Privacy & Confidentiality
Version 1.0Last updated 26 May 2026
Article 1
Identity of the controller
The controller of the personal data collected via the KolyMe Platform is:
- Resolvue, SARL de droit béninois
- RCCM: RB/COT/25 B 40320
- Tax ID (IFU): 3202595779025
- Registered office: Ahouassa, 2ème arrondissement, Cotonou, Littoral, Bénin
- General contact: contact@kolyme.com
Data Protection Officer (DPO):
- Email: privacy@kolyme.com
- Postal address: DPO Resolvue, Ahouassa, 2ème arrondissement, Cotonou, Littoral, Bénin
Article 2
Representative in the European Union (Article 27 GDPR)
In accordance with Article 27 of Regulation (EU) 2016/679 (GDPR), Resolvue, as a controller established outside the European Union and offering its services to persons located in the Union, designates a representative to serve as the point of contact for supervisory authorities and data subjects in the Union.
The representative designation is currently in progress. Contact details will be published before the service is officially opened to users residing in the European Union.
Article 3
Categories of personal data collected
Depending on your use of the Platform, we collect the following categories:
- Identification: last name, first name, email address, phone number, profile picture, country of residence.
- Account and authentication: password (hashed), identifiers from third-party identity providers (Google, Facebook, Apple, passkey), login timestamps.
- Identity verification (KYC): a copy of an official identity document and a selfie, data extracted by OCR from the document (encrypted), a hash of the document number, a face-match score. No biometric template of your face is retained after verification.
- Payment data: payment tokens, method used, amounts. KolyMe does not store full card numbers or security codes: these data are entered directly on the secure pages of the payment providers.
- Transactions: Trips, Listings, Bookings, Handover and Delivery Codes, statuses.
- Communications: contents of messages exchanged via the Platform's internal messaging.
- Preferences: language, currency, theme (light/dark), choices regarding notification channels and commercial communications.
- Technical data: IP address, session identifier, user agent (browser, device), action logs for audit and security purposes.
We do not collect your precise geolocation (GPS) nor user-to-user evaluations (this feature is not currently active).
Article 4
Purposes and legal bases of processing
Your data are processed for the following purposes and legal bases:
- Service provision (contract performance, Art. 6(1)(b) GDPR): account creation and management, Listing publication, matchmaking, payment processing, generation and verification of Handover and Delivery Codes.
- Identity verification (legitimate interest, Art. 6(1)(f) GDPR; explicit consent for functional biometric data, Art. 9(2)(a) GDPR): prevention of fraud and identity theft.
- Security and fraud prevention (legitimate interest, Art. 6(1)(f) GDPR): access logs, anomaly detection, incident handling.
- Legal obligations (legal obligation, Art. 6(1)(c) GDPR): retention of evidence, response to requests from authorities, tax and accounting obligations.
- Service communications (contract performance): confirmations, transaction notifications, security alerts.
- Commercial communications (consent or legitimate interest depending on jurisdiction): newsletter, information on new features. You can opt out at any time from your settings or via contact@kolyme.com.
- Fraud prevention and prevention of Platform circumvention (legitimate interest - art. 6.1.f GDPR): automated analysis of the content of messages exchanged before a booking is confirmed, in order to detect and mask the sharing of personal contact details. You have a right to object to this processing (see the « Your rights » section).
- Support, disputes and community safety (contract performance - Art. 6(1)(b) GDPR; legitimate interest - Art. 6(1)(f) GDPR): occasional review of the content of internal messaging conversations by our authorised staff, including after a booking is confirmed, where a dispute, a report, a fraud suspicion or a support request justifies it. Every review is purpose-bound, limited to the conversation concerned and recorded in an audit log.
Article 5
Data retention periods
Your data are retained for the time strictly necessary to the purpose pursued, within the following limits:
- Active user account: for the entire duration of your relationship with KolyMe.
- Identity verification files (KYC): identity documents and selfies are deleted at the latest 30 days after the verification is finalised. Hashes (of the document number) and the verification status are kept to prevent fraudulent re-registration.
