Legal documents

Privacy policy

Madata takes the protection of its clients' and staff's personal information very seriously.

This English version is provided for convenience. The French version at /politique-de-confidentialite remains the legally binding text under Ivorian law.

Publisher of this website and of the Madata solution: Adisa Lab, a company incorporated under Ivorian law, registered with the Abidjan Trade and Personal Property Credit Register under number RCCM CI-ABJ-03-2026-B12-05009, with its registered office in Abidjan, Côte d’Ivoire. Contact: [email protected].

Madata has designed this privacy policy to clarify its ongoing commitment to protect the right to privacy and the protection of personal information of its clients and staff. At all times, Madata aims to meet the expectations of its clients and staff by respecting their privacy while complying with applicable laws and professional duties.

In this policy, “Madata” refers to Adisa Lab, the company publishing the Madata solution, registered with the Abidjan Trade and Personal Property Credit Register under number RCCM CI-ABJ-03-2026-B12-05009, acting as data controller within the meaning of the applicable regulations.

01Principle 01: Responsible use of personal information

We are accountable for the personal information in our possession or under our control. Adisa Lab is accountable for all personal information in its possession, including information received directly from clients and staff, as well as information received indirectly. We have implemented policies and procedures designed to protect the personal information of our clients and staff. We have appointed a Personal Information Protection Officer who oversees privacy protection on behalf of Madata. For any question: [email protected]

02Principle 02: Justification for collecting personal information

Before or at the time of collecting personal information directly, Madata states the purposes for which it does so. In most cases, Madata uses and/or shares personal information about its clients solely in the course of delivering professional services. When a visitor browses our website, data files (cookies, pixel tags) may be placed on their device. They allow us to keep certain information about the use of the website: the date of the most recent visit, the pages viewed and the files downloaded. These files are only placed after your explicit agreement, collected through the banner shown on your first visit. The tools involved and their retention periods are detailed in principle 09 below.

03Principle 03: Minimisation of the personal information collected

Madata limits both the quantity and the nature of the personal information its organisation collects. Madata only collects personal information reasonably necessary to deliver its services and operate its business activities.

04Principle 04: Limited disclosure and retention of personal information

Madata uses and discloses your personal information only for the purposes for which it has obtained your consent, or as otherwise permitted or required by law. We only retain personal information for as long as necessary to fulfil the stated purposes. • HR and employee records: kept in accordance with employment laws and standards. • Job applicants: information retained for 24 months in order to contact them about other open positions. • If an applicant is hired, the information collected during the hiring process is retained to establish and manage the employment relationship.

05Principle 05: Adequate safeguards

Madata protects personal information through security measures commensurate with its degree of sensitivity. Madata protects personal information by using secure facilities and industry-standard tools and practices. • Personal information is stored in secure environments that are not publicly accessible. • Data is hosted on secure servers to which access is strictly limited to authorised personnel. • This data may be processed by third-party service providers. In such cases, Madata ensures that these third parties are bound by appropriate safeguards.

06Principle 06: Transparency

Madata will respond to any complaint or question regarding the privacy of personal information. In the case of a complaint, we will investigate and try to reach a resolution. Anyone who has concerns about Madata's compliance with its practices is invited to share those concerns with the Personal Information Protection Officer, ideally in writing. The Officer will ensure that any complaint triggers an internal investigation and will make every effort to communicate findings to the complainant within 30 days of receiving the complaint.

07Principle 07: Deletion of user data

In accordance with data protection requirements and the terms of third-party platforms (notably Meta/Facebook), any user may at any time request the deletion of the personal information that Madata holds about them, including information obtained through a connection with a third-party service (Facebook Login, Google, etc.). To exercise this right, simply send an email to [email protected] with the subject "Deletion of my data", specifying the email address associated with the account (and, where applicable, the identifier of the third-party service concerned). Madata processes these requests within a maximum of 30 days and confirms the effective deletion by return email. The deleted data includes the profile, the associated content, the connection logs and all the information collected through third-party services (name, email address, profile picture, external identifier).

08Principle 08: Data obtained from Google services (Gmail, Google Calendar)

