Skip to content

Privacy

Personal data processed by 221 and 221 Pay, purposes, legal bases, recipients, retention periods, security and the rights of data subjects.

Last updated: 7 October 2026

This policy describes the processing of personal data carried out for the 221 hub and the 221 Pay payment service (the “Service”). It supplements the terms of use, whose definitions apply here. This policy is a translation; the French version prevails.

Processing is carried out in accordance with Law No. 2008-12 of 25 January 2008 on the protection of personal data and under the supervision of the Commission for the Protection of Personal Data (CDP), the independent administrative authority established by that law. Processing related to 221 Pay is also subject to the regulations on combating money laundering and terrorist financing, in particular Law No. 2024-08 of 14 February 2024.

2. Controller

The controller is Orvene Labs Technologies, publisher of the Service (orvlabs.com). Any question or request about personal data is sent to [email protected].

3. Data processed

3.1 Browsing without an account

Browsing the hub requires neither an account nor a cookie. To apply the quotas of the API without a key, 221 records a SHA-256 fingerprint of the IP address together with a daily call counter. Such a fingerprint remains personal data, because it can be matched to an IP address. Dataset downloads are counted using a salted fingerprint of the IP address, erased the next day. As for any web page, the server receives the technical information of each request (IP address, browser, page requested) to serve the site and keep it secure.

3.2 Account

Opening an Account involves processing the following data: name, email address, password fingerprint (the password itself is never stored), email verification status, language and notification preferences, and, for each session, the IP address and browser used.

3.3 Sign-in with GitHub or Google

Sign-in with GitHub or Google is optional. When it is chosen, 221 receives from the provider the name, email address, profile picture and account identifier with that provider, as well as the access tokens needed for sign-in. The provider handles sign-in under its own privacy policy.

3.4 Two-factor authentication

When two-factor authentication is enabled, 221 stores the authenticator app secret in encrypted form and the backup codes as fingerprints.

3.5 Projects, keys and integrations

221 processes Projects, their Members and roles, the fingerprints of API Keys (never the key itself), webhook addresses and their delivery history, favourites, dataset subscriptions and usage counters.

3.6 Payment data (221 Pay)

For each Operation, 221 processes the payer’s phone number, the mobile money operator, the amount, the currency, the reference provided by the Merchant, the timestamp and the status, and, where the Merchant enables receipts, the Customer’s email address. For Payouts, 221 processes the Payout Number and the name of its holder. For Disputes, 221 processes the evidence submitted. The Merchant’s name and logo are displayed on payment pages.

3.7 Identity verification (221 Pay)

Identity verification is required before any Payout. It covers images of the identity document (front and, except for passports, back), the identity data extracted from the document and, where the verification policy requires it, a selfie and a liveness check. For a legal entity, documents relating to the company, its directors and its beneficial owners are added. This data is stored on 221’s servers and is accessible only to authorised staff, including the moderators in charge of verification.

3.8 Error reports

The error report form collects the reporter’s email address and the content of the report: dataset, version, place, current value, expected value and source. The content of the report, without the email address, may be published in a public tracker; the form rejects any email address or phone number in these fields. An anti-spam check (Cloudflare Turnstile) verifies that the submission comes from a person, and submissions are counted by IP address fingerprint to limit their number.

3.9 Support and correspondence

Email exchanges with 221 are kept to handle the request and to retain evidence of it.

3.10 Conversational assistant

When enabled, the conversational assistant processes the messages entered in the signed-in area. It is disabled by default. It never receives an API Key, a password or an identity document, and none of this information should be shared with it.

PurposeDataLegal basis
Provide the hub and apply quotasIP address fingerprint, counters, Account dataPerformance of the terms of use
Manage the Account, sign-in and securityAccount, sessions, two-factor authentication, GitHub or Google sign-inPerformance of the terms of use
Send account emails, quota alerts and notifications for followed datasetsEmail address, preferencesPerformance of the terms of use; consent for optional notifications
Execute 221 Pay OperationsPayment dataPerformance of the terms of use
Send a receipt to the CustomerCustomer’s email addressMerchant’s instruction, on the legal basis it holds
Verify identity, prevent fraud, combat money launderingIdentity data, payment dataLegal obligation; performance of the terms of use
Handle error reportsEmail address, report contentConsent
Respond to requests and disputes, establish evidenceCorrespondence, logsPerformance of the terms of use; legal obligation
Keep accounts and respond to authoritiesOperations, FeesLegal obligation

221 does not use personal data for advertising, and does not sell or rent it.

5. Data of Merchants’ Customers

For Customer data transmitted through 221 Pay, the Merchant determines the purposes of its collection and is responsible for it towards its Customers; 221 processes it on the Merchant’s behalf and according to its instructions. However, 221 processes this data on its own behalf where it must comply with its legal obligations, in particular fraud prevention and anti-money laundering. A Customer who wishes to exercise their rights may contact the Merchant or 221.

