Privacy Policy
This policy describes how Proxia Digital (the "Provider") collects, uses and protects personal data in the Lehno service (the "Service").
Applicable legal framework
- Law no. 2024/017 of 23 December 2024 on the protection of personal data — the governing text. It applies to any processing carried out on Cameroonian territory or concerning residents of Cameroon. It makes all processing subject to prior authorisation by the data protection authority (art. 19) and any transfer out of Cameroon subject to prior authorisation together with an equivalent level of protection (art. 32). The compliance period it opened (art. 73) expired on 23 June 2026.
- Law no. 2010/012 of 21 December 2010 on cybersecurity and cybercrime — the underlying framework.
- Law no. 2023/007 of 25 July 2023 — Charter for the protection of children online. It concerns the Service because a user may keep a page about a child they know (see section 3).
- Regulation (EU) 2016/679 ("GDPR") — applicable only to people residing in the European Union, alongside Cameroonian law.
The supervisory authority ("Personal Data Protection Authority") is created by law 2024/017; its operating arrangements await an implementing decree.
1. Data controller
Proxia Digital Akwa, Douala, Cameroon Phone: +237 691 980 189 Email: hello@lehno.io
Data Protection Officer (DPO): Valentine Nguemne — hello@lehno.io The role is held by the company's leadership; it is not delegated to a third party.
2. Data collected
2.1 What you provide about yourself
- Account: email address, username, language, time zone, and the hour your reminders are sent. The Service uses no password: you sign in with a one-time code sent by email, or with a Google or Apple account you connect.
- Your Wall: if you publish it, the address you chose, your welcome note, your public interests, your birthday and your wishlist.
- Payment: for a mobile money account, the phone number attached to it, which is needed to start a transaction and to issue a refund. For a card, only an opaque reference returned by the provider is kept: no banking data reaches us.
2.2 What you provide about the people you love
See section 3, which is devoted to it.
2.3 What is collected automatically
- Technical: IP address, device and client type, language.
- Security: sign-in attempts and their outcome, device identifiers, per-device limits on account creation.
- Logs: a correlation identifier, the path called, the status returned, the duration, and — when there is a session — the account identifier, never its email address.
2.4 What we do not collect
- No banking data passes through or is stored on our servers.
- The content of notes, wishes and messages never enters a technical log, nor do one-time codes, session or link tokens, mobile money account numbers and card references. These fields are masked as they are written, not afterwards.
3. Data about the people you love
This is what makes the Service unusual, and it deserves to be said plainly.
What is recorded. Lehno lets you keep one page per person: a name you use for them, a birthday or occasion, a tone, a language, free-form notes about their tastes, gift ideas, a wishlist. Someone can also fill in a page themselves, through a collection link you send them; with a public link, they may add their name and a hint of how you know each other.
Why this is personal data. On its own, "likes specialty coffee" is nothing. Attached to a name and a date, it becomes information relating to an identifiable person, and the law treats it as such — however ordinary it is.
On what basis. You note what you know about people close to you for personal use, which for you is a household activity. That exemption does not cover the Provider, who supplies the means of processing: our legal basis is legitimate interest (art. 6.1.f GDPR and the corresponding Cameroonian provision) — yours, to prepare an occasion; ours, to make the service possible. We do not ask each person for consent: it would be unworkable, and this basis does not require it.
What we rule out. No enrichment from any outside source: nothing enters a page that you or someone close to you did not put there. No resale, no transfer for advertising, no commercial profiling. No page is visible to any user but you. The Service collects no identity number, postal address or health data about anyone, and never invites you to enter any.
Sensitive occasions. Some occasions are marked sensitive. The Service adapts its tone and produces no gift ideas for them.
Generated content. When you ask for a portrait, gift ideas or a message, the text of the relevant notes and the person's name are sent to the generation processor (section 5). Nothing is sent unless you started the action, and its cost is shown to you first.
When the person is a child. A child's birthday is exactly what the Service is for: a page may therefore concern a minor. Law no. 2023/007 of 25 July 2023 applies, and law no. 2024/017 sets the data-protection age of majority at 18. In that case: the Provider carries out no profiling of the child, sends them nothing, and exposes them on no public surface; the rights below are exercised by their parent or legal representative, who may request erasure of what concerns them on the same terms as an adult.
What becomes public. Only your Wall is public, and only if you publish it: it shows nothing but what you put there about yourself. No one else's page appears on it. Birthday notes left for you are never displayed.
Rights of someone without an account. A person who appears on a page without having an account can write to the DPO (hello@lehno.io) to learn what concerns them, have it corrected, or have it erased. We handle the request directly when the person is identifiable in our data; otherwise we pass it to the owner of the page, who remains in charge of their own notebook. An erasure request is carried out without asking for a reason.
