Choose your language

Privacy and Policy

We want everyone to have fair and equal access to our digital services.

Applicable Legal Framework

This Policy is governed by Law No. 019/AN/23/9th L of 6 July 2025 on the Digital Code, in particular Book One relating to the protection of personal data, as well as by the implementing texts, standards, decisions, guidelines and recommendations adopted by the competent authorities, including the National Commission for the Protection of Personal Data.

Considering Tamini’s activity as an insurance company established in Djibouti, this Policy is also to be read in light of Djibouti’s insurance regulations, including Law No. 40/AN/99/4th L of 8 June 1999, its implementing texts and the applicable prudential, accounting and sector-specific rules.

Tamini ensures compliance with the applicable prior formalities for its personal data processing activities. Depending on the nature of the processing, such activities may be subject to prior declaration, simplified declaration, exemption or prior authorization by the Commission.

Where required by applicable regulations, Tamini completes the necessary formalities with the Commission before implementing the relevant processing activity. Any substantial change to a processing activity that has already been declared or authorized is reviewed to determine whether an update, a new declaration or a new authorization is required.


1. Introduction

Tamini Insurance SA (“Tamini”, “we”, “us” or “our”) is an insurance company based in Djibouti. Tamini provides insurance solutions for individuals, professionals and businesses, including motor, home, travel, marine, business, retail and personal insurance products.

Tamini operates in accordance with cooperative insurance and Takaful principles, with a commitment to transparency, fairness, mutual assistance and customer protection.

This Privacy Policy explains how Tamini collects, uses, retains, shares and protects personal data when you interact with us through our digital channels, including the website, mobile application, digital forms, social media channels and related services.

This Policy is aligned with internationally recognized data protection principles and the laws applicable in the Republic of Djibouti.

By using our digital services or communicating with us, you acknowledge that your personal data is processed as described in this Policy.


2. Who We Are

Tamini Insurance SA is the data controller responsible for deciding why and how your personal data is processed in connection with our services.


3. Scope

This Policy applies to personal data collected through Tamini’s website, mobile application, social media channels, digital forms, customer service interactions and insurance services.

Third-party platforms, including social media networks, app stores, analytics tools and payment providers, act as independent data controllers for their own processing activities. Tamini is only responsible for personal data that it directly collects and processes for its own purposes.


4. Personal Data We Collect

4.1 Data You provide

4.2 Data Collected Automatically

4.3 Data from Third Parties


5. How We Collect Personal Data

Tamini collects personal data when you use our services, submit forms, create an account, request a quote, purchase a policy, file a claim, communicate with us or interact with our digital platforms.

Tamini also collects certain data automatically and from authorized third parties involved in providing insurance services, contract management, payments, assistance, claims handling, security or regulatory compliance.


6. Why We Use Your Personal Data

Tamini uses personal data for the following purposes:


7. Legal Bases for Processing

Where applicable, Tamini relies on the following legal bases:


8. Sensitive Personal Data

Tamini processes sensitive personal data only where necessary, proportionate and permitted by law, including health data, bodily injury claims data or data required for the administration of Takaful insurance.

Where sensitive data is processed, Tamini applies enhanced protection measures: strictly limited access to authorized personnel, confidentiality, access controls, traceability, security measures and, where required by law, explicit consent or another appropriate legal condition.

Tamini avoids any wording suggesting that data directly or indirectly revealing religious beliefs is collected beyond what is strictly required for the administration of Takaful products or the performance of insurance services.


9. Cookies and Tracking Technologies

Tamini uses cookies and similar technologies to operate the website, improve performance, secure the services, measure audience and analyze the use of digital services. Where required, your consent is obtained for non-essential cookies, including analytics or marketing cookies. You can manage or withdraw your consent at any time through your browser settings or through our cookie preference manager where available.

The analytics tool actually used by the website or application must be confirmed by the technical team. This section will be updated if an analytics tool, SDK or third-party provider is confirmed.


10. Mobile App Permissions

The Tamini mobile application may request certain permissions on your device strictly for service delivery and proper functionality. Each permission is used only for the purposes described below. You may decline or revoke it at any time in your device settings, noting that some features may then be limited.


11. Account Management and Deletion

Users can create and manage an account. Account deletion requests can be submitted via the application or by contacting Tamini.

Deleting your account does not automatically terminate your active insurance contracts, nor delete data that Tamini is legally or regulatorily required to retain. Certain data is retained in accordance with the periods set out in the “Data Retention” section.


12. Data Sharing

Tamini shares personal data only where such sharing is necessary, proportionate and authorized, including with:

Tamini does not sell your personal data. Partners and providers acting on behalf of Tamini are required to protect personal data, preserve confidentiality and comply with applicable obligations.

Payments: Tamini does not store full payment card data. Payments are processed by third-party payment providers required to apply appropriate security standards, including PCI-DSS standards where applicable.

13. International Transfers

Certain personal data may be processed, stored or hosted outside the Republic of Djibouti, in particular where Tamini uses cloud hosting, technical administration, analytics, notification or maintenance services located abroad.

Where personal data is transferred to or hosted outside Djibouti, Tamini applies appropriate technical security measures designed to protect personal data against unauthorized access, loss, alteration, disclosure or destruction.

Tamini also ensures that providers involved in hosting, maintenance, analytics, notification or technical support are selected and managed in accordance with applicable personal data protection requirements. Where necessary, Tamini implements or completes appropriate contractual safeguards, including confidentiality, security, purpose limitation, subcontracting, location, assistance with data subject rights and security incident notification commitments.

Tamini will update this section once the analytics tools, notification services, technical providers or applicable contractual safeguards have been confirmed.


