IK
Inefable KoumbaSoftware Engineer · Data & Networks
Back to Portfolio
OFFICIAL UNIFIED LEGAL HUB|2.4.0 (Unified Multi-Product Edition)

Legal Hub — Privacy Policy & Terms of Service

Unified legal framework, privacy policy, regulatory disclosures, and terms of service governing all websites, mobile applications (iOS & Android), APIs, and digital services developed by Inefable Koumba and MAZALA-FIRM.

Publisher & Controller

Inefable Koumba (Surprise Inefable Koumba Missoundou)

MAZALA-FIRM / Inefable Koumba Software Engineering

Jurisdiction

Brazzaville, Republic of the Congo

Loi n° 29-2019 & OHADA

Last Revision

September 7, 2026

Annual Full Audit

DPO / Legal Contact

[email protected]

SLA 48h / 30-Day Purge

European Union & UK

GDPR / UK GDPR (Regulation 2016/679)

Full compliance with legal bases, DPO access, data subject rights, and standard contractual clauses.

United States (California)

CCPA / CPRA & CalOPPA / COPPA

Right to know, delete, correct, non-discrimination, strict under-13 protections, and explicit zero-sale declaration.

Republic of the Congo

Loi n° 29-2019 du 10 octobre 2019

Compliance with personal data protection and cybersecurity mandates governing Congolese entities.

Global App Stores

Apple Guideline 5.1 & Google Play Developer Policy

Conspicuous permission justifications, transparent third-party disclosures, and direct in-app & web account deletion.

Section 1

1. Scope, Applicability & Data Controller Identity

Defines the scope of this Legal Hub across all software products, mobile applications, and web platforms developed or operated by Inefable Koumba.

This master legal document governs all digital platforms, mobile applications (distributed via Apple App Store, Google Play Store, or independent APK/IPA distribution), web applications, APIs, smart bots, and software services engineered, operated, or maintained by Surprise Inefable KOUMBA MISSOUNDOU (commercially operating as Inefable Koumba and MAZALA-FIRM, hereinafter referred to as 'we', 'our', or 'us').

Products covered under this unified legal hub include, without limitation: Volten AI (customer automation platform), Rhodium (events & concierge booking), Koyeba (real-time trivia mobile gaming), MyBGR (AI resume & career mobile assistant), Jecontribue (solidarity & payment infrastructure), as well as municipal portals, client solutions, and personal developer utilities.

For the purposes of the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), Law No. 29-2019 of the Republic of the Congo, and related data privacy regulations, the Data Controller is Inefable Koumba, reachable directly at [email protected].

Section 2

2. Categories of Personal Data Collected

Transparent breakdown of information you provide directly, technical telemetry, hardware permissions, and transaction records.

A. Information Provided Directly by the User

Depending on which application or website you interact with, we may collect the following user-submitted information:

  • Account Identity: Full name, username, email address, phone number, profile photo, and securely salted/hashed passwords (stored using modern bcrypt or Argon2 cryptographic hashing).
  • User-Generated Content: Messages sent through contact forms, AI prompts submitted in assistant interfaces, resume details inputted into MyBGR (work experience, education, skills), or event reservations submitted in Rhodium.
  • Customer Support & Feedback: Records of correspondence, bug reports, and diagnostic descriptions provided when requesting assistance.

B. Information Collected Automatically (Telemetry & Device Diagnostics)

To maintain service stability, prevent fraudulent abuse, and optimize performance across device form factors:

  • Network and Device Identifiers: Anonymized IP addresses, browser user agent, device model, operating system version, and system language settings.
  • App Performance & Crash Logs: Stack traces, memory usage events, and session anomalies collected via privacy-conscious telemetry tools (e.g. Firebase Crashlytics) to repair software bugs.

