Purpose and scope
This document governs use of the relevant AfriEuro Links, LaDOS or CEOS service, including public, marketplace, registration and authenticated-workspace interactions. Access to a feature does not override role permissions, contractual controls, law or a separate signed agreement.
Accountability and records
Material approvals, changes, consents, transactions and high-risk decisions are recorded through role-based workflows and audit logs. Records are retained according to purpose, legal requirements and approved retention schedules.
Sensitive information
Identity documents, financial credentials, protected research information, health/safeguarding data, private designs and confidential commercial information are restricted to authorised workflows. Public pages expose only approved information.
Security and fraud prevention
The service uses layered controls including secure sessions, MFA where required, access control, CSRF protection, rate limiting, security logging, encryption in transit, restricted file handling and incident-response workflows. Users must not share passwords, authentication codes or private keys.
Rights and complaints
Participants can use the applicable service channels to request correction, access, objection, withdrawal where legally available, complaint handling and escalation. Contractual and statutory rights remain subject to the governing jurisdiction and the facts of the relationship.
Applicable privacy framework
For European participants/entities, personal-data processing is designed around the GDPR principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality and accountability. Electronic identification and trust-service workflows are designed to interoperate with the current eIDAS/European Digital Identity framework where applicable.
International transfers
Cross-border transfers require an appropriate legal basis, approved data-sharing scope, minimisation and contractual/technical safeguards. Federation is not permission for unrestricted replication.
Lawful processing
The system records processing purpose, consent where consent is relied on, role/relationship and disclosure scope. Consent is not used where another lawful basis is the correct basis.
Data subject requests
Requests are authenticated before personal information is disclosed or changed. Sensitive records can require enhanced verification and human review.
Retention and deletion
Retention is defined by record class, legal/contractual obligation, dispute/audit need and evidence integrity. Data that no longer has an approved purpose is deleted, anonymised or archived under controlled retention.