's data. We do not knowingly allow a child to self-register outside that institutional or guardian context. If you believe a child has provided us personal data outside these safeguards, please contact us immediately.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you via email or an in-app notice. Continued use of the platform after changes constitutes acceptance of the updated policy.
15. Contact & complaints
Questions about this policy, or a request to exercise your rights? Reach us at privacy@beoneofus.work.
If you are not satisfied with our response, you may lodge a complaint with Rwanda's National Cyber Security Authority (NCSA), the supervisory authority for data protection in Rwanda.