C. Payment and Transactional Information

For applications featuring event ticketing (Rhodium), donations (Jecontribue), or premium digital upgrades:

  • Credit card and debit payments are processed directly by certified PCI-DSS Level 1 payment providers (such as Stripe). We NEVER collect, see, or store full credit card numbers or security CVV codes on our servers.
  • Mobile Money payments (e.g. Airtel Money, MTN Mobile Money) are transacted through licensed telecom API aggregators. Only transaction reference IDs, status tokens, and timestamps are retained for receipt delivery.
  • In-App Purchases on mobile are processed exclusively by Apple App Store (In-App Purchase) or Google Play Billing.
Section 4

4. Mobile App Hardware Permissions & Safety (Apple & Google Play)

Detailed disclosure of device permissions requested by our mobile applications, why they are needed, and how they are protected.

In accordance with Apple App Store Review Guidelines (Guideline 5.1.1) and Google Play Developer Policies (User Data Policy), our mobile applications only request access to device hardware features when strictly necessary for user-initiated functionality. We never access your hardware silently or in the background without explicit permission.

Camera Access (NSCameraUsageDescription / CAMERA)

Used strictly when you choose to scan a physical resume/document (e.g. MyBGR OCR engine), scan a QR entrance badge (e.g. Rhodium Ticket Scanner), or take a live profile picture. Photos are processed locally or uploaded only upon your direct confirmation.

Photo Library / Storage (NSPhotoLibraryUsageDescription / READ_MEDIA_IMAGES)

Allows you to select and upload an existing document, avatar image, or PDF file into the app, or to save an exported file (such as an ATS-compliant resume from MyBGR or an event ticket receipt from Rhodium).

Push Notifications (APNs / Firebase Cloud Messaging)

Used to send transactional alerts, such as event booking confirmations, critical security notices, tournament start notifications (Koyeba), or customer service updates. You may revoke push notification permissions at any time in your device settings.

Location Services (NSLocationWhenInUseUsageDescription / ACCESS_COARSE_LOCATION)

Where applicable (e.g. event discovery nearby in Rhodium), coarse or fine location is requested strictly while the app is in use to show venues within your geographic vicinity. Background location is NOT collected.

Zero Background Eavesdropping & Zero Data Selling Guarantee

We do NOT record your microphone in the background, we do NOT track your device across third-party apps or websites (IDFA tracking is NOT used without ATT consent), and we NEVER sell your personal data to data brokers or ad networks.

Section 5

5. Subprocessors, Cloud Infrastructure & Third-Party SDKs

Transparent inventory of reputable infrastructure and cloud providers handling data on our behalf.

We partner only with industry-recognized cloud platforms that adhere to rigorous security standards (ISO 27001, SOC 2 Type II, GDPR alignment):

Hosting, Edge Compute & Security

Cloudflare Inc. (Global CDN, SSL/TLS termination, DDoS mitigation, R2 storage) and AWS / Render / IONOS (cloud virtual machines and managed microservices).

Database & Backend Storage

PostgreSQL, Turso / LibSQL (distributed edge SQL), Redis (caching and pub/sub), and Supabase. All databases feature hardware encryption at rest and mandatory TLS in transit.

Mobile Services & Push Infrastructure

Google Firebase (Firebase Authentication, Cloud Messaging FCM, Crashlytics) and Apple Push Notification service (APNs).

Payment Gateways

Stripe Inc. (for card processing) and telecom Mobile Money operators (Airtel Money, MTN Mobile Money). Payment handling is restricted to PCI-DSS certified conduits.

Section 6

6. Your Global Privacy Rights (GDPR, CCPA/CPRA & Local Laws)

Full enumeration of individual rights to access, correct, delete, port, and restrict the use of your personal data.

Rights Under GDPR (European Union & UK Citizens)

Under Regulation (EU) 2016/679, you hold the following rights:

  • Right of Access (Art. 15): Obtain confirmation of whether your data is processed, and receive a portable copy.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal records.
  • Right to Erasure / 'Right to be Forgotten' (Art. 17): Request permanent deletion of your data when no longer necessary.
  • Right to Restriction of Processing (Art. 18): Restrict processing during verification of data accuracy or objections.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format (JSON/CSV).
  • Right to Object (Art. 21): Object at any time to processing based on legitimate interests.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with an official Supervisory Authority (such as the CNIL in France, the ICO in the UK, or your local data protection agency).

