CodeWifi · OZi-CONNECT

Privacy Policy

Last updated: 23 September 2026
Lire en français →
Draft pending legal review. This policy accurately describes how the platform currently works. Before final publication, have it reviewed by a lawyer admitted in Côte d'Ivoire, and complete the data processing declaration with ARTCI if this has not yet been done.

In short

1Who processes your data

Controller
OZIPROHOLDING SARLU
Trade register
RCCM CI-ABJ-03-2023-B13-12349
Registered office
Abidjan Yopougon, Quartier Millionnaire — 08 BP 1473 Cocody, Côte d'Ivoire
Contact
partnership@oziproholding.com
ARTCI declaration
[NUMBER TO BE ADDED]

Processing is subject to Ivorian law no. 2013-450 of 19 June 2013 on the protection of personal data.

2Two levels of responsibility

The platform serves two distinct audiences, and our role differs for each.

For operators (our customers)

We are the data controller for account data: we decide what is collected and why.

For WiFi end customers

When someone buys a voucher or connects to a hotspot, the operator is the data controller. We act as data processor: we process this data on the operator's behalf, following their instructions, and we do not use it for our own purposes.

In practice: if you are a WiFi customer and wish to exercise your rights over your data, contact the operator of the hotspot you use first. We will assist them in handling your request.

3Data we collect

Operator account

DataPurposeProtection
NameAccount identificationPlain text
EmailLogin, notifications, supportPlain text
Phone numberContact, Mobile Money payoutsPlain text
City, countryBusiness locationPlain text
PasswordAuthenticationHashed (bcrypt)

Passwords are transformed by a one-way function: they cannot be recovered, including by us. If forgotten, a password is reset, never resent.

Phone number verification

If sign-up is done with a phone number (signing up by email is also possible and is not affected), a 6-digit verification code is sent to confirm it is a real, reachable number.

DataPurposeProtection / Retention
Verification codeConfirm the number belongs to the operatorHashed (bcrypt), expires after 10 minutes
Phone numberDelivery of the codeSent to the delivery provider (WhatsApp or, as a fallback, SMS)

The code is sent primarily via WhatsApp (Meta API). If delivery fails, a fallback SMS is sent via Africa's Talking. The phone number is shared with either provider solely to deliver the code, never for any other purpose.

Voucher purchase by an end customer

DataPurposeRetention
Phone numberMobile Money collectionErased if payment fails or expires
Name (optional)Sales tracking by the operatorPer operator settings
Payment methodTransaction routingWith the transaction
Transaction referenceAccounting reconciliationWith the transaction

No banking or card data is stored by CodeWifi. Payments are handled by a specialised provider.

People connected to a hotspot

DataPurposeRetention
MAC addressLive display of active sessionsIn memory, ~17 seconds
Local IP addressLive display of active sessionsIn memory, ~17 seconds
Session duration and data volumeUsage monitoring by the operatorIn memory, ~17 seconds

This data is never written to our database. It is read directly from the router at the moment the operator views their screen, held in memory for a few seconds, then automatically discarded. It also disappears whenever the server restarts.

Voucher-sharing detection (anti-fraud)

To spot a WiFi voucher being shared abusively across several devices, we count the number of distinct devices that have used the same voucher.

DataPurposeProtection
Hashed MAC fingerprintCount distinct devices using the same voucherOne-way HMAC-SHA256 hash, dedicated key

The real MAC address is never stored and cannot be reconstructed from this fingerprint. It cannot identify a device outside the voucher it is tied to: it is only used to count, never to track a person. It is automatically deleted 60 days after the voucher's last use (automatic purge, no human action required).

Equipment and transactions

DataPurposeProtection
VPN public key, internal tunnel addressSecure router connectionTechnical, not personal
Router API passwordRemote managementAES-256-GCM encrypted
Mobile Money payout numberRevenue payoutPlain text

4Logs and tracking

We keep no persistent browsing logs: visitor IP addresses are not written to disk. A login attempt counter is held in memory for fifteen minutes to limit brute-force attacks, then cleared.

The platform includes no analytics, advertising or third-party tracking tools: no Google Analytics, no advertising pixel, no behavioural tracking service.

The only cookies used are strictly necessary for operation: maintaining the login session and security. No advertising cookies are set.

If a server-side technical error occurs, a diagnostic report is automatically sent to Sentry (Functional Software, Inc.), our incident-tracking tool, hosted in the European Union (Germany). This report contains the error message and its technical context — never a password, authentication token or phone number: this information is automatically stripped before sending.

5Who receives your data

Your data is not sold, rented or traded. It is shared only with:

RecipientData sharedReason
Mobile Money payment providerPhone number, amount, chosen operatorTransaction execution
DigitalOcean (hosting)All hosted dataServer hosting (Frankfurt, Germany)
Sentry (Functional Software, Inc.)Technical error messages and related context (never a password, token or phone number)Troubleshooting and bug fixing (EU hosting)
Meta (WhatsApp Business Platform)Phone number, verification codeDelivery of the verification code via WhatsApp
Africa's TalkingPhone number, verification codeDelivery of the code via SMS, only if WhatsApp fails
Competent authoritiesOn formal legal request onlyLegal obligation

Transfer outside Côte d'Ivoire. Our servers are located in Germany, subject to the European GDPR. This transfer is necessary to provide the service and benefits from a recognised protection framework.

6Retention periods

DataPeriod
Active operator accountFor the duration of the contractual relationship
Closed account30 days for export, then deletion
Sold vouchers and transactionsStatutory accounting retention (10 years)
Reserved unpaid vouchersPhone number erased after 3 minutes
Live WiFi sessionsA few seconds, in memory
Device fingerprint (MAC hash)Rolling 60 days from last use, then automatic deletion
Phone verification code10 minutes, then automatically invalidated

7Security

We apply the following measures:

No system is infallible. In the event of a data breach likely to harm you, we will inform you as soon as possible and make the required notifications.

8Your rights

Under law no. 2013-450, you have the following rights:

To exercise these rights, write to partnership@oziproholding.com. We respond within thirty (30) days. Proof of identity may be requested to prevent disclosure to a third party.

You may also refer the matter to ARTCI, the data protection authority in Côte d'Ivoire.

9Minors

The platform is intended for adult professionals. We do not knowingly collect data concerning minors. Should such data be sent to us in error, it would be deleted upon notification.

10Changes to this policy

This policy may be amended to reflect changes to the platform or to regulations. Substantial changes are notified by email. The last update date appears at the top of the page.

11Contact

Email
partnership@oziproholding.com
Mail
OZIPROHOLDING — 08 BP 1473 Cocody, Abidjan, Côte d'Ivoire