Broco Privacy Policy

Global

Effective September 17, 2026

This version applies to new commitments from its effective date. Notice rules and conditions applicable to existing customers are preserved; this publication is not a retroactive amendment of their contracts.

1. Scope and responsibility

This Policy explains how Broco Technologies, Inc. processes personal information in connection with its websites, applications, accounts, dashboards, APIs and enabled financial, payment, cash, merchant and logistics services.

Broco is incorporated in Delaware, United States. Its registered address is 1111B S Governors Avenue, Ste 96387, Dover, DE 19904, United States. Contact: support@broco.app.

Broco is responsible for processing where it determines why and how personal information is used. Financial-service, verification and other entities may be independently responsible for their own processing. Where an entity acts on another entity's instructions, its responsibilities follow the applicable arrangement and law. A service-specific notice explains additional processing where needed.

This Policy is separate from the General Terms. Acknowledging it does not provide blanket consent to optional processing. Additional country notices apply to the processing within their stated scope.

2. Information we collect

Depending on the features you use and your role, we may collect:

  • Identity and eligibility: name, date of birth, nationality, address, identity documents, photographs, selfie or liveness information, verification results, business registrations, beneficial-ownership and source-of-funds information. Sensitive or biometric verification information may be involved where the relevant process uses it.
  • Profile and contact: telephone number, email address, profile information, account settings, permissions and information about the organisation you represent.
  • Services and transactions: account, wallet, transfer, cash, merchant, card, subscription and payment records, including sender, recipient and beneficiary details.
  • Professional and logistics activity: merchant, agent, driver, transporter, fleet, shipment, delivery, scan and cash-reconciliation records associated with an enabled service.
  • Technical information: device identifiers, IP address, operating-system and application information, and access or usage information. Approximate or precise location may be processed where enabled or needed for a feature, with applicable permissions and notice.
  • Communications and choices: support messages, complaints, marketing preferences, cookie choices and analytics information where the relevant technology is used.

We obtain information from you, through use of the services, and from the entities involved in providing or protecting them. These may include financial and verification providers, merchants, logistics providers, telecom or billing providers, Business administrators and public sources. Information about recipients or beneficial owners may be supplied by another service user.

Where information is mandatory, the collection process explains why it is needed and the effect of not providing it. The information required may differ by service, country and risk profile.

3. Purposes and applicable grounds

PurposeUseGround where the applicable law requires one
Account administrationCreate profiles, manage access, authenticate users and communicate account information.Contractual necessity for requested functions; an identified legitimate interest for necessary account security where permitted.
Requested servicesHandle instructions, subscriptions, payments, merchant activity, delivery and reconciliation within Broco's role.Contractual necessity; applicable recordkeeping obligations where they bind Broco.
Verification and complianceEstablish eligibility and support identity, business, sanctions and financial-crime checks.A legal obligation directly applicable to Broco where one exists; otherwise the relevant necessary contractual or lawful interest basis. Another entity's obligation is not automatically Broco's legal obligation.
Security and disputesDetect misuse, investigate incidents and complaints, protect users and address claims.Applicable legal obligations or identified legitimate interests, assessed against individuals' rights where required.
Service improvementMaintain and improve platform functions and reliability.Legitimate interests where permitted and proportionate; consent where the relevant measurement requires it.
Optional marketingSend permitted product or promotional communications.Consent where required by privacy or communications rules; otherwise the specific lawful basis permitted for the channel and audience.

Contractual necessity covers information genuinely needed for the requested service. A legitimate-interest basis requires the relevant necessity and balancing assessment where applicable. We do not use it to replace consent where consent is required.

Sensitive or biometric processing needs the additional condition, consent or authorisation required by applicable law. The relevant collection notice explains the actual verification process and available choices. An operating-system permission alone does not supply every required legal basis.

4. Verification, automated checks and review

Verification, fraud prevention, sanctions screening, transaction monitoring and security may use automated assistance. Broco may access verification information through the relevant verification interface; the service notice must distinguish information available to Broco from information held only by another entity.

Where a decision is based solely on automated processing and has legal or similarly significant effects, the rights provided by applicable law remain available. The relevant notice must explain qualifying decisions, their significance and the required information about the process.

You can contact support to contest an eligibility or restriction decision and request human review where available or legally required. We will route the request to the entity responsible for that decision. Review does not guarantee approval of a service for which eligibility is not established.

5. Sharing information

We may share information necessary for an identified purpose with:

  • financial-service entities, banks, account infrastructure providers, card issuers and payment processors;
  • identity and business verification providers;
  • cash-service and agent networks;
  • merchants, ecommerce and fulfilment providers;
  • logistics companies, carriers, fleets and delivery participants;
  • telecom operators and billers;
  • cloud, communications, security and analytics providers;
  • the organisation you represent and its authorised administrators;
  • professional advisers and recipients authorised by you;
  • courts, regulators, law-enforcement bodies and authorities where disclosure is lawfully required or justified.

Recipients may process information on instructions or under their own responsibilities. Their role determines the applicable contractual controls and notice. Access to a professional profile does not authorise unrelated use of another person's information.

6. International processing

Broco is based in the United States and supports cross-border services. Information may be processed in the United States, the European Economic Area, the United Kingdom, countries where services are offered and locations used by the relevant providers.

The location of processing depends on the actual service and infrastructure. Incorporation does not determine the location of every record. Where a transfer is restricted, it must use the mechanism and any formalities required for that transfer. These may include applicable adequacy arrangements, contractual safeguards, local authorisations or another legally available mechanism.

This list is not a representation that every mechanism is in place for every flow. You can request information about the destinations and safeguards applicable to the processing affecting you. Relevant country notices must provide additional information required locally.

7. Retention

We retain information for the period necessary for its purpose and applicable obligations. Criteria differ by category:

  • profile information is needed while the relevant account or relationship is active, then for necessary closure, outstanding obligations or claims;
  • verification information is retained for the verification purpose and applicable lawful compliance or recordkeeping requirements;
  • transaction and accounting records are retained for applicable legal periods and necessary reconciliation or disputes;
  • support and complaint records are retained to handle the matter and any justified legal follow-up;
  • security and technical records are retained for proportionate incident investigation and protection;
  • consent and contractual-version records are retained where needed to demonstrate the choices and agreement concerned.

Closing an account does not delete records that must lawfully be retained. It also does not justify indefinite retention of every item. Where information is no longer needed, it must be deleted or effectively anonymised, subject to justified preservation requirements. A provider acting under its own responsibility may have a separate lawful retention period.

8. Rights and requests

Depending on applicable law, you may have rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent and protection in relation to qualifying automated decisions.

To exercise a right, contact support@broco.app, preferably with “Privacy request” in the subject. Describe the information or processing concerned. We may request information reasonably necessary to verify identity or authority; avoid sending unnecessary identity-document copies or authentication secrets.

We handle privacy requests without undue delay and within the deadlines required by applicable data-protection law. Any extension will be used only where legally permitted, with the information required by that law. If a request is limited or refused, we will explain the reason and available next steps to the extent permitted by law.

Withdrawal of consent does not affect lawful earlier processing. Other processing may continue only on its own valid basis. You may complain to