Privacy notice
What MoNGO collects, why, who sees it, and how to get something taken down.
Who this applies to
MoNGO is a referral directory for NGOs in Mauritius. It never handles donations or payments. This notice covers everyone whose personal data the platform processes: NGO staff who run a page, company staff who search and make contact, visitors who use the contact or report forms, and the people who appear in photographs an NGO publishes.
The data controller is the operator of this site. Processing is carried out under the Mauritius Data Protection Act 2017 (“the Act”).
What is collected, and why
Nothing below is bought from a third party or inferred from your behaviour elsewhere. Everything is either given to us directly or generated by using the site.
- NGO organisation and contact detailsLawful basis: Contract / legitimate interest
- Name, legal name, registration number, description, address, district, founding year, staff and volunteer counts, website and Facebook links, NSIF registration status and dates, and contact email, phone and WhatsApp number. An NGO supplies these to be listed. Contact email, phone and WhatsApp are never shown on a public page and are not part of any public API response — enquiries are routed to the organisation by email on the server side, so that these cannot be scraped.
- Company detailsLawful basis: Contract
- Company name, business registration number, financial-year end, CSR budget, and the contact details of the person using the workspace. The CSR budget is commercially sensitive: it is readable only by that company’s own signed-in users and appears in no public page or API response.
- Account dataLawful basis: Contract
- Email address, display name, role, and a one-way hash of your password. The password itself is never stored and cannot be recovered from the hash.
- Contact-form submissionsLawful basis: Consent / legitimate interest
- When you contact an NGO through this site we record the optional name and email address you give, your message, and any intended contribution amount you state. This is passed to the NGO you chose so it can reply to you directly, and it is retained so the NGO and (where a company sent it) the company can see how the enquiry was resolved.
- Content reportsLawful basis: Legal obligation / legitimate interest
- The reason you select, any detail you write, and the email address you optionally supply. Reports are readable by administrators only. See taking content down below.
- Media, including photographs of peopleLawful basis: Consent
- Images uploaded by NGOs — logos, cover images, and photographs attached to project updates, which may include identifiable beneficiaries. NGOs are contractually required to obtain the consent of anyone identifiable before publishing their image, and remain responsible for that consent. If your photograph has been published without your consent, use the takedown route below.
- Page viewsLawful basis: Legitimate interest
- When a public NGO or project page loads, the site records which page was viewed and when, so the NGO can see whether its page is being seen. No IP address, no device identifier, no cookie and no cross-site identifier is recorded with it, and the raw events are aggregated into daily counts and then deleted. This is not analytics about you; it is a counter about the page.
- Technical and security dataLawful basis: Legitimate interest
- Your IP address is used transiently to apply rate limits to the login, contact and report forms, which is what stops them being used for spam or password guessing. Administrative actions are written to an audit log recording who did what, to which record, when, and from which IP address — deliberately as identifiers only, never copies of the personal data involved. Signed-in users are issued a single session cookie, which is strictly necessary for signing in; the site sets no advertising or analytics cookies.
Who your data is shared with
Not sold, never. There is no advertising on this site and no data is transferred to advertisers, brokers or list vendors.
Your data reaches other parties in exactly three ways:
- The NGO you contact. Sending an enquiry passes your message and the contact details you gave to that organisation, so it can reply.
- The public, for what an NGO chooses to publish. An NGO page, its projects and its updates — including any photographs — are public and indexable by search engines once published.
- Service providers acting on our instructions. Hosting, transactional email delivery, backup storage and (if enabled) error monitoring. They process data only to provide those services.
How long it is kept
- Raw page-view events — deleted once rolled up into daily counts (this is already how the code behaves). Daily counts are aggregate figures and contain no personal data.
- Contact enquiries — retained while the NGO and company need them to track the outcome, then deleted. Period to be set.
- Content reports — retained after resolution as the record of a moderation decision. Period to be set.
- Accounts and organisation records — for as long as the organisation is listed, and for a defined period afterwards. Period to be set.
- Audit log — long-retained by design, because it is the record of who changed what. Period to be set.
Your rights under the Act
You have the right to ask what personal data we hold about you and to receive a copy; to have inaccurate data corrected; to have data erased where there is no longer a lawful reason to keep it; to object to processing based on legitimate interests; and to withdraw consent where processing relies on it — including consent to a photograph.
Exercise any of these by writing to the operator at the address below. We will respond within the period the Act allows. If you are not satisfied, you may complain to the Data Protection Office of Mauritius, which supervises compliance with the Act.
Taking content down
Every published NGO page and project page carries a “Report this content” control. Anyone can use it — no account is needed and you do not have to identify yourself — and it is the correct route for a photograph published without consent, for which the report form has a dedicated “Safeguarding concern” reason so it is visible immediately to whoever triages the queue.
A report goes to an administrator, who reviews it and, where warranted, unpublishes the content — at which point the page stops being served publicly and disappears from the browse indexes. The action is recorded in the audit log.
Two honest limits. The form confirms that your report was received but tells you nothing else, because answering differently would let it be used to probe which pages exist. And a report is reviewed by a person, so it is not instantaneous — if the matter is urgent, write to the operator directly as well.
Security
Traffic is served over HTTPS. Passwords are stored only as hashes. Uploaded media is held in private storage and served only for content that is currently published. Sessions use a single, strictly necessary cookie, and access to every record is scoped so that one organisation cannot read another’s.
Changes and contact
If this notice changes materially we will say so on this page. To exercise a right, ask a question, or report a concern, write to the operator of this site — the contact address will be published here before launch.