Your data belongs to you.
We keep it safe.
This policy explains, without needless jargon, what data we collect when you use Savoira, why we use it, who we share it with (very few people), and how you stay in control of it at all times.
Overview
Savoira is a learning platform operated by Savoira SAS, based in Kinshasa, Democratic Republic of the Congo. We process personal data when you create an account, take a course, pay for a path, or interact with our site.
This policy applies to all of our services, website, mobile apps, and any other interface carrying the Savoira brand. It should be read alongside our Terms of Service and our Cookie Policy.
Data we collect
We collect three kinds of data:
Data you give us
- Account: name, email address, phone number, password (hashed).
- Profile: photo, bio, paths of interest, level, languages you understand.
- Payment : no banking data. Online sales are not open, so no card number or mobile-money identifier is entered, transmitted or stored. Access paid for offline is opened by hand: we keep only the amount and the date, for invoicing.
- Coursework : quiz answers, submitted work, projects, messages sent to support.
Data collected automatically
- Usage: courses visited, lessons completed, time spent, exercise scores.
- Device: device type, browser, language, time zone, screen resolution.
- Technical logs: IP address, timestamps, error codes, used for security and debugging.
Data we receive from third parties
- Social login: if you sign in with Google, GitHub or LinkedIn, those services send us an identifier, your name and your email. We never pull in your contact list.
- Partner employers: if your employer funds your training, we share your completion status with them, it's written into their contract.
We never collect sensitive data as defined by the GDPR (origin, political opinions, religion, sexual orientation, health). If that kind of information appears in submitted work, it is treated as course content and is not indexed.
How we use your data
Every piece of data has a declared purpose. Here is the full map:
| Purpose | Data involved | Duration |
|---|---|---|
| Provide the service (account creation, course access) | Account, profile, coursework | Life of the account |
| Authentication and security | Hashed password, IP, logs | 13 months max |
| Payment processing | Payment data, invoices | 10 years (tax requirement) |
| Personalized recommendations | Usage, level, paths of interest | Life of the account |
| Communications (transactional) | Email, phone | Life of the account |
| Communications (newsletter) | Until you unsubscribe | |
| Anonymized analytics | Aggregated usage, device | 25 months |
| Issuing and verifying certificates | Name, path completed | Permanent (unless you ask) |
Legal basis (GDPR)
If you live in the European Economic Area, we process your data under four legal bases. Each processing activity listed in the previous section rests on one of them.
Sharing with third parties
We don't sell your data. We share it in only three cases:
Main subprocessors
| Provider | Service | Location |
|---|---|---|
| Namecheap | Website hosting, database, email delivery | United States (Phoenix, Arizona) |
| Meta Platforms | Sign-in codes sent over WhatsApp | Ireland / United States |
| Sign-in with a Google account, if you use it | Ireland / United States | |
| pawaPay | Mobile Money collection: your number, the amount, the operator | Lithuania / United Kingdom |
| Cloudflare | Anti-bot check at sign-up (Turnstile): IP address and browser signals | United States |
| StopForumSpam | Sign-up reputation: email address and IP address, checked against a public spammer database | United Kingdom |
| Adobe | Displaying course PDFs in the player, if you open that tab | Ireland / United States |
How long we keep your data
While your account is active, we keep your data to provide the service. Here's what happens if you delete your account:
Your certificates remain publicly verifiable by their number, even after the account is deleted, unless you explicitly ask us to remove them.
Security
Security isn't a feature, it's a requirement. Here's what we actually do:
- TLS 1.3 encryption for all network traffic.
- AES-256 encryption at rest for databases and backups.
- Passwords hashed with Argon2id (never stored in plain text).
- Two-factor authentication available (TOTP, SMS).
- Annual external security audits and penetration testing.
- Internal access limited to what's strictly needed, logged, and revoked automatically.
If a data breach affects your information, we notify you by email within 72 hours and post a notice on the site, as required by the GDPR and DRC Law 22/041.
Your rights
At any time, you have the right to:
You exercise these rights by writing to :mail from the account's address. The Delete my account button in your space (Profile & settings → Security) drafts the message for you. We reply within 30 days, and most often within 48 business hours.
If you feel your rights haven't been respected, you can lodge a complaint with the relevant authority, the CNIL in France, the APD in Belgium, or the DRC's data protection authority.
Cookies and tracking
We deliberately keep the number of cookies low, grouped into three categories. You can manage your preferences at any time from the cookie banner or your account settings.
| Category | What it does | Consent | Duration |
|---|---|---|---|
| Essential | Session, authentication, security, language | Not required | Session – 12 months |
| Preferences | Language, theme, last lesson | Not required | 12 months |
| Analytics | None. We install no analytics tool. | - | - |
| Marketing | None. We don't do remarketing. | - | - |
International transfers
Your data is stored on the server that hosts Savoira, located in the United States (Phoenix, Arizona). Our other processors operate from the United States or Ireland: transfers to those countries are governed by standard contractual clauses approved by the European Commission, or by adequacy decisions where they exist.
For users living in the DRC or other African countries, we apply a level of protection at least equivalent to what DRC Law 22/041 requires.
Minors
Savoira is intended for people aged 16 and over. We do not knowingly create accounts for anyone under 16. If you believe an account was created for a minor, email us at contact@savoira.com: we will delete it within 7 days.
Between 16 and 18, signing up requires a legal guardian's consent. We do not verify it when the account is created: we rely on you, and on them.
Changes to this policy
We may update this policy to reflect changes in our services, in regulations, or in our practices. The last-updated date is shown at the top of this page.
For any significant change, we notify you by email at least 30 days before it takes effect. The change log is available on request at contact@savoira.com.
Contact us
Three ways to reach us, depending on what you need: