Privacy Policy & Cookie Management
Version 1.0 β Effective date: June 17, 2026
Mify β Event Invitation Platform
Showcase: event.mifyyy.com | Application: app.mifyyy.com | Documentation: docs.mifyyy.com
Contact: privacy@mifyyy.com
This document is the official privacy policy of Mify. It describes in a complete and transparent manner the collection, processing, retention and protection of your personal data, as well as the use of cookies on our showcase site, documentation site and application.
1. Data Controller Information
In accordance with GDPR principles voluntarily adopted by Mify as a reference standard, the data controller is:
| Name | Mify |
| Legal status | Independent SaaS |
| Email address | privacy@mifyyy.com |
| Showcase site | event.mifyyy.com |
| Application | app.mifyyy.com |
| Documentation | docs.mifyyy.com |
| Headquarters / Territory | Madagascar |
| Data Protection Officer | Mify internal officer |
Mify is committed to processing your personal data in accordance with the principles of lawfulness, fairness, transparency, minimization, accuracy, storage limitation, integrity and confidentiality.
2. Definitions and Terminology
Personal Data
Any information relating to an identified or identifiable natural person (name, email address, IP address, location data, etc.).
Processing
Any operation performed on personal data: collection, recording, organization, retention, adaptation, use, communication or destruction.
Controller
The legal entity that determines the purposes and means of processing.
Sub-processor
Any entity that processes personal data on behalf of the controller.
Consent
Any freely given, specific, informed and unambiguous expression of will by which the data subject accepts the processing of their data.
Cookie
A small text file placed on the user's device during browsing, used to store session, preference or tracking information.
Organizer User
Person who has created a Mify account to organize an event (wedding, baptism, birthday).
Guest
Natural person accessing Mify public pages via an invitation link or QR code.
3. Scope of Application
This policy applies to all data processing carried out in the context of:
- Browsing the showcase site event.mifyyy.com
- Browsing the documentation site docs.mifyyy.com
- Accessing and using the Mify application via app.mifyyy.com
- Public invitation pages (invitation links, QR codes, RSVP)
- Public event modules (gallery, guestbook, program, menu, dress code, location, games)
- Email communications sent by Mify
- Contact and support forms
This policy does not apply to third-party websites to which Mify may redirect. Mify is not responsible for the privacy practices of these third parties.
4. Personal Data Collected
4.1 β Organizer Users
4.1.1 Identification & Account Data
| Data | Source | Required? |
|---|---|---|
| First and last name | Direct input / Google OAuth | Yes |
| Email address | Direct input / Google OAuth | Yes |
| Profile photo | Google OAuth (optional) | No |
| Unique identifier (UUID) | Auto-generated | Yes |
| Account creation date | Automatic | Yes |
| JWT authentication tokens | Auto-generated | Yes |
4.1.2 Event Data
- Event name (wedding, baptism or birthday)
- Event type, date(s), venue(s) and optional GPS coordinates
- Ceremony program, menu(s), dress code
- Couple / family story (optional text and media)
- RSVP deadline
4.1.3 Guest & Family Management Data
| Data | Description |
|---|---|
| Family / group name | Guest group name |
| Member names | First and last name of each guest |
| Group email address | Optional |
| Phone number | Optional |
| Assignment QR code | Unpredictable identifier generated by Mify |
| RSVP response | Present / Absent / Pending |
| Assigned table | Table number or name in seating plan |
4.1.4 Financial & Payment Data
4.1.5 Google Drive Data (Photo Gallery)
When the organizer connects their Google Drive account to activate the photo gallery:
- OAuth 2.0 tokens (access_token and refresh_token): encrypted at rest
- Identifiers of selected Google Drive folders
- File metadata (names, types, modification dates)
The photos themselves never transit through Mify servers: guests view them directly from Google Drive.
4.2 β Data Collected from Guests
| Data | Context | Required? |
|---|---|---|
| RSVP response (present/absent) | RSVP form on public page | No |
| Number of confirmed attendees | RSVP form | No |
| Member names (open mode) | Guest input | No |
| Guestbook messages | Public form | No |
| Votes / Game participation | Interactive event games | No |
| IP address | Automatic during browsing | Technical |
| User-Agent (browser/OS) | Automatic during browsing | Technical |
Public pages do not require account creation. Guest data is never used for commercial or advertising purposes.
