Docs Mify Event
Open the app

Privacy Policy

Privacy Policy & Cookie Management

Version 1.0 β€” Effective date: June 17, 2026

Mify β€” Event Invitation Platform

Showcase: event.mifyyy.com | Application: app.mifyyy.com | Documentation: docs.mifyyy.com

Contact: privacy@mifyyy.com

This document is the official privacy policy of Mify. It describes in a complete and transparent manner the collection, processing, retention and protection of your personal data, as well as the use of cookies on our showcase site, documentation site and application.

1. Data Controller Information

In accordance with GDPR principles voluntarily adopted by Mify as a reference standard, the data controller is:

NameMify
Legal statusIndependent SaaS
Email addressprivacy@mifyyy.com
Showcase siteevent.mifyyy.com
Applicationapp.mifyyy.com
Documentationdocs.mifyyy.com
Headquarters / TerritoryMadagascar
Data Protection OfficerMify internal officer

Mify is committed to processing your personal data in accordance with the principles of lawfulness, fairness, transparency, minimization, accuracy, storage limitation, integrity and confidentiality.

2. Definitions and Terminology

Personal Data

Any information relating to an identified or identifiable natural person (name, email address, IP address, location data, etc.).

Processing

Any operation performed on personal data: collection, recording, organization, retention, adaptation, use, communication or destruction.

Controller

The legal entity that determines the purposes and means of processing.

Sub-processor

Any entity that processes personal data on behalf of the controller.

Consent

Any freely given, specific, informed and unambiguous expression of will by which the data subject accepts the processing of their data.

Cookie

A small text file placed on the user's device during browsing, used to store session, preference or tracking information.

Organizer User

Person who has created a Mify account to organize an event (wedding, baptism, birthday).

Guest

Natural person accessing Mify public pages via an invitation link or QR code.

3. Scope of Application

This policy applies to all data processing carried out in the context of:

  • Browsing the showcase site event.mifyyy.com
  • Browsing the documentation site docs.mifyyy.com
  • Accessing and using the Mify application via app.mifyyy.com
  • Public invitation pages (invitation links, QR codes, RSVP)
  • Public event modules (gallery, guestbook, program, menu, dress code, location, games)
  • Email communications sent by Mify
  • Contact and support forms

This policy does not apply to third-party websites to which Mify may redirect. Mify is not responsible for the privacy practices of these third parties.

4. Personal Data Collected

4.1 β€” Organizer Users

4.1.1 Identification & Account Data

DataSourceRequired?
First and last nameDirect input / Google OAuthYes
Email addressDirect input / Google OAuthYes
Profile photoGoogle OAuth (optional)No
Unique identifier (UUID)Auto-generatedYes
Account creation dateAutomaticYes
JWT authentication tokensAuto-generatedYes

4.1.2 Event Data

  • Event name (wedding, baptism or birthday)
  • Event type, date(s), venue(s) and optional GPS coordinates
  • Ceremony program, menu(s), dress code
  • Couple / family story (optional text and media)
  • RSVP deadline

4.1.3 Guest & Family Management Data

DataDescription
Family / group nameGuest group name
Member namesFirst and last name of each guest
Group email addressOptional
Phone numberOptional
Assignment QR codeUnpredictable identifier generated by Mify
RSVP responsePresent / Absent / Pending
Assigned tableTable number or name in seating plan

4.1.4 Financial & Payment Data

πŸ”’

Mify never collects bank card numbers. Payments are processed via local mobile operators (Mvola, Orange Money) or bank transfer. Mify only receives transaction references and statuses.

4.1.5 Google Drive Data (Photo Gallery)

When the organizer connects their Google Drive account to activate the photo gallery:

  • OAuth 2.0 tokens (access_token and refresh_token): encrypted at rest
  • Identifiers of selected Google Drive folders
  • File metadata (names, types, modification dates)

The photos themselves never transit through Mify servers: guests view them directly from Google Drive.

4.2 β€” Data Collected from Guests

DataContextRequired?
RSVP response (present/absent)RSVP form on public pageNo
Number of confirmed attendeesRSVP formNo
Member names (open mode)Guest inputNo
Guestbook messagesPublic formNo
Votes / Game participationInteractive event gamesNo
IP addressAutomatic during browsingTechnical
User-Agent (browser/OS)Automatic during browsingTechnical

Public pages do not require account creation. Guest data is never used for commercial or advertising purposes.

