Privacy policy
Effective . Last updated .
This policy explains how IMIZI Cyber Consulting Ltd ("IMIZI Cyber", "we", "us") collects and
uses personal data through this website, imizicyber.com. We follow Rwanda's Law N° 058/2021 of 13/10/2021 relating to the protection of personal data and privacy. Where the EU General Data Protection Regulation (GDPR) applies to you, we respect the
rights it gives you as well.
1. Who is responsible for your data
IMIZI Cyber Consulting Ltd decides why and how personal data collected through this website is processed.
IMIZI Cyber Consulting LtdNorrsken House, 1 KN 78 St, Kigali, Rwanda
Email: info@imizicyber.com
Phone: +250 793 146 617
IMIZI Cyber Consulting Ltd is registered with the National Cyber Security Authority (NCSA) as a data controller under Law N° 058/2021 relating to the protection of personal data and privacy.
2. What this policy covers
This policy covers this website and the forms on it. It does not cover data we handle during a client engagement: that is governed by the engagement contract and NDA, and described on how we handle your data.
3. What we collect, and why
We collect only what each feature needs. The legal grounds named below are those in Article 46 of Law N° 058/2021.
With every form below, we also receive the page you sent the form from and the name of the website that referred you (for example google.com), if any. We use this to understand which pages lead people to contact us; the legal ground is our legitimate interest in knowing that. Section 5 explains how it is collected.
3.1 Contact form
- What: your name, work email, organisation (optional), the service you are interested in, your message, and how you heard about us if you choose to say.
- Why: to reply to your enquiry and, if you want, scope an engagement.
- Legal ground: steps you ask us to take before entering into a contract.
3.2 Breach Exposure Report
- What: your work email, organisation, the domain to assess, your full name, role and country, an optional note on what prompted the request, how you heard about us if you choose to say, and your confirmation that you are authorised to request an assessment for that domain.
- Why: to qualify the request, verify the domain and your authority over it, and prepare the report.
- Legal ground: steps you ask us to take before entering into a contract, and our legitimate interest in making sure exposure data about an organisation goes only to someone authorised to receive it.
3.3 Security Score
- What: if you only take the quiz, your answers stay in your browser and nothing is sent to us. If you request the PDF report, we receive your name, work email, organisation, your score and band, and your answers.
- Why: to record your request and, with your consent, follow up about your result (see section 4). The PDF itself is generated in your browser.
- Legal ground: our legitimate interest in knowing who uses the tool; your consent for any follow-up.
3.4 Resource downloads
- What: your name, work email, organisation, and which resource you downloaded.
- Why: to understand who uses the free resources we publish. The PDF is generated in your browser. We do not send follow-ups from this form unless you ask us to.
- Legal ground: our legitimate interest in understanding who uses our resources.
3.5 Email, WhatsApp and booked calls
- What: what you send us, and the name, email and notes you enter when you book a call.
- Where you booked from: Book a Free Call links tell Cal.com which page and button you used and, if you came from another website, its name. Cal.com stores this with your booking.
- Why: to reply, hold the call you booked, and follow up on it.
- Legal ground: steps you ask us to take before entering into a contract.
3.6 Visiting the site
- Analytics: Cloudflare Web Analytics measures visits with a cookieless beacon (section 5). Legal ground: our legitimate interest in understanding how the site is used.
- Bot checks: when a form uses Cloudflare Turnstile, it runs a check in your browser to tell people from automated spam, and Cloudflare processes technical signals about your browser for that check. Legal ground: our legitimate interest in keeping our forms free of automated abuse.
- Delivery and security logs: Cloudflare processes your IP address, browser details and request times to deliver the site and protect it from attacks. We do not use this data to identify or track individual visitors.
We do not sell or rent personal data, use advertising or social-media tracking pixels, take payments through this website, or make decisions about you based solely on automated processing.
4. Follow-up emails
The Security Score form tells you that our team may follow up about your result. That follow-up relies on your consent, which you give by submitting the form with that notice beside it.
You can withdraw your consent at any time, and withdrawing is as easy as giving it (Article 8). You also have the right to object to direct marketing at any time (Article 19). Reply "unsubscribe" to any follow-up, or email info@imizicyber.com, and we stop.
5. Cookies, analytics and browser storage
This website sets no cookies, so there is no cookie banner.
Cloudflare Web Analytics. Each page loads a small cookieless JavaScript beacon
from
static.cloudflareinsights.com. It sends the page address, your browser and
operating system type, and page-load timings to Cloudflare through /cdn-cgi/rum on
this domain. We see aggregate reports only, not individual visitors.
Where you came from. When you send a form or click Book a Free Call, the page reads
two things at that moment: which page of this site you are on, and the name of the website that
sent you here (for example google.com; never the full address). If the link you followed to this
site carried campaign labels, such as utm_source=linkedin, the booking link
passes those labels on too. This uses no cookies, stores nothing on your device, and does not
track you across other websites. A visit that moves through several pages is not linked
together.