California Consumer Privacy Act (CCPA / CPRA Disclosures)

If you reside in California, United States, California law grants specific protections:

  • Right to Know & Access: Learn the categories and specific pieces of personal information collected over the preceding 12 months.
  • Right to Delete: Request deletion of personal information collected from you.
  • Right to Correct: Request correction of inaccurate personal data.
  • Do Not Sell or Share My Personal Information: We declare under penalty of perjury that we DO NOT sell personal information to third parties, and we DO NOT share your data for cross-context behavioral advertising.
  • Non-Discrimination: We will never discriminate against you (deny services, charge different prices, or degrade quality) for exercising any of your CCPA rights.

Republic of the Congo (Law No. 29-2019 Protection)

In accordance with Law No. 29-2019 of October 10, 2019 on the Protection of Personal Data in the Republic of the Congo, all Congolese citizens and residents are guaranteed the right to confidentiality, human dignity, and secure processing of personal identifiers.

Children's Privacy Protection (COPPA & CalOPPA Compliance)

Our applications and services are not directed at children under the age of 13 (or under 16 within the European Economic Area). We do not knowingly collect personal information from minors. If you believe that a minor has provided us with personal data without parental consent, please contact [email protected] immediately, and we will delete the data without delay.

Section 7 — Mandatory

7. Account & Data Deletion Procedure (Apple Guideline 5.1.1(v) & Google Play)

Explicit instructions for permanently deleting user accounts and purging personal data both in-app and via web/email.

In compliance with Apple App Store Review Guideline 5.1.1(v) and Google Play Developer Data Safety mandates, every user has the absolute right to terminate their account and permanently erase all associated personal data at any time, easily and without unnecessary hurdles.

Method 1: Direct In-App Deletion

If you are using any of our mobile applications with user registration (e.g. Rhodium, Koyeba, MyBGR):

  • 1. Open the mobile app on your iOS or Android device.
  • 2. Navigate to Profile / Settings > Security & Account.
  • 3. Tap 'Delete Account' (or 'Supprimer mon compte').
  • 4. Confirm your selection. Your authentication credentials, profile information, and active tokens are purged immediately from production databases.

Method 2: Web & Email Self-Serve Deletion Request

If you cannot access your mobile device or prefer a web-based deletion request:

  • Send an email to [email protected] with the subject line: 'Account & Data Deletion Request'.
  • Include the name of the application (e.g. Volten AI, Rhodium, Koyeba, MyBGR) and your registered email address or username.
  • Service Level Agreement (SLA): We acknowledge receipt within 48 hours and permanently delete all records within 30 days. You will receive a formal confirmation receipt once deletion is completed.

Data Retention & Post-Deletion Purge Details

Upon account deletion, all active databases immediately sever links to your identity. Encrypted system backups overwrite naturally on a rolling 30-day lifecycle, after which no copies remain.

Irreversible Action

Deleting your account is permanent. It removes active subscriptions, saved resumes, tournament scores, and ticket purchase history. This action cannot be undone.

Section 8 — Terms

8. Terms of Service — Acceptance, License & Permitted Use

Binding contractual terms governing your rights to install, access, and interact with our applications and websites.

By accessing, downloading, browsing, or utilizing any website, mobile application, or digital service developed or operated by Inefable Koumba and MAZALA-FIRM, you expressly agree to be bound by these Terms of Service. If you do not agree to these terms, you must refrain from accessing or installing our software.

License Grant

We grant you a personal, revocable, non-exclusive, non-transferable, non-sublicensable, limited license to download and run our applications on personal devices strictly for personal or authorized professional use, subject to these Terms.

Prohibited Uses & User Conduct

When using our applications or platforms, you agree that you will NOT:

  • Reverse engineer, decompile, disassemble, or attempt to derive source code from any compiled binary, bytecode, or proprietary API without prior written consent.
  • Deploy automated bots, scrapers, web spiders, or crawlers that disrupt service performance, bypass rate limits, or harvest user data.
  • Exploit, scan, or probe software vulnerabilities or transmit viruses, worms, malware, or destructive code.
  • Impersonate any person or entity, forge header tokens, or misrepresent affiliation with Inefable Koumba, MAZALA-FIRM, or partner entities.
  • Utilize our services for illegal activities, illicit money laundering, distribution of abusive or unlawful material, or violation of third-party intellectual property.
Section 9 — Terms

9. In-App Purchases, Subscriptions & Financial Transactions

Rules governing digital goods, mobile app billing through Apple & Google, telecom mobile money, and refund mechanisms.

