← Back to Gephra Ltd

Privacy

Data Deletion

How to request deletion of Personal Data associated with Gephra’s websites, products, platforms, and services.

Data deletion at Gephra

GEPHRA LTD (“Gephra,” “we,” “us,” or “our”) provides this page to explain how individuals may request deletion of Personal Data associated with Gephra’s websites, products, platforms, and services.

This process applies to Personal Data processed through:

  • gephra.com
  • Gephra HOPILLA
  • Gephra Sustaina
  • other Gephra Services that reference this deletion process

Requesting deletion from Gephra

Where Gephra controls the Personal Data concerned, you may request deletion by contacting privacy@gephra.com.

Your request should include sufficient information for Gephra to identify the relevant data or account, such as:

  • your name
  • your email address or other account identifier
  • the Gephra Service concerned
  • a brief description of the information you would like deleted

Please do not send passwords, authentication secrets, payment credentials, or other unnecessary sensitive information with your request.

Identity verification

Gephra may request reasonable information to verify your identity or authority before processing a deletion request. Verification is intended to prevent unauthorized persons from deleting or obtaining information associated with another individual or organization.

Gephra will request only information reasonably necessary for this purpose.

Customer-controlled data

Some Gephra Services are provided to businesses and organizations that control the Personal Data processed through those Services.

For example, a hotel, lodge, resort, serviced apartment, guest house, or other hospitality business may use Gephra HOPILLA to process information relating to its guests, employees, or operations.

Where the relevant Customer determines how and why Personal Data is processed, the Customer generally controls that data and Gephra processes it on the Customer’s behalf. If your deletion request concerns Personal Data held by a Gephra Customer, you should normally submit the request directly to that Customer.

Examples may include:

  • hotel guest records
  • reservations
  • stay information
  • Customer-managed employee records
  • Customer-managed transaction records
  • information submitted to a Customer through a Gephra-powered service

Gephra will support the relevant Customer in carrying out valid deletion requests where required by applicable law or contractual obligations.

Account deletion

Where a Gephra Service provides an account-deletion function within the application, you may use that function to initiate deletion. Where no self-service deletion function is available, a request may be submitted to privacy@gephra.com.

Deletion of an account may result in loss of access to associated Services, settings, records, or other information linked to that account. Where the account is controlled by an organization, certain account actions may need to be performed or authorized by that organization.

What happens after a request

After receiving a deletion request, Gephra may:

  1. 1verify the identity or authority of the requester
  2. 2determine whether Gephra or a Customer controls the relevant Personal Data
  3. 3identify the information covered by the request
  4. 4determine whether any information must or may lawfully be retained
  5. 5delete, anonymize, or otherwise remove applicable Personal Data
  6. 6communicate the outcome of the request where appropriate

Requests will be handled in accordance with applicable data protection and privacy requirements.

Information that may be retained

Deletion does not necessarily require immediate removal of every record associated with an individual. Gephra may retain information where reasonably necessary for purposes including:

  • compliance with legal or regulatory obligations
  • tax and accounting requirements
  • security and fraud prevention
  • investigation of abuse or security incidents
  • establishment, exercise, or defence of legal claims
  • enforcement of contractual obligations
  • maintenance of required audit records
  • other purposes permitted by applicable law

Where possible, Personal Data that is no longer required may be deleted or anonymized.

Backups

Personal Data deleted from active systems may remain temporarily within protected backups until those backups are overwritten or expire through established retention processes.

Backup data will not ordinarily be restored or otherwise processed except where required for legitimate recovery, security, or legal purposes.

Third-party services

Where Personal Data has been provided directly to an independent third-party service, such as a payment provider, communications provider, or other external platform, deletion may also be subject to that third party’s privacy and deletion procedures.

A request submitted to Gephra does not automatically delete information independently controlled by another organization.

Deletion requests connected to external platforms

Gephra Services may integrate with external platforms that require a publicly accessible data-deletion instructions URL. Unless a product-specific deletion process is provided, this page serves as Gephra’s general deletion instructions at https://gephra.com/data-deletion.

Requests arising from an external platform integration may be submitted to privacy@gephra.com. The requester should identify the relevant Gephra Service and external platform to allow the request to be located and processed appropriately.

Privacy Policy

Additional information about how Gephra handles Personal Data is available in the GEPHRA LTD Privacy Policy.

Contact

GEPHRA LTD

KG 65 STREET
Kigali, Rwanda

Privacy: privacy@gephra.com
General enquiries: info@gephra.com

© Gephra Ltd. All rights reserved.