Privacy Policy
1. Data Controller
The Controller for the personal data collected through the Software and other Services is RYAKEZA - Comércio e Prestação de Serviços, Lda., headquartered in Luanda, Talatona Municipality, Patriota Neighbourhood, Esplendor das Acácias Condominium, House E66. Where the Company processes personal data on behalf of and according to the instructions of the Client (for example, student, employee or end-customer data entered into the Software by the Client), the Company acts as a Processor, with the Client being the Controller of that data, under the terms defined in a specific Data Processing Agreement. This Policy complies with Law No. 22/11 of 17 June (Angola Personal Data Protection Law) and other applicable legislation.
2. Scope and Application
This Policy applies to the processing of personal data of: (i) Clients and their representatives; (ii) End Users of the Software (employees, students, guardians, consumers of e-commerce platforms); and (iii) visitors to the Company\u2019s institutional website.
3. Data Subject to Processing
Depending on the Service used, the Company may process the personal data you voluntarily provide: identification and contact data, authentication data, billing data, payment data and technical usage data (such as IP address, device type and pages visited on the institutional website, collected in an aggregated and anonymous manner whenever possible).
4. Purposes and Legal Basis of Processing
Contract performance: provision of the Software and other contracted Services, account management, billing and technical support — basis: performance of a contract to which the data subject is a party or pre-contractual steps. Electronic invoicing: issuance, transmission and retention of invoices as required by AGT — basis: compliance with a legal obligation. Integrated payments: technical processing of transactions and direct debit mandates — basis: contract performance and compliance with legal obligations applicable to the Angola Payments System. Security and fraud prevention: detection of unauthorised access and abusive use of the Software — basis: legitimate interest of the Company. Service communications: system notices, updates and changes to these Terms — basis: contract performance and legitimate interest. Commercial communications: sending promotional information about new products or features — basis: prior consent of the data subject, revocable at any time.
5. Data Sharing and Processors
The Company may share personal data with: service providers acting on behalf of the Company (data hosting, technical maintenance, data analysis, communications), as Processors, subject to a written contract with confidentiality and security obligations; EMIS – Empresa Interbancária de Serviços and the financial institutions participating in the Angola Payments System, to the extent strictly necessary for processing payment and direct debit operations; the General Tax Administration (AGT), in the context of complying with electronic invoicing obligations; and judicial, administrative or regulatory authorities, when required by law, court decision or order of a competent authority.
6. International Data Transfers
If the technical hosting of the Software or specific modules involves storing or processing data outside Angolan territory, the Company ensures that such transfer observes the guarantees required by Law No. 22/11, namely through appropriate contractual clauses with the hosting provider, and the Client is informed, upon request, about the location of the servers used.
7. Retention Period
Personal data is retained for the duration of the contractual relationship with the Client, and for as long as necessary to respond to their requests. After its termination, for the additional period necessary to comply with applicable legal obligations (namely fiscal and electronic invoicing) or until the expiry of the limitation period for any liability related to the provision of the Services. After these periods, the data is deleted or anonymised, unless there is a legal obligation to retain it for a longer period.
8. Information Security
The Company implements technical and organisational measures appropriate to the risk, including access control, encryption of sensitive data in transit and at rest, activity logging and security incident response procedures, to protect personal data against unauthorised access, loss, alteration or improper disclosure. In the event of a personal data breach likely to pose a high risk to data subjects\u2019 rights, the Company will notify the competent supervisory authority and the affected data subjects, under the terms and deadlines required by applicable legislation.
9. Data Subject Rights
Under Law No. 22/11, the data subject may, at any time, exercise the following rights with the Company, through the contacts indicated in section 1: Access: obtain confirmation of whether their data is processed and information about its origin, purposes, data categories and recipients; Rectification and updating: correct incomplete, inaccurate or outdated data; Erasure: request the deletion of data whose processing does not comply with the law, without prejudice to the Company\u2019s legal retention obligations; Objection: object, on grounds relating to their particular situation, to processing based on the legitimate interest of the Company; Withdrawal of consent: where processing is based on consent (e.g. commercial communications), withdraw it at any time, without affecting the lawfulness of processing carried out previously. The Company responds to requests within the applicable legal deadline.
Last updated: 05 Sep 2026
RYAKEZA - Comércio e Prestação de Serviços, LDA
Rua Condomínio Esplendor das Acácias, Casa n.º E66, Bairro Patriota, Talatona, Luanda
E-mail: geral@ryakeza.com
· Tel: 949 307 001