Privacy Policy
Effective date: July 2026. How we collect, use, and protect your personal data.
Overview
This Privacy Policy explains how Imhotep Systems collects, uses, discloses, and protects personal data in connection with our website, platform, applications, and edge devices. It applies to visitors, prospective customers, customers, and end users of systems built on our infrastructure, except where a separate Data Processing Agreement governs our role as a processor on behalf of a customer.
Our role: controller vs. processor
When you interact directly with Imhotep as a visitor or prospective customer, we act as a data controller for that information. When our customers use our Services to process their own end users' data (for example, a business running its operations through Imhotep's workflow tools), we act as a data processor on behalf of that customer, who is the controller. The terms of that processing are governed separately in our Data Processing Agreement.
Information we collect
We may collect the following categories of information: • Account and contact information you provide, such as name, email, company, and role. • Usage data, including how you interact with the Services, log data, device and browser information, and diagnostic data. • Content and data you or your organization submit through the Services, including business data processed through workflow applications. • Data collected by edge devices where deployed, which may include operational, sensor, or environmental data depending on the deployment, as specified in your device documentation. • Communications data, such as support requests and correspondence with us.
How we use information
We use information to provide and operate the Services, maintain security and prevent abuse, improve and develop new features, communicate with you about the Services, meet legal and regulatory obligations, and, where you've consented, for marketing purposes. We do not sell personal data.
AI model training
We do not use Customer Data to train models shared across customers unless you've explicitly opted in. Where opted in, data is anonymized or aggregated before use. Enterprise and government customers may negotiate additional restrictions as part of their enterprise agreement.
Legal basis for processing
Where required under applicable data protection law, including Rwanda's Law No. 058/2021 relating to the protection of personal data and privacy, or the EU General Data Protection Regulation for relevant users, we process personal data on the basis of contract performance, legitimate interest, legal obligation, or consent, depending on context.
International data transfers
Where data is transferred across borders, including to or from Rwanda, we take steps to ensure appropriate safeguards are in place, consistent with applicable law. Government and critical-industry clients may request in-country or regional data residency guarantees, which will be specified in the applicable enterprise agreement.
Data security
We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, including encryption in transit and at rest, access controls, and regular security review. No system is completely secure, and we encourage you to use strong account practices.
Data retention
We retain personal data for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods for Customer Data processed on behalf of customers are governed by the applicable Data Processing Agreement or enterprise contract.
Your rights
Depending on your location and applicable law, you may have rights to access, correct, delete, or restrict processing of your personal data, and to object to certain processing or request data portability. To exercise these rights, contact privacy@imhotep.systems. Where Imhotep acts as a processor on behalf of a customer, requests should generally be directed to that customer, and we will support them as required by our agreement.
Children's privacy
The Services are not directed to individuals under 18, and we do not knowingly collect personal data from children.
Edge device data specifics
Where edge devices collect operational or environmental data as part of a deployment, the specific categories of data collected, retention periods, and whether data is processed locally versus transmitted to Imhotep's infrastructure will be described in the applicable product or deployment documentation.
Changes to this policy
We may update this Privacy Policy periodically. Material changes will be communicated with reasonable notice, and the effective date above will be updated accordingly.
Contact us
For privacy questions or to exercise your rights, contact privacy@imhotep.systems, or write to Imhotep Systems Ltd, Kigali, Rwanda.