Effective date: 20 July 2026 · Last updated: 9 September 2026
This Privacy Policy explains how Tyndill Finance & Forex Bureau Ltd (“Tyndill”, “we”, “us”) collects, uses, shares, and protects your personal data when you use our money-transfer and mobile-money services through the Tyndill app, our WhatsApp service, our website, and our branch in Kigali. We are committed to protecting your privacy in line with Rwanda’s Law No. 058/2021 relating to the protection of personal data and privacy and the guidance of the National Cyber Security Authority (NCSA).
1. Who we are
Tyndill Finance & Forex Bureau Ltd is a registered bureau de change, money-transfer and mobile-money agency based in Kigali, Rwanda, serving transfers between Rwanda and Sudan, Egypt, Tanzania, Saudi Arabia and the United Arab Emirates. For the personal data described here, Tyndill is the data controller. You can reach us using the details in section 13.
2. Personal data we collect
Identity & contact
- Full name and preferred language;
- Phone number(s), including your WhatsApp number and mobile-money (MoMo) number;
- Email address and country of residence;
- Identification details you provide for verification (e.g. ID/passport) where required by law.
Transaction & financial data
- Transfer amount, currencies, exchange corridor, and applicable rate;
- Sender and recipient details (name, account or phone number, destination);
- Payment proofs and receipts you upload (including the bank/mobile-money screenshots), and the transfer proofs we provide to you.
Communications
- Messages, voice notes, and images you exchange with us on WhatsApp or in the app, and our replies;
- Support requests and correspondence.
Technical data
- Log-in and device information, IP address, and activity logs used for security and fraud prevention.
3. How we collect it
- Directly from you — when you register, request a transfer, upload a receipt, or contact us on WhatsApp, the app, or at our branch;
- Automatically — through your use of the app and website (security logs);
- From partners — such as mobile-money and payment providers involved in completing your transfer.
4. How and why we use your data
- To provide the service — process and settle your transfers, issue receipts, and keep your transaction history (performance of our contract with you);
- Legal & regulatory compliance — identity verification, anti-money-laundering (AML) and counter-terrorist-financing (CFT) checks, record-keeping, and reporting where required (legal obligation);
- Fraud prevention and security — verifying payment proofs and protecting accounts (legitimate interest);
- Communication — sending transfer confirmations, receipts, verification codes, and support responses on WhatsApp, email, or the app;
- Service improvement — understanding and improving how our services work.
5. Who we share it with
We share personal data only as needed to deliver the service and meet our legal obligations, with:
- Contabo GmbH (European Union) — hosts our application, our database and the files you upload. Receives all platform data;
- Anthropic PBC (United States) — reads identity documents and payment receipts automatically to assist our staff with data entry. Receives identity-document images, receipt images and conversation content;
- Meta Platforms (Ireland and United States) — operates the WhatsApp Business channel. Receives your messages, media and phone number;
- Resend (United States) — delivers our emails. Receives your name, email address and the content of the message;
- Constt Information Technology (United States) — hosts our domain's DNS and our email mailboxes. Receives email you send to us;
- MTN Rwanda (Rwanda) — mobile-money settlement, once enabled. Receives payer and payee numbers and amounts;
- Rwanda Revenue Authority, the National Bank of Rwanda, courts and law enforcement — only what a lawful request requires.
Every provider above is bound by a written agreement covering confidentiality, security and breach notification, and may process your data only on our instructions.
Automated reading of your identity document and receipts does not decide anything about you on its own. A member of our staff reviews and approves before any transfer is acted on.
We do not sell your personal data.
6. WhatsApp & messaging
When you contact Tyndill on WhatsApp, your messages are delivered through the WhatsApp Business Platform provided by Meta. We use these messages to serve you, process transfers, and send confirmations and receipts. Meta’s handling of messages is also governed by its own privacy terms. By messaging us, you consent to receiving service-related replies, documents, and notifications from Tyndill on WhatsApp.
7. International data transfers
Because we move money between Rwanda and other countries, some data (such as recipient details) is necessarily processed outside Rwanda to complete your transfer. Our application, database and uploaded files are stored in the European Union; our DNS, mailboxes, email delivery and automated document reading are provided from the United States, and the WhatsApp channel from Ireland and the United States.
Each of these transfers is covered by Standard Contractual Clauses, and we have applied to the National Cyber Security Authority for authorization to store personal data outside Rwanda under Article 50 of Law No. 058/2021.
8. How long we keep it
- Identity documents and identification records — 7 years after your relationship with us ends;
- Transaction records, receipts and ledger movements — 7 years from the date of the transaction;
- WhatsApp conversations and media — 24 months, or 7 years where the message is evidence for a transaction;
- Access and audit records — 7 years, because these records evidence financial transactions and follow the same statutory period;
- Your account and profile — until you close your account, plus 1 year;
- One-time codes and sessions — minutes to days; they expire automatically.
The seven-year periods are set by financial record-keeping rules. We cannot delete those records earlier, even at your request, until the period has run. After it has, data is deleted or anonymised.
9. How we protect it
- Encryption of data in transit (HTTPS/TLS);
- Role-based access controls so staff see only what their job requires, with branch-level isolation;
- Audit logging of sensitive actions (who did what, and when);
- Session timeouts and authentication controls on staff and client accounts;
- Regular backups and access restrictions on our servers.
10. Your rights
Under Law No. 058/2021 you have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request deletion of your data, subject to our legal record-keeping obligations;
- Object to or request restriction of certain processing;
- Withdraw consent where processing is based on consent;
- Lodge a complaint with the National Cyber Security Authority (NCSA) of Rwanda.
To exercise any of these rights, contact us using the details below. We may need to verify your identity before acting on a request. Note that some data must be retained to meet AML/CFT obligations even if you ask for deletion.
11. Children
Our services are intended for individuals aged 18 and over. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date above shows the latest version, and material changes will be communicated through the app or WhatsApp.