6. Recipients and processors

Data is accessible to authorised 221 staff, within the limits of their duties. It may be disclosed to the following recipients:

RecipientRoleData concerned
Dedicated server hosting providerHosting of the Service and its databasesAll Service data
HostingerSending emails from the orvlabs.com domain mailboxEmail address, email content
Cloudflare (Turnstile)Anti-spam check of the error report formTechnical browser data, IP address
GitHubGitHub sign-in, if chosen; public tracking of error reportsGitHub profile; report content, without email address
GoogleGoogle sign-in, if chosenGoogle profile
Licensed partner institutions and operatorsExecution of payment Operations and regulatory obligationsPayment data, identity data where regulations require it
KairosConversational assistant platform, operated by the same group; disabled by defaultMessages entered in the assistant
MerchantBeneficiary of the OperationPayment data of its Customers, through the dashboard, the API and webhooks
AuthoritiesCDP, judicial, administrative, tax and supervisory authorities, CENTIF, where the law requiresData required

Processors act only on 221’s instructions and are bound by confidentiality and data security obligations. Where a provider acts on its own behalf, in particular GitHub and Google for sign-in, its own privacy policy applies. Links to third-party services lead to sites that 221 does not control.

7. Transfers outside Senegal

Some recipients are established or process data outside Senegal, in particular the email, anti-spam and sign-in providers, and the payment partners established in the other UEMOA countries where 221 Pay is available. These transfers are limited to the data needed and are carried out under the conditions laid down by Law No. 2008-12 and by the decisions of the CDP.

8. Retention periods

DataPeriod
Sign-in sessions7 days, extended on each use; deleted on expiry
API usage counters, including the IP address fingerprint30 days
Salted IP address fingerprints for downloadsErased the next day
Webhook delivery history30 days
Sign-in anti-abuse windows1 hour
Account, Projects, API Keys, webhooks, favourites, subscriptionsUntil the Account is deleted
Email address of an error reportDeleted 30 days after the decision
Error report anti-spam counterErased within 3 hours
Content of an error reportKept with its tracking number, without email address
Payment Operations and FeesStatutory retention period for accounting records and transactions
Identity verification dataPeriod required by AML/CFT regulations, from the end of the relationship
CorrespondenceTime needed to handle the request, then the applicable limitation period

When these periods expire, the data is deleted or anonymised. It may be kept longer where an authority requires it or for the establishment, exercise or defence of legal claims.

9. Security

221 implements technical and organisational measures appropriate to the risks: encryption of exchanges, fingerprints of passwords, backup codes and API Keys, encryption of two-factor secrets, isolation of Projects, role-based access control, restricted access to identity data, logging of sensitive actions, rate limiting and security updates. Since no measure can guarantee absolute security, 221 informs data subjects and the CDP of a data breach where the law requires. Each User protects their own credentials, in accordance with the terms of use.

10. Access by 221 staff

A 221 administrator may open a session in a User’s place (session impersonation) in two cases only: to assist that User or to investigate abuse. This access is reserved for authorised staff, and the session so opened records the administrator’s identity. Access to identity verification data is reserved for staff in charge of verification and compliance.

11. Cookies and local storage

The Service uses only:

  • a session cookie, secure and inaccessible to scripts, set at sign-in and valid for 7 days, extended on each use;
  • temporary technical cookies during sign-in with GitHub or Google, needed to secure that sign-in;
  • the browser’s local storage for the chosen theme (light or dark), which is not sent to 221.

The Service sets no advertising cookie and uses no advertising tracker. As these cookies are strictly necessary for the Service, they do not require prior consent.

12. Rights of data subjects

In accordance with Law No. 2008-12, every person has a right to information, access, rectification, deletion and objection to the processing of their data, on legitimate grounds. From the Settings of the signed-in area:

  • Export my data downloads a JSON file containing the profile, Projects, API Keys (without their secret), webhooks, favourites and subscriptions;
  • Delete my account deletes the Account and Projects and revokes their API Keys. This deletion is irreversible. It is not possible while a Live mode balance remains; data whose retention is required by law, in particular Operations and identity verification data, is kept for the period stated in article 8.

Other requests, including those concerning an IP address fingerprint, are sent to [email protected]. 221 may request proof of identity before responding and responds within the time limits set by law. The right to object does not apply to processing required by a legal obligation.

13. Complaints

Any person may lodge a complaint with the Commission for the Protection of Personal Data (CDP). Contacting 221 first is recommended, to allow a quick response.

14. Automated decisions

Automated fraud prevention and compliance checks may delay or block an Operation. Any decision to refuse a verification, or to suspend or close an Account, is reviewed by a person on request sent to [email protected].

15. Minors

The Service is reserved for persons aged at least 18. 221 does not knowingly collect data relating to minors and deletes a minor’s Account as soon as it becomes aware of it, subject to legal retention obligations.

16. Changes

221 may change this policy. Any material change is notified at least 30 days before it takes effect, by email and on the site, except for a change required by law or by the security of the Service, which may apply immediately. The date of the last update appears at the top of the page.

17. Contact

Orvene Labs Technologies, [email protected]. See also the legal notice and the Report an error page.