NezaCampaign

Privacy policy

Last updated 8 October 2026

Neza Campaign is operated by Nezalab Technology. This policy covers two groups of people: our customers, who sign up to send campaigns, and the contacts our customers send to.

Our role

For customer accounts we are the data controller. For contact lists, the customer who uploads them is the controller and decides who to message; we process those contacts only on the customer’s instructions and to run the service, as a processor under Rwanda’s Law N° 058/2021 on the protection of personal data and privacy.

What we store

  • Customer accounts. Your email address, organisation name and a cryptographic hash of your password. We never store the password itself.
  • Contacts. The email addresses, phone numbers, names, tags and any other columns a customer imports, and the lists and segments they belong to.
  • Consent records. For each contact and each channel (email, SMS): whether they agreed to receive messages, when, and how that was recorded — for example a sign-up form or an import whose uploader confirmed the contacts opted in.
  • Suppression lists. Addresses that unsubscribed, bounced, complained or asked not to be contacted. These are kept so we can keep honouring that request, even if the contact record itself is deleted.
  • Delivery events. When campaigns are sent: delivery, bounce, complaint, open and click events for each message, used for reporting and to protect deliverability.

Uploaded CSV files are deleted as soon as they have been processed.

How we use it

To deliver the messages our customers send, to honour unsubscribes and suppression, to show customers reports about their campaigns, to detect and stop abuse, and to meet legal obligations. We do not sell personal data, we do not use contact lists for our own marketing, and we never share one customer’s contacts with another.

Who else receives data

  • Amazon Web Services (Amazon SES) delivers campaign email. It receives the recipient address and the message, and reports back deliveries, bounces and complaints.
  • Mobile network operators will deliver SMS campaigns once that channel launches. They receive the recipient phone number and the message.
  • Our hosting provider runs the servers that store the service’s data.

We may disclose information where the law requires it or where it is necessary to investigate abuse of the service.

If you received a message

Every campaign email contains an unsubscribe link that takes effect immediately. To find out what a sender holds about you, or to ask for it to be corrected or deleted, contact the sender first — they control their list. You can also write to us at support@nezamail.com and we will help, including by suppressing your address across the customer’s account.

Retention

Contacts are kept until the customer deletes them or closes their account. Suppression entries are kept for as long as the customer’s account exists, because deleting them would allow messages to resume. Delivery events are kept for up to 13 months.

Security

Connections to Neza Campaign use TLS. Passwords are stored as hashes, each customer’s data is isolated from every other customer’s, and administrative access to servers is restricted.

Contact

Questions about this policy: support@nezamail.com. We will update this page and the date above if the policy changes.