4.3 β Technical Data Collected Automatically
| Technical data | Usage | Duration |
|---|---|---|
| IP address | Security, anti-abuse | 90 jours / days |
| User-Agent | Compatibility, debugging | 90 jours / days |
| Session cookies (JWT HTTP-only) | Secure authentication | Session + 30 days |
| HTTP access logs | Monitoring, debugging | 90 jours / days |
| Application error logs | Technical debugging | 30 jours / days |
| Performance metrics | Platform optimization | Aggregated, 1 year |
5. Purposes and Legal Bases for Processing
| Purpose | Legal basis | GDPR Ref. |
|---|---|---|
| Account creation and management | Contract performance | Art. 6(1)(b) |
| Provision of Mify service (invitations, RSVP, galleryβ¦) | Contract performance | Art. 6(1)(b) |
| Generation and management of invitation QR codes | Contract performance | Art. 6(1)(b) |
| Family and guest management | Contract performance / Legitimate interest | Art. 6(1)(b)(f) |
| Processing Γ la carte payments | Contract performance | Art. 6(1)(b) |
| Sending transactional emails | Contract performance | Art. 6(1)(b) |
| Secure authentication via JWT cookies | Legitimate interest (security) | Art. 6(1)(f) |
| Fraud prevention and platform security | Legitimate interest | Art. 6(1)(f) |
| Service improvement and technical debugging | Legitimate interest | Art. 6(1)(f) |
| Compliance with legal and accounting obligations | Legal obligation | Art. 6(1)(c) |
| Analytics cookies on event.mifyyy.com and docs.mifyyy.com (with consent) | Consent | Art. 6(1)(a) |
When Mify relies on legitimate interest as a legal basis, a balancing test has been carried out between Mify's interests and the fundamental rights of the data subjects.
6. Data Retention Periods
| Category | Duration | Justification |
|---|---|---|
| Active account data | Activity period + 3 years | Contractual relationship |
| Inactive account data (>2 years) | Deleted after 30-day notice | Data minimization |
| Event data | Account period + 2 years post-closure | Contract + evidence |
| Guest data (RSVP, messages) | Event duration + 1 year | Service rendered |
| Payment data | 10 years | Accounting obligation |
| Access logs | 90 jours / days | Security / debugging |
| Error logs | 30 jours / days | Technical maintenance |
| Google Drive OAuth tokens | Until revocation | Service operation |
| JWT session cookies | Session + 30 days | Authentication |
| Analytics cookies | 13 months maximum | GDPR standard |
| Media (Cloudflare R2, Cloudinary) | Until deletion by organizer | Service rendered |
Upon expiry of the applicable period, data is permanently deleted or irreversibly anonymized. Backups are purged within an additional 30 days. Deletion requests are processed within a maximum of 30 business days.
7. Data Sharing and Transfers
| Recipient | Shared data | Justification |
|---|---|---|
| Guests via public page | Event details, program, menu, dress code | Invitation service |
| Organizer | RSVP responses, guestbook messages, statistics | Event management |
| Technical sub-processors | Minimum necessary data | Service execution |
| Competent authorities | On legal request only | Legal obligation |
8. Sub-processors and Third-Party Providers
Mify relies on carefully selected technical providers to operate the platform. Each is bound by a data processing agreement (DPA) compliant with GDPR.
| Category | Provider | Location | Guarantees |
|---|---|---|---|
| Hosting & infrastructure | Secure cloud infrastructure | European Union | DPA + CCT |
| Media storage | Cloudflare R2 | European Union | DPA Cloudflare |
| Authentication | Google OAuth 2.0 | Global | DPA Google |
| Photo gallery | Google Drive API | Global | DPA Google |
| Transactional emails | Brevo | France (EU) | DPA Brevo |
| Music catalog | Jamendo | Luxembourg (EU) | CGU Jamendo |
| Media (read access) | Cloudinary | UE / US | DPA + CCT |
None of these providers are authorized to use your data for purposes other than those strictly necessary for service execution. For the full list, contact privacy@mifyyy.com.
9. Cookie Management Policy
9.1 β Scope
- event.mifyyy.com β showcase site: navigation, functional and analytics cookies
- docs.mifyyy.com β documentation site: technical navigation cookies only
The Mify application (app.mifyyy.com) uses technical authentication mechanisms (JWT tokens) that are not subject to cookie consent as they are strictly necessary for service operation.
9.2 β event.mifyyy.com Cookies
π’ Strictly necessary cookies (exempt from consent)
| Cookie name | Duration | Purpose |
|---|---|---|
mify_lang | 1 year | Language preference (FR / MG / EN) |
mify_cookie_consent | 12 months | Storing your cookie consent choice |
π΅ Functional cookies (consent required)
| Cookie name | Duration | Purpose |
|---|---|---|
mify_theme | Persistent | Site visual theme preference |
π Analytics cookies (consent required)
| Tool | Purpose | Max duration | Sharing |
|---|---|---|---|
| Anonymized internal metrics | Page views, visitor origin, performance | 13 months | None |
9.3 β docs.mifyyy.com Cookies
The documentation site collects only the technical navigation data strictly necessary for its operation. No additional advertising, analytics or functional cookies are placed.
