Privacy Policy
Last updated August 18, 2026
What personal data Fursa collects, why, how we protect it, and the choices you have.
1. Who we are
Dinovix Ltd operates Fursa and is the data controller responsible for the personal data described in this policy. For any privacy matter you can reach us at privacy@fursa.space.
2. Data we collect
We collect the following categories of personal data:
- Account data — your email address, and, if you sign in with Google, the name and profile information Google shares with us. Passwords are handled by Firebase Authentication and are never visible to us.
- Eligibility inputs — the answers you provide about your background, education, work, language and finances so that we can assess routes and produce a score. You choose what to enter.
- Usage and device data — basic technical information such as your approximate region, browser type and interactions, used to operate and improve the service.
- Payment data — where you buy a paid term, transaction details processed by Chariow, together with the name and phone number you give at checkout. We receive confirmation of payment; we do not receive or store your full card number or mobile-money PIN.
3. How we use your data
We use personal data to:
- authenticate you and keep your account secure;
- assess eligibility, generate your score, cost estimate and checklist;
- operate, maintain, secure and improve the service;
- process payments and manage subscriptions;
- communicate with you about your account and important changes;
- comply with legal obligations and prevent fraud or abuse.
4. Our legal basis
We process your data where it is necessary to provide the service you have requested (performance of a contract), where you have given consent (which you may withdraw), where we have a legitimate interest in operating and securing Fursa, and where we must to comply with the law. Our handling of personal data is aligned with the applicable data-protection framework of the Republic of Cameroon, including Law No. 2010/012 of 21 December 2010 on cybersecurity and cybercriminality, and with recognised international standards.
5. Cookies
We use a small number of strictly necessary cookies to sign you in and remember your language preference. We do not use advertising cookies. Full detail is in our Cookie Policy.
6. Who we share data with
We do not sell your personal data. We share it only with service providers who process it on our behalf under contract, namely:
- Google Firebase — authentication, database (Cloud Firestore) and hosting infrastructure;
- Chariow and Korapay — payment processing for the transaction you make;
- Sentry — error monitoring, so we can find and fix faults in the service. Sentry may receive technical details of the error and, where relevant to diagnosing it, the request that triggered it;
- Resend — delivery of account and transactional email (sign-in links, receipts, reminders you have not turned off).
- Vercel Analytics — aggregated page-view and performance counts. It does not use cookies and does not identify you individually.
- Google Analytics (GA4) — aggregated audience and page-view measurement, so we can see which parts of the service people actually use. It sets cookies (see the Cookie Policy) and receives your IP address, which Google truncates before storage; we do not send it your name, email or profile answers, and we do not use it for advertising. It is not loaded on the staff portal.
We may also disclose data where required by law, to enforce our terms, or to protect the rights and safety of our users.
7. International transfers
Our providers may process data on servers located outside your country. Sentry, for example, processes data in Germany; Google Firebase operates infrastructure across several regions, including the European Union. Where data is transferred internationally, we rely on providers who are themselves contractually bound — under their own data processing agreements with us — to Standard Contractual Clauses or an equivalent safeguard recognised under the GDPR and UK GDPR.
8. How long we keep it
We keep personal data only as long as needed for the purposes above. While your account is active, that means your profile, eligibility inputs and workspace data. If you delete your account — yourself, from Settings, or by asking us to — we erase your personal data within 30 days, other than what we must keep for longer to meet a legal, accounting or security obligation. Payment and transaction records in particular are kept for longer, as most tax and accounting law requires of a business, even after the account that made the payment is gone.
9. Security
Access is protected by authentication and enforced by database security rules that scope every record to its owner. Sessions use an httpOnly cookie that page scripts cannot read. Traffic to the service is protected by standard web security headers, including a strict content security policy. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.
10. Your rights
You have rights over your personal data, including access, correction, deletion, restriction, objection and portability, and the right to withdraw consent. You can export or delete your own account data at any time from Settings, without asking us — see our Data Protection & Your Rights page for what each right means and how to exercise it, including for anything the self-service tools do not cover.
11. Children
Fursa is not directed at children and is intended for users aged 18 and over. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. We will change the date at the top and, for material changes, provide a more prominent notice.
13. Contact
For any question about your privacy, or to exercise a right, contact privacy@fursa.space.