1. Who we are
Rosiovend Limited ("Rosiovend", "we", "us", "our") operates the Rosiovend platform at rosiovend.com. We are registered in the Federal Republic of Nigeria with our principal office at Victoria Island, Lagos.
Under most data-protection laws applicable to our service, we act as the data controller for personal data collected through our marketing site, our authentication system, and our own billing operations. For your business's customer and staff data uploaded to the Service, you are the data controller and we act as your data processor.
2. Scope of this policy
This Privacy Policy applies to:
- Visitors to rosiovend.com and our marketing pages.
- Business owners and admins who register a Rosiovend account.
- Staff members invited by a registered business.
- Customers of registered businesses interacting with Rosiovend-hosted storefronts (where Rosiovend is a processor).
If you are a customer of a Rosiovend-powered business, that business is the data controller for your data. Direct privacy requests to that business; we will assist them in responding.
3. Data we collect
We collect the following categories of personal data:
| Account data | Name, email, phone number, password hash, business name, business address, country, role |
|---|---|
| Identity verification | Government-issued ID number (NIN, Ghana Card, etc.) and document images for KYC where regulation requires it |
| Payment data | Billing address, last-4 of card, payment method token (full card numbers handled by PCI-DSS-compliant processors — we never store them) |
| Business operational data | Orders, customers, inventory, staff records, transactions, product images and descriptions you upload |
| Usage data | Pages visited, features used, IP address, device type, browser, session duration, click events |
| Communications | Support tickets, emails to our team, in-app chat transcripts, feedback submissions |
| Cookies & similar | See our Cookie Policy for the full list and durations |
4. How we use your data
We use personal data to:
- Provide, maintain, and improve the Service.
- Authenticate you and protect your account.
- Process payments and send invoices and receipts.
- Send service-essential notifications (security alerts, billing, system updates).
- Respond to support requests and feedback.
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Comply with legal, tax, anti-money-laundering, and regulatory obligations.
- Conduct anonymised, aggregated product analytics to improve Rosiovend.
- Send marketing communications (only with your consent — and you can opt out at any time).
5. Legal basis for processing
Under the NDPR, NDPA, and equivalent legislation in our supported countries, we rely on the following lawful bases:
- Contractual necessity — processing required to deliver the Service you subscribed to.
- Consent — for marketing emails and optional analytics cookies. Withdrawable at any time.
- Legitimate interests — fraud detection, security, product improvement (balanced against your rights).
- Legal obligation — tax reporting, KYC, anti-money-laundering, lawful court orders.
- Vital interests — in rare cases, to protect a person from imminent harm (e.g., responding to a credible threat).
7. International data transfers
Wherever possible, your data is stored within Africa (primarily Nigeria and South Africa). Some service providers operate from the European Union, the United Kingdom, or the United States. When data is transferred outside your country of registration, we use safeguards required by applicable law:
- Standard Contractual Clauses (where required by GDPR / UK GDPR).
- NITDA-approved data-protection agreements for Nigerian residents.
- POPIA section 72 cross-border transfer safeguards for South African residents.
- Provider certifications (ISO 27001, SOC 2 Type II) where applicable.
8. How long we keep data
We retain personal data only as long as necessary for the purposes described in this policy, or as required by law:
| Active account data | For the duration of your subscription |
|---|---|
| Closed accounts | 12 months after termination, then deleted or anonymised |
| Financial / transaction records | Up to 7 years (tax authority requirements) |
| KYC / identity records | 5 years after relationship ends (AML requirements) |
| Marketing consent records | Until withdrawn, plus 2 years for proof of consent |
| Support tickets | 3 years after resolution |
| Server logs | 90 days, except where retained for security investigation |
9. Your rights
Subject to the law that applies to you, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data (subject to our legal retention duties).
- Restriction — limit how we process your data while we resolve a complaint.
- Portability — receive your data in a structured, machine-readable format.
- Object — to processing based on legitimate interests or for direct marketing.
- Withdraw consent — at any time, where processing is based on consent.
- Lodge a complaint with your data-protection authority (see below).
To exercise any right, email privacy@rosiovend.com or use the in-app Privacy Centre in your dashboard. We will respond within 30 days (or sooner where the law requires).
Your data-protection authority
- Nigeria: Nigeria Data Protection Commission (NDPC) — ndpc.gov.ng
- Ghana: Data Protection Commission — dataprotection.org.gh
- Kenya: Office of the Data Protection Commissioner — odpc.go.ke
- South Africa: Information Regulator — inforegulator.org.za
- Côte d'Ivoire: ARTCI — artci.ci
10. Automated decisions & AI
We use AI and automated systems to power features such as fraud detection, inventory forecasting, menu intelligence, and the AI assistant. Where an automated decision could have a significant effect on you (for example, blocking a transaction flagged as fraudulent), you have the right to:
- Request human review of the decision.
- Express your point of view and provide additional context.
- Receive an explanation of the logic involved.
AI features are designed to assist, not replace, human judgment. Your data is not used to train external AI models without your explicit consent.
11. Children's data
Rosiovend is a business platform and not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided data to us, please contact privacy@rosiovend.com and we will delete it promptly.
12. Security
We apply technical and organisational measures appropriate to the risk:
- TLS 1.3 encryption in transit; AES-256 at rest.
- Role-based access controls and least-privilege principles for our staff.
- Multi-factor authentication for all production systems.
- Continuous security monitoring, dependency scanning, and quarterly penetration testing.
- Encrypted, geo-redundant backups and tested disaster-recovery procedures.
- Mandatory security training for every Rosiovend employee.
If you believe you have found a security issue, please report it to security@rosiovend.com. We commit to acknowledge within 24 hours.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes at least 14 days before they take effect, by email and via in-app notification. The "Effective" date at the top of this page shows when it was last updated.
15. Contact our DPO
For privacy questions, data-subject requests, or to contact our Data Protection Officer:
Rosiovend Limited — DPO
Victoria Island, Lagos, Federal Republic of Nigeria
DPO: dpo@rosiovend.com
Privacy: privacy@rosiovend.com
Security: security@rosiovend.com
General: hello@rosiovend.com