African Forensic Sciences Academy

AFSA Privacy Policy

African Forensic Sciences Academy (AFSA) Registered as an International NGO by the Rwanda Governance Board; Reg. No. N000001RGB|INGO|RC|07|2024
August 2026

At a Glance

  • AFSA collects your personal data mainly to run your membership, process payments, organise events, and communicate with you.
  • We do not sell your personal data, and we only share it with the people and service providers who need it to deliver AFSA’s work to you.
  • Rwanda’s Law N° 058/2021 of 13/10/2021 Relating to the Protection of Personal Data and Privacy gives you rights over your data: to access it, correct it, restrict or object to its use, move it, or have it erased. Section 10 below explains how to use them.
  • The National Cyber Security Authority (NCSA) is Rwanda’s supervisory authority for data protection. You can complain to AFSA first, and to the NCSA if you are not satisfied with our response.

The sections below set out the full detail.

1. Introduction and Scope

The African Forensic Sciences Academy (“AFSA,” “we,” “us,” or “our“) is a voluntary, non-political, non-profit scientific organisation and a registered International NGO under the laws of the Republic of Rwanda. AFSA represents the interests of forensic science practitioners across Africa, in line with our vision of being the leader in promoting excellence and integrity in forensic science on the continent.

This Privacy Policy explains how AFSA collects, uses, shares, stores, and protects personal data, and what rights you have over that data. It applies to:

  • Our website, AFSA.Africa, and any AFSA microsites (e.g. conference sites such as AFSA2024.AFSAfsa.Africa);
  • The AFSA Membership Portal (membership.afsa.africa) and the systems behind it;
  • Membership applications, renewals, and member records;
  • Event, conference, and webinar registrations;
  • Donations and other payments made to AFSA;
  • Newsletters and other communications from AFSA; and
  • Any other occasion on which you share personal data with AFSA, including by email, WhatsApp, telephone, or paper/PDF forms.

This Policy is issued in accordance with Rwanda’s Law N° 058/2021 of 13/10/2021 Relating to the Protection of Personal Data and Privacy (the “Data Protection Law”), which is enforced by the National Cyber Security Authority (NCSA) as Rwanda’s supervisory authority for data protection.

If you do not agree with this Policy, please do not submit personal data to AFSA. Where AFSA needs your consent for a specific activity (for example, to send you the AFSA newsletter), we will always ask for it separately and you may withdraw it at any time.

2. Who We Are

For the purposes of the Data Protection Law of Rwanda, the data controller is:

African Forensic Sciences Academy (AFSA) KN 8 Ave, Kacyiru, Kigali, Rwanda RGB Reg. No.: N000001RGB|INGO|RC|07|2024 Telephone / WhatsApp: +250 795 580 320, Email: [email protected]

3. Personal Data We Collect

We collect different categories of personal data depending on how you interact with AFSA:

  1. a) Identity and contact data: full names, title, email address, phone/WhatsApp number, postal address, country of residence and, where relevant to membership eligibility, nationality.
  2. b) Professional and academic data: your forensic science discipline or field of interest, qualifications, CV, proof of work experience, and proof of registration with an academic institution (for student membership), submitted when you apply for or renew AFSA membership.
  3. c) Membership and governance data: your membership category (Full, Associate, Student, Affiliate, or Honorary), membership number and status, votes cast at Annual General Meetings (for Full Members), and any role you hold on the Board, a Committee, or a Working Group.
  4. d) Financial data: membership fees and event fees paid or owed, donation amounts, payment method and reference numbers, and refund history. AFSA does not itself store your full card number; card and mobile-money payments are processed by our payment service provider (currently DPO Pay), and bank transfers are processed by AFSA’s bank in Rwanda.
  5. e) Event and conference data: registrations for AFSA webinars, workshops, and conferences (such as AFSA2024), attendance records, and, where you choose to provide them, dietary or accessibility requirements.
  6. f) Communications data: correspondence you send us by email, WhatsApp, the AFSA contact form, or Google Forms, and records of our replies.
  7. g) Account and technical data: your login credentials and activity on the AFSA Membership Portal, and standard website usage data such as IP address, browser/device type, and pages visited, collected automatically when you use afsa.africa.
  8. h) Content you choose to share: research, presentations, testimonials, or photographs you submit for AFSA newsletters, the AFSA website, or AFSA social media.

Children

AFSA’s services are intended for adults working, studying, or training in forensic science. We do not knowingly collect personal data from children under 16 without the consent of a parent or legal guardian, as required by Article 9 of the Data Protection Law. If you believe a child has provided us with personal data without appropriate consent, please contact us so we can address this aspect and delete their data.

