AFYO← Back to home

Last updated 10 August 2026

Privacy Policy

This policy informs you of AFYO’s commitments regarding the protection of personal data. AFYO acts as data controller for the processing described below. It applies to the afyo.fr website (the “Platform”), which enables Clients, in particular members of the African diaspora residing in Europe, to remotely fund healthcare services delivered to their relatives (the “Patients”) by partner healthcare professionals located in certain African countries.

This English version is a courtesy translation; the French version is authoritative.

On this page

  1. 1The data we process
  2. 2The purposes of our processing
  3. 3Legal bases
  4. 4Recipients of your data
  5. 5Transfer of your data
  6. 6Retention period
  7. 7The security of your data
  8. 8The rights granted to you
  9. 9Cookies
  10. 10Minors
  11. 11Changes to this policy
  12. 12Questions? Problems? Suggestions?

AFYO applies a strict minimisation principle: we only collect the data strictly necessary to operate the service, and no medical data is collected at registration. As AFYO is being incorporated, the registration details will be added upon registration.

1

The data we process

Data relating to Clients

  • Identity and identification: surname, first name, email address, telephone number where applicable;
  • Payment method: processed directly by our payment provider Stripe - AFYO keeps neither card numbers nor full bank details;
  • Connection data: IP addresses, event logs, authentication data;
  • Order history: Services ordered, amounts, statuses, Access codes issued and validated;
  • Support exchanges: messages, complaints, reviews where applicable;
  • Platform preferences and settings;
  • Management: invoicing, accounting, handling of unpaid amounts and disputes.

Data relating to Patients

The Client enters the data of their relative beneficiaries, limited to: surname, first name, relationship to the Client, country and, where applicable, contact details. The Client warrants that they have informed the Patient (or their legal representative) and have their agreement to share this data.

Please note: associating a Patient with a specific Service (medicine, examination, consultation) may constitute health data within the meaning of Article 9 of the GDPR. Such data is subject to reinforced measures: access strictly limited to authorised staff, encryption, and no use whatsoever for commercial, advertising or profiling purposes.

Data relating to Healthcare professionals

  • Identity and contact details of the representative and the establishment;
  • Supporting documents of legal existence and practising authorisation;
  • Invoicing and payout data (payout details, Wallet history);
  • History of Access code validations and associated connection data.
2

The purposes of our processing

We carry out processing for the following purposes:

  • enabling you to create and use your personal area;
  • verifying the email address at registration and authenticating Users at each login;
  • enabling the Client to create and manage their Patient beneficiaries;
  • enabling the ordering and funding of Services, and the generation, transmission and validation of Access codes;
  • enabling payment and, for Healthcare professionals, the payout of the corresponding sums;
  • verifying and listing partner Healthcare professionals (checking practising documents);
  • managing the relationship, complaints and terminations;
  • sending you service messages (Order confirmation, issuance and validation of an Access code, refund) by email and, where applicable, by SMS;
  • managing invoicing and accounting;
  • preventing and detecting fraud, money laundering and terrorist financing, and securing the Platform (logging, rate-limiting, incident handling);
  • measuring the Platform’s audience and, subject to your consent, sending you a newsletter about our news and updates;
  • handling requests to exercise your rights;
  • handling unpaid amounts and disputes, as well as any reviews submitted.

Patients’ data and data related to Services are never used for prospecting, advertising, commercial profiling or transfer to third parties.

3

Legal bases

We only process your data where at least one of the following bases applies:

  • performance of the contract between us: management of accounts, Orders, payments, Access codes, payouts;
  • compliance with a legal obligation: accounting, reporting obligations, fight against fraud and money laundering, response to requests from authorised authorities;
  • our legitimate interest, or that of a third party: security of the Platform, fraud prevention, improvement of our services, dispute management;
  • your consent: audience measurement and newsletter, non-essential cookies, and any processing of health data requiring it under Article 9.2.a of the GDPR.

As regards health data that may be processed when placing an Order, processing is based on the explicit consent of the data subject (Article 9.2.a of the GDPR), obtained at the time of the Order.

4

Recipients of your data

The data collected is intended for us as data controller. Only authorised staff have access to it. The following may also be recipients, strictly within the limits of what is necessary to them:

  • the Healthcare professional chosen by the Client: they receive only the information necessary to deliver the Service (Patient’s identity, Service ordered, Access code), to the exclusion of any other Client data;
  • our technical subprocessors, on documented instructions and under Article 28 of the GDPR: hosting of the application and database (Vercel, Supabase), domain name and email (IONOS), payment processing (Stripe), payouts to professionals (PawaPay), transactional email (Resend), audience measurement (Google Analytics, subject to your consent);
  • third parties or legally authorised authorities, to meet our legal obligations (tax administration, judicial authorities, TRACFIN where applicable).

We make no Patient or Service data available to commercial partners, and your data is never sold to third parties. In the event of an acquisition or transfer of all or part of our business, we will ensure the acquirer uses your data in accordance with this policy.

