Privacy Policy
Last updated: 5 août 2026
This policy describes how [À COMPLÉTER — raison sociale, ex. « ITIA SARL »] collects, uses, stores, shares and protects the personal data of people who use ITIA. It applies to the website, to the ITIA mobile application and to every related service, whatever interface you use to reach them.
We have written it to be exhaustive rather than reassuring. It is long because a platform that sells digital projects, ships parcels, hosts video meetings, runs an investor area and operates a conversational assistant handles data of very different kinds, and each deserves to be described for what it is.
1. Who is responsible for your data
The data controller is [À COMPLÉTER — raison sociale, ex. « ITIA SARL »], [À COMPLÉTER — forme juridique OHADA, ex. SARL, SA, SAS], whose registered office is at [À COMPLÉTER — adresse complète], Yaoundé, Cameroun, registered with the Trade and Personal Property Credit Register under number [À COMPLÉTER — n° RCCM, ex. « RC/YAO/2026/B/… »].
Any question, request to exercise your rights, or complaint may be sent to contact@itia-web.com. That mailbox is read by a person, not by a machine.
2. Applicable legal framework
Our processing is governed by Cameroonian Law No. 2024/017 of 23 December 2024 on the protection of personal data, which is our reference framework.
For individuals residing in the European Union, Regulation (EU) 2016/679 (GDPR) also applies, as ITIA offers its services to people located in that territory. Where the two diverge, we apply the more protective rule.
People residing in other countries retain the benefit of the mandatory provisions of their local law.
3. The data we collect
Account data. Your name, your email address and, where you set one, your password — stored in an encrypted, irreversible form, so that we cannot read it. If you sign in with Google, we receive your name, address and profile picture from Google. We also record the authentication provider used and the verification status of your address.
Profile data. Collected during onboarding or from your settings: telephone number and country code, city, chosen language and, where applicable, your company.
Order and payment data. Your purchase history, amounts, currencies, dates, payment statuses and the transaction identifiers passed on by the payment provider. We never receive, process or store your bank card number.
Delivery data. For physical products: delivery address, contact telephone number, access notes you leave for the courier, and the stages of the handover.
Video meeting data. Your display name and email address for the meetings you are invited to; picture and sound during the meeting, which are never recorded; and, where transcription is requested, the text of what was said.
Application data. If you apply for a role: name, contact details, position sought, CV, cover letter, portfolio and professional profile.
Conversation data. The messages you exchange with our team or with the Aria assistant, along with any documents you attach.
Technical data. IP address, browser and system type, pages visited, connection timestamps, device identifiers for mobile notifications, and the events recorded in our audit log.
4. Why we use them, and on what basis
Managing your account and performing our contracts. Creating and securing your account, processing your orders, delivering your files, arranging your appointments, shipping your parcels. Basis: performance of the contract between us.
Meeting our legal obligations. Keeping invoices and accounting records, responding to requests from competent authorities. Basis: legal obligation.
Securing the platform. Preventing fraud, detecting abnormal access, limiting abuse, maintaining an audit log. Basis: our legitimate interest in protecting our users and our service.
Running our business. Understanding what sells, how customers find us, and where the service deserves improvement. These dashboards inform our internal decisions: they are used neither for advertising nor for profiling, and no one is approached commercially on that basis. Basis: legitimate interest.
Keeping you informed. Order confirmations, appointment reminders, security alerts, meeting minutes. These messages relate to the service and are not marketing. Basis: performance of the contract.
Recruiting. Reviewing applications and contacting relevant candidates. Basis: your consent, obtained explicitly at the time of submission, and pre-contractual steps.
Should we ever wish to send you anything beyond these service-related messages, we will ask for your agreement beforehand, separately, and you will be able to withdraw it as easily as you gave it.
5. Who your data is shared with
We do not sell your data, to anyone, ever, and we do not exchange contact lists. Your data is accessible only to our team and to the providers strictly necessary to operate the service, each within the limits of its role:
- Vercel — hosting of the website and application.
- MongoDB Atlas — database, hosted in the European Union.
- Cloudflare R2 — private storage of files, attachments and transcripts.
- Stripe Payments Europe, Limited (carte bancaire) et CamPay (Mobile Money MTN / Orange) — payment processing.
- Google — sign-in with Google, bot protection through reCAPTCHA, mobile application notifications, and the model powering the Aria assistant.
- 8x8 (Jitsi as a Service) — carrying video meetings and, where requested, transcribing them.
- Make — scenarios sending transactional emails.
- Anthropic — translation of site content.
- Microsoft Power BI — management dashboards.
To these is added our data analyst, who builds the dashboards mentioned above. She is bound by a signed confidentiality undertaking, accesses data in read-only mode through a dedicated account, and never has access to your passwords, your two-factor secrets or your payment methods.
Finally, we may be required to disclose certain data to a duly empowered judicial or administrative authority. In such a case we limit ourselves strictly to what is required, and inform you where the law does not forbid us from doing so.
6. Transfers outside Cameroon
ITIA operates from Cameroon with an international clientele. Several of the providers listed above process data abroad, in particular in the European Union and the United States.
These transfers are limited to what is strictly necessary and framed by recognised safeguards: contractual protection undertakings entered into by our providers and, for the data of European residents, the European Commission’s standard contractual clauses or an equivalent mechanism. Your data therefore enjoys the same level of protection wherever it is processed.
7. How long we keep them
- Account — for as long as your account exists. On closure, or after prolonged inactivity, the data is deleted.
