Last updated: 7 October 2026
This policy describes the processing of personal data carried out for the 221 hub and the 221 Pay payment service (the “Service”). It supplements the terms of use, whose definitions apply here. This policy is a translation; the French version prevails.
1. Legal framework
Processing is carried out in accordance with Law No. 2008-12 of 25 January 2008 on the protection of personal data and under the supervision of the Commission for the Protection of Personal Data (CDP), the independent administrative authority established by that law. Processing related to 221 Pay is also subject to the regulations on combating money laundering and terrorist financing, in particular Law No. 2024-08 of 14 February 2024.
2. Controller
The controller is Orvene Labs Technologies, publisher of the Service (orvlabs.com). Any question or request about personal data is sent to [email protected].
3. Data processed
3.1 Browsing without an account
Browsing the hub requires neither an account nor a cookie. To apply the quotas of the API without a key, 221 records a SHA-256 fingerprint of the IP address together with a daily call counter. Such a fingerprint remains personal data, because it can be matched to an IP address. Dataset downloads are counted using a salted fingerprint of the IP address, erased the next day. As for any web page, the server receives the technical information of each request (IP address, browser, page requested) to serve the site and keep it secure.
3.2 Account
Opening an Account involves processing the following data: name, email address, password fingerprint (the password itself is never stored), email verification status, language and notification preferences, and, for each session, the IP address and browser used.
3.3 Sign-in with GitHub or Google
Sign-in with GitHub or Google is optional. When it is chosen, 221 receives from the provider the name, email address, profile picture and account identifier with that provider, as well as the access tokens needed for sign-in. The provider handles sign-in under its own privacy policy.
3.4 Two-factor authentication
When two-factor authentication is enabled, 221 stores the authenticator app secret in encrypted form and the backup codes as fingerprints.
3.5 Projects, keys and integrations
221 processes Projects, their Members and roles, the fingerprints of API Keys (never the key itself), webhook addresses and their delivery history, favourites, dataset subscriptions and usage counters.
3.6 Payment data (221 Pay)
For each Operation, 221 processes the payer’s phone number, the mobile money operator, the amount, the currency, the reference provided by the Merchant, the timestamp and the status, and, where the Merchant enables receipts, the Customer’s email address. For Payouts, 221 processes the Payout Number and the name of its holder. For Disputes, 221 processes the evidence submitted. The Merchant’s name and logo are displayed on payment pages.
3.7 Identity verification (221 Pay)
Identity verification is required before any Payout. It covers images of the identity document (front and, except for passports, back), the identity data extracted from the document and, where the verification policy requires it, a selfie and a liveness check. For a legal entity, documents relating to the company, its directors and its beneficial owners are added. This data is stored on 221’s servers and is accessible only to authorised staff, including the moderators in charge of verification.
3.8 Error reports
The error report form collects the reporter’s email address and the content of the report: dataset, version, place, current value, expected value and source. The content of the report, without the email address, may be published in a public tracker; the form rejects any email address or phone number in these fields. An anti-spam check (Cloudflare Turnstile) verifies that the submission comes from a person, and submissions are counted by IP address fingerprint to limit their number.
3.9 Support and correspondence
Email exchanges with 221 are kept to handle the request and to retain evidence of it.
3.10 Conversational assistant
When enabled, the conversational assistant processes the messages entered in the signed-in area. It is disabled by default. It never receives an API Key, a password or an identity document, and none of this information should be shared with it.
4. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Provide the hub and apply quotas | IP address fingerprint, counters, Account data | Performance of the terms of use |
| Manage the Account, sign-in and security | Account, sessions, two-factor authentication, GitHub or Google sign-in | Performance of the terms of use |
| Send account emails, quota alerts and notifications for followed datasets | Email address, preferences | Performance of the terms of use; consent for optional notifications |
| Execute 221 Pay Operations | Payment data | Performance of the terms of use |
| Send a receipt to the Customer | Customer’s email address | Merchant’s instruction, on the legal basis it holds |
| Verify identity, prevent fraud, combat money laundering | Identity data, payment data | Legal obligation; performance of the terms of use |
| Handle error reports | Email address, report content | Consent |
| Respond to requests and disputes, establish evidence | Correspondence, logs | Performance of the terms of use; legal obligation |
| Keep accounts and respond to authorities | Operations, Fees | Legal obligation |
221 does not use personal data for advertising, and does not sell or rent it.
5. Data of Merchants’ Customers
For Customer data transmitted through 221 Pay, the Merchant determines the purposes of its collection and is responsible for it towards its Customers; 221 processes it on the Merchant’s behalf and according to its instructions. However, 221 processes this data on its own behalf where it must comply with its legal obligations, in particular fraud prevention and anti-money laundering. A Customer who wishes to exercise their rights may contact the Merchant or 221.