14. Data Retention

Tamini Insurance SA is the data controller responsible for deciding why and how your personal data is processed in connection with our services.

Retention periods are determined based on criteria such as the duration of the contractual relationship, applicable limitation periods in insurance, and accounting, regulatory, prudential, evidentiary and litigation-related obligations.

By way of indication:

These periods may be extended where required by law, a competent authority, an audit, an investigation, litigation or the protection of the rights of Tamini, its customers or third parties.


15. Security, Confidentiality and Privacy by Design

Tamini applies appropriate technical, organizational and physical security measures designed to protect personal data against unauthorized access, loss, alteration, destruction or unauthorized disclosure.

These measures include, where appropriate, encryption of data in transit, access controls, restriction of access to authorized personnel, traceability, backups, access rights management, staff awareness and regular assessment of security measures.

Tamini applies the principle of data protection by design and by default. This means that personal data protection is integrated into the design, development, configuration and operation of its services, applications, forms and internal systems. By default, only the personal data necessary for each specific purpose is collected, used, retained and made accessible to authorized persons.

While Tamini applies appropriate technical, organizational and physical measures designed to protect personal data, it is acknowledged that no digital environment can be entirely free from security risks.


16. Personal Data Breaches

Tamini implements appropriate measures to prevent, detect, assess and respond to incidents that may affect the confidentiality, integrity or availability of personal data.

A personal data breach means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data processed by Tamini.

In the event of a personal data breach, Tamini promptly assesses the nature of the incident, the categories of data affected, the approximate number of affected individuals, the likely consequences of the breach and the measures taken or proposed to address it.

Where notification is required under applicable regulations, Tamini notifies the competent personal data protection Commission without undue delay and, in any event, no later than seventy-two (72) hours after becoming aware of the breach. If notification cannot be made within this timeframe, Tamini provides the reasons for the delay.

Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, Tamini informs those individuals without undue delay, using clear and plain language, of the nature of the breach, its likely consequences, the measures taken or proposed to address it, and how further information may be obtained.

Tamini maintains an internal register of personal data breaches, including the facts relating to the incident, its effects, the corrective measures taken and, where applicable, the notifications made to the Commission and/or affected individuals.

Processors and service providers acting on behalf of Tamini are required to inform Tamini without undue delay of any actual or suspected personal data breach of which they become aware.


17. Your Rights

Subject to applicable law, you have rights over your personal data, including:

To exercise these rights free of charge, contact Tamini at the dedicated data protection address indicated in Section 2. Tamini may request verification of your identity before processing the request. Tamini responds without undue delay and, in any event, within the applicable legal timeframe, subject to the exceptions provided by law.


18. Marketing Communications

You may opt out of marketing communications at any time via the unsubscribe link in our messages, in the application settings where this feature is available, or by contacting Tamini.

Withdrawing marketing consent does not affect essential service communications related to your contracts, policies, claims, payments, legal obligations or security.


19. Children’s Privacy

Tamini’s digital services are not intended for children, meaning individuals under eighteen (18) years of age.

Tamini does not knowingly collect personal data relating to children without the appropriate authorization of a parent, legal guardian or legal representative, unless such collection is necessary within the legitimate framework of insurance services.

This may include situations where a child is designated as a beneficiary, insured person, dependent or person concerned by an insurance contract, insurance request or claim file initiated by a responsible adult.

Where personal data relating to a child is processed in this context, Tamini limits its collection and use to the information strictly necessary for the provision of insurance services, contract management, claims handling, compliance with legal and regulatory obligations, or the protection of the child’s rights and interests.

If Tamini becomes aware that personal data relating to a child has been collected or processed in a manner that does not comply with this Policy or applicable regulations, Tamini takes appropriate measures to delete, anonymize or regularize such data without undue delay, subject to applicable legal or regulatory retention obligations.


20. Social Media

When you interact with Tamini via social media, these platforms act as independent data controllers and apply their own privacy policies.

Tamini is responsible only for personal data that it directly receives and processes for its own purposes, for example when you send a private message to Tamini or when Tamini responds to your request.

We encourage you to avoid publicly sharing sensitive, financial, medical, identity, contract or claims-related data, and to use our secure channels for any matters relating to your policies or claims.


21. Third-Party Services

Our platforms may contain links to or integrations with third-party services. These services are provided by independent third parties and may apply their own terms and privacy policies.

Tamini is not responsible for the privacy practices of such third parties where they process data for their own purposes. We encourage you to review their respective privacy policies before using these services.


22. Automated Decision-Making

Tamini does not make decisions that produce legal effects concerning you or significantly affect you solely on the basis of automated processing of personal data, without appropriate human involvement.

As part of its insurance activities, Tamini may use certain automated tools to assist its teams with operations such as risk assessment, pricing, request management, anomaly detection or fraud prevention. These tools are used as decision-support instruments and do not replace human assessment where an important decision concerning you must be made.

Where the use of automated processing is likely to have a significant effect on your situation, Tamini implements appropriate safeguards, including the possibility to request human intervention, obtain useful information about the general logic of the processing, express your point of view and request a review or challenge of the decision, subject to legally protected secrets and applicable legal or regulatory obligations.

Tamini does not base significant automated decisions on special categories of personal data unless this is authorized by applicable regulations and accompanied by appropriate safeguards to protect your rights, freedoms and legitimate interests.


23. Changes to This Policy

This Policy may be updated periodically to reflect changes in our services, practices, providers, technical infrastructure or applicable regulations.

The most recent version is published on our website together with the last-updated date. In the event of a material change, Tamini notifies you through appropriate means, including via the website, application, email or service notification where relevant.


24. Contact

For any questions regarding this Policy or the processing of your personal data: