Privacy Policy
1. Data Controller
KantoBiz, operated by Waviloid Studio, headquartered in Antananarivo, Madagascar (STAT: 70209 11 2023 0 04896, NIF: 4018072810), is the data controller for your personal data within the meaning of the General Data Protection Regulation (GDPR).
1.1. Contact
For any questions regarding the protection of your personal data, you may contact us at:
- Email: contact@digiwide.io
- Address: IVJ 12 TER EA Ambohimanarina, Antananarivo, Madagascar
1.2. Data Protection Officer
A Data Protection Officer (DPO) is in the process of being appointed. In the meantime, any requests regarding your rights may be sent to contact@digiwide.io.
2. Data Collected
In the context of using our platform, we collect and process the following categories of personal data:
2.1. Identification Data
This data is necessary for the creation and management of your user account.
- Full name, email address
- Date of birth, gender
- Phone number
- Postal address
2.2. Profile Data
This data allows us to personalize your experience on the platform.
- Profile picture and cover photo
- Biography and description
- Links to social networks (Facebook, Instagram, TikTok, X, YouTube)
- Preferred language and currency
2.3. Financial Data
This data is processed in the context of payments and transfers via our platform.
- Banking information (IBAN, SWIFT) — AES-256 encrypted
- Transaction history
- Payment information processed by Stripe (tokenized, never stored on our servers)
2.4. Identity Documents
As part of the certification process, artists may submit identity documents. Original files are temporarily stored in encrypted form. Only the text extracted by OCR is retained after validation.
- National identity card or passport
- Entity documents (Kbis, articles of association, etc.)
- Accepted formats: PDF, PNG, JPEG (max 10 MB, max 2 files)
3. Purposes of Processing
Your personal data is processed for the following purposes:
3.1. Contract Performance
Processing is necessary for the performance of the contract binding you to KantoBiz.
- Creation and management of your user account
- Connecting artists and bookers
- Managing bookings and services
- Processing payments and bank transfers
- Generating and managing service contracts
3.2. Legitimate Interest
Some processing is based on our legitimate interest.
- Improving the platform and user experience
- Fraud prevention and security
- Technical error monitoring (Sentry)
3.3. Legal Obligation
Some processing is required by law.
- Retention of invoices and accounting data (10 years)
- Responding to judicial requests
4. Retention Period
We retain your personal data for the period strictly necessary for the purposes described above.
4.1. Applicable Durations
- Active account: duration of service use
- Inactive account: deletion scheduled after 2 years of inactivity
- Accounting data and invoices: 10 years
- Identity documents: files deleted after validation, OCR text retained
- Read notifications: 30 days
- Server logs: duration to be defined (recommendation: 12 months)
5. Recipients and Sub-processors
Your data may be shared with the following sub-processors, subject to appropriate safeguards:
5.1. List of Sub-processors
- Oracle Cloud (backend hosting — USA)
- Vercel (web hosting — USA)
- Cloudinary (media storage — Ireland)
- Stripe (payments — USA)
- Sentry (error monitoring — USA)
- Mapbox (geocoding — USA)
5.2. International Transfers
Data transfers to third countries (USA, Ireland) are governed by Standard Contractual Clauses (SCCs) and protected by TLS and AES-256 encryption.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal data.
6.1. Technical Measures
- AES-256-CBC encryption with random 16-byte IV
- Password hashing with bcrypt (10 rounds)
- JWT tokens with 7-day expiry and revocation system
- Zlib compression before API response encryption
- PCI DSS compliance via Stripe (card data never stored)
7. Cookies
Our platform uses only technical cookies strictly necessary for the operation of the service. No analytical or advertising cookies are used.
7.1. Cookies Used
- Authentication token (JWT)
- User preferences (language, currency)
- Browsing session
8. Your Rights
In accordance with the GDPR, you have the following rights regarding your personal data:
8.1. List of Rights
You may exercise these rights by contacting us at contact@digiwide.io.
- Right of access: obtain a copy of your data
- Right of rectification: correct inaccurate data
- Right to erasure: request the deletion of your account
- Right to portability: receive your data in a structured format
- Right to object: object to certain processing activities
- Right to restriction: request the suspension of processing
- Right to lodge a complaint with the CNIL (www.cnil.fr)
8.2. Post-Certification Restriction
After your identity certification has been validated, certain data (first name, last name, date of birth, gender) can no longer be modified to ensure consistency with the verified documents. For any modification request, please contact support.
9. Policy Updates
We reserve the right to modify this privacy policy. In the event of a substantial change, you will be notified by email at least 30 days before the changes take effect. The date of the last update is indicated at the top of the document.