Legal

Data Processing & Sub-Processors

Version 2.2  ·  Effective 30 August 2026 (replaces the version of 16 August 2026)  ·  Bodiop Ltd · TIN 155969694

What this page is. Bodiop Ltd is the data controller for subscriber data. To run the Service we rely on a small number of outside providers, who act as data processors on our instructions.

This page names every one of them, says exactly what each can access, and sets out the terms we require of them under Articles 21–25 and 38 of Law N° 058/2021 (the DPP Law). It is published so you can see the full list rather than take our word for it.

1. The controller

Bodiop Ltd
TIN 155969694 · Registered in the Republic of Rwanda
Registered office: Kirehe, Eastern Province, Rwanda
NCSA-registered Data Controller 001/2376/0426, valid to 22 April 2029 — view certificate
Data protection contact: privacy@bodiop.rw · WhatsApp +250 729 909 068

Bodiop Ltd determines why and how subscriber personal data is processed, and remains accountable for it whichever provider holds it at a given moment.

2. Current sub-processors

This is the complete list as at the effective date above.

ProcessorPurposePersonal data accessibleLocation
Hetzner Online GmbH Cloud hosting for our server, automation and database — our primary infrastructure All subscriber data, as the underlying host Germany (EU)
Meta Platforms
WhatsApp Business Cloud API
Delivery of alerts and service messages Mobile number; content of messages sent and received Ireland / United States
MTN Rwanda
Mobile Money Collections
Payment requests, confirmations and refunds Mobile number, amount, date, transaction reference Rwanda
Google LLC
Workspace & Sheets
Operational records, business email, and sending service emails to subscribers (delivery-recovery link, deletion confirmation) Profile and subscription records, including your email address; correspondence and the content of service emails we send you United States / EU
DeepSeek AI screening, extraction and summarisation of opportunity listings None. Receives public listings only, not subscriber data. China
OpenAI, L.L.C. Converts subscriber skills, interests and target roles into numeric match vectors (embeddings) Your skills, interests and target roles as text — never your identity, contact details, employment status, education, experience, certifications, or any special-category field United States
Cloudflare, Inc. DNS, CDN, TLS and protection for bodiop.rw IP address and request metadata, in transit Global edge network
Microsoft Corporation
Clarity
Website analytics and heatmaps on bodiop.rw Anonymised browsing behaviour; text input is masked United States / EU

n8n is not a sub-processor. Our automation runs on self-hosted n8n installed on our own Hetzner server. No subscriber data is transmitted to n8n GmbH or to any n8n-operated cloud service. n8n is software we run, not a party we share data with.

Providers previously listed and no longer used: Airtable (never brought into production), which never held Bodiop subscriber data.

3. What we require of every processor

We engage a processor only where it offers written data protection terms at least equivalent to the following. These are the commitments we rely on, and we do not claim rights we have not actually been granted.

  1. Instruction only. Process personal data solely to deliver the contracted service on our documented instructions, and not for its own purposes — in particular not to train general-purpose models on our data, not to profile our subscribers, and not to sell or share the data.
  2. Confidentiality. Bind every person with access to enforceable confidentiality obligations.
  3. Security. Maintain appropriate technical and organisational measures — encryption in transit and at rest, access control, logging, tested backups and vulnerability management — proportionate to the risk.
  4. Sub-processors. Engage further sub-processors only under terms no less protective than these, remain fully liable for them, and give us advance notice of changes with a right to object.
  5. Assistance with your rights. Help us respond to access, rectification, erasure, restriction, objection and portability requests within the time the DPP Law allows, and pass any request received directly to us rather than acting on it.
  6. Breach notification. Notify us without undue delay after becoming aware of a personal data breach, with enough detail for us to meet our own 48-hour obligation to the NCSA.
  7. Deletion or return. Delete or return all personal data at the end of the service, except where law requires retention.
  8. Transparency and audit. Make available the information needed to demonstrate compliance. For our larger providers this is satisfied by recognised independent audit reports and certifications rather than an on-site inspection, and we accept that. Where a provider is small enough for us to audit directly, we reserve that right on reasonable notice.
  9. Transfers. Apply a lawful transfer mechanism for any processing outside Rwanda — see section 5.

4. What we commit to as controller

5. Transfers outside Rwanda

Most of our processors operate outside Rwanda. For each transfer we rely on one or more of the mechanisms permitted under the DPP Law: contractual clauses imposing protection equivalent to Rwandan law, the processor's own certified transfer framework, and rigorous data minimisation.

Minimisation is the safeguard that does the most work. The processor located furthest away — the AI provider in China — receives no subscriber personal data at all in normal operation, because the AI reads opportunity listings rather than people. The full profile stays on our own server in Germany.

Where we cannot satisfy ourselves that a transfer is adequately protected, we do not make it.

6. Changes to this list

We update this page whenever a processor is added, replaced or removed, and we change the version number and effective date at the top.

Where a new processor would gain access to subscriber personal data, we notify subscribers by WhatsApp or email before it begins processing. If the change requires fresh consent, we ask for it rather than assume it.

To be told of changes to this list directly, email privacy@bodiop.rw with the subject "Sub-processor notifications".

7. Duration, termination and governing law

Each processing arrangement lasts as long as that processor provides its service to Bodiop Ltd, plus any period we are required to retain records. If a processor materially breaches its data protection obligations, we may terminate its service with immediate effect and move the processing elsewhere.

This page and the arrangements it describes are governed by the laws of the Republic of Rwanda, and any dispute falls to the competent courts of Kigali. Nothing here limits any right you have under the DPP Law or your ability to complain to the supervisory authority.

Data protection queries

Bodiop Ltd · TIN 155969694 · Kirehe, Eastern Province, Rwanda

Email: privacy@bodiop.rw

WhatsApp: +250 729 909 068

Supervisory authority: Data Protection and Privacy Office, National Cyber Security Authority — cyber.gov.rw