Apple App Store & Google Play In-App Purchases

All digital purchases and recurring subscriptions conducted within our iOS or Android applications are processed through the official billing mechanisms of Apple Inc. (Apple Media Services Terms and Conditions) or Google LLC (Google Play Terms of Service). Subscriptions automatically renew unless canceled at least 24 hours prior to the end of the current billing cycle via your App Store or Google Play account management settings.

Mobile Money & Direct Web Purchases

For web-based services, event tickets (Rhodium), or donation transactions (Jecontribue), payment is executed via verified Mobile Money operators or authorized payment gateways. All prices are clearly quoted prior to order confirmation, including applicable taxes or telecom fees.

Refund Policy

For in-app purchases through mobile stores, refunds are governed strictly by Apple's or Google's respective refund policies. For direct transactions, refunds are granted if an event is cancelled by the organizer or if an unresolvable technical failure on our end prevented the delivery of the purchased service.

Section 10 — Terms

10. Intellectual Property Rights & Ownership

Protection of software code, algorithms, UI designs, brand marks, and proprietary systems created by Inefable Koumba.

All intellectual property rights in and to our applications, websites, codebases, microservices, APIs, algorithms, visual layouts, graphical assets, icons, logos, brand names (including Inefable Koumba, MAZALA-FIRM, Volten AI, Rhodium, Koyeba, MyBGR, and Jecontribue) are and remain the exclusive property of Inefable Koumba (or our licensors and project partners).

Nothing in these Terms grants you any right, title, or interest in our trademarks, trade secrets, copyrighted software, or patented systems, except for the limited license granted herein.

Section 11 — Terms

11. Disclaimer of Warranties & Limitation of Liability

Standard legal disclaimer governing service availability, performance, and maximum statutory liability limits.

OUR APPLICATIONS, WEBSITES, AND DIGITAL SERVICES ARE PROVIDED ON AN 'AS IS' AND 'AS AVAILABLE' BASIS, WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WITHOUT LIMITATION ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, OR NON-INFRINGEMENT.

TO THE MAXIMUM EXTENT PERMITTED UNDER APPLICABLE LAW, INEFABLE KOUMBA AND MAZALA-FIRM SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES (INCLUDING LOSS OF PROFITS, LOSS OF DATA, DEVICE MALFUNCTION, OR BUSINESS INTERRUPTION) ARISING OUT OF OR RELATING TO YOUR ACCESS TO OR USE OF (OR INABILITY TO ACCESS OR USE) OUR SERVICES.

Section 12 — Final

12. Governing Law, Dispute Resolution & Contact Information

Jurisdiction, dispute settlement mechanisms, and official communication channels for privacy inquiries and legal notices.

These Terms and all matters arising out of our Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of the Congo, without regard to conflict of law principles, alongside international data protection norms applicable to cross-border consumers (including mandatory consumer protection statutes in the user's country of habitual residence).

Before filing any formal legal proceeding, you agree to contact us in good faith to seek an amicable, swift resolution.

Official Contact & Data Protection Inquiries

For any privacy questions, exercise of GDPR/CCPA rights, app compliance verification, or legal notices:

  • Full Name: Surprise Inefable KOUMBA MISSOUNDOU (Inefable Koumba)
  • Professional Entity: MAZALA-FIRM / Inefable Koumba
  • Location: Brazzaville, Republic of the Congo
  • Direct Legal / DPO Email: [email protected]
  • Response Time Guarantee: All legitimate privacy requests are answered and acknowledged within 48 hours and fulfilled within 30 days maximum.

Developer Transparency Commitment

This legal hub is drafted with legal rigor to satisfy review standards across Apple App Store Connect (Guideline 5.1), Google Play Developer Console, European GDPR, and applicable laws in the Republic of the Congo. For technical or compliance audits, contact Inefable Koumba directly.