Privacy Policy for Muswada
Last updated: August 2026
Protecting your personal data is a priority for Muswada. This privacy policy informs you how we collect, use, share and protect your personal information.
ARTICLE 1: Data Controller
1.1 Controller Identity
The Data Controller for personal data collected on the Muswada site is:
- Company name: Maonoo, LLC
- Legal form: Limited Liability Company (LLC)
- Registered office: 131 Continental Dr, Suite 305, Newark, DE 19713, United States
- Operating office: Dandji Lot 649, Cotonou, Benin
- Website: https://www.muswada.com
1.2 Data Protection Officer (DPO)
For any questions regarding the protection of your personal data, you may contact our Data Protection Officer:
- Email: [email protected]
- Postal address: Maonoo, LLC, DPO, Dandji Lot 649, Cotonou, Benin
ARTICLE 2: Data Collected
2.1 Registration Data
When creating your account, we collect the following data:
| Data | Character | Purpose |
|---|---|---|
| Email address | Mandatory | Identification, communications, account recovery |
| Username/pseudonym | Mandatory | Public identification on the platform |
| Password | Mandatory | Account access security (stored hashed with bcrypt) |
| Avatar | Optional | Profile customization |
2.2 Profile Data
After registration, you may complete your profile with:
| Data | Character | Purpose |
|---|---|---|
| Biography | Optional | Presentation to other members |
| Social media links | Optional | Networking (Twitter, Facebook, Instagram) |
| Language preferences | Optional | Interface customization |
| Profile photo | Optional | Visual customization |
2.3 Activity Data
We collect data related to your use of the platform:
Content created:
- Published stories (title, description, chapter content)
- Comments and reviews
- Posts on the news feed
- Private messages
Interactions:
- Library (favorite stories and reading progress)
- Reading history
- Likes and votes
- Subscriptions (follows) between users
2.4 Technical Data
When using the site, we automatically collect:
| Data | Purpose | Retention Period |
|---|---|---|
| IP address | Security, fraud prevention, statistics, approximate geolocation (country) | 12 months |
| Detected country (via IP) | Personalized content recommendations by region | 12 months |
| User-Agent (browser, operating system) | Display optimization, statistics | 12 months |
| FCM Token (Firebase Cloud Messaging) | Push notification delivery | Until logout or revocation |
Anonymous reading identifier (mws-anon-reader-id) | Aggregated reading statistics: counting each non-logged-in reader only once (never linked to an account — see Cookie Policy, Article 3.4) | 13 months (in your browser) |
| Session cookies | Authentication, preferences | See Article 10 |
| Connection logs | Security, audit | 12 months |
2.5 Payment Data
Important: Muswada does NOT store your bank card data.
Payments are processed by our provider Stripe, PCI-DSS certified. Stripe stores and processes:
- Stripe customer ID
- Transaction history
- Card information (encrypted by Stripe)
For more information, see Stripe's privacy policy: https://stripe.com/privacy
2.6 Author Data (KYC and Payment)
For Authors wishing to earn revenue and make withdrawals, we collect the following additional data:
| Data | Character | Purpose |
|---|---|---|
| Copy of identity document (ID card, passport or driver's license) | Mandatory (before first withdrawal) | Identity verification (KYC), AML/CFT compliance |
| Bank details (IBAN) or Mobile Money number | Mandatory (before first withdrawal) | Revenue transfer execution |
| Tax identification number (TIN/NIF) | Mandatory (if EU or US resident) | Tax reporting obligations (DAC7 Directive 2021/514, IRS) |
| W-8BEN or W-9 form | Mandatory (if US-sourced income) | IRS tax compliance |
| Proof of address | Conditional (if revenue > EUR 5,000/year) | Enhanced verification (due diligence) |
| Selfie and facial biometric data | Mandatory (if verification via Smile ID) | Identity verification by facial comparison, AML/CFT compliance |
Legal basis: contract performance (Article 6.1.b GDPR) and legal obligation (Article 6.1.c GDPR -- AML/CFT Directives 2015/849 and 2018/843, DAC7 Directive 2021/514, Beninese law no. 2018-17).
