Privacy Policy

This is the single privacy policy for everything IyedeX does. Part one applies to everyone. After it come three parts, one for each kind of relationship we have with the people whose data we hold: the products anyone can use, the work we do for businesses, and the work we do for public institutions.

Updated
September 2026
Scope
B2C · B2B · B2G
Governing law
Tunisian law
Part I

Common rules

These rules hold wherever your data reaches us. A later part may add to them for a particular product or contract; where a later part is stricter, the stricter rule wins.

1. Who we are

IyedeX is a Tunisian company based in Sfax that builds artificial-intelligence software and products for Tunisia. Its legal representative and the person answerable for data protection is Iyed Chraiti.

  • Company: IyedeX, Sfax, Tunisia
  • Contact for anything in this policy: contact@iyedex.tn
  • Data protection contact: Iyed Chraiti, at the same address

For our own products we are the data controller: we decide what is collected and why. For work carried out under a contract with a business or an institution we are usually the processor, acting on that client's instructions. Parts three and four say what that changes.

2. Scope

It covers the iyedex.tn website, the 3amAli assistant on the web and in its mobile application, every other product we publish, and the personal data we handle while working for business and public-sector clients.

It does not cover other companies' websites we link to. Once you follow a link out, their policy applies, not ours.

3. Data we hold

Three kinds, and it is worth keeping them apart.

  • What you give us. Your name and email address when you open an account, anything you write in a contact or partnership form, and what you send a product while using it: messages, questions, files and images.
  • What the service records. The exchanges you have with an assistant, the features you use, the pages you open, how long you stay, and the errors the system hits.
  • What your device reveals. IP address, browser or app version, operating system, language and time zone, and device identifiers. We need these to serve the request at all, and to tell ordinary use apart from abuse.

We do not ask for, and do not want, special categories of data: health, beliefs, political opinions, biometrics. If you put such information into a conversation it is handled like the rest of that conversation, but we never seek it out and never build profiles on it.

4. Purpose and basis

  • To run the service you asked for: creating and holding your account, answering what you ask, keeping your history where you can find it, and supporting you when something breaks. Basis: performance of the contract between us.
  • To keep the service safe and standing up: spotting abuse, preventing fraud, tracing faults, and keeping capacity ahead of demand. Basis: our legitimate interest in a service that works.
  • To make the product better: understanding where answers fall short and where the Tunisian dialect is misread, and improving our models, prompts and routing on the strength of it. Basis: our legitimate interest, and your right to object at any time (see section 8).
  • To meet a legal duty: where Tunisian law, or a lawful order from a court or authority, requires us to keep or hand over information. Basis: legal obligation.

5. Sharing

We do not sell your personal data, and we do not rent it. We never have. It is shared only in these cases:

  • Service providers who host, send email, or keep the service running, under a written contract that binds them to confidentiality and to using the data only for the task we set them.
  • Model providers. Until our own Tunisian model is finished, part of what an assistant does runs on third-party models we have fine-tuned. That means the text of a prompt can be processed on their infrastructure to produce the answer. We choose providers who are contractually barred from using it to train their own models, and we send them no more than the request needs.
  • Authorities, where the law or a valid legal order requires it, and no further than the order reaches.
  • An acquirer, if the company is ever merged, acquired or sold, in which case this policy travels with the data and you will be told before anything changes.
  • Anyone, in aggregate: counts and statistics that identify nobody.

6. Place and retention

We host in Tunisia wherever we can, and it is the direction the company is moving in. Some infrastructure and some model providers sit outside the country, so your data may be processed abroad. Where it is, we require a written data-protection agreement and standard contractual safeguards before anything is sent.

We keep it no longer than the reason for holding it:

  • Account details: for as long as the account is open, then erased within 30 days of deletion.
  • Conversations and history: until you delete them, or until the account is deleted.
  • Technical and security logs: 12 months, then erased.
  • De-identified data used to improve models: kept for as long as it is useful, and only once it can no longer be traced back to you.
  • Records we are legally obliged to keep: for the period the law sets, and no longer.