- Payment data: kept for the time necessary to perform the Transaction and to comply with applicable accounting and tax obligations.
- Internal communications: kept until the related Booking is closed, then archived for the legally applicable durations.
- Audit logs (security, fraud): kept for a reasonable duration aligned with legal and operational requirements.
- Account deletion: on user request, the account is subject to a confirmation period of 7 days, then anonymised within at most 30 days.
- Message-moderation verdicts: kept for security and fraud-prevention purposes for as long as strictly necessary for that purpose and no longer than the retention period of your account; verdicts revealing no violation are deleted after 6 months. The encrypted original versions of masked messages, kept server-side solely to allow review, are deleted together with the message concerned.
Article 6
Recipients of the data and sub-processors
Resolvue never sells, rents or shares your personal data with third parties for advertising or commercial purposes.
Your data are accessible, strictly within the scope of their duties, to authorised personnel of Resolvue. They may be communicated to the following categories of recipients:
- Technical sub-processors: providers of the Platform, acting on written instructions of Resolvue and contractually bound to confidentiality (notably Resend for transactional emails, Sentry for error tracking, Better Stack for log aggregation, Firebase Cloud Messaging for push notifications, Africa's Talking for SMS in Africa, Meta Platforms (WhatsApp Business) for WhatsApp notifications).
- Third-party authentication providers (Google, Apple, Meta) when you choose to log in via these providers.
- Payment providers: Stripe for bank cards (via Stripe Connect on behalf of Resolvue, LLC), FedaPay for West African mobile wallets, MTN Mobile Money for MTN MoMo payments.
- Other providers: ExchangeRate-API for currency rates (no personal data transmitted), IONOS SARL for hosting, Healthchecks.io for scheduled-task monitoring (no personal data transmitted).
- Authorities: on substantiated request, to the competent judicial or administrative authorities.
- Message moderation: Cloudflare, Inc. (United States), for the automated analysis of the content of pre-booking messages for moderation purposes. This transfer outside the European Union is framed as set out in the « International data transfers » section.
Other users of the Platform can see the information that you voluntarily publish (name, picture, Trips or Listings) as part of the matchmaking.
Article 7
International data transfers
Some of our sub-processors are established outside Benin or the European Union, notably in the United States (Resend, Sentry, Firebase, Meta, Google, Apple, Stripe via Resolvue, LLC). To frame these transfers to countries lacking an adequacy decision, Resolvue relies on the mechanisms provided by the GDPR:
- Standard Contractual Clauses (SCC) approved by the European Commission (Implementing Decision 2021/914);
- Additional appropriate technical and organisational safeguards (encryption in transit, access control, data minimisation in the transfers);
- Transfer Impact Assessments (TIA) when required.
You can obtain a copy of the applicable safeguards by writing to privacy@kolyme.com.
As part of automated message moderation, the content of messages exchanged before a booking is confirmed is transferred to Cloudflare, Inc., located in the United States. This transfer is framed by the European Commission's Standard Contractual Clauses (art. 46 GDPR), together with a transfer impact assessment.
Article 8
Your rights
In accordance with the GDPR and equivalent legislation, you have the following rights over your data:
- Right of access (Art. 15 GDPR): know what data we hold about you and obtain a copy.
- Right of rectification (Art. 16 GDPR): correct inaccurate data or complete them, directly from your settings for the fields available, or via privacy@kolyme.com.
- Right of erasure (Art. 17 GDPR): request the deletion of your account from the app or by writing to privacy@kolyme.com. The procedure includes a confirmation period and an anonymisation period described in Article 5.
- Right of restriction (Art. 18 GDPR): request restriction of processing in the cases provided by the GDPR.
- Right of portability (Art. 20 GDPR): receive your data in a structured, commonly used format. Until a self-service export feature is available, a copy may be provided on request to privacy@kolyme.com.
- Right of objection (Art. 21 GDPR): object to the processing of your data for reasons relating to your particular situation, and at any time to processing for direct marketing purposes.
- Post-mortem directives: provide directives regarding the fate of your data after your death, where the applicable law so provides.