9.4 β Managing Your Consent
On your first visit to event.mifyyy.com, a cookie management banner is presented to you. You can accept all cookies, reject non-essential cookies, or customize your preferences by category. Your choice is stored for 12 months and can be changed at any time via the 'Manage my cookies' link in the footer.
| Browser | Cookie settings access |
|---|---|
| Google Chrome | Settings β Privacy and security β Cookies |
| Mozilla Firefox | Settings β Privacy and Security β Cookies |
| Microsoft Edge | Settings β Cookies and site permissions |
| Safari (macOS) | Preferences β Privacy |
| Safari (iOS) | Settings β Safari β Advanced |
10. Rights of Data Subjects
In accordance with GDPR principles adopted by Mify, you have the following rights:
Right of access
Obtain confirmation of processing and receive a copy of your data
Deadline: 1 monthRight to rectification
Correct any inaccurate or incomplete data
Deadline: 1 monthRight to erasure
Request deletion of your data
Deadline: 1 monthRight to restriction
Freeze processing in certain cases
Deadline: 1 monthRight to portability
Receive your data in a structured, readable format
Deadline: 1 monthRight to object
Object to processing based on legitimate interest
Deadline: 1 monthWithdrawal of consent
Withdraw your consent at any time
Deadline: ImmediateAutomated decision
Mify does not use profiling or automated decision-making
Deadline: N/ATo exercise your rights:
Send your request to privacy@mifyyy.com indicating your identity and the right you wish to exercise. Mify commits to responding within one month, extendable by two months for complex cases.
11. Data Security
Mify implements appropriate technical and organizational measures to protect your data against unauthorized access, disclosure, alteration or destruction.
| Measure | Description |
|---|---|
| Encryption in transit | TLS 1.3 on all communications |
| Encryption at rest | Database, backups and OAuth tokens encrypted |
| HTTP-only + Secure + SameSite=Strict cookies | JWT tokens inaccessible from JavaScript |
| Unpredictable QR codes | Cryptographically generated |
| Data isolation | Event data is never accessible from another event |
| Server-side validation | All user inputs are validated independently of the frontend |
| Encrypted backups | Performed regularly |
Organizational measures
- Access to production data restricted to the minimum necessary
- Separation of development, test and production environments
- No real personal data in development environment
- Sensitive environment variables never integrated into source code
In the event of a breach likely to pose a risk to your rights, Mify commits to notifying the competent supervisory authority as soon as possible and informing you directly if the risk is high.
12. Data of Minors
The Mify platform is intended for adults (18 and over) for creating organizer accounts. In the context of family events, information relating to children may be entered by the adult organizer (first name in the guest list, for example).
This data is processed with the greatest care: it is minimal, used only within the strict framework of event organization, and is not subject to any profiling or commercial processing. The organizer is responsible for ensuring the lawfulness of collecting data on minors.
13. Changes to This Policy
Mify reserves the right to modify this policy to comply with new legal obligations, reflect service evolution, or incorporate user feedback.
- In case of substantial changes affecting your rights, an email will be sent to the address associated with your account at least 30 days before the changes take effect.
- An information banner will be displayed on the platform.
- Minor changes take effect immediately without prior notice.
- Continued use of the platform after notification constitutes acceptance of the new policy.
14. Complaints and Contact
| Channel | |
| Address | privacy@mifyyy.com |
| Recommended subject | [DONNΓES] β Objet de la demande |
| Response time | 5 business days (acknowledgment) / 1 month (processing) |
| Accepted language(s) | French, Malagasy, English |
If you disagree with Mify's response:
- Restate your request specifying the reason for disagreement at privacy@mifyyy.com
- Contact the competent supervisory authority in your country of residence
- Exercise a judicial remedy before the competent courts
Supervisory Authority
CMIL β Malagasy Commission for Information Technology and Freedoms
Personal data protection authority β Madagascar
Applicable legal framework: Law nΒ°2014-038 on the protection of personal data, enacted on January 9, 2015.
15. Final Provisions
This policy is governed by Law nΒ°2014-038 on the protection of personal data in Madagascar, enacted on January 9, 2015. Mify also applies, as good practice and international reference standard, the principles of Regulation (EU) 2016/679 (GDPR).
- In case of dispute, the parties will endeavor to find an amicable solution. Failing that, the competent courts of Madagascar will be seized.
- This policy, combined with Mify's Terms of Service, constitutes the entirety of Mify's commitments regarding personal data protection.
- In case of conflict between two versions, the most recent version prevails. If a provision is declared void, the others remain fully in force.
- The French version is authoritative.