7. Security

  • Everything in transit is encrypted with TLS.
  • Sensitive data is encrypted at rest.
  • Access is limited to the people who need it to do their job, on the principle of least privilege, and access to personal data is logged.

One honest exception. Your email address and username are not encrypted at rest. Account recovery and user administration need them readable. We would rather say so than let you assume otherwise.

No system on the internet is perfectly secure and we will not claim ours is. If a breach ever affects your data, we will tell you and the Instance Nationale de Protection des Données Personnelles without undue delay, and we will say plainly what happened and what to do about it.

8. Your rights

Over the data we hold about you, you have the right to:

  • See it: ask for a copy of what we hold.
  • Correct it: have anything wrong put right.
  • Erase it: have it deleted, subject to what we are legally required to keep.
  • Object: including objecting to your data being used to improve our models, which we will honour without you having to give a reason.
  • Restrict: have us hold it but stop using it while a dispute is settled.
  • Take it with you: receive it in a portable format.

Write to contact@iyedex.tn. We answer within 30 days. We may ask you to confirm who you are first, which protects you rather than us. If our answer does not satisfy you, you may complain to the Instance Nationale de Protection des Données Personnelles (INPDP) in Tunisia.

9. Children

Our products are not for children under 13, and we do not knowingly collect anything from them. If we learn that we hold data from a child under 13 without verified parental consent, we delete it.

Between 13 and 18, we ask that a parent or guardian read this policy and agree to the use of the service. If you are a parent and believe your child has given us data, write to contact@iyedex.tn and we will remove it.

10. Governing law

We work under Tunisian law, and in particular Loi organique n° 2004-63 du 27 juillet 2004 on the protection of personal data, under the supervision of the INPDP. Where a client, a market or a user brings stricter obligations with them (the GDPR among them), we apply the stricter standard rather than the minimum.

11. Changes

We update this page when what we do changes. The date at the top always says when. If a change is significant we will not rely on you noticing: we will say so by email or in the product itself before it takes effect, and we will spell out what changed.

12. Contact

Any question about this policy, any request about your data, any complaint:

We reply to every privacy request within 30 days.

Part II · B2C

General public

Products published for the general public, which anyone can open or sign up for. Each has its own section below. What it says adds to Part one.

3amAli

3amAli is a free assistant that understands and answers in Tunisian, on the web at 3amali.tn and in its mobile application. This section is the privacy policy for both.

What it collects

  • Account: your name and email address, and your password, which is stored hashed and is never readable by us.
  • Messages: what you write to the assistant and what it answers, kept so your history is there when you come back.
  • Images and files you send it to be read.
  • Preferences: the subject you are in, your language, and the settings you choose.
  • App activity: the features you use and the screens you open.
  • Diagnostics: crashes, errors and performance, so faults can be found.
  • Device and technical data: IP address, app or browser version, operating system, language, time zone and device identifiers.

3amAli shows no advertising, and none of this is collected for advertising, sold, or shared with data brokers.

Your conversations

First, we answer you: your message goes to the model that handles that subject and the reply comes back. Then it is kept in your history so you can find it again from any device you are signed in on.

Separately, we use conversations to make the assistant better at Tunisian: where it misreads a word, misses a reference, or answers a question about a Tunisian procedure wrongly. Before a conversation is used that way it is de-identified: names, email addresses, phone numbers and other identifiers are stripped, and it is no longer connected to your account.

You can say no. Write to contact@iyedex.tn and ask that your conversations not be used to improve or train our models. We will apply it to what we hold and to everything after, and you do not have to give a reason. Saying no does not limit the assistant in any way.

The models

We are building our own model for the Tunisian dialect. Until it is ready, 3amAli runs on third-party models we have fine-tuned, with our own prompting and our own routing between subjects. In practice that means the text of your message may be sent to a model provider outside Tunisia in order to produce the answer.

We only work with providers who are contractually barred from using what we send to train their own models, and we send only what the request needs. When our own model takes over, this section will change and we will say so.