Your requests are handled within one (1) month, extendable by two (2) months in case of complexity. Proof of identity may be requested if reasonable doubt exists.
Article 9
Competent supervisory authority
If you believe that the processing of your data does not comply with applicable law, you have the right to lodge a complaint with the competent data protection authority in your country of residence.
For users residing in the European Union, the competent authority is that of your place of residence; for example, in France, the Commission Nationale de l'Informatique et des Libertés (CNIL - https://www.cnil.fr).
Article 10
Data security
10.1 Technical measures
Without this list being exhaustive, KolyMe implements:
- Encryption of data in transit using a minimum of TLS 1.3;
- Encryption of identity verification files at rest (AES-256), using a key managed separately from the data;
- Hashing of passwords using an adaptive algorithm with salting;
- Strong authentication via passkey (WebAuthn) where supported by the device;
- Limiting session data to what is strictly necessary.
10.2 Organisational measures
- Access to data restricted to authorised personnel, on a least-privilege basis;
- Continuous monitoring of errors and anomalies via Sentry, with an internal process for qualifying and handling incidents;
- Segregation of environments (production, staging, development);
- Selection of sub-processors based on their data protection commitments, formalised by contract (DPA) where applicable.
10.3 Data protection by design
In accordance with Article 25 GDPR, KolyMe applies data protection by design and by default principles: data minimisation, protective default settings, user control over their preferences (see Article 14).
Article 11
Personal data breach notification
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, Resolvue undertakes to:
- Document the breach and the actions taken;
- Notify the competent supervisory authority within seventy-two (72) hours of becoming aware of it, in accordance with Article 33 GDPR where applicable;
- Communicate the breach to the data subjects concerned without undue delay where the risk is high, in accordance with Article 34 GDPR.
Article 12
Profiling and automated decisions
KolyMe may rely on limited profiling for fraud prevention purposes: behavioural analyses and risk scoring on registrations, payments and Transactions. No decision producing significant legal effects (account suspension, blocking of a Transaction) is taken solely on the basis of automated processing: any adverse decision is subject to human review before execution.
For the same fraud-prevention purpose, the content of messages exchanged before a booking is confirmed is automatically analysed to mask the sharing of personal contact details; repeated attempts may lead to the message being blocked. You may report a masking or a block that you believe to be erroneous in order to obtain a human review, which may lift the masking and cancel the warning.
Article 13
Protection of minors
The Platform is open to persons aged at least sixteen (16) years. Children are not its target audience and KolyMe does not knowingly collect data concerning persons under that age.
If you believe an account has been created in breach of this rule, you can notify us at privacy@kolyme.com. The account will be reviewed and, if applicable, deleted.
Article 14
Electronic communications and user choices
14.1 Transactional communications
Communications necessary to the operation of the service (confirmations, security alerts, transaction notifications) are sent to you on the basis of contract performance. You cannot object to them while your account is active.
14.2 Commercial communications
Commercial communications (newsletter, product news, offers) are governed by your preference settings accessible from your account. You may at any time withdraw your consent or object to them, purpose by purpose, without affecting the operation of the service.
14.3 Channels
Communications may be sent to you by email, SMS, push notifications or WhatsApp, depending on your preferences and the channels available for your phone number.
Article 15
Amendment of the Privacy Policy
This Policy may be amended, in particular to reflect changes in the Platform, in the legal framework or in the sub-processors used. The applicable version is the one in force on the date of your consultation.
Substantive changes will be notified to you by any appropriate means (in-Platform notification, email). Continued use of the Platform after the new version's effective date constitutes acceptance. If you refuse the changes, you may exercise your right to erasure in accordance with Article 8.
Article 16
How to delete your account
You can delete your KolyMe account at any time, directly in the app. Go to Settings, open Confidentiality, then Delete my account and Request deletion; you confirm through a secure link we send to your email. You can also request deletion by contacting us at contact@kolyme.com.
After you request deletion, you have 7 days to cancel and keep your account. Once that period ends, your account is deactivated and your personal data are anonymised within 30 days, except for data we are legally required to keep (in particular transaction and accounting records), as described in the data retention section above.