- Orders and invoices — ten years, as required by accounting and tax obligations.
- Deliveries — three years after handover, to handle any complaint.
- Meeting transcripts and minutes — twelve months.
- Applications — two years from receipt, unless earlier deletion is requested.
- Conversations — three years after the last exchange.
- Technical logs and audit log — twelve months.
Once these periods expire, the data is deleted or irreversibly anonymised.
8. Our video meetings
When you join a meeting from your personal area, picture and sound travel through 8x8 (Jitsi as a Service). We never record our meetings — neither sound nor picture.
A meeting may nevertheless be transcribed, so that we can send you written minutes. This is never automatic: only the person hosting can decide it, you are told on screen the moment it begins, and you may object — the transcription is then stopped. The text and its summary are kept for twelve months, then deleted.
The room is accessible only to the people listed for that meeting: the right to enter is verified each time it is opened, and the room address is never circulated by email.
9. If you apply to work with us
We receive your name, contact details, the position sought, your CV and, if you provide them, your cover letter, portfolio and professional profile. These are used for recruitment only: they never join any commercial list and are never used to approach you.
We keep your application for two years from the date you send it. A role that did not match your profile in January may open in October, and we would rather be able to call you back than ask you to send everything again. You accept this period by ticking the box provided at the time of submission, and you may change your mind at any time: an email to contact@itia-web.com is enough to have your application deleted, with no need to justify yourself.
10. The Aria assistant
Aria answers your questions about our projects and services. The content of your exchanges is sent to the model provider to produce the answer, then kept so that the conversation history remains available in your area.
We encourage you not to enter sensitive data there — health data, opinions, credentials, banking details. Aria is an information tool: its answers constitute neither professional advice nor a contractual commitment by ITIA.
10.1 Improving the quality of Aria
To measure and improve the quality of Aria's answers — checking that it quotes the right prices, replies in your language, and stays within its scope — we keep a copy of exchanges in an evaluation set that is separate from your personal history. That set could, in the future, be used to train a model belonging to ITIA; no decision has been taken to that effect to date.
That copy is anonymous: it contains neither your name, nor your account identifier, nor your IP address, and nothing allows it to be traced back to you. Before storage, e-mail addresses, phone numbers and long digit sequences are automatically replaced with generic placeholders. We keep the text of the question, the text of the answer, the language used and the name of the model queried — nothing else.
Legal basis: our legitimate interest in improving the quality of our service (Article 6(1)(f) GDPR for the individuals concerned).Retention: twenty-four months, after which records are deleted automatically.
Because these records are anonymous, they can no longer be found or linked to a person: we are therefore unable to extract yours after the fact. If you do not want your exchanges to appear there, do not use Aria, or write to us beforehand at the address given in section 1. Your personal conversation history remains deletable at any time from your account.
11. Notifications
We send you notifications related to the service: order confirmation, delivery progress, meeting reminder, security alert. On the mobile application they rely on a device identifier that you can revoke by uninstalling the application or withdrawing the permission in your phone settings.
12. Automated decisions
We take no decision producing legal effects concerning you on the sole basis of automated processing. Analyses carried out for management purposes are aggregated and are not used to assess an individual. Scores produced by our project-assessment tools relate to projects, not to people, and are always reviewed by a member of the team.
13. How we protect your data
Passwords hashed irreversibly; all exchanges encrypted over HTTPS; files stored in private space and delivered through signed, time-limited links; two-factor authentication available on every account; access restricted according to each person’s role; rate limiting on sensitive entry points; a timestamped audit log protected against alteration.
No system is perfect. In the event of a breach likely to create a risk to your rights, we inform the competent authority and, where the risk is high, we notify you directly, describing what happened and what you can do about it.
14. Your rights
You have the following rights at all times:
- Access — to know what data we hold and obtain a copy of it.
- Rectification — to have inaccurate information corrected.
- Erasure — to request deletion of your data, subject to our retention obligations.
- Objection — to object to processing based on our legitimate interest.
- Restriction — to request that a contested processing be frozen.
- Portability — to receive your data in a machine-readable format.
- Withdrawal of consent — where processing rests on it, without affecting what was done beforehand.
- Post-mortem directions — to determine what becomes of your data after your death.
An email to contact@itia-web.com is enough: no form, no justification required. We reply within one month, extended to three months for complex requests, in which case we tell you. We may ask for proof of identity where reasonable doubt exists — that is a protection against impersonation, not an obstacle.
15. Cookies and trackers
We use only strictly necessary cookies: those that maintain your session, remember your chosen language and secure our forms. No advertising tracker, no profiling tool, no sharing with an ad network.
Should we one day add audience measurement, we will do so only with your prior agreement, obtained through a banner that makes refusing as easy as accepting. You also retain control from your browser settings.
16. Minors
Our services are not intended for people under eighteen and we do not knowingly collect their data. If you become aware that a minor has provided us with information, please report it to contact@itia-web.com and we will delete it.
17. Changes to this policy
This policy evolves with our services and the legal framework. The applicable version is the one published on this page, with its update date shown at the top. Where a change materially affects your rights, we notify you directly rather than relying on you to re-read it.
18. Complaints
If our answer does not satisfy you, you may refer the matter to the competent Cameroonian data protection authority.
People residing in the European Union may also refer the matter to their national supervisory authority — in France, the CNIL (www.cnil.fr).
We would rather settle things directly, however: write to us first at contact@itia-web.com. See also our legal notice and our terms and conditions of sale.