Deletion

You can delete a single conversation from your history at any time, from inside the app or the website.

To delete your whole account and everything attached to it:

  • In the app or on the website: Settings → Account → Delete account.
  • Or by email: write to contact@iyedex.tn from the address on the account, asking for deletion. We will confirm it is you, then delete.

When you delete an account, your name, email, password, preferences, conversations and history are erased from our live systems immediately and from our backups within 30 days. Two things do not come back with them: records we are legally required to keep, and data already de-identified for model improvement, which by then can no longer be linked to you. Deletion is permanent; we cannot restore an account afterwards.

App permissions

The app asks for a permission only at the moment the feature needs it, and refusing one only turns that feature off.

  • Photos and camera: only when you choose to send an image to be read. We do not browse your gallery and we do not take pictures in the background.
  • Notifications: only if you turn them on, to tell you an answer is ready or that something changed.
  • Network access: required: the assistant runs on our servers, not on your phone.

3amAli does not ask for your contacts, your location, your microphone, your call log or your files.

Age

You must be at least 13 to open a 3amAli account. Between 13 and 18 we ask that a parent or guardian agrees to it first. See section 9 of Part one.

Future products

When we release another consumer product it gets its own section here, listing what it collects and why, before it launches. This part is the whole list: if a product is not named here, it is not live.

Part III · B2B

Businesses

Software, models and integrations built for a company under contract. The data involved is that company's, not ours, and it is handled accordingly.

Our role

When we build or run something for a business, the personal data inside it belongs to that business and it stays the controller. We are the processor: we act on its written instructions and on nothing else. The signed contract, and the data-processing agreement attached to it, govern the relationship; where they say something different from this page, they win.

Data subjects

Separately from client data, we hold ordinary business-contact details for the people we work with: name, role, work email and phone, and the record of what was discussed and agreed. We hold that as controller, to run the relationship and to meet our accounting and legal duties, and we keep it for the length of the relationship plus the period Tunisian law requires.

Client data

  • We process it only to deliver what was agreed.
  • We do not use client data to train our models, or to improve anything outside that client's own project, unless the client asks for it in writing.
  • We do not mix one client's data with another's.
  • We engage a subprocessor only with the client's agreement, and only under terms at least as strict as ours.
  • At the end of the engagement we return the data or destroy it, whichever the client chooses, and confirm in writing when it is done.

Security

Client environments are separated, access is limited to the team on that project and is logged, and credentials are held in a secret manager rather than in code or in a message. We notify the client of any incident affecting their data without undue delay and support them in meeting their own notification duties. Clients may audit these arrangements on reasonable notice, in the way their contract sets out.

Part IV · B2G

Public institutions

Work for ministries, agencies, public establishments and local authorities. Everything in Part three applies, and these obligations are added on top of it.

Sovereignty

Data belonging to a public institution, and any data about citizens it entrusts to us, is hosted in Tunisia. Where a project genuinely cannot be delivered without a component outside the country, we say so before the contract is signed, name the component and the country, and proceed only with the institution's written agreement. Building the option to keep this work entirely inside Tunisia is a large part of why the company exists.

Citizen data

Data about citizens, processed on behalf of an institution, is used for that institution's purpose and for nothing else. It is never used to train our models, in any form, de-identified or not, and it is never reused for another client. We hold it for the period the institution sets, and we return or destroy it at the end of the engagement.

Audit and reporting

We work within Tunisian public-procurement rules and within whatever framework the institution operates. We provide the documentation a public body needs to satisfy itself: how a system is built, where the data goes, who can reach it, and we accept audit and inspection on the terms the contract sets. Incidents affecting an institution's data are reported to it, and to the INPDP where the law requires, without undue delay.

Artificial intelligence

Where a system we build informs a decision that affects a member of the public, we say so in the documentation, we do not present a model's output as a determination, and we build in a route for a person to review it. A model can be wrong, and a public service must be able to catch it when it is.