

Last updated: 2026-08-02
KFC Delivery, (herein referred to as “we", "us" or "our"), operates the KFC Delivery mobile application, and related ordering and delivery services (together, the "Services").
This Privacy Policy applies to personal data processed through the Services where the data subject is located in Rwanda, including where a service provider processes the data outside Rwanda. It should be read together with any just-in-time notices displayed when we request device permission or optional consent.
We do not intentionally request sensitive personal data. Do not place health, medical, biometric, religious or other sensitive information in delivery instructions unless it is strictly necessary. Where sensitive personal data is knowingly processed, we will do so only where permitted by Rwanda law, with the required consent or other lawful authority, and with enhanced safeguards.
Where personal data is not obtained directly from you, we will provide the information required by law unless a lawful exception applies.
We process personal data only for specified, lawful and necessary purposes. The lawful basis depends on the activity:
Where we rely on legitimate interests, we assess the necessity of the processing and balance our interests against the possible impact on your rights and freedoms.
| Purpose | Personal data used | Lawful basis |
|---|---|---|
| Create and secure an account; authenticate sign-in | Relevant account, order, delivery, location, payment, device or communication data | Performance of a contract or steps requested before entering a contract; legitimate interests in account security. |
| Accept payment; prepare, fulfil, deliver, track, refund and support an order | Relevant account, order, delivery, location, payment, device or communication data | Performance of the delivery contract; compliance with payment, tax, consumer protection and accounting obligations. |
| Use precise location to select an address or support an active delivery | Relevant account, order, delivery, location, payment, device or communication data | Performance of the contract and device permission; consent where required for optional or background location. |
| Prevent fraud, abuse, unauthorised access and security incidents | Relevant account, order, delivery, location, payment, device or communication data | Legitimate interests and legal obligations, balanced against your rights. |
| Operate, troubleshoot, test and improve essential App performance | Relevant account, order, delivery, location, payment, device or communication data | Legitimate interests in reliable and secure Services; consent for non-essential analytics or tracking. |
| Respond to support requests, complaints and disputes | Relevant account, order, delivery, location, payment, device or communication data | Performance of the contract, legal obligations and legitimate interests in resolving claims. |
| Send marketing, offers, surveys and promotional notifications | Relevant account, order, delivery, location, payment, device or communication data | Your separate, freely given consent. Marketing consent is not a condition for ordering food. |
| Comply with law, regulator requests, audits, legal claims and enforcement | Relevant account, order, delivery, location, payment, device or communication data | Legal obligation, public interest where applicable, or establishment, exercise and defence of legal claims. |
We will send promotional email, SMS, push notifications or personalized offers only where we have a valid lawful basis, including your separate consent where required. Consent must be specific, informed and indicated by a clear affirmative action; pre-ticked boxes or bundled consent should not be used.
You may withdraw marketing consent at any time through the App preference center, the unsubscribe link in an email, the opt-out instruction in an SMS, your device notification settings, or by contacting privacy@kfeah.com. Withdrawal does not affect processing that occurred lawfully before withdrawal and does not stop essential service messages about an active order, payment, security or account administration.
You may object at any time to processing for direct marketing, including related profiling. We do not sell, rent or trade personal data to data brokers or third-party advertisers.
Personal data is stored in Rwanda unless storage outside Rwanda is permitted under Rwanda law and covered by a valid authorisation from the National Cyber Security Authority/Data Protection & Privacy Office. Our current hosting location is in Africa, UAE and USA.
Where personal data is transferred to or accessed from another country, we will identify the destination country, use a lawful transfer ground, implement appropriate safeguards, enter into the required written contract with the recipient.
We retain personal data only for as long as necessary for the stated purpose, to comply with applicable legal obligations, or to establish, exercise or defend legal claims. The approved retention schedule must be completed before publication:
When retention expires, we securely delete the data or irreversibly anonymize it. Pseudonymized or de-identified data remains subject to data-protection controls where re-identification remains reasonably possible.
We implement and regularly review technical and organizational safeguards appropriate to the nature and risk of the processing. These must include, where appropriate, encryption in transit and at rest, role-based access controls, least-privilege access, multi-factor authentication for administrative accounts, secure software development, vulnerability and dependency management, logging and monitoring, protected backups, vendor due diligence, staff confidentiality and training, incident response, and periodic testing of safeguards.
No internet-connected service is risk-free. This statement does not reduce our legal duty to implement appropriate security or respond to incidents.
The Services are not directed to children under 16. Where we know that personal data belongs to a child under 16, we will obtain verifiable consent from a holder of parental responsibility in accordance with Rwanda law, unless processing is necessary to protect the child’s vital interests or another lawful exception applies.
A parent or guardian may contact the DPO to request access, correction, restriction or deletion of a child’s personal data.
Subject to the conditions and exceptions in Rwanda law, you may:
Erasure is not the same as a user-interface “anonymization” switch. We will assess a valid erasure request and delete personal data unless continued retention is required or permitted by law. Where data must be retained, we will restrict it to the applicable lawful purpose.
You may update basic account details in the Profile or Account Settings section. For access, portability, objection, restriction, erasure, withdrawal of consent, representation or other formal requests, email privacy@kfeah.com or contact the DPO using the details in Section 17.
We may request proportionate information to verify identity and protect accounts from unauthorized requests. We will respond in writing or electronically within 30 days of receiving a valid request or explain the lawful reason for non-compliance.
If you are dissatisfied with our response, you may appeal or complain to the Data Protection & Privacy Office. Current contact details include: 21 KG 7 Ave, A&P Building, Ground Floor, Kacyiru, Kigali; toll-free 9080; complaint@dpo.gov.rw; or dpp@dpo.gov.rw. A statutory appeal should be lodged within the period provided by Rwanda law, including within 30 days after receiving our response where applicable.
We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects on customers. If this changes, we will provide meaningful information about the logic, significance and expected consequences, identify the lawful basis, and provide the safeguards and rights required by law.
Any personalization, recommendations, fraud screening or marketing segmentation that does not have such significant effects will still be subject to transparency, lawful-basis, objection and consent requirements.
We maintain an incident-response and breach-notification procedure. Where a personal-data breach occurs, we will notify the supervisory authority within 48 hours after becoming aware of it and submit the available-facts breach report within 72 hours, as required by Rwanda law.
Where a breach is likely to create a high risk to your rights and freedoms, we will communicate the breach to you in writing or electronically, unless a lawful exception applies.
We may update this Privacy Policy to reflect changes in the Services, vendors, law or processing. The current version will display an effective date and version number. Material changes will be communicated through an appropriate channel before they take effect. Where a new purpose requires consent, we will request fresh consent rather than treating continued use as consent.