Biometric data: Identity verification via Smile ID may involve processing of biometric data (facial comparison selfie/ID document) within the meaning of Article 9 of the GDPR. This processing is based on the Author's explicit consent (Article 9.2.a GDPR), specifically collected during the KYC procedure. The Author may refuse biometric processing and opt for manual verification by our compliance team (extended processing time).
Retention periods:
- Identity document and KYC data: 5 years after the end of the contractual relationship
- Bank details / Mobile Money: duration of the relationship + 5 years
- Tax number and tax forms: 6 years after the last declaration
- Payout history: 10 years (accounting obligations)
Enhanced security measures:
- Encryption at rest (AES-256) for identity document copies
- Access restricted to authorized personnel (accounting and compliance department)
- Logging of all access to KYC data
- Secure deletion upon expiration of retention periods
2.7 Reading Session Data (Premium Plan)
As part of the Premium Plan and the CPL (Cost Per Read) calculation, we collect:
| Data | Purpose | Retention Period |
|---|---|---|
| Reading session duration | CPL calculation, legitimacy validation | Plan duration + 12 months |
| Chapter completion percentage | Reader score calculation for CPL | Plan duration + 12 months |
| Session legitimacy indicator | Fraud prevention (readings too fast, bots) | Plan duration + 12 months |
| Session start and end date and time | Traceability, deduplication | Plan duration + 12 months |
Legal basis: performance of the Premium Plan contract (Article 6.1.b GDPR) and legitimate interest in preventing abuse (Article 6.1.f GDPR).
The User may contest a session flagged as non-legitimate by contacting support at [email protected].
2.8 Sale Consent and Author Age Verification (Paid Content)
As part of activating a paid access type (Premium, Paid, Paid + Space) described in Article 12quater.7 of the Terms of Service, we collect:
| Data | Purpose | Retention Period |
|---|---|---|
| Sale consent (timestamp, IP address, accepted Terms version) | Evidence of having informed and obtained acceptance of the locking and withdrawal conditions (Article 12quater.7 of the Terms) | Account lifetime + 5 years after deletion |
| Frozen copies ("snapshots") of content at the time of each purchase | Guarantee the buyer access to the exact version of the content purchased (Article 12quater.6 of the Terms), even if the Author later modifies it | Lifetime of the related purchase (see Article 5.2) |
| Author's self-declared date of birth | Verifying that the Author is of legal age (18) before activating any paid access type | Account lifetime, then 5 years after deletion (see Article 5.2) |
Legal basis: performance of the contract (Article 6.1.b GDPR), necessary for concluding a valid sales contract, and legal obligation relating to the contracting parties' legal capacity and the protection of minors (Article 6.1.c GDPR).
On the self-declared date of birth: this data is declarative (not verified against an ID document) and becomes immutable once recorded, to prevent any further attempt with a different date. This immutability, and its retention even after a refusal, rests on Muswada's legitimate interest in preventing circumvention of the minor-protection mechanism (Article 6.1.f GDPR).
If the Author later completes an identity verification (KYC) as part of an earnings withdrawal request (Article 2.6), the ID-verified date of birth replaces the initial declaration and becomes the reference data.
The self-declared or verified date of birth is never made public: it is accessible only to the Author themselves (on their own profile) and to authorized Muswada staff.
The Author may exercise their rights of access and rectification over this data under the conditions of Articles 8 and 9, subject to the immutable nature of the date of birth once recorded, justified by the need to preserve the integrity of the minor-protection mechanism.