4. How We Collect Personal Data

  • Directly from you: when you apply for or renew membership (currently via a Google Form linked from AFSA.Africa), register for an event, make a donation or payment, subscribe to the AFSA newsletter, contact us, or create an account on the AFSA Membership Portal.
  • Automatically: through standard website logs and, where used, cookies and similar technologies (see Section 12).
  • From third parties: only where the Data Protection Law allows this (Article 14); for example, from institutions confirming a student’s registration, from event co-organisers such as the Rwanda Forensic Institute for jointly run conferences, or from information you have made publicly available (such as a professional profile you link to your application).

5. Why We Process Your Personal Data, and Our Legal Basis

Article 46 of the Data Protection Law requires us to have a lawful basis for every purpose for which we process personal data. The table below sets out our main purposes and the basis we rely on.

PurposeWhat this involvesLegal basis
Assessing and administering membership applications and renewalsReviewing your application category, credentials, and supporting documentsYour consent; processing of the membership applications
Verifying eligibility for membershipVerifying qualifications, experience, or criteria for specific categories e.g. AfricanPerformance of the membership relationship; AFSA’s legitimate interest in maintaining a credible register of applicants and practitioners
Collecting membership fees, event fees, and donations, and processing refundsPayment processing via bank transfer or DPO Pay, and applying the AFSA Refund PolicyPerformance of the membership/event relationship; compliance with legal and financial record-keeping obligations
Organising AFSA events, conferences, and webinarsRegistration, logistics, attendance recordsYour consent; performance of the event registration relationship
Operating and securing the AFSA Membership PortalAccounts, logins, member communicationsProcessing of the membership relationship; AFSA’s legitimate interest in keeping the Portal secure
Sending the AFSA newsletter and updatesEmail communications about AFSA’s workYour consent (you may withdraw it at any time — see Section 10)
AFSA governanceAGM notices, elections, Board/Committee records, voting records for Full MembersPerformance of the membership relationship; AFSA’s legitimate interest as a member-governed body
Enforcing the AFSA Constitution and Code of ConductInvestigating complaints; suspending or expelling members where warrantedAFSA’s legitimate interest in maintaining professional standards
Meeting AFSA’s legal and regulatory obligationsReporting to the Rwanda Governance Board, the NCSA, tax authorities, auditors and other legally mandated authoritiesCompliance with a legal obligations
Research, publications, and knowledge-sharing consistent with AFSA’s missionShowcasing member research on AFSA platforms and newsletters, with your consentYour consent; research purposes recognised under Article 10(5)
Protecting AFSA, our members, and the publicPreventing fraud, misuse of the AFSA name, or security incidentsAFSA’s legitimate interest

Automated decision-making. AFSA does not use automated decision-making alone or profiling to decide membership applications, event eligibility, or any other outcome that would produce legal and/or compliance effects on you. Membership decisions are made by AFSA’s Membership Committee.

6. Who We Share Your Personal Data With

We share personal data only where necessary, and never sell it. Recipients may include:

  • AFSA’s Board, Membership Committee, and authorised staff or volunteers, who are bound by confidentiality under the AFSA Code of Conduct;
  • Payment service providers, currently DPO Pay, to process card and mobile-money payments;
  • AFSA’s bank(s) in Rwanda (currently Ecobank Rwanda PLC), for bank-transfer payments of membership and event fees;
  • Email and communications service providers, e.g. MailChimp used to send the AFSA newsletter and membership communications (this includes standard delivery, open, and click statistics);
  • Forms and productivity tools, currently including Google Forms, used for some membership and event-registration submissions, when you use these, Google also processes your data under its own privacy terms;
  • Website hosting, content-delivery, and image-optimisation providers that keep afsa.africa and the Membership Portal running;
  • Co-hosts and partners for specific events for purposes such as event organising and marketing. Information will be limited to what is necessary to organise the joint event;
  • Professional advisers, such as auditors, lawyers, and IT contractors, under confidentiality obligations;
  • Other entities that require it for legal and compliance purposes, e.g. The Rwanda Governance Board, the National Cyber Security Authority of Rwanda (NCSA), courts, or other authorities where AFSA is legally obligated to share information.

Where a third party processes personal data on AFSA’s behalf, Article 4 of the Data Protection Law of Rwanda requires a written contract governing the legal processing, and AFSA  puts such contracts in place with its service providers.

