LegalGDPR Compliant

Privacy Policy

AtMGA Follow UP, operated by Mi Kandra, we are committed to protecting your personal data and respecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding it.

Last updated:

Data We Collect

We collect information you provide directly to us, as well as data generated automatically when you use our platform.

Information you provide:

  • Account details: name, email address, password (hashed)
  • Company information: company name, industry, address
  • Billing data: payment method (processed securely via papi.mg — we do not store card details)
  • Content you create: products, customers, transactions, messages, social media posts
  • Communications: support tickets, chat messages

Automatically collected data:

  • Usage data: pages visited, features used, session duration
  • Device and browser information
  • IP address and approximate location
  • Cookies and similar tracking technologies (see §6)

How We Use Your Data

We use your personal data for the following purposes:

  • Provide, operate and maintain the MGA Follow UP platform
  • Process payments and manage subscriptions
  • Send transactional emails (invoices, password resets, alerts) via Resend
  • Deliver AI assistant (Degany) features, including LLM-powered analysis
  • Improve and personalise your experience
  • Monitor platform health, security and performance
  • Comply with legal obligations
  • Send service-related communications (no unsolicited marketing without consent)

Data Storage & Security

Your data is stored on servers within secure data centres. We use industry-standard measures to protect your information:

  • All data in transit is encrypted via TLS/HTTPS
  • Passwords are hashed using bcrypt — never stored in plain text
  • Database access is restricted and monitored
  • Redis cache data is encrypted and access-controlled
  • Media files are stored on your self-hosted MinIO instance — they never leave your infrastructure
  • Two-factor authentication (2FA) is available to all users
  • Regular automated backups

While we apply rigorous security measures, no system is completely immune to risk. We encourage you to use a strong unique password and enable 2FA.

Sharing of Data

We donotsell your personal data. We share it only with the following trusted sub-processors, strictly to provide the service:

Sub-processorPurpose
papi.mgPayment processing
ResendTransactional email delivery
Upstash RedisCaching & real-time messaging
Anthropic / OpenAI / GoogleAI assistant (Degany) — prompts are not used to train models

We may also disclose data when required by law or to protect the rights and safety of our users and the public.

Your Rights

Depending on your jurisdiction (including GDPR in the EU/EEA), you have the following rights over your personal data:

  • Right of access — request a copy of your data
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten") — delete your account and associated data
  • Right to data portability — receive your data in a machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to restrict processing — limit how we process your data
  • Right to withdraw consent — for any processing based on consent

To exercise any of these rights, go to Settings → Account → Delete Accountin the platform, or contact us at privacy@mga-followup.com. We will respond within 30 days.

Cookies

We use cookies and similar technologies to operate and improve the platform. Types used:

  • Essential cookies — required for authentication and session management (cannot be disabled)
  • Functional cookies — remember your preferences (language, theme, layout)
  • Analytics cookies — aggregate, anonymised usage data to improve the product (opt-out available)

You can manage cookies in your browser settings. Disabling essential cookies will prevent you from logging in.

Children's Privacy

MGA Follow UP is a business-oriented platform and is not directed at children under the age of 16. We do not knowingly collect personal data from minors. If you believe a minor has provided us with their data, please contact us immediately so we can delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top and, for material changes, notify you by email or via an in-app notification at least 14 days before the change takes effect.

Continued use of the platform after the effective date constitutes acceptance of the revised policy.

Contact us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out:

Company:Mi Kandra

Product:MGA Follow UP.

Email:privacy@mga-followup.com