Last updated 18 February 2026
Data protection and GDPR compliance
Personal data & processing:
Legal obligations and GDPR compliance:
Security & processors:
Transfers outside the EU:
Monarck NEO Ltd commitments:
Personal data & processing
What personal data do you collect on KOVALLI?
We only collect the data strictly necessary for the service to operate: surname, first name, email address, login credentials, billing data, and the operational data entered through the platform. No sensitive data within the meaning of the GDPR is collected without explicit consent.
For what purposes do you process my data?
The data is used solely to:
-
Provide access to the KOVALLI platform,
-
Manage user accounts,
-
Provide customer support,
-
Ensure the security of the service,
-
Meet our legal obligations.
Where is the data stored?
The data is hosted in secure data centres in Mauritius. Appropriate safeguards are in place to ensure a level of protection equivalent to that required by the GDPR (standard contractual clauses, reinforced technical measures, etc.).
Who has access to my data?
Only authorised staff of Monarck NEO Ltd and, where applicable, processors bound by GDPR-compliant contractual clauses may access your data, in strict compliance with the data minimisation principle.
Legal obligations and GDPR compliance
Are you GDPR compliant?
Yes. Monarck NEO Ltd complies with all GDPR principles, in particular:
-
Privacy by Design & by Default,
-
A documented record of processing activities,
-
Data protection impact assessments (DPIA) for high-risk processing,
-
Strict management of retention periods,
-
An appointed DPO,
-
Breach notification within the legal deadlines.
Do you have a DPO?
Yes. A Data Protection Officer (DPO) has been appointed at Monarck NEO Ltd to ensure compliance and to respond to all requests relating to the rights of data subjects.
What happens in the event of a data breach?
We have a breach management procedure in place. In the event of a leak or unauthorised access, the affected users and the CNIL (or any other competent authority) will be notified within 72 hours.
Your rights
What are my rights over my data?
Under the GDPR, you have the following rights:
-
Access,
-
Rectification,
-
Erasure (the “right to be forgotten”),
-
Restriction,
-
Objection,
-
Portability.
How do I exercise my rights?
You can send your request to our DPO at dpo@kovalli.net or through the interface provided in your user account. You will receive a response within a maximum of 30 days.
Security & processors
How do you ensure data security?
-
Encryption of data in transit (TLS 1.3) and at rest,
-
Regular backups,
-
Strict access controls,
-
Access logging,
-
Regular security testing.
Do you work with processors?
Yes, in some cases (for example for transactional email or hosting). All our processors are bound by a GDPR-compliant DPA (Data Processing Agreement).
Transfers outside the EU
Is storing data in Mauritius lawful under the GDPR?
Yes, provided that appropriate safeguards are in place, such as:
-
Standard contractual clauses (SCC),
-
Country risk assessment,
-
Additional measures (pseudonymisation, strong encryption, access policy).
Monarck NEO Ltd strictly applies these requirements.
Monarck NEO Ltd commitments
Do you provide a DPA to your clients?
Yes. Any client can sign a data processing agreement (DPA) on request.
Do you have a public privacy policy?
Yes. Our privacy policy is available from the platform’s home page and covers all of our commitments and practices.
Do you carry out GDPR compliance audits?
Yes. We regularly carry out internal audits and, where necessary, external audits to ensure our ongoing compliance.