2.9: Data from Social Login (Google and Facebook)
Muswada lets you create your account and sign in using your Google or Facebook account (so-called "OAuth" authentication). This method is optional: you can always use a Magic Link sent by email, or a Passkey. This section explains precisely which data we receive from Google and Facebook, what we do with it, and above all what we cannot see.
a) Data we retrieve
When you choose to sign in with Google or Facebook, and after you have granted your authorization on the provider's consent screen, we receive only the following three items:
| Data | Source | Use by Muswada |
|---|---|---|
| Email address | Google / Facebook | Unique identifier of your account; generation of your initial username (the part before the "@") |
| Name | Google / Facebook | Display name of your profile |
| Profile picture | Google / Facebook | Your profile avatar |
We request no extended permission ("scope") beyond these three items. The email address provided by Google or Facebook is treated as already verified: you therefore have no additional verification email to confirm.
b) What Muswada CANNOT see
The authorization you grant is strictly limited to the three items above. In particular:
With Google, Muswada cannot:
- read, send or access your Gmail emails;
- access your Google Drive files;
- access your contacts, calendar or any other Google service.
With Facebook, Muswada cannot:
- see your posts or publish on your behalf on your timeline;
- access your friends list;
- read or send Messenger messages;
- access your photos, videos or any other data from your Facebook account.
c) Use of this data
The three retrieved items are used exclusively to:
- authenticate you and secure access to your account;
- create your account and pre-fill your profile (username, display name, avatar), which you can then freely edit;
- send you the necessary transactional communications (service emails and notifications relating to your account);
- make you identifiable to other users: your username and avatar are public, as for any Muswada account.
d) Sharing of this data
Data obtained from your Google or Facebook login (email address, name, profile picture) is never sold, nor disclosed to data brokers. Nor is it transmitted to Meta as part of the advertising pixel (Article 3.6): if you have consented to that pixel, Meta may be informed that a registration took place from your browser ("CompleteRegistration" event), but receives neither your email address, nor your name, nor your profile picture. It is processed under the same conditions as the other data in your account (Articles 6 and 7).
e) Legal basis
The processing of these three items is based on the performance of the contract (Article 6.1.b GDPR): they are necessary to create your account and provide the authentication service you requested by choosing social login. The retrieval is triggered by your voluntary action and by the authorization you grant on Google's or Facebook's consent screen.
f) Revoking access
You can withdraw the access granted to Muswada at any time, directly from the security settings of your Google or Facebook account:
- Google: Google Account → Security → "Your connections to third-party apps & services";
- Facebook: Settings & privacy → Settings → "Apps and websites".
Revocation prevents any future login via that provider. It does not delete your Muswada account or the data already recorded: you can continue to sign in by another method (Magic Link, Passkey), or request deletion of your account (Articles 8 and 9).
Important distinction: this section concerns signing in via Google/Facebook (an authentication method). It is distinct from the "social media links" you may voluntarily add to your profile (Article 2.2): those links are merely display references and give Muswada no access to the corresponding accounts.
ARTICLE 3: Purposes of Processing
Your personal data is processed for the following purposes:
3.1 Contract Performance
- Management of your user account
- Provision of platform services (publication, reading, interactions)
- Management of Premium subscriptions and payments
- Customer support and technical assistance
3.2 Legitimate Interests
- Improvement of our services and user experience
- Fraud prevention and platform security
- Statistics and audience analysis (anonymized)
- Personalization of the news feed and recommendations
- Geographic recommendations: Using your IP address to determine your country and offer relevant content from your region (local authors, stories, posts)
3.3 Consent
- Sending push notifications
- Sending newsletters and marketing communications
- Use of non-essential cookies
- Loading of the Meta advertising pixel and transmission of browsing events to Meta (Article 3.6)
3.4 Legal Obligations
- Retention of connection data (legal obligation)
- Response to requests from competent authorities
- Fight against illegal content
3.5 Editorial features and advertising
We editorially feature selected stories and content from the platform. These featured selections may be targeted by country: we use your country, estimated from your IP address, to show you selections relevant to your region.
- Data used: only your country, estimated via IP address (approximate location). This in-house editorial mechanism relies on no behavioral profiling, no targeting by age, city or interests, and uses no advertising cookie.
- Purpose: to display editorial featured selections relevant to your country.
