Privacy Policy
This Privacy Policy explains how Digisi Rwanda Limited (“Digisi”, “we”, “us”) processes information when providing Oz FreightOps and the supporting Oz Core platform, including the API, customer console, freight-operations workflows, and configured integrations.
1. Roles and scope
Depending on the processing context, Digisi may act as a data controller for information used to operate its own accounts, security, support, and billing functions, and may process customer-supplied freight information on behalf of an organization using the Service.
2. Information we process
Account information: email address, organization name, role, and authentication information. Passwords are stored as one-way password hashes rather than plaintext.
API credentials: the Service stores a one-way API-key hash and display prefix rather than the full secret after creation.
Usage and technical metadata: endpoint, model, token counts, latency, HTTP status, timestamps, request identifiers, and bounded operational/security metadata.
Freight operations content: inbound sender address, subject, parsed message body, message identifier, extracted business facts, confidence, review notes, suggested actions, quote and shipment records, shipment updates, and related operational/audit history.
Original freight email attachments: files received with freight email are stored within the organization boundary. Supported files may be temporarily parsed for bounded text extraction and document analysis.
Uploaded/retrieval content: upload or retrieval features can store files and extracted or chunked retrieval content where persistence is required by the feature.
Audit and security data: actor, organization, timestamp, resource identifiers, IP address where applicable, and bounded event metadata.
Billing information: where paid billing is live, Paddle processes payment details. The Service is designed to store the customer/subscription identifiers and billing state needed to associate an organization with billing status.
Cookies: the console uses an HttpOnly session cookie for authentication. The current product does not use advertising or behavioral-tracking cookies.
3. Why we process information
We process information to authenticate users; provide freight intake, extraction, document handling, operator workflows, model routing, billing, and customer support; maintain tenant isolation and audit records; investigate failures or security events; prevent abuse; and maintain service reliability.
We do not sell customer data. The current Service does not use customer freight messages, attachments, prompts, or model outputs to train our models.
4. AI-assisted processing and human review
Oz FreightOps uses AI to assist classification, structured extraction, document analysis, and draft preparation. AI output can be incomplete or incorrect. Consequential actions including pricing, booking commitments, cancellations, carrier selection, shipment-update application, and customer-facing sends remain behind explicit human review or action.
5. Providers and recipients
The Service may make information available to configured providers only as needed to operate requested features, with customer authorization where applicable, or where legally required. Provider categories include Hetzner for documented production infrastructure in Helsinki, Finland; Groq when a request is deliberately routed to a configured hosted model; Paddle for payment and subscription processing; and customer-selected email or integration providers.
6. International storage and transfers
Production infrastructure is documented in Finland, and optional providers may process information in other countries. Where information is stored or processed outside Rwanda, Digisi applies the notices, safeguards, contracts, registrations, or authorizations required by applicable law.
7. Retention
The general business target for operational customer data is 24 months. Different periods may apply where law, fraud or security investigation, billing, dispute preservation, backup recovery, or an applicable customer contract requires it. Production backups may retain deleted data for a bounded recovery period.
8. Privacy rights and requests
Subject to applicable law and the role in which Digisi processes information, individuals may have rights to request information about processing; access or a copy of personal data; correction; restriction; erasure; objection; portability; information about international transfers; and protections relating to solely automated decisions. Requests may be sent to [email protected].
Rights and complaints are handled in accordance with applicable law, including Rwanda's Law No. 058/2021 relating to the protection of personal data and privacy where applicable.
9. Security
The Service uses controls including password hashing, hashed and revocable API keys, TLS for production traffic, organization scoping, role checks, audit logs, restricted freight-ingestion scopes, attachment access controls, request-size limits, same-origin protections, bounded logs, backup/restore tooling, and explicit human-approval gates. No security measure can guarantee absolute security.
10. Children's privacy
Oz FreightOps is a business service and is not directed at children.
11. Changes
Material changes may be communicated through the Service, by email, or another reasonable method where required.
12. Contact
Privacy questions and requests may be sent to [email protected].