Afriset Fintech

Privacy

Effective 2026-07-02 · updated 2026-07-07 · Afriset is operated by Vibermacher (Pty) Ltd.

This website (afriset.com)

The register site is static. We run no analytics, no cookies, no trackers, and no third-party embeds (fonts are self-hosted). Our hosting provider (Cloudflare) may process standard connection data (such as IP addresses) transiently to serve and protect the site, per its own policies; we do not receive or keep per-visitor records from it.

The Afriset MCP server (mcp.afriset.com)

When your tools call the MCP server, the fields our code writes are the tool name (e.g. list_licensed), the resolved, coarse query arguments — the canonical activity and jurisdiction ids, the origin and target jurisdictions for a cross-market mapping, and the licence category for a requirements lookup — a count of records the query returned, and a timestamp. When a query names a market or activity we don't yet recognize, we store a normalized, length-capped form of that term (uppercased letters/numbers only) so we can see which markets are being asked for that we don't yet cover. That is the full extent of it: no account identifiers, no caller identity, no IP addresses, and no free-text argument content. These aggregate counts exist solely to measure whether the service is useful and what to build next (our public usage metrics).

These events are recorded as aggregate analytics (Cloudflare Workers Analytics Engine) — counts grouped by the fields above, not per-caller records. Our hosting provider (Cloudflare) also keeps short-retention operational logs that attach its own invocation metadata (such as the request URL and response status) under its retention policies — the same hosting-provider carve-out as the website above: Cloudflare may process standard connection data (such as IP addresses) transiently to serve and protect the endpoint; we do not use it to identify callers.

The change-alerts waitlist

If you join the change-alerts waitlist on this site, that is the one place we collect personal data, and it is separate from the PII-free MCP logging above. We collect only what you choose to give us: your email address, an optional organisation name, the markets or licence types you tick (chosen from a fixed list), an optional free-text note if you write one (what you'd like us to prioritise), together with the timestamp of your consent. We do not collect your IP address, your device, or any other identifier.

The lawful basis is your consent (you must tick the box to submit), and the sole purpose is to notify you about the change-alerts product and ask which markets to prioritise. We do not share or sell this data, and we do not use it for any other purpose. It is stored in our own Cloudflare infrastructure (a private key-value store) — no third-party form or email service is involved.

Retention & deletion: we keep your entry only until the change-alerts product launches and you decide whether to continue, or until you ask us to remove it — whichever comes first — and we review the list periodically to drop stale entries. You can have your data deleted at any time: email [email protected] and we will remove it. Consistent with POPIA, Nigeria's NDPA and the GDPR, you may also request access to, or correction of, what we hold.

The dataset itself

Afriset publishes facts about licensed corporate entities from official public regulator registers, with source and as-of date on every fact. We do not collect or publish personal data. If a regulator's register embeds personal data (e.g. a named contact), we do not republish it.

Corrections & contact

Corrections are handled in the open: revisions are retained, never silently overwritten. Anything privacy-related: [email protected].