- Legal basis: legitimate interest (Article 6.1.f GDPR).
- No sharing or sale: the data used by this editorial mechanism is never shared or sold to third parties. The Meta advertising pixel, subject to your consent, is described in Article 3.6.
- Right to object: you can disable this targeting at any time via the "Do not personalize based on my country" option in your account settings. You will then only see featured selections intended for "everyone".
- Retention: the IP address is retained for 12 months (see Article 5).
3.6 Advertising via the Meta Pixel (with your consent)
To measure the effectiveness of its own advertising campaigns on Facebook and Instagram, Muswada uses the Meta Pixel, described in detail in Article 3.5 of our Cookie Policy.
- Data concerned: browsing events ("PageView": viewing a page; "CompleteRegistration": creating an account), technical data (page address, IP address, browser characteristics) and the
_fbpcookie (duration: 3 months). No data from your account or from forms (email, name, photo, etc.) is transmitted to Meta in this context. - Purpose: measurement and optimization of Muswada's advertising campaigns on Meta platforms.
- Legal basis: your prior explicit consent (Article 6.1.a GDPR and Article 5(3) of the e-Privacy Directive). The pixel is never loaded without your acceptance via the consent banner.
- Joint controllers: for the collection and transmission of this data, Maonoo, LLC and Meta Platforms Ireland Limited act as joint controllers (CJEU, "Fashion ID" judgment, C-40/17), under the terms of Meta's Controller Addendum: https://www.facebook.com/legal/controller_addendum. Meta is solely responsible for the subsequent processing it carries out.
- Transfers outside the EU: see Article 7; transfers to Meta Platforms, Inc. (United States) are governed by Meta's Standard Contractual Clauses.
- Withdrawal of consent: at any time, as easily as you gave it, via the "Manage cookies" link at the bottom of each page, with no effect whatsoever on your access to the service. Withdrawal does not affect the lawfulness of prior transmissions.
- Important: this data is not sold; the internal reading audience measurement (first-party anonymous identifier, Article 2.4) is independent of the pixel and is not affected by this choice.
Meta's privacy policy: https://www.facebook.com/privacy/policy
ARTICLE 4: Legal Basis for Processing
In accordance with the General Data Protection Regulation (GDPR), each data processing is based on a legal basis:
| Processing | Legal Basis | GDPR Reference |
|---|---|---|
| Account management | Contract performance | Article 6.1.b |
| Authentication via social login (Google, Facebook) | Contract performance | Article 6.1.b |
| Platform services | Contract performance | Article 6.1.b |
| Payments and subscriptions | Contract performance | Article 6.1.b |
| Security and fraud prevention | Legitimate interest | Article 6.1.f |
| Anonymized statistics | Legitimate interest | Article 6.1.f |
| Reading audience measurement (anonymous identifier) | Legitimate interest | Article 6.1.f |
| Personalization | Legitimate interest | Article 6.1.f |
| Geographic recommendations (country via IP) | Legitimate interest | Article 6.1.f |
| Push notifications | Consent | Article 6.1.a |
| Marketing communications | Consent | Article 6.1.a |
Meta advertising pixel (_fbp cookie, browsing events) | Consent | Article 6.1.a |
| Log retention | Legal obligation | Article 6.1.c |
| Judicial requisitions | Legal obligation | Article 6.1.c |
| Author age verification (legal age required for monetization) | Contract performance + Legal obligation | Articles 6.1.b and 6.1.c |
ARTICLE 5: Retention Period
Your data is retained for the following periods:
5.1 Active Account Data
| Data Type | Retention Period |
|---|---|
| Registration data | Lifetime of the account |
| Profile data | Lifetime of the account |
| Published content | Lifetime of the account (or until deletion by the user) |
| Private messages | Lifetime of the account |
| Library and preferences | Lifetime of the account |
5.2 After Account Deletion
| Data Type | Retention Period | Justification |
|---|---|---|
| Identification data | 30 days | Possibility of reactivation |
| Connection data (logs) | 12 months | Legal obligation |
| Billing data | 10 years | Accounting obligations |
| Self-declared date of birth (Author age verification) | 5 years after deletion | Statute of limitations under ordinary civil law, applicable if a minor Author's legal capacity is contested |
