Frequently asked questions
Data residency, compliance, pricing, implementation, and more.
Where is my data stored?
All application data — sites, tasks, submissions, reports, and photos — is stored with Supabase, hosted on Amazon Web Services (AWS) in the eu-west-3 (Paris) region. Other AWS regions (e.g. af-south-1 Cape Town) can be configured for ministry clients on request.
Is data encrypted?
Yes. In transit, all traffic is encrypted with TLS 1.3. At rest, AWS applies AES-256 encryption. Session cookies are HttpOnly, Secure, and SameSite=Strict — they cannot be read by browser JavaScript, eliminating session theft via XSS.
Who can access our data?
Only your users, based on their assigned role (operator, supervisor, ministry, executive, admin). Row-level security (RLS) policies enforce these restrictions server-side. LevelThree engineers only access production on your explicit authorisation, via audited access.
Is Baobab GDPR-compliant?
Our architecture is designed around GDPR principles: data minimisation, encryption, right of access and erasure, and breach notification within 72 hours. We offer a Data Processing Agreement (DPA) before contract signing.
Can we request data deletion?
Yes. Deleting any user, site, or report is available directly in the application. Full organisation deletion (including backups) is performed within 30 days of contract termination, on request.
How does offline mode work?
Baobab is a Progressive Web App (PWA). Field operators can submit photo evidence and complete tasks without internet connectivity. Data is queued locally and synchronised automatically when connectivity returns.
What happens if synchronisation fails?
Pending submissions remain in the local queue until successfully synced. In the case of a permanent error (e.g. the task was archived in the meantime), the submission is flagged as non-syncable and the operator is prompted to contact their supervisor.
Do we need to install a mobile app?
No. Baobab is a PWA accessible from any mobile browser (Chrome, Safari). Operators can add it to their home screen for quick access without going through an app store. An initial connection is required; after that, offline mode is available.
What languages are supported?
French is the primary platform language. English is fully available as an option. PGES reports can be generated in either language according to client requirements.
How long does implementation take?
For a standard deployment (PTA import, role configuration, team training), we estimate 2–4 weeks from contract signing. Projects with complex organisational structures or custom integration needs may require more time.
What integrations are available?
Baobab integrates natively with Supabase (open database exportable as CSV/JSON), Twilio for SMS authentication codes, and Anthropic for PTA analysis and report drafting. We support PDF and DOCX report exports for ministry submissions.
How is pricing structured?
Pricing is based on the number of active projects and users. We offer annual licences for enterprises and pricing adapted to African public administrations. Contact us for a quote.
Can we get a Data Processing Agreement (DPA)?
Yes, a GDPR-compliant DPA is available on request before contract signing. It defines our obligations as a processor, the data processed, the purposes, and the security measures in place.
What is the platform uptime?
Baobab is deployed on Vercel and Supabase, both of which publish real-time status pages. Our contractual target is 99.5% uptime outside planned maintenance windows. Offline operations are unaffected by service interruptions.
How do we get started?
Fill out the contact form to schedule a demo or request access to the test environment. We guide you from importing your first PTA through to training your field teams.