Privacy policy
Last updated
This policy explains what personal information Migambi Global Ltd collects through this website, why we collect it, how long we keep it, and what you can ask us to do with it. It covers this website only. It does not cover software we build for clients, which is governed by the contract for that project.
Who is responsible for your data
Migambi Global Ltd is the data controller for information collected through this site. We are a software studio registered in Rwanda and based in Kigali, Rwanda. You can reach us at hello@migambiglobal.com, which is also the address to use for any request described below.
What we collect
Information you send us. When you submit the contact form we receive your name, your email address, and anything else you choose to put in the form — optionally your company, where you are based, the type of work you are after, a budget range, and your description of the project. None of those optional fields are required to reach us.
Technical information. Our hosting provider records standard server logs when a page is requested: the IP address making the request, the page, the timestamp, and the browser's user-agent string. These are generated by the infrastructure rather than collected by us, and we use them only to keep the site available and secure. When you submit the form we also store your browser's user-agent string alongside the message, and a one-way hash of your IP address — not the address itself — purely to stop the same sender flooding the form.
What we do not do
We do not run analytics, advertising, or tracking scripts on this site. We do not use tracking or advertising cookies. We do not build profiles of visitors, and we do not sell, rent, or trade personal information to anyone. Our fonts are served from our own domain rather than a third-party font service, so simply reading a page does not disclose your visit to another company.
Why we use it, and on what basis
We use what you send us to answer your enquiry, to scope and quote work, and to keep a record of what was discussed. Where the law requires a legal basis, ours is your consent in sending the message, and our legitimate interest in responding to it and in running the studio. Where a request turns into a project, we process it to take steps at your request before entering a contract.
We do not send marketing email. If we ever do, it will be something you opt into explicitly, and every message will carry a one-click unsubscribe.
Who else processes it
We keep the list of third parties deliberately short, and each one acts on our instructions rather than for its own purposes:
- Our hosting provider serves the site and generates the server logs described above.
- Google Cloud Firestore stores what you send through the contact form. The database is in the European Union, and it is not readable from the public internet — only our own server-side code can reach it.
- Resend sends us the notification email that tells us your message has arrived. If it is unavailable, your message is still stored; only the notification is delayed. If our server cannot be reached at all, the form falls back to opening a message in your own email application, in which case nothing passes through a third party.
- Our email provider stores the resulting correspondence.
We may also disclose information where the law requires it, or where it is necessary to establish or defend a legal claim.
Where your data is processed
Our providers operate infrastructure outside Rwanda, so information you send is processed in other countries. Contact-form messages are stored in the European Union; the notification that a message has arrived passes through a provider in the United States. Where a transfer of this kind takes place we rely on the safeguards our providers put in place, such as standard contractual clauses.
How long we keep it
Enquiries that do not become projects are kept for up to twenty-four months, so we can pick up a conversation that resumes later, and then deleted. Correspondence connected to a project is kept for the life of the engagement and for as long afterwards as tax and contract law requires. Server logs are kept for a short period by our hosting provider and then rotated out.
Cookies and local storage
This site sets no cookies. It stores nothing in your browser — no local storage, no session storage, no device identifiers of any kind. Nothing about your visit persists after you close the tab.
Your rights
Under Rwandan data protection law, and under the GDPR if you are in the European Union or the United Kingdom, you can ask us to give you a copy of the personal information we hold about you, correct it if it is wrong, delete it, restrict what we do with it, or object to our processing it. Where it applies, you can also ask us to send it to you in a portable format.
Write to hello@migambiglobal.com and we will respond within one month. There is no charge. If you are not satisfied with our response you can complain to the National Cyber Security Authority in Rwanda, or to your local supervisory authority if you are in the EU or the UK.
Keeping it secure
The site is served over HTTPS, and access to the inbox that receives enquiries is limited to the people who need it. No system is perfectly secure, but we do not collect more than we need, which is the most effective protection available.
Children
This site is aimed at businesses and is not directed at children. We do not knowingly collect information from anyone under 18. If you believe a child has sent us personal information, write to us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top of this page. Where a change is significant we will say so on this page rather than expecting you to compare versions.
Contact
Questions about this policy, or any request about your data, go to hello@migambiglobal.com.