Privacy policy
What we actually collect, why, how long we keep it and how to take back control of it. Senegalese law and the GDPR, kept apart rather than blended.
Version 2.0 · Last updated:
Data controller
The controller of the personal data collected on this site is:
TeraLink Ubuntu
Digital and communication agency, and software publisher
Name under which this site is published
For any question about your data, write to us at the address given at the end of this page. We acknowledge receipt and reply within the time stated under “Your rights”.
The two regimes that apply
We are based in Senegal and we work for clients in Senegal, in France and elsewhere. Two sets of rules therefore apply to our processing, and they do not overlap exactly. Rather than blending them until it is no longer clear which one governs what, here is which applies to whom.
| Instrument | When it applies | Authority to refer to |
|---|---|---|
| Senegalese law no. 2008-12 of 25 January 2008 on the protection of personal data | To all our processing: it is the law of the country where we are established and where our processing takes place. | The Personal Data Protection Commission (CDP), in Dakar. |
| Regulation (EU) 2016/679, the GDPR | Where we offer our services to people located in the European Union, or monitor their behaviour — Article 3(2). That is the case: we have clients in the Union. | The supervisory authority of your country of residence — the CNIL in France. |
What we do in practice. We apply the higher level of protection of the two to everyone, without looking at where a request comes from. That is easier to keep to than a dual regime, and it is more honest: we do not want to have to explain one day that someone had fewer rights than someone else because they lived elsewhere.
The difference that remains is which authority you can turn to, and it depends on where you live: it is set out in the table above, and repeated under “Your rights”.
What we collect
We collect only what we need in order to reply. No form on this site asks for information that is not directly used to handle your request, and no mandatory field has been added “just in case”.
- Contact, quote and booking forms: first name, last name, email address, phone number, organisation name when you provide it, and the content of your message.
- Training or event registration: the same information, plus the course or event you selected.
- Unsolicited application: the same information, plus the role you are aiming for and, if you provide it, a link to a profile or portfolio. No attachment is accepted: receiving files from strangers opens an attack surface this form has no business opening.
- Newsletter: your email address, the date on which you consented to receive it, and — for mailings that carry it — whether a message was opened or a link followed.
- Conversational assistant: the content of the messages you send to it.
- Traffic counting: the items described in the next section. No cookie, no IP address kept.
- Technical logging: your IP address is read on each form submission to limit the number of requests per visitor and filter out automated submissions. It is used for that calculation, for a few minutes, and is linked to no profile.
We never ask for special-category data: origin, political, philosophical or religious beliefs, trade-union membership, health, sexual orientation, genetic or biometric data. Please do not include any in a free-text field — and if you have, tell us and we will delete it.
How we count visits
We want to know which pages are read. We do not need to know who reads them, and we have made it impossible for ourselves to find out. This site therefore loads no third-party analytics tool: the counting is written into the site’s own code, and here is exactly what it does.
| Recorded | Never recorded |
|---|---|
| The path of the page viewed and the language. | Your IP address. |
| One of three device classes, derived from the window width. | Your full browser string. |
| The country, when the host provides it. | Your city, your region, your location. |
| The domain of the site you came from. | That site’s full address — it would reveal the query typed into a search engine. |
| The time spent on the page, capped at thirty minutes. | Any identifier that outlives the day. |
To tell two visits by the same person apart from a visit by two people, a fingerprint is computed with SHA-256 from your IP address, your browser and a salt that changes every day. The salt is derived from the date and a server secret; it is stored nowhere. The fingerprint therefore counts distinct visitors within a day, and becomes useless the next — nobody, not even us, can link two days together.
Nothing is stored on your device for this counting: no cookie, no local storage. That is why there is nothing to accept or refuse about it in the consent panel. Recognised bots and automated tools are excluded from the count.
Legal basis: our legitimate interest in knowing what is read on our own site, balanced by measures that make individual tracking impossible beyond a single day. Detailed views are kept for ninety days — an administration setting allows this to go down to seven days or up to two years — then aggregated into daily totals that relate to nobody.
We say it plainly: for as long as it exists, the day’s fingerprint remains personal data under the Regulation, even though we cannot trace it back to you. You may object to this processing by writing to us. But we cannot match your request to a specific fingerprint: we would not know which one to erase. What is certain is that it disappears at the end of the retention period stated above.
Why, on what basis, for how long
Each processing operation rests on a defined legal basis. The table below sets out all of them: there are no others.
| Purpose | Legal basis | Retention |
|---|---|---|
| Answering a contact or quote request | Pre-contractual steps taken at your request | 3 years after the last exchange |
| Arranging an appointment | Pre-contractual steps taken at your request | 1 year after the appointment |
| Handling a training or event registration | Performance of the contract | 5 years (accounting obligations) |
| Handling an unsolicited application | Steps preliminary to recruitment, taken at your request | 2 years after the last exchange, unless you ask for deletion |
| Sending the newsletter and measuring whether it is read | Your consent, withdrawable at any time | Until consent is withdrawn |
| Running the conversational assistant | Legitimate interest: informing visitors | For the session; no lasting storage on our side |
| Counting site traffic | Legitimate interest: knowing how our own site is used | 90 days, then anonymous aggregates |
| Limiting automated submissions and abuse | Legitimate interest: service security | A few minutes |
| Keeping accounts and defending a claim | Legal obligation, and legitimate interest in asserting a right | The applicable limitation periods |
We do not sell any data, we do not rent out any list, we do not carry out unsolicited canvassing, and we take no automated decisions producing legal effects concerning you or similarly significantly affecting you.