| Published content | Immediate anonymization | Preservation of discussion integrity |
5.3 Technical Data
| Data Type | Retention Period |
|---|---|
| IP addresses | 12 months |
| Detected country (geolocation) | 12 months |
| Security logs | 12 months |
| Session cookies | Until session closure or expiration |
| FCM tokens | Until revocation or logout |
ARTICLE 6: Data Recipients
6.1 Internal Access
Your data is accessible only to authorized persons within Maonoo, LLC:
- Technical team (maintenance and development)
- Moderation team (reported content only)
- Customer service (within the scope of support)
- Management (supervision)
6.2 Subcontractors
We use the following subcontractors:
| Subcontractor | Country | Data Processed | Purpose | Safeguards |
|---|---|---|---|---|
| Firebase (Google) | USA | FCM token, device ID | Push notifications | Standard Contractual Clauses (SCCs) |
| Stripe | USA | Email, customer ID, transactions | Payments | PCI-DSS certified, SCCs |
| MinIO (self-hosted) | Dedicated server | Uploaded files (avatars, images) | Storage | Controlled infrastructure |
6.3 Authorized Third Parties
Your data may be communicated to:
- Judicial authorities upon legal request
- Law enforcement in case of manifestly illegal content
6.4 No Sale of Data
Muswada never sells your personal data to third parties.
ARTICLE 7: Transfers Outside the European Union
Some of your data may be transferred to countries outside the European Union, including the United States (Firebase, Stripe and, if you have consented to the advertising pixel, Meta — see Article 3.6).
7.1 Appropriate Safeguards
These transfers are governed by:
- Standard Contractual Clauses (SCCs): Adopted by the European Commission, they guarantee an adequate level of protection
- Data Privacy Framework: For certified companies (Stripe, Google)
7.2 Your Rights
You can obtain a copy of the safeguards relating to transfers by contacting us at: [email protected]
ARTICLE 8: User Rights (GDPR)
In accordance with the GDPR, you have the following rights over your personal data:
8.1 Right of Access
You may obtain confirmation that your data is being processed and access all your personal data.
8.2 Right to Rectification
You may request the correction of inaccurate or incomplete data.
8.3 Right to Erasure ("right to be forgotten")
You may request the deletion of your data in the following cases:
- Data is no longer necessary for the purposes for which it was collected
- You withdraw your consent (if processing is based on consent)
- You object to the processing and there is no overriding legitimate ground
- Data has been unlawfully processed
Exceptions: This right does not apply when processing is necessary to comply with a legal obligation or for the establishment, exercise or defense of legal claims.
8.4 Right to Data Portability
You may receive your data in a structured, commonly used and machine-readable format (JSON, CSV), and transmit it to another data controller.
Data concerned:
- Registration and profile data
- Content you have published (stories, chapters, comments)
- Library and reading history
8.5 Right to Object
You may object to the processing of your data:
- On grounds relating to your particular situation (processing based on legitimate interest)
- At any time for direct marketing purposes
8.6 Right to Restriction
You may request restriction of processing in the following cases:
- You contest the accuracy of the data (during verification)
- The processing is unlawful and you prefer restriction to erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing (during verification of legitimate grounds)
8.7 Right to Withdraw Consent
When processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of prior processing.
8.8 Post-Mortem Directives
You may define directives relating to the retention, erasure and communication of your data after your death.
ARTICLE 9: Exercising Your Rights
9.1 How to Exercise Your Rights
You may exercise your rights in several ways:
Via your personal space:
- Modification of your profile data
- Download of your data (export)
- Deletion of your account
- Management of notification preferences
By email:
- Address: [email protected]
- Subject: "GDPR rights exercise - [your right]"
By postal mail: Maonoo, LLC - DPO Service Dandji Lot 649 Cotonou, Benin
9.2 Identity Verification
To protect your data, we may ask you to prove your identity before acting on your request.