6. Recipients and processors
Data is accessible to authorised 221 staff, within the limits of their duties. It may be disclosed to the following recipients:
| Recipient | Role | Data concerned |
|---|---|---|
| Dedicated server hosting provider | Hosting of the Service and its databases | All Service data |
| Hostinger | Sending emails from the orvlabs.com domain mailbox | Email address, email content |
| Cloudflare (Turnstile) | Anti-spam check of the error report form | Technical browser data, IP address |
| GitHub | GitHub sign-in, if chosen; public tracking of error reports | GitHub profile; report content, without email address |
| Google sign-in, if chosen | Google profile | |
| Licensed partner institutions and operators | Execution of payment Operations and regulatory obligations | Payment data, identity data where regulations require it |
| Kairos | Conversational assistant platform, operated by the same group; disabled by default | Messages entered in the assistant |
| Merchant | Beneficiary of the Operation | Payment data of its Customers, through the dashboard, the API and webhooks |
| Authorities | CDP, judicial, administrative, tax and supervisory authorities, CENTIF, where the law requires | Data required |
Processors act only on 221’s instructions and are bound by confidentiality and data security obligations. Where a provider acts on its own behalf, in particular GitHub and Google for sign-in, its own privacy policy applies. Links to third-party services lead to sites that 221 does not control.
7. Transfers outside Senegal
Some recipients are established or process data outside Senegal, in particular the email, anti-spam and sign-in providers, and the payment partners established in the other UEMOA countries where 221 Pay is available. These transfers are limited to the data needed and are carried out under the conditions laid down by Law No. 2008-12 and by the decisions of the CDP.
8. Retention periods
| Data | Period |
|---|---|
| Sign-in sessions | 7 days, extended on each use; deleted on expiry |
| API usage counters, including the IP address fingerprint | 30 days |
| Salted IP address fingerprints for downloads | Erased the next day |
| Webhook delivery history | 30 days |
| Sign-in anti-abuse windows | 1 hour |
| Account, Projects, API Keys, webhooks, favourites, subscriptions | Until the Account is deleted |
| Email address of an error report | Deleted 30 days after the decision |
| Error report anti-spam counter | Erased within 3 hours |
| Content of an error report | Kept with its tracking number, without email address |
| Payment Operations and Fees | Statutory retention period for accounting records and transactions |
| Identity verification data | Period required by AML/CFT regulations, from the end of the relationship |
| Correspondence | Time needed to handle the request, then the applicable limitation period |
When these periods expire, the data is deleted or anonymised. It may be kept longer where an authority requires it or for the establishment, exercise or defence of legal claims.
9. Security
221 implements technical and organisational measures appropriate to the risks: encryption of exchanges, fingerprints of passwords, backup codes and API Keys, encryption of two-factor secrets, isolation of Projects, role-based access control, restricted access to identity data, logging of sensitive actions, rate limiting and security updates. Since no measure can guarantee absolute security, 221 informs data subjects and the CDP of a data breach where the law requires. Each User protects their own credentials, in accordance with the terms of use.
10. Access by 221 staff
A 221 administrator may open a session in a User’s place (session impersonation) in two cases only: to assist that User or to investigate abuse. This access is reserved for authorised staff, and the session so opened records the administrator’s identity. Access to identity verification data is reserved for staff in charge of verification and compliance.
11. Cookies and local storage
The Service uses only:
- a session cookie, secure and inaccessible to scripts, set at sign-in and valid for 7 days, extended on each use;
- temporary technical cookies during sign-in with GitHub or Google, needed to secure that sign-in;
- the browser’s local storage for the chosen theme (light or dark), which is not sent to 221.
The Service sets no advertising cookie and uses no advertising tracker. As these cookies are strictly necessary for the Service, they do not require prior consent.
12. Rights of data subjects
In accordance with Law No. 2008-12, every person has a right to information, access, rectification, deletion and objection to the processing of their data, on legitimate grounds. From the Settings of the signed-in area:
- Export my data downloads a JSON file containing the profile, Projects, API Keys (without their secret), webhooks, favourites and subscriptions;
- Delete my account deletes the Account and Projects and revokes their API Keys. This deletion is irreversible. It is not possible while a Live mode balance remains; data whose retention is required by law, in particular Operations and identity verification data, is kept for the period stated in article 8.
Other requests, including those concerning an IP address fingerprint, are sent to [email protected]. 221 may request proof of identity before responding and responds within the time limits set by law. The right to object does not apply to processing required by a legal obligation.
13. Complaints
Any person may lodge a complaint with the Commission for the Protection of Personal Data (CDP). Contacting 221 first is recommended, to allow a quick response.
14. Automated decisions
Automated fraud prevention and compliance checks may delay or block an Operation. Any decision to refuse a verification, or to suspend or close an Account, is reviewed by a person on request sent to [email protected].
15. Minors
The Service is reserved for persons aged at least 18. 221 does not knowingly collect data relating to minors and deletes a minor’s Account as soon as it becomes aware of it, subject to legal retention obligations.
16. Changes
221 may change this policy. Any material change is notified at least 30 days before it takes effect, by email and on the site, except for a change required by law or by the security of the Service, which may apply immediately. The date of the last update appears at the top of the page.
17. Contact
Orvene Labs Technologies, [email protected]. See also the legal notice and the Report an error page.