Local storage. We store one item in your browser, imizi-theme,
which remembers whether you chose the light or dark theme. It contains no personal data and is
never sent to us or anyone else.
Third-party pages. Booking pages (Cal.com) and WhatsApp are run by those providers under their own privacy policies and may set their own cookies.
6. Who processes data for us
These providers process personal data on our behalf, each under its written data-processing terms (Article 4). Apart from disclosures the law requires, no one else receives personal data from this website.
| Provider | What it does for us | Data involved | Where |
|---|---|---|---|
| Cloudflare, Inc. | Hosting and content delivery, Web Analytics, and Turnstile bot checks on forms | Request data including IP address and browser details; the analytics beacon data described in section 5; Turnstile check signals | Global network; US company |
| Formspree, Inc. | Receives and stores submissions from all four forms on this site | Everything you enter in a form, plus the page you sent it from and the name of the website that referred you, if any | United States |
| Google (Google Workspace) | Our email, and Google Meet for booked calls | Emails you send us, form notifications, call details | Global infrastructure; US company |
| Cal.com, Inc. | Booking pages for the free call | Name, email and any notes you add when booking; the page and button you booked from, and the name of the website that referred you, if any | United States |
| WhatsApp (Meta) | Only if you choose to message us on WhatsApp | Your phone number, profile and the messages you send | Global infrastructure; US company |
7. Transfers outside Rwanda
All of the providers in section 6 operate outside Rwanda, so data you submit through this website is transferred to, and stored in, other countries, principally the United States and the European Union. Law N° 058/2021 governs this in three articles:
- Article 48 allows a transfer outside Rwanda on listed grounds. We rely on the transfer being necessary for steps you asked us to take before a contract (replying to you, preparing a report you requested, holding a call you booked) and, for follow-up emails, on your consent.
- Article 49 requires a written contract with anyone who receives the data outside Rwanda. Each provider processes it under written data-processing terms with us.
- Article 50 requires personal data to be stored in Rwanda unless a registration certificate issued by the NCSA authorises storage outside Rwanda.
We keep the data held by these providers to what each feature needs, and delete it on the schedule in section 8.
8. How long we keep data
- Form submissions, emails and booking details: kept for as long as we need to respond to your request, and for up to 12 months after that for follow-up, then deleted. If you become a client, the engagement contract sets retention instead.
- Analytics: Cloudflare Web Analytics gives us aggregate metrics only; we hold no per-visitor analytics data.
- Theme preference: stays in your browser until you clear it.
9. Your rights
Law N° 058/2021 gives you the following rights. You can use any of them by writing to dpo@imizicyber.com.
- Access (Article 18): to know why we process your data, get a copy of it, learn who has had access to it and where it came from, and whether it has been transferred outside Rwanda.
- Objection (Article 19): to ask us to stop processing that causes or is likely to cause you harm or distress, and to stop direct marketing at any time.
- Portability (Article 20): to receive the data you gave us in a structured, readable format, or have it sent to another organisation where technically feasible.
- No solely automated decisions (Article 21): we do not make decisions about you based solely on automated processing.
- Restriction (Article 22): to have processing restricted while the accuracy of your data or your objection is being checked, or when processing is unlawful and you prefer restriction to erasure.
- Erasure (Article 23): to have your data deleted when it is no longer needed, when you withdraw consent or object, or when it was processed unlawfully.
- Rectification (Article 24): to have inaccurate data corrected and incomplete data completed.
- Designating an heir (Article 25): to give an heir rights over your data by will.
- Representation (Article 26): to act through a parent, guardian or person you authorise in writing, where the law provides for it.
- Withdrawing consent (Article 8): at any time, as easily as you gave it.
We respond within 30 days. If you are not satisfied with our response, you can appeal to the NCSA within 30 days of receiving it. If the GDPR applies to you, you can also contact your local data protection authority.
10. How we protect data
- HTTPS with TLS on every page, and HSTS so browsers never fall back to plain HTTP
- A strict Content Security Policy on every page
- A static website: no database and no user accounts on our side; form data goes from your browser to Formspree
- Service providers chosen for their security posture
- Regular security review of our own web properties
11. Children
This website and our services are not directed at anyone under 18, and we do not knowingly collect personal data from children. If you believe we have, email dpo@imizicyber.com and we will delete it.
12. Changes to this policy
When our practices, providers or legal requirements change, we update this policy and the "last updated" date at the top of this page.
13. Complaints
You can complain to the supervisory authority at any time:
National Cyber Security Authority (NCSA)Republic of Rwanda
cyber.gov.rw
14. Contact us
IMIZI Cyber Consulting LtdNorrsken House, 1 KN 78 St, Kigali, Rwanda
Privacy and data requests: dpo@imizicyber.com
General enquiries: info@imizicyber.com
Security issues: responsible disclosure policy