9.3 Response Time
We respond to your requests within one month of receipt. This period may be extended by two additional months in case of complex requests or high volume of requests, after informing you.
9.4 Free of Charge
Exercising your rights is free. However, in case of manifestly unfounded or excessive requests (particularly due to their repetitive nature), we may:
- Charge reasonable fees
- Refuse to act on the request
ARTICLE 10: Cookies
10.1 What is a Cookie?
A cookie is a small text file stored on your device when you visit our site. It allows us to remember your preferences and improve your experience.
10.2 Types of Cookies Used
Strictly necessary cookies (no consent required):
- Session cookies (Better Auth authentication)
- Security cookies (CSRF protection)
- Essential preference cookies (language)
Functional cookies (consent required):
- Reading preferences (theme, font size)
- Navigation choice memory
Analytical cookies (consent required):
- Anonymized audience statistics
- Site performance improvement
Advertising cookies (consent required):
- Meta Pixel (
_fbp) — measuring Muswada's advertising campaigns (see Article 3.6 and our Cookie Policy, Article 3.5)
10.3 Cookie Management
You can manage your cookie preferences:
- Via the consent banner on your first visit
- Via your browser settings
- Via our cookie preference center accessible from the footer
10.4 Cookie Duration
| Cookie Type | Lifespan |
|---|---|
| Session | Until browser closure |
| Authentication | 30 days (if "Remember me" enabled) |
| Preferences | 1 year |
| Analytics | 13 months maximum |
Advertising (Meta Pixel, _fbp) | 3 months |
ARTICLE 11: Data Security
11.1 Technical Measures
We implement the following security measures:
Encryption:
- Communications encrypted via HTTPS/TLS 1.3
- Passwords hashed with bcrypt (cost factor 12)
- Authentication tokens signed and encrypted
Enhanced Authentication:
- Two-factor authentication (2FA) available
- Magic Links for passwordless login
- PassKeys (WebAuthn) supported
- OAuth verification with Google, Facebook, Twitter, Apple
Infrastructure:
- Secure servers with firewall
- Regular encrypted backups
- Intrusion monitoring and detection
- Regular security updates
11.2 Organizational Measures
- Data access limited to authorized personnel
- Principle of least privilege
- Personnel awareness of data protection
- Security incident management procedures
11.3 Breach Notification
In case of a data breach likely to result in a risk to your rights and freedoms, we commit to:
- Notifying the competent supervisory authority within 72 hours
- Informing you as soon as possible if the risk is high
ARTICLE 12: Protection of Minors
12.1 Minimum Age
Muswada is intended for persons aged 13 years and older.
We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child under 13 has provided us with personal data, please contact us immediately.
12.2 COPPA Compliance (United States)
In accordance with the Children's Online Privacy Protection Act (COPPA), we do not collect information from children under 13 without verifiable parental consent.
12.3 Minors Aged 13 to 16 (European Union)
For European Union users aged 13 to 16, parental consent is required for the processing of personal data for online services, in accordance with Article 8 of the GDPR and applicable national legislation.
ARTICLE 13: California-Specific Rights (CCPA)
This section applies to California residents, in accordance with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).
13.1 Categories of Data Collected
Over the past 12 months, we have collected the following categories of data:
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Email, username, IP address | Yes |
| Personal information (Cal. Civ. Code 1798.80) | Name, email | Yes |
| Protected characteristics | None | No |
| Commercial information | Purchase history | Yes |
| Biometric data | None | No |
| Internet activity | Browsing history, interactions | Yes |
| Geolocation data | Country (approximate via IP) for recommendations | Yes |
| Professional information | None | No |
| Educational information | None | No |
| Inferences | Reading preferences | Yes |
| Sensitive information | None | No |
13.2 Right to Know
You have the right to request:
- Categories of personal data collected
- Categories of sources of this data
- Purposes of collection or sale
- Categories of third parties with whom we share data
- Specific personal data we have collected about you
13.3 Right to Delete
You have the right to request deletion of your personal data, subject to exceptions provided by law (legal obligations, ongoing transactions, security, etc.).
