Conditions et politiques
Privacy policy
What personal data Mandi collects, why, how long it is kept, and how to exercise your rights.
Last updated: 21 September 2026
This English version is provided for convenience. In case of any discrepancy, the French version prevails.
This document is a working draft. It describes what Mandi does today, but it must be reviewed by a lawyer before it binds the organisation. Passages still open are marked “to be completed”.
1. Our principle
We collect the minimum amount of data needed for our services to work. We do not sell any personal data and we do not do targeted advertising.
The data controller is Mandi, who can be reached at contact@mandia.org.
2. The data we process
When you visit the website. Technical connection data: IP address, browser type, pages viewed, date and time. It is used to run the website, secure it and measure its audience in aggregate form.
Audience measurement. We do it ourselves, without cookies and without any third-party service. For each page viewed, we record the page path, the site you came from (its name only), your country, the type of device, browser and operating system, and the language of the site. Your IP address is used to work out the country, on our servers, and is then not kept. To count visitors without tracking them, we compute a fingerprint from the IP address, the browser and a random value that changes every day and is destroyed after two days: it is therefore impossible to recognise you from one day to the next, or to trace back to your address.
On the data platform (dataset.mandia.org). We also count what visitors do, to learn what is useful: searches (any email addresses and phone numbers they contain are masked before recording), downloads, trials of models and spaces, likes, publications, sign-ups and sign-ins. If you are signed in, the action is linked to your account; otherwise, to the daily fingerprint described above. This data is only viewed in aggregate form, in the administration console.
Security. When a request looks like an attack (probing for known vulnerabilities, injection attempts, repeated wrong passwords, excessive requests), we record the IP address, the country, the request and the browser, in order to detect and block attacks. Technical errors on the website are also recorded, without identifying data, so they can be fixed.
When you support the organisation. Name, email address, phone number if you provide it, amount and chosen payment method, and the transaction reference. Bank card or mobile money details are processed by the payment provider: they do not pass through our servers and we do not keep them.
When you write to us. The content of your message and the contact details you include in it.
When you use a model. The content you submit and the answer produced, for the duration of the conversation. Public conversations may be kept in anonymised form to evaluate the quality and safety of the model. Please do not enter sensitive data or information that could identify a person.
When you have an account on the platform. Email address, name, role, and a log of the actions taken on content.
3. Why we process it
| Purpose | Legal basis |
|---|---|
| Providing and securing the website and the platform | Legitimate interest of the organisation |
| Measuring the website's audience, anonymously | Legitimate interest |
| Processing and following up a contribution, issuing a receipt | Performance of the relationship and accounting obligation |
| Replying to a message | Legitimate interest |
| Evaluating and improving the quality and safety of the models | Legitimate interest, on anonymised data |
| Meeting our legal obligations | Legal obligation |
4. How long
- Technical logs: twelve months at most.
- Audience measurement and actions on the data platform (without IP address): thirteen months.
- Security log (with IP address): ninety days.
- Contribution data: the period required by applicable accounting obligations, then deletion or anonymisation.
- Messages: three years from the last exchange.
- Platform accounts: for the duration of the assignment, then deletion within six months.
5. Who has access
Only the people at Mandi who need it. We use technical providers for hosting, sending emails and collecting contributions; they act on our instructions and are bound by confidentiality. (List of processors and hosting countries to be completed.)
We do not transfer your data to third parties for commercial purposes. Data is disclosed to an authority only upon a legally grounded request.
6. Hosting and transfers
We favour hosting as close as possible to our users and are working towards an infrastructure we control. Where a provider hosts data outside Côte d'Ivoire, we ensure an appropriate level of protection. (To be specified once the final infrastructure has been decided.)
7. Your rights
In accordance with Law No. 2013-450 of 19 June 2013 on the protection of personal data, you have the right of access, rectification, objection, erasure and restriction, as well as the right to set instructions for what happens to your data after your death.
To exercise them, write to contact@mandia.org. We reply within one month. You may also contact the Telecommunications Regulatory Authority of Côte d'Ivoire (ARTCI), which is responsible for the protection of personal data.
8. Security
Passwords are stored in encrypted form, exchanges with the website are encrypted in transit, and access to the platform is logged. As no system is infallible, we will inform you without delay in the event of a data breach likely to affect you.
9. Minors
Our services are not intended for people under sixteen. If you find that a minor has sent us data, write to us: we will delete it.
10. Changes to this policy
This policy evolves with our services. The date of the last update appears at the top of the page.
A question about this document? contact@mandia.org