Who has access to your data
Your data is accessible to the TeraLink Ubuntu team handling your request, and to a limited number of technical providers acting on our behalf, on our instructions and under a written contract.
- Hosting: the site and its database are hosted with an infrastructure provider acting on our behalf, bound by a processing agreement.
- Email delivery: confirmation messages and the newsletter are routed through a delivery provider acting on our behalf.
- Conversational assistant: when you write to the assistant, the content of your message is sent to the language-model provider configured in the administration area. That provider is chosen from a closed list — Anthropic, OpenAI, Google, Mistral AI, Groq, Cohere, Cerebras ou OpenRouter — some of which are established in the European Union and others in the United States. Do not write any confidential information in that window.
None of these providers is permitted to use your data for its own purposes, or to pass it on. We require each of them not to train any model on what we send.
We may also be required to disclose data upon request from a duly empowered judicial or administrative authority. Where the law does not forbid us to, we tell you.
Transfers outside Senegal and outside the Union
Some of our data travels outside Senegal, and some outside the European Union — that is the case for messages sent to the assistant when the configured provider is established in the United States.
Two requirements then apply at once, and we treat them separately because they do not say the same thing.
- Under Senegalese law: law no. 2008-12 governs transfers of data to a third country and makes them conditional on the level of protection it affords. The transfers we carry out are limited to what is necessary for the service described on this page to work.
- Under the GDPR: for the data of people located in the Union, transfers to the United States rest on the standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), incorporated into our providers’ data processing terms.
The country in which this site’s servers are located is not stated on this page as long as we cannot assert it without reservation. We would rather say nothing than state a location we could not demonstrate. You can ask us for it: we will answer with the host’s name and the actual country.
Your rights
The rights below are open to you wherever you live: we apply the more protective standard to everyone.
- Access: obtain confirmation that we process data about you, and receive a copy of it.
- Rectification: have inaccurate or incomplete information corrected.
- Erasure: request deletion of your data, except where a legal obligation or the defence of a right requires us to keep it.
- Restriction: request that processing be frozen while a dispute is examined.
- Portability: receive, in a structured, machine-readable format, the data you provided to us.
- Objection: object to processing based on our legitimate interest, and to any canvassing — in the latter case without having to give reasons.
- Withdrawal of consent: at any time, without affecting what was done before the withdrawal. Every newsletter carries an unsubscribe link that works in one click.
- Post-mortem directives: set out what should happen to your data after your death.
To exercise these rights, write to us at the address given at the end of this page. We reply within one month. If the request is complex, or if requests are numerous, that period may be extended by two months — we then tell you within the first month, and say why.
We may ask for something that lets us verify your identity, only where there is reasonable doubt as to who is making the request — never as a matter of course, and never a copy of an identity document where something else will do.
If our answer does not satisfy you, you may refer the matter to the Senegalese Personal Data Protection Commission (CDP). If you live in the European Union, you may refer it to the supervisory authority of your country of residence — the CNIL in France — and, in every case, seek a judicial remedy.
Data processed in our software
Beyond this website, TeraLink Ubuntu publishes and operates its own software — TeraLearn, TeraFlow, TeraSchool and TeraPodcast, and those that will follow. The data processed there follows different rules, because our role there is not the same.
- When you use one of our products on your own behalf, we are the controller: the rules set out on this page apply.
- When your employer, your school or an organisation gives you access to one of our products, that body decides what data is collected and how it is used. It is the controller; we act only as a processor, on its instructions and under a written contract complying with Article 28 of the GDPR. Send your rights requests to it: we forward any that reach us, but we cannot answer on its behalf.
In both cases: we access the content of your data only where it is necessary for a technical intervention you requested, or for the security of the service, and never for commercial purposes. Such access is logged. We train no artificial-intelligence model on the content you place in our software, neither for ourselves nor for a third party.
At the end of a contract, your data is returned to you in a usable format on request, for ninety days, then deleted from our systems, backups included. The detailed conditions are set out in the software licence.
Security
Here are the measures we actually apply. We announce none that the code does not deliver.
- Exchanges with the site are encrypted in transit (HTTPS/TLS).
- Passwords are never stored in clear text.
- Access keys to third-party services are encrypted before being stored in the database.
- Content submitted through forms is validated on the server and sanitised before storage, to rule out injection.
- Access to the administration area is restricted to authorised accounts, and actions there are logged.
- Form submissions are rate-limited per visitor, to contain automated attempts.
- The site’s responses carry security headers that, among other things, forbid it being displayed in a frame on another site.
No system is infallible. Should a data breach likely to create a risk to your rights occur, we would notify the competent authority within seventy-two hours and inform you directly where the risk is high — without waiting to be compelled to.
Minors
This site is addressed to professionals and to adults. We do not knowingly collect data about a child. If you find that a minor has sent us data, write to us: we will delete it without delay.
Some of our products — a school platform, for instance — process data about minors. In that case we act only as a processor for the school, which remains the controller and remains responsible for informing families.
Changes to this policy
This policy may change, in particular if we add a service or change provider. The version in force, its date and its number appear at the top of the page. In the event of a substantial change affecting your rights, we inform the people concerned by email, before the change takes effect where possible.
Contact us
To exercise your rights, ask a question about this document or report a problem: