Privacy

Privacy Policy

In accordance with GDPR (EU) 2016/679 — Last updated: June 2026

1. Data Controller

Data controller: Afrilink Digital Group SAS (Société par Actions Simplifiée), represented by Abdourahamane Sampou & Moro Sangare, 1-7 Avenue Meissonier, 93250 Villemomble, France. SIREN: 105207864 — SIRET: 10520786400015 — VAT ID: FR57105207864. Email: contact@afrilink-dg.com. Technical processor (Art. 28 GDPR): Core Industry (Isam Al-Ani), Max Schwarze Weg 27A, 46236 Bottrop, Germany.

2. Data Collected

Consumer users: tracking number entered (for search), IP address (security logs), browser/device data. GP operators: account information (name, company, email, phone), kiosk configuration data, transaction data (parcels, transfers, amounts), subscription and billing data. Recipients of money transfers: name and phone number (provided by the sending GP operator). Marketing communications (newsletter, promotional emails): email address — only with prior consent. All data is processed in accordance with applicable law.

3. Legal Basis for Processing (Art. 6 GDPR)

Parcel and transfer tracking (consumer portal): Art. 6(1)(b) GDPR — performance of a contract / pre-contractual steps at the user's request. GP operator account management: Art. 6(1)(b) GDPR — contractual necessity. Security, fraud prevention (IP logs): Art. 6(1)(f) GDPR — legitimate interest. Billing and legal compliance: Art. 6(1)(c) GDPR — legal obligation. Marketing communications and optional analytics cookies: Art. 6(1)(a) GDPR — consent, withdrawable at any time via contact@afrilink-dg.com.

4. Hosting & Infrastructure

The website linkaf.net is hosted by Netlify, Inc. (44 Montgomery Street, Suite 300, San Francisco, CA 94104, USA). Application data is processed via Google LLC / Firebase / Google Cloud Platform (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), hosted on European servers (EU region: europe-west1). Any transfers to third countries are governed by Standard Contractual Clauses adopted by the European Commission (Decision 2021/914/EU).

5. Cookies & Consent

Essential cookies (session, language preference, consent status) are strictly necessary and do not require consent under CNIL guidelines. Analytics and marketing cookies are only placed after your explicit consent via the cookie banner. You may withdraw consent at any time using the cookie icon at the bottom of the page or by contacting contact@afrilink-dg.com. Non-essential scripts are blocked until you accept.

6. Data Sharing

Personal data is never sold or rented. Data may be shared with: Core Industry (technical processor, under an Art. 28 GDPR data processing agreement); Netlify, Inc. (website hosting); Google LLC / Firebase (application infrastructure, governed by SCCs); competent supervisory authorities or courts upon legally valid request. GP operators, as independent controllers, are responsible for the personal data of their own customers.

7. Retention Periods

Technical logs (IP): max. 12 months (LCEN obligation). GP operator account data: duration of subscription + 3 years (commercial and tax obligations). Transaction data (parcels, transfers): 5 years (accounting legal obligation). Tracking numbers consulted by consumers: session only, max. 30 days in debug logs. Marketing consent data: until withdrawal of consent or 12 months after last activity.

8. Your Rights (GDPR Art. 15–22)

You have the right to: access (Art. 15), rectification (Art. 16), erasure / right to be forgotten (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and withdrawal of consent (Art. 7). To exercise your rights or withdraw consent: contact@afrilink-dg.com — we respond within 1 month. You may also lodge a complaint with the French data protection authority (CNIL, www.cnil.fr) or the competent supervisory authority in your country of residence.

9. Security

Afrilink Digital Group and Core Industry implement appropriate technical and organisational measures (Art. 32 GDPR): HTTPS/TLS encryption for all communications; access restricted to authorised personnel; regular security audits; isolated database with role-based access control; secure backup procedures with defined retention windows.

10. Policy Updates

This policy may be updated to reflect changes in applicable law or our data processing practices. The date of last update is shown above. In the event of material changes affecting your rights, you will be informed by email (if you have an account) or by a prominent notice on the platform.