When a user chooses to connect their Google account to Madata, the application accesses the following data, and only the following data. DATA ACCESSED • Identity (scopes "openid" and "email"): the email address of the connected Google account. It is used to link the connection to the correct Madata user and to display the sending address for outgoing messages. • Sending email (scope "https://www.googleapis.com/auth/gmail.send"): this level of access only allows Madata to send messages on the user's behalf. It grants no right to read, search, modify or delete anything in the Gmail mailbox. Madata does not read any of the user's email, and no Gmail mailbox content is stored in Madata. • Calendar (scope "https://www.googleapis.com/auth/calendar"): reading the user's calendar events in order to display them in the Madata calendar, and creating, updating or cancelling events when the user acts from within Madata. The event data processed consists of the title, dates and times, location, description and list of attendees. USE This data is used exclusively to provide the user-facing features requested by the user: sending business documents (quotations, invoices, payment reminders) from their professional address, and displaying and managing their schedule inside Madata. It is never used for advertising, ad targeting, profiling, creditworthiness or lending purposes, and it is never sold. TRANSFER TO THIRD PARTIES Calendar data (title, dates, location, attendees) may be transmitted to our artificial intelligence providers when the user asks the Mia assistant about their schedule. Those providers are Google (Gemini), OpenAI and Anthropic. They act as processors, solely on Madata's instructions and in order to answer the user's request, under commercial plans that contractually exclude the training of models on the transmitted data. Email content is never transmitted to an artificial intelligence provider, as Madata has no access to it. No Google user data is transferred or sold to data brokers, advertisers or any third party for their own purposes. PROTECTION Google access and refresh tokens are stored securely and are accessible only to authorised personnel. All exchanges with the Google APIs take place exclusively over HTTPS. RETENTION AND DELETION Tokens are retained for as long as the Google connection remains active. The user may disconnect at any time from their Preferences in Madata, which immediately deletes the tokens from our servers. They may also withdraw the authorisation granted to Madata directly from their Google account at https://myaccount.google.com/permissions. Any token that becomes invalid is purged automatically. A global deletion request may be sent to [email protected] with the subject "Deletion of my data" and will be processed within 30 days, in accordance with principle 07. LIMITED USE Madata's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

09Principle 09: Cookies, audience measurement and advertising

On your first visit, a banner lets you accept, decline, or choose category by category. No measurement or advertising cookie is placed on your device before you agree. One point of transparency about the Google tools. They run in "advanced consent mode": the Google script loads as soon as the page opens, but in a state where all data storage is denied. In that state it sends Google a so-called "cookieless" measurement: no cookie placed, no advertising identifier, no data that would let you be recognised from one visit to the next. It is used purely to estimate visit volumes statistically. If you accept, full measurement is enabled; if you decline, it stays limited to this anonymous form. The Meta and TikTok advertising tools, by contrast, are not loaded at all until you accept the "Advertising" category: no script, no request. You may change your choice at any time by clicking "Manage cookies" at the bottom of every page. Declining has no effect on your access to the site or to our services. CATEGORY 1 — STRICTLY NECESSARY (always on) These cookies do not require consent because the site cannot work without them. They are used neither for audience measurement nor for advertising. • Session and authentication: keeps you signed in to your client area. Duration: the session, or 30 days if you ask to stay signed in. • Language preference: remembers your French or English choice. Duration: 12 months. • Consent ("mt_consent"): records exactly the choice you express in the banner, so we do not ask again on every page. Duration: 13 months. • Security: protection against automated form submissions (Google reCAPTCHA). CATEGORY 2 — AUDIENCE MEASUREMENT (subject to your agreement) Provider: Google Ireland Limited. • Google Analytics 4: number of visitors, pages viewed, navigation paths, traffic sources. We use it to understand which pages are useful to you. IP addresses are truncated before storage. Cookies "_ga" and "_ga_*", set only if you accept. Duration: 13 months. • Google Tag Manager: a technical tool for managing the tags above. It does not set a cookie of its own. If you decline, these cookies are not set and only the cookieless measurement described above remains. Ad click identifiers are then masked and requests go through a cookie-free domain. CATEGORY 3 — ADVERTISING (subject to your agreement) These tools let us measure how well our campaigns work and avoid showing you irrelevant ads. • Meta Pixel — Meta Platforms Ireland Limited: measurement of Facebook and Instagram campaigns, and building of advertising audiences. Cookies "_fbp", and "_fbc" if you arrive from an ad. Duration: 3 months. • TikTok Pixel — TikTok Information Technologies UK Limited: measurement of TikTok campaigns. Cookies "_ttp" and "_tt_enable_cookie". Duration: 13 months. DATA SENT We send these tools the page viewed, where the visit came from, and the steps completed (account creation, plan selection, payment, provisioning). The amount of a subscription taken out is sent so that we can measure campaign profitability. We never send them your name, email address, phone number, company name, or any data entered in your client area. Page addresses containing a token or an identifier (activation, invitation or survey links) are always redacted before anything is sent. TRANSFERS OUTSIDE THE EUROPEAN UNION These providers may transfer data to the United States, on the basis of the European Commission's standard contractual clauses and, for the entities concerned, the EU-US Data Privacy Framework. You may refuse these transfers at any time by declining categories 2 and 3 in the banner.

Questions about your privacy?

Reach out to our Personal Information Protection Officer.

[email protected]