5

Transfer of your data

The Platform’s data is hosted by our providers (Vercel, Supabase). Some of our technical subprocessors (hosting, payment, email, audience measurement) may process data outside the European Union, in particular in the United States; these transfers are governed by the mechanisms provided in Chapter V of the GDPR (adequacy decision, European Commission standard contractual clauses, additional measures where applicable).

Moreover, the very operation of the service involves communicating certain data (Patient’s identity, Service ordered, Access code) to Healthcare professionals located outside the European Union, in the Covered Countries (currently the Republic of the Congo and the Democratic Republic of the Congo). This transfer is necessary for the performance of the contract and in the data subject’s interest, in accordance with Article 49.1.b and c of the GDPR. It is governed by contractual confidentiality and data-protection commitments imposed on each Healthcare professional when listed: limitation of the data received to the strict minimum, prohibition of reuse for other purposes, reinforced confidentiality obligation, and deletion of the data at the end of the agreed periods.

6

Retention period

Retention periods are proportionate to the purposes for which the data was collected:

  • Account data (Client / Healthcare professional): duration of the contractual relationship, then intermediate archiving from closure or last activity.
  • Order data and accounting records: 10 years (accounting and tax obligations, Art. L. 123-22 of the Commercial Code).
  • Service-related data (Patient / Access code): period strictly necessary to perform the Order, then restricted archiving for the duration of legal limitation periods.
  • Healthcare professional listing documents: duration of the partnership, plus limitation periods.
  • Connection and security logs: at most 6 to 12 months, unless an incident justifies longer retention for evidential purposes.
  • Newsletter: until you withdraw your consent.
  • Cookies and trackers: see the Cookie Policy (13 months maximum).

Beyond these periods, data is anonymised and kept for statistical purposes only, with no exploitation of any kind. Account deletion is carried out by deactivation (soft delete) then purge at the end of the legal periods. You also have a right to erasure that you may exercise at any time.

7

The security of your data

AFYO has implemented measures to protect the confidentiality, security and integrity of your data: encryption of exchanges (TLS), role-based access control verified server-side, authentication with mandatory email verification, request rate-limiting, logging of security events, data minimisation, hosting with providers offering recognised guarantees, and no storage of bank data. Data likely to reveal health information is subject to reinforced access restrictions.

In the event of a data breach likely to create a risk to your rights and freedoms, AFYO will notify the CNIL within 72 hours and, where the risk is high, the persons concerned, in accordance with Articles 33 and 34 of the GDPR. When you choose a password, it is your responsibility to choose a strong, unique one and to keep it confidential.

8

The rights granted to you

How to exercise your rights

You may exercise your rights electronically at info@afyo.fr or by post at AFYO’s registered office, providing proof of identity. We respond within one (1) month, extendable by two (2) months for complex requests. The Patient, although without an account, has the same rights over the data concerning them and may exercise them at the same addresses, directly or through the Client who designated them.

Right of access and rectification

You may obtain confirmation that your data is being processed, access it, obtain a copy and have it rectified, together with information on the purposes, categories of data, recipients, retention period and your rights.

Right to erasure

You may request erasure of your data where it is no longer necessary, where consent is withdrawn, where you object without overriding legitimate grounds, or where processing is non-compliant. This right does not apply where retention is necessary to comply with a legal obligation (in particular accounting) or to defend legal claims.

Right to restriction

You may request restriction of processing in the cases provided by the regulation, in particular where you contest the accuracy of your data or object to its erasure.

Right to object

You may object, on grounds relating to your particular situation, to processing based on our legitimate interest, and at any time and without reason to the processing of your data for prospecting purposes.

Right to portability

Where processing is based on your consent or on a contract and carried out by automated means, you may receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically possible.

Right to withdraw consent

Where processing is based on your consent, you may withdraw it at any time, without affecting prior processing.

Right to lodge a complaint

If you believe AFYO is not meeting its obligations, you may refer the matter to the CNIL, the competent authority in France, at https://www.cnil.fr/fr/plaintes.

Post-mortem directives

You may set directives regarding the retention, erasure and communication of your data after your death, in accordance with the applicable legal framework.

9

Cookies

When browsing the Platform, cookies are placed on your device, either directly when strictly necessary for the operation of the service, or after obtaining your consent where the regulation requires it. To learn more, please consult our Cookie Policy, available on the Platform.

10

Minors

The Platform is not intended, as a User, for persons under 18, and we knowingly collect no data from them for the purpose of creating an account. In France, consent to the processing of a minor’s data is validly given alone only from the age of 15.

However, a Patient beneficiary may be a minor: their data is then entered by the Client, under the responsibility of the Patient’s legal representative, and processed with the reinforced protections described in this policy. The Client warrants that they have the authorisation of the minor Patient’s legal representative.

11

Changes to this policy

This policy may change, in particular if the service is extended to new countries or new features. Any material change will be brought to your attention by any appropriate means (notification, email, banner) with a new update date.

12

Questions? Problems? Suggestions?

For any question about this policy and, more generally, about the collection and processing of your personal data by AFYO, contact us at info@afyo.fr.

See also

Terms of UseThe terms governing use of the platform.→Terms of Sale & ServiceThe terms of sale and service.→Legal NoticeLegal information about the site publisher.→Cookie PolicyThe cookies we use and your choices.→