4.3 β€” Technical Data Collected Automatically

Technical dataUsageDuration
IP addressSecurity, anti-abuse90 jours / days
User-AgentCompatibility, debugging90 jours / days
Session cookies (JWT HTTP-only)Secure authenticationSession + 30 days
HTTP access logsMonitoring, debugging90 jours / days
Application error logsTechnical debugging30 jours / days
Performance metricsPlatform optimizationAggregated, 1 year

5. Purposes and Legal Bases for Processing

PurposeLegal basisGDPR Ref.
Account creation and managementContract performanceArt. 6(1)(b)
Provision of Mify service (invitations, RSVP, gallery…)Contract performanceArt. 6(1)(b)
Generation and management of invitation QR codesContract performanceArt. 6(1)(b)
Family and guest managementContract performance / Legitimate interestArt. 6(1)(b)(f)
Processing Γ  la carte paymentsContract performanceArt. 6(1)(b)
Sending transactional emailsContract performanceArt. 6(1)(b)
Secure authentication via JWT cookiesLegitimate interest (security)Art. 6(1)(f)
Fraud prevention and platform securityLegitimate interestArt. 6(1)(f)
Service improvement and technical debuggingLegitimate interestArt. 6(1)(f)
Compliance with legal and accounting obligationsLegal obligationArt. 6(1)(c)
Analytics cookies on event.mifyyy.com and docs.mifyyy.com (with consent)ConsentArt. 6(1)(a)

When Mify relies on legitimate interest as a legal basis, a balancing test has been carried out between Mify's interests and the fundamental rights of the data subjects.

6. Data Retention Periods

CategoryDurationJustification
Active account dataActivity period + 3 yearsContractual relationship
Inactive account data (>2 years)Deleted after 30-day noticeData minimization
Event dataAccount period + 2 years post-closureContract + evidence
Guest data (RSVP, messages)Event duration + 1 yearService rendered
Payment data10 yearsAccounting obligation
Access logs90 jours / daysSecurity / debugging
Error logs30 jours / daysTechnical maintenance
Google Drive OAuth tokensUntil revocationService operation
JWT session cookiesSession + 30 daysAuthentication
Analytics cookies13 months maximumGDPR standard
Media (Cloudflare R2, Cloudinary)Until deletion by organizerService rendered

Upon expiry of the applicable period, data is permanently deleted or irreversibly anonymized. Backups are purged within an additional 30 days. Deletion requests are processed within a maximum of 30 business days.

7. Data Sharing and Transfers

βœ…

Mify never sells, rents or commercializes your personal data to third parties.

RecipientShared dataJustification
Guests via public pageEvent details, program, menu, dress codeInvitation service
OrganizerRSVP responses, guestbook messages, statisticsEvent management
Technical sub-processorsMinimum necessary dataService execution
Competent authoritiesOn legal request onlyLegal obligation

8. Sub-processors and Third-Party Providers

Mify relies on carefully selected technical providers to operate the platform. Each is bound by a data processing agreement (DPA) compliant with GDPR.

CategoryProviderLocationGuarantees
Hosting & infrastructureSecure cloud infrastructureEuropean UnionDPA + CCT
Media storageCloudflare R2European UnionDPA Cloudflare
AuthenticationGoogle OAuth 2.0GlobalDPA Google
Photo galleryGoogle Drive APIGlobalDPA Google
Transactional emailsBrevoFrance (EU)DPA Brevo
Music catalogJamendoLuxembourg (EU)CGU Jamendo
Media (read access)CloudinaryUE / USDPA + CCT

None of these providers are authorized to use your data for purposes other than those strictly necessary for service execution. For the full list, contact privacy@mifyyy.com.

9. Cookie Management Policy

9.1 β€” Scope

  • event.mifyyy.com β€” showcase site: navigation, functional and analytics cookies
  • docs.mifyyy.com β€” documentation site: technical navigation cookies only

The Mify application (app.mifyyy.com) uses technical authentication mechanisms (JWT tokens) that are not subject to cookie consent as they are strictly necessary for service operation.

9.2 β€” event.mifyyy.com Cookies

🟒 Strictly necessary cookies (exempt from consent)

Cookie nameDurationPurpose
mify_lang1 yearLanguage preference (FR / MG / EN)
mify_cookie_consent12 monthsStoring your cookie consent choice

πŸ”΅ Functional cookies (consent required)

Cookie nameDurationPurpose
mify_themePersistentSite visual theme preference

πŸ“Š Analytics cookies (consent required)

ToolPurposeMax durationSharing
Anonymized internal metricsPage views, visitor origin, performance13 monthsNone
🚫

Mify does not use Google Analytics, Facebook Pixel, or any third-party advertising tracking tool on event.mifyyy.com.

9.3 β€” docs.mifyyy.com Cookies

The documentation site collects only the technical navigation data strictly necessary for its operation. No additional advertising, analytics or functional cookies are placed.