7. International Data Transfers

Some of AFSA’s service providers (for example, our email and payment processors) may be based, or process data, outside Rwanda. For this reason we require your  consent, since there is a need for the transfer to perform your membership or event contract with AFSA.

AFSA relies on these grounds for its current international transfers. Where required, we take reasonable steps to select service providers who offer an appropriate level of protection for your data.

8. How Long We Keep Your Data

We keep personal data only for as long as necessary for the purposes described in this Policy or as legally required, generally for the periods outlined below:

  • Membership records: for the duration of your membership,  or as long as legally mandated to do so in order  to fulfill governance, audit, and legal requirements.
  • Rejected or incomplete applications: the same as for membership records.
  • Financial, payment, and donation records: for the period required by Rwandan tax and accounting legislation.  
  • Event registration and attendance records: for the duration of the event and a further period for reporting, audit and compliance requirements.
  • Newsletter and marketing data: until you unsubscribe, or after a period of prolonged inactivity (as defined byAFSA from time to time).
  • Website and Portal logs: for the legally required length of time which may be up to 24 months.

At the end of the applicable retention period, we destroy or irreversibly de-identify personal data in line with Article 52 of the Data Protection Law.

9. How We Keep Your Data Secure

In line with Article 47 of the Data Protection Law of Rwanda, AFSA takes reasonable technical and organisational measures to protect personal data against loss, misuse, and unauthorised access, including restricting access to personal data to those who need it, using secure connections for the website and Membership Portal, and reviewing our safeguards as risks change.

If a data breach occurs, AFSA will notify the NCSA within 48 hours of becoming aware of it and submit a full report within 72 hours, as required by Articles 43 and 44 of the Data Protection Law. Where a breach is likely to result in a high risk to your rights and freedoms, we also have to notify you directly as stipulated by Law

10. Your Rights Under the Data Protection Law

As a data subject, you have the following rights under Chapter III of the Data Protection Law:

  • Right to access: to ask what personal data we hold about you, why, and who it has been shared with (Article 18).
  • Right to object: to ask us to stop processing your data, including for direct marketing e.g. notification of upcoming events (Article 19).
  • Right to data portability: to receive your data in a structured, readable format, or have it sent to another data controller where feasible (Article 20).
  • Right regarding automated decisions: not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Article 21). 
  • Right to restriction: to ask us to pause processing while you dispute its accuracy or lawfulness (Article 22).
  • Right to erasure: to ask AFSA to delete your data where it is no longer needed, or when you withdraw consent, or it has been unlawfully processed (Article 23).
  • Right to rectification: to have inaccurate or incomplete data corrected (Article 24).
  • Right to withdraw consent: at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 8).
  • Right to representation: if you are unable to represent yourself, an authorised representative may exercise these rights on your behalf (Article 26).
  • Right to human intervention: if an automated decision is made you have the right to request that a human intervention be made to assess the automated decision

How to exercise your rights. Contact AFSA using the details in Section 2 or Section 13. We will respond within 30 days of receiving your request, as required by the Data Protection Law of Rwanda. We may need to verify your identity before acting on a request. If you wish to withdraw from AFSA services, please do so in writing to the email stated in Section 2. 

If you are not satisfied with our response, you have the right to appeal to the NCSA within 30 days of receiving it. The NCSA is required to respond to appeals within 60 days.

11. Registration with the National Cyber Security Authority

Under Articles 29 to 36 of the Data Protection Law of Rwanda, organisations that process personal data in Rwanda are required to register with the NCSA as a data controller. 

12. Cookies and Similar Technologies

AFSA.Africa may use cookies and similar technologies to keep the website running, remember your preferences, and understand how the site is used (for example, through our website host or image-delivery provider). You can control or disable cookies through your browser settings; doing so may affect how parts of the website function. We do not use cookies to build advertising profiles of visitors.

13. Contacting Us and Complaints

For questions about this Policy or to exercise your rights, contact:

African Forensic Sciences Academy via email at [email protected] 

If you are not satisfied with how AFSA has handled your personal data, you may lodge a complaint with:

National Cyber Security Authority (NCSA), Data Protection Office Website: cyber.gov.rw Email: [email protected]  

14. Changes to This Policy

AFSA may update this Policy from time to time to reflect changes in our activities or in the law. The “last updated” date indicates when it was last revised.  

15. Governing Law

This Policy, and AFSA’s processing of personal data, is governed by the laws of the Republic of Rwanda, in particular Law N° 058/2021 of 13/10/2021 Relating to the Protection of Personal Data and Privacy.