Skip to content

Legal

Privacy Policy

Last updated: 16 September 2026

Template — pending legal review

This document is a working draft prepared for transparency. It has not yet been reviewed or approved by qualified legal counsel and does not constitute legal advice. The final executed version issued with a contract prevails over anything on this page.

This policy explains what personal data LAHJA AI collects, why we collect it, how voice recordings in particular are handled, how long we keep things, who else sees them, and how you can get your data corrected or deleted.

1.Who we are

LAHJA AI SARL ("LAHJA AI", "we", "us") is a human data company established in Algiers, Algeria. We collect, annotate and evaluate language data — principally in Algerian Darija, Maghrebi Arabic, Tamazight, Modern Standard Arabic and French — and deliver it to organisations building artificial intelligence systems.

This policy explains what personal data we handle, why, and what you can do about it. It covers three groups: contributors who perform paid language tasks, client contacts who commission work, and visitors to our website.

For personal data relating to our own contributors and our own operations, LAHJA AI is the controller. Where a client supplies us with data to process on their behalf, that client is the controller and we act as processor under a separate data processing agreement.

2.Data we collect from contributors

To recruit, qualify, assign, review and pay contributors, we collect the following.

  • Identity and contact details: name, email address, phone number, date of birth and wilaya of residence.
  • Language profile: native language and dialect, regional origin, proficiency levels in other languages, and any dialect variants you can produce.
  • Skills and credentials: education, profession, and where a project requires it, evidence of a professional qualification or licence.
  • Equipment and environment: device type, headset, connection quality and recording conditions.
  • Availability and work preferences.
  • Task output: audio recordings of your voice, transcripts, translations, annotations, ratings and written justifications.
  • Quality and performance records: review decisions, rejection reasons, agreement statistics and contributor scores.
  • Payment records: amounts earned per task, the payment method used and the date of payment.
  • Consent records: which document version you accepted and when.
  • Technical records: authentication events, IP address at sign-in and audit-log entries for privileged actions.

3.Data we collect from clients and visitors

From client contacts we collect business contact details, the content of enquiries and proposals, project specifications, and records of the engagement. This is business-relationship data, not consumer profiling.

From website visitors we collect only what is needed to operate and secure the site, and any information you choose to send us through a contact or proposal form. We do not sell visitor data, and we do not use it to build advertising profiles.

4.Why we process personal data, and on what basis

Every category of data we hold is tied to a specific purpose and a lawful basis.

  • Performance of a contract: administering your account, assigning and reviewing tasks, delivering projects and making payments.
  • Consent: recording your voice, using your recordings in datasets delivered to clients, and any optional communications. Consent is captured explicitly, with the document version and timestamp, and can be withdrawn for future processing.
  • Legitimate interests: protecting the Platform against fraud and abuse, maintaining quality records, and improving our own methodology — balanced against your rights and never used to justify selling your data.
  • Legal obligation: keeping tax, accounting and payment records for the periods required by Algerian law.

5.Voice recordings — specific terms

Voice is biometric-adjacent data and we treat it with particular care. Before any audio task, you are shown a separate voice-recording consent that explains what will be recorded, that the recordings will be included in datasets delivered to clients for training, testing and evaluating AI systems, and that those datasets are supplied with a pseudonymous contributor identifier rather than your name.

We do not publish recordings publicly. Files are never served from a public bucket; each file is delivered through a short-lived signed URL issued after an authorisation check.

Withdrawing voice-recording consent stops any further recording and any further inclusion of your voice in new deliveries. It cannot retroactively recall recordings already delivered to a client under a licence, because we no longer control those copies. We will tell you honestly which of your recordings fall into that category.

We do not currently perform automated speaker verification or voice-based identity matching. If we introduce it, it will be described here and consented to separately before it is applied to your recordings.

6.Anonymisation in delivered datasets

Datasets are delivered with pseudonymous contributor identifiers — for example DZ-000428 — together with only the attributes the project requires, such as region, dialect, age band and gender.

Direct identifiers including your name, email address, phone number and exact address are stripped from deliverables. They are disclosed only where a specific contract requires identified contributors and you have consented to that disclosure for that project.

Pseudonymisation is not the same as irreversible anonymisation: we retain the mapping internally so that quality, payment and consent records remain auditable. Clients do not receive that mapping.

7.How long we keep data

We keep personal data only as long as it serves the purpose it was collected for, and then for any period we are legally required to retain it.

  • Application data for unsuccessful or abandoned applications: deleted or anonymised within a defined retention window unless you ask us to keep it for future projects.
  • Account and profile data: kept while the account is active, and deleted or anonymised after closure subject to legal retention.
  • Task output and quality records: retained for the life of the relevant client licence and as evidence of the work performed.
  • Payment and tax records: retained for the statutory period required under Algerian law.
  • Consent records: retained for as long as needed to evidence that consent was validly obtained.
  • Audit logs: retained on an append-only basis for security and accountability.

8.Sub-processors and service providers

We use a small number of service providers to run the Platform: cloud hosting and object storage, database hosting, transactional email delivery, and error and performance monitoring. Each is engaged under a written contract that limits them to processing data on our instructions.

We do not sell personal data, and we do not share it with advertising networks or data brokers. Clients receive only the deliverable defined in their contract.

A current list of sub-processors is available to clients on request, and material changes are notified to clients in line with their data processing agreement.

9.International transfers

Our clients are frequently outside Algeria, and some of our infrastructure providers operate in other jurisdictions. That means personal data — including voice recordings included in a delivered dataset — may be transferred across borders.

Where a transfer takes place, we rely on contractual safeguards with the receiving party covering security, purpose limitation, onward transfer and deletion. Where the destination's law offers weaker protection than Algerian law, the contract, not the local default, defines what the recipient may do.

10.Security

Access to personal data is restricted by role and enforced on the server. Passwords are hashed with argon2id, sessions are stored server-side with hashed tokens, files are served only through short-lived signed URLs, uploads are validated and size-limited, sensitive endpoints are rate limited, and privileged actions are written to an append-only audit log.

No system is perfectly secure. If a breach affecting personal data occurs, we will investigate, contain it, notify affected clients in line with their agreements and notify affected individuals where the risk to them warrants it.

11.Your rights and the deletion workflow

Subject to applicable law, you can ask us to give you a copy of the personal data we hold about you, correct inaccurate data, delete data, restrict or object to certain processing, or withdraw a consent you previously gave.

Account deletion follows a defined workflow. You submit a request from your account or by email; we verify that the request genuinely comes from you; we identify what can be deleted and what must be retained for legal, tax or existing-licence reasons; we delete or anonymise the rest; and we confirm the outcome to you in writing, itemising anything retained and why.

We aim to respond to any rights request within 30 days. We do not charge for this, and exercising a right will never affect your quality scores or your access to work.

12.Children

The Platform is not intended for anyone under 18 and we do not knowingly collect data from minors. If we learn that a contributor account was created by a minor, we will close it and delete the associated data except where we are legally required to retain records.

13.Changes and contact

We may update this policy. The revised version is published here with a new "Last updated" date, and material changes affecting contributors are notified in the Platform.

To exercise a right, ask a question, or raise a concern, write to contact@lahja.ai, or to network@lahja.ai for contributor matters. Postal address: LAHJA AI SARL, Algiers, Algeria.

Questions about this document? Write to contact@lahja.ai.