Privacy Policy
Effective date: 7 July 2026 Last updated: 7 July 2026
1. Who we are (data controller)
Market Access Africa Sàrl (Sàrl), Chemin du Chamoliet 32A, 1226 Thônex, Canton of Geneva, Switzerland, registered under UID CHE-153.426.102 ("Market Access Africa", "MAA", "we") is the controller responsible for personal data processed through shaami.africa, intelligence.shaami.africa, the Shaami Intelligence tool, and The Shaami Regulatory Spotlight newsletter (the "Services").
Privacy contact: regulatory@marketaccess.africa.
This Policy is written to meet the Swiss Federal Act on Data Protection (revFADP, in force 1 September 2023) and, where it applies to you, the EU/UK General Data Protection Regulation (GDPR). We also aim to respect the Protection of Personal Information Act (POPIA, South Africa) and Kenya's Data Protection Act 2019, given our African audience.
2. What personal data we collect
We collect only what we need for the purposes below.
a) Newsletter (The Shaami Regulatory Spotlight). Your email address when you subscribe, plus subscription status. Handled through Mailchimp.
b) Contact / enquiry forms. The details you submit — typically name, email address, organisation, and your message — so we can respond.
c) Shaami Intelligence — sign-in gate. To use the tool you provide your email address (verified by a one-time code) and, optionally, your company and role, and your choice about receiving updates. Stored in our database (chat_users).
d) Assessment inputs. The product profile and questions you enter (e.g. product category, target markets, approvals held, manufacturer location). These are sent to our AI provider to generate your Assessment (see Section 4). Please do not enter more personal data than necessary.
e) Feedback and "share your experience". If you rate an Assessment, leave a comment, or share a registration timeline, we store that input (feedback, community_timelines). If you opt in to be contacted about a shared experience, we also store the name and email you provide for that purpose.
f) Abuse-prevention data. To enforce fair-use limits we store a hashed (pseudonymised) form of your IP address with timestamps (rate_limits). We do not store your raw IP for this purpose.
g) Technical and usage data. Standard information your browser sends and that our hosting/CDN provider logs — such as IP address, device/browser type, pages viewed, and timestamps — used for security, diagnostics and aggregate analytics.
We do not intentionally collect special-category / sensitive personal data, and we ask you not to submit it.
3. Why we use your data and our legal basis
| Purpose | revFADP / GDPR legal basis |
|---|---|
| Send the newsletter you subscribed to | Consent (GDPR Art. 6(1)(a)); withdraw any time via the unsubscribe link |
| Respond to your enquiries | Contract / pre-contract and our legitimate interest in responding (Art. 6(1)(b)/(f)) |
| Provide Shaami Intelligence and generate Assessments | Contract (providing the service you request) and legitimate interest (Art. 6(1)(b)/(f)) |
| Verify your email (one-time code) | Necessary to provide access; legitimate interest / contract |
| Improve accuracy from feedback and shared experiences | Consent (where you opt in) and legitimate interest in improving the Services |
| Contact you about a shared experience | Consent (opt-in only) |
| Rate limiting, security, fraud/abuse prevention | Legitimate interest in protecting the Services |
| Aggregate analytics and diagnostics | Legitimate interest |
| Comply with legal obligations | Legal obligation |
Where we rely on legitimate interests, we have weighed them against your rights; you may object (Section 8). For processing based on consent, you may withdraw it at any time without affecting prior processing.
4. AI processing of your inputs
When you generate an Assessment, the product profile and question you submit are transmitted to our AI provider, Anthropic (Claude), which processes them to produce the response. We instruct the model to answer only from our curated sources. Because this input leaves our environment for processing, do not enter personal data about patients or other third parties, or confidential information, unless you have a lawful basis and it is necessary. Anthropic processes the input to return the Assessment and under its terms does not use business/commercial API inputs to train its models. See Anthropic's privacy terms for details.
5. Who we share data with (processors and third parties)
We do not sell your personal data. We share it with service providers ("processors") who act on our instructions under data-processing agreements, and only as needed:
| Provider | Role | Data involved | Location |
|---|---|---|---|
| Supabase | Database + email one-time-code authentication | Email gate details, feedback, shared experiences, hashed IPs | European Union (EU) |
| Resend | Sends the one-time verification code email | Email address | USA |
| Mailchimp (Intuit) | Newsletter delivery | Newsletter email | USA |
| Vercel | Website hosting & content delivery | Technical/log data, IP | USA / global edge |
| Anthropic (Claude) | AI that generates Assessments | Your assessment inputs | USA |
| Cloudflare (cdnjs) | Serves one library used only in the admin tool | IP address | USA / global |
We may also disclose data where required by law, to protect our rights or safety, or in connection with a corporate transaction (with continued protection).
6. International transfers
We are based in Switzerland; several processors are in the United States or operate globally. Where we transfer personal data outside Switzerland/the EEA to a country without an equivalent level of protection, we rely on appropriate safeguards, such as the European Commission / Swiss FDPIC Standard Contractual Clauses, and/or the provider's certification under the EU–US and Swiss–US Data Privacy Framework, as applicable. You may request a copy of the relevant safeguards using the contact in Section 11.
7. How long we keep data
We keep personal data only as long as necessary for the purposes above or as required by law:
- Newsletter: until you unsubscribe or ask us to delete it.
- Enquiries: for as long as needed to handle your request and a reasonable period afterwards.
- Sign-in / tool accounts and feedback: for the duration of the pilot and a reasonable period thereafter, then deleted or anonymised.
- Hashed IP / rate-limit records: purged after 30 days.
- Aggregate/anonymised data: may be kept indefinitely as it no longer identifies you.
8. Your rights
Subject to applicable law, you have the right to: access your personal data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing; withdraw consent; data portability; and to lodge a complaint with a supervisory authority. Under the revFADP you have, in particular, rights of information and access.
To exercise any right, contact us (Section 11). We respond within the timeframes required by law and free of charge, save for manifestly unfounded or excessive requests. You can unsubscribe from the newsletter at any time via the link in every email.
Supervisory authorities: the Swiss Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch; if the GDPR applies to you, your local EU/EEA data-protection authority; in South Africa the Information Regulator; in Kenya the Office of the Data Protection Commissioner.
9. Cookies and local storage
Our sites do not use advertising or cross-site tracking cookies. We use browser local/session storage for the site to function — for example, to remember your sign-in session, cache a recent Assessment on your device, and store your interface preferences. This information stays in your browser and is not used to track you across other websites. You can clear it via your browser settings, though some features may then not work.
10. Security, and children
We take reasonable technical and organisational measures to protect personal data (including hashing IPs used for rate limiting, encrypted transport, and access controls). No method of transmission or storage is completely secure. The Services are intended for professional use and are not directed to children under 16; we do not knowingly collect their data.
11. Contact and changes
To exercise your rights or ask about this Policy: regulatory@marketaccess.africa, Market Access Africa Sàrl, Chemin du Chamoliet 32A, 1226 Thônex, Canton of Geneva, Switzerland.
We may update this Policy; the "Last updated" date reflects the current version, and we will flag material changes on this page.