4. Purposes and legal bases
Law no. 2024/017 makes consent — free, informed, specific, unambiguous and express — the principle of processing (art. 9), and accepts that it is not required where processing is necessary to perform a contract, to comply with a legal obligation, or for a legitimate interest that does not override the rights of the person. The Service's processing breaks down as follows:
- Performance of the contract: creating and running the account, providing the Service, reminders, collection links, the Wall, buying credits.
- Legitimate interest: the pages about people close to you (section 3), preventing abuse (limits, token replay detection, audit logs), and keeping the Service sound.
- Consent (art. 9): usage measurement, and any communication not needed to run the Service. No advertising tracker exists in the product.
- Legal obligation: keeping authentication records and accounting documents.
For people residing in the European Union, these four bases correspond to articles 6.1.b, 6.1.f, 6.1.a and 6.1.c of the GDPR respectively.
5. Recipients and processors
Your data may be passed to the following processors, strictly for the purposes described, under a contract compliant with article 28 GDPR:
- Generation processors — producing portraits, gift ideas and messages. Only the text of the relevant notes and the person's name are sent to them. The providers under consideration are Anthropic PBC (United States), xAI (United States) and DeepSeek (China), with routing and fallback between them; each is enabled only once the transfer safeguards required by law no. 2024/017 are in place with them, and this list is updated at that point.
- Resend (United States) — the Service's emails: one-time codes, reminders, confirmations. The recipient's address and the message body are passed to it for the time it takes to deliver.
- OneSignal (United States) — push notifications.
- Sentry — technical error tracking. Incidents carry the correlation identifier and, where applicable, the account identifier — never the content of notes, never an email address.
- Contabo GmbH (Aschauer Straße 32a, 81549 Munich, Germany) — hosting of the servers and the database, in Germany.
- MTN Mobile Money and Orange Money — collecting payment for credits.
6. International transfers
Hosting is itself a transfer. The Service's data is hosted in Germany, and some processors are established in the United States. Law no. 2024/017 (art. 32) makes any transfer out of Cameroon subject to prior authorisation by the data protection authority and to a verified equivalent level of protection. The Provider carries out that formality for each of its transfers, and enables no new recipient outside Cameroon before it completes.
For people residing in the European Union, such transfers are additionally covered by the standard contractual clauses approved by the European Commission (art. 46 GDPR). A copy can be obtained from the DPO.
7. Retention
- Active account: as long as it is active, and three (3) years after the last sign-in.
- Pages, notes, wishes: erased when the owner's account is deleted, or sooner at their request or at the request of the person concerned.
- Contributions through a collection link: the lifetime of the link, which the owner can revoke at any moment.
- Birthday notes received: erased when the account is deleted.
- Audit and security logs: 12 months.
- One-time codes: a few minutes, then purged.
- Accounting documents: the period required by applicable regulation.
8. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection; the right to withdraw consent at any time without affecting processing already carried out; and the right to give directions about your data after your death.
Exercise them with the DPO: hello@lehno.io. A reply is provided within one month at most. You can also delete your account from the app, without going through us.
9. Complaints
- Cameroon: to the Personal Data Protection Authority established by law no. 2024/017, once its operating arrangements are set by decree. In the meantime, complaints may be addressed to the Provider, who keeps a register of them, or to ANTIC for cybersecurity matters.
- European Union: to the supervisory authority of your country of residence.
10. Security
- Encrypted connections end to end (HTTPS/TLS).
- One-time codes hashed under a key (HMAC-SHA-256), compared in constant time, consumed atomically.
- Session token rotation, with the whole lineage revoked at the first sign of replay.
- Strict per-account isolation enforced at the repository level: a request outside its scope does not return an authorisation error, it returns an absence.
- Link tokens grant access to one resource, never to a set, and can be revoked at any moment.
- Audit logs kept 12 months; encrypted backups.
In the event of a personal data breach, the Provider follows its incident response plan and notifies the data protection authority without delay, as law no. 2024/017 requires (art. 22).
12. Minors
The Service is intended for people aged 18 or over, the data-protection age of majority under law no. 2024/017. The civil age of majority in Cameroon is 21. No processing is intended for anyone under 18 acting for themselves; an account found to belong to a minor is deleted without delay. Data about a child recorded by someone close to them is covered by section 3.
13. Changes
This policy may change. Any substantial change is notified by email or in the Service at least fifteen (15) days before it takes effect, and requires fresh acceptance at the next sign-in. Each acceptance is timestamped and kept (version, date, IP address), and appears in the export of your data. Earlier versions are kept and provided on request.
_References to articles of law no. 2024/017 are drawn from concordant public sources; they will be confirmed against the text as published in the Official Gazette._
14. Contact
Data Protection Officer: Valentine Nguemne Proxia Digital — Akwa, Douala, Cameroon Phone: +237 691 980 189 Email: hello@lehno.io