9.4 β€” Managing Your Consent

On your first visit to event.mifyyy.com, a cookie management banner is presented to you. You can accept all cookies, reject non-essential cookies, or customize your preferences by category. Your choice is stored for 12 months and can be changed at any time via the 'Manage my cookies' link in the footer.

BrowserCookie settings access
Google ChromeSettings β†’ Privacy and security β†’ Cookies
Mozilla FirefoxSettings β†’ Privacy and Security β†’ Cookies
Microsoft EdgeSettings β†’ Cookies and site permissions
Safari (macOS)Preferences β†’ Privacy
Safari (iOS)Settings β†’ Safari β†’ Advanced

10. Rights of Data Subjects

In accordance with GDPR principles adopted by Mify, you have the following rights:

Right of access

Obtain confirmation of processing and receive a copy of your data

Deadline: 1 month

Right to rectification

Correct any inaccurate or incomplete data

Deadline: 1 month

Right to erasure

Request deletion of your data

Deadline: 1 month

Right to restriction

Freeze processing in certain cases

Deadline: 1 month

Right to portability

Receive your data in a structured, readable format

Deadline: 1 month

Right to object

Object to processing based on legitimate interest

Deadline: 1 month

Withdrawal of consent

Withdraw your consent at any time

Deadline: Immediate

Automated decision

Mify does not use profiling or automated decision-making

Deadline: N/A

To exercise your rights:

Send your request to privacy@mifyyy.com indicating your identity and the right you wish to exercise. Mify commits to responding within one month, extendable by two months for complex cases.

11. Data Security

Mify implements appropriate technical and organizational measures to protect your data against unauthorized access, disclosure, alteration or destruction.

MeasureDescription
Encryption in transitTLS 1.3 on all communications
Encryption at restDatabase, backups and OAuth tokens encrypted
HTTP-only + Secure + SameSite=Strict cookiesJWT tokens inaccessible from JavaScript
Unpredictable QR codesCryptographically generated
Data isolationEvent data is never accessible from another event
Server-side validationAll user inputs are validated independently of the frontend
Encrypted backupsPerformed regularly

Organizational measures

  • Access to production data restricted to the minimum necessary
  • Separation of development, test and production environments
  • No real personal data in development environment
  • Sensitive environment variables never integrated into source code

In the event of a breach likely to pose a risk to your rights, Mify commits to notifying the competent supervisory authority as soon as possible and informing you directly if the risk is high.

12. Data of Minors

The Mify platform is intended for adults (18 and over) for creating organizer accounts. In the context of family events, information relating to children may be entered by the adult organizer (first name in the guest list, for example).

This data is processed with the greatest care: it is minimal, used only within the strict framework of event organization, and is not subject to any profiling or commercial processing. The organizer is responsible for ensuring the lawfulness of collecting data on minors.

13. Changes to This Policy

Mify reserves the right to modify this policy to comply with new legal obligations, reflect service evolution, or incorporate user feedback.

  • In case of substantial changes affecting your rights, an email will be sent to the address associated with your account at least 30 days before the changes take effect.
  • An information banner will be displayed on the platform.
  • Minor changes take effect immediately without prior notice.
  • Continued use of the platform after notification constitutes acceptance of the new policy.

14. Complaints and Contact

ChannelEmail
Addressprivacy@mifyyy.com
Recommended subject[DONNÉES] — Objet de la demande
Response time5 business days (acknowledgment) / 1 month (processing)
Accepted language(s)French, Malagasy, English

If you disagree with Mify's response:

  1. Restate your request specifying the reason for disagreement at privacy@mifyyy.com
  2. Contact the competent supervisory authority in your country of residence
  3. Exercise a judicial remedy before the competent courts

Supervisory Authority

CMIL β€” Malagasy Commission for Information Technology and Freedoms

Personal data protection authority β€” Madagascar

Applicable legal framework: Law nΒ°2014-038 on the protection of personal data, enacted on January 9, 2015.

15. Final Provisions

This policy is governed by Law nΒ°2014-038 on the protection of personal data in Madagascar, enacted on January 9, 2015. Mify also applies, as good practice and international reference standard, the principles of Regulation (EU) 2016/679 (GDPR).

  • In case of dispute, the parties will endeavor to find an amicable solution. Failing that, the competent courts of Madagascar will be seized.
  • This policy, combined with Mify's Terms of Service, constitutes the entirety of Mify's commitments regarding personal data protection.
  • In case of conflict between two versions, the most recent version prevails. If a provision is declared void, the others remain fully in force.
  • The French version is authoritative.