13.4 Right to Correct
You have the right to request correction of your inaccurate personal data.
13.5 Right to Opt-Out of Sale
Muswada does not sell your personal data. If you have consented to the Meta advertising pixel (Article 3.6), the transmission of browsing data to Meta may constitute "sharing" within the meaning of the CPRA for cross-context behavioral advertising purposes. This sharing only occurs with your prior explicit opt-in consent, and you may refuse it or end it at any time via the "Manage cookies" link in the footer, which constitutes the exercise of your right to opt out.
13.6 Non-Discrimination
We will not discriminate against you for exercising your CCPA rights. You will not experience:
- Service denial
- Different pricing
- Different level or quality of service
13.7 Exercising Your CCPA Rights
To exercise your rights, contact us:
- Email: [email protected]
- Online form: https://www.muswada.com/privacy-request
We will verify your identity before processing your request. You may designate an authorized agent to exercise these rights on your behalf.
13.8 Response Time
We respond to verifiable requests within 45 days. This period may be extended by an additional 45 days if necessary, after notification.
ARTICLE 14: Beninese Legislation
14.1 Legal Framework
The processing of your personal data complies with Beninese data protection legislation, including:
- Law No. 2017-20 of April 20, 2018 on the Digital Code of the Republic of Benin
- Provisions relating to the protection of personal data
14.2 Data Protection Authority
The Personal Data Protection Authority (APDP) is the competent supervisory authority in Benin.
14.3 Your Rights in Benin
In accordance with Beninese legislation, you have the following rights:
- Right to information
- Right of access
- Right to rectification
- Right to object
- Right to deletion
ARTICLE 15: Complaint to a Supervisory Authority
If you believe that the processing of your personal data constitutes a violation of your rights, you may file a complaint with a supervisory authority:
15.1 European Union
You may contact the data protection authority of your country of residence. For example:
- France: Commission Nationale de l'Informatique et des Libertes (CNIL) - https://www.cnil.fr
- Belgium: Data Protection Authority - https://www.autoriteprotectiondonnees.be
- Other countries: List of authorities: https://edpb.europa.eu/about-edpb/about-edpb/members_en
15.2 Benin
- Personal Data Protection Authority (APDP)
- Website: https://apdp.bj
15.3 United States (California)
- California Attorney General
- Website: https://oag.ca.gov/privacy
ARTICLE 16: Policy Modifications
16.1 Policy Evolution
We may modify this privacy policy to reflect changes in our practices or legal requirements.
16.2 Notification of Modifications
In case of substantial modification:
- We will inform you by email (if you have an account)
- We will display a visible notice on the site
- The "last updated" date will be updated
16.3 Access to History
Previous versions of this policy are retained and may be obtained upon request.
16.4 Acceptance of Modifications
Continued use of our services after notification of modifications constitutes acceptance of the updated policy.
ARTICLE 17: Contact
For any questions regarding this privacy policy or the processing of your personal data:
Data Protection Service
- Email: [email protected]
- Recommended subject: "Privacy question" or "GDPR request"
Postal Address
Maonoo, LLC Data Protection Service Dandji Lot 649 Cotonou, Benin
Response Time
We commit to responding to your questions within 72 business hours.
Summary of Your Rights
| Right | Description | How to Exercise |
|---|---|---|
| Access | Obtain a copy of your data | Personal space or email |
| Rectification | Correct inaccurate data | Personal space or email |
| Erasure | Delete your data | Personal space or email |
| Portability | Receive your data in exportable format | Personal space (export) |
| Objection | Refuse certain processing | |
| Restriction | Temporarily freeze processing | |
| Withdraw consent | Withdraw your consent at any time | Account settings |
Last updated: August 2026
Copyright 2026 Maonoo, LLC - All rights reserved