Privacy
Privacy policy
How Toumai Partners SUARL processes the personal data of users of the TEMIA RETAIL platform. Version of 22 September 2026. Courtesy translation; the French version prevails.
1. Who is responsible?
Toumai Partners SUARL, Sénégal, [RCCM / NINEA to be filled in the issuer details], publishes the TEMIA RETAIL platform. Two situations coexist. For user accounts (identity, credentials, logins, training results and certificates), Toumai Partners acts as data controller. For operating data entered by a customer organisation in its workspace (staff, schedules, incidents, visits, station data), the customer organisation is the controller and Toumai Partners acts as processor, on its instructions only and under the terms.
2. Legal framework
Processing is carried out in accordance with Senegalese Law No. 2008-12 of 25 January 2008 on the protection of personal data and the decisions of the Commission de protection des Données Personnelles (CDP). Where users reside in the European Union, the General Data Protection Regulation (GDPR) also applies. Customer organisations established in other countries remain responsible for compliance with their local law for the data they enter.
3. Data processed
Account: name, e-mail address, password (stored as a hash, never in clear), language, organisation and scope, role. Login and security: IP address, date and time of login, browser, log of sensitive actions (account creation, changes to operating data, exports). Training: paths followed, assessment answers, scores, certificates issued. Operations (on behalf of the customer organisation): station staff (name, position, contract, schedule), authors of entries, station or incident photos, HSSE reports. The Platform collects no sensitive data and does not request identity documents.
4. Purposes and legal bases
Providing the service and managing accounts (performance of the contract); securing the Platform, detecting fraud and unauthorised access, keeping an audit log (legitimate interest and security obligations); issuing and verifying training certificates (performance of the contract); invoicing customer organisations and keeping accounting records (legal obligation); sending service e-mails — activation, password reset, due-date reminders, operating alerts requested by the organisation (performance of the contract). No data is used for advertising or sold to third parties.
5. Recipients and processors
Data is accessible to authorised Toumai Partners staff for operation and support, and to the customer organisation's users according to the roles and scopes it defines (a station manager sees only their station, an area manager their area, etc.). Organisations' workspaces are segregated. Toumai Partners uses the hosting provider IONOS (servers in the European Union) and, for sending e-mails, the hosting provider's mail service. No other processor is involved without prior information to the customer organisation. Data may be disclosed to authorities where required by law.
6. Transfers
Data is hosted in the European Union and accessed from the countries where the customer organisation and its users are located (notably West Africa and the Middle East). Toumai Partners accesses data from Senegal and from its places of operation. Such access uses encrypted connections (HTTPS) and is limited to the needs of the service.
7. Retention periods
Account and training data: for the term of the customer organisation's contract, then 90 days after its end to allow export, unless the organisation requests earlier deletion. Certificates issued: kept as a number and date to allow verification, for 5 years. Login and audit logs: 12 months. Invoices and accounting records: 10 years (legal obligation). Backups: rolling 30 days. Unconverted trial workspaces: deleted 90 days after the end of the trial.
8. Security
Encrypted connections (HTTPS), passwords hashed with a robust algorithm, protection against brute-force attacks, time-limited activation and reset tokens, strict segregation between organisations, role- and scope-based access control, audit log of sensitive actions, regular backups, security updates. No system is infallible: in the event of a data breach likely to create a risk for individuals, Toumai Partners informs the customer organisation without undue delay and, where required by law, the competent authority.
9. Cookies
The Platform uses only a session cookie, strictly necessary to keep you logged in, and a language preference. No advertising cookies, no third-party trackers, no external audience measurement. Browser local storage may be used for offline entry on certain screens; that data stays on your device until it is synchronised.
10. Your rights
You have the right of access, rectification, erasure, objection and restriction, and the right to data portability where applicable. You can change your details and password from your account. For other requests, write to [e-mail to be filled in] stating your organisation; you will receive a reply within one month. Where Toumai Partners acts as processor, your request is forwarded to your organisation, which decides. You may also lodge a complaint with Senegal's Commission de protection des Données Personnelles (CDP, Dakar) or, if you reside in the European Union, with your country's supervisory authority.
11. Minors
The Platform is a professional tool for employees and contractors of customer organisations; it is not intended for persons under 16.
12. Changes
This policy may be updated to reflect changes in the service or in regulations. The version date appears at the top of the page; substantial changes are flagged in the Platform.
13. Contact
Toumai Partners SUARL — Sénégal
E-mail: [e-mail to be filled in]