Privacy Policy
Last updated: August 2026
Keynus Blueprint Launch respects your privacy. This policy explains what personal data we collect, why we use it, how we protect it, and your rights under Rwanda's Law No. 058/2021 relating to the Protection of Personal Data and Privacy (DPP Law).
Data controller
Keynus Blueprint Launch is the data controller for personal information collected through this website and our programs. For privacy requests contact [email protected].
What we collect
- Identity and contact: name, email, phone, nationality, city, and country.
- Account and security: password hash, session data, verification tokens.
- Application data: venture name, stage, motivation, and related form fields.
- Event data: registrations, pass status, check-in records where applicable.
- Communications you send us and operational messages we send you.
- Technical data: logs, device/browser metadata needed to secure and operate the service.
Why we use personal data
- To create and manage your account (contract and legitimate interest).
- To review applications and run cohorts (contract and legitimate interest).
- To coordinate events, passes, and check-in (contract and legitimate interest).
- To send operational messages such as verification, passes, and schedule updates (contract).
- To improve the platform and maintain security (legitimate interest).
- Marketing beyond operational messages only with your consent where required.
Rwanda data protection (DPP Law)
- KBL processes personal data of individuals in Rwanda in line with Law No. 058/2021.
- We register as a data controller with the National Cyber Security Authority (NCSA) / Data Protection and Privacy Office where required.
- We designate a contact point for data protection inquiries and cooperate with the supervisory authority when required.
Cross-border storage and processors
- Some infrastructure providers may store or process data outside Rwanda (for example hosting, CDN, email delivery, and backups).
- Where cross-border storage or transfer applies, we take steps required under the DPP Law, including registration and appropriate safeguards as advised by qualified counsel.
- We use processors only for defined purposes and require appropriate security measures.
Retention
We retain data while your account is active and as needed for legal, tax, and operational records. Application and event records may be kept for a reasonable period after participation ends. You may request correction or deletion where applicable law allows.
Your rights
- Request access to personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion or restriction where applicable under the DPP Law.
- Withdraw consent for optional processing where processing is consent-based.
- Lodge a complaint with the NCSA / Data Protection and Privacy Office if you believe your rights are violated.
Security
Access to member data is restricted to authorised staff. Passwords are stored hashed. Do not share your login credentials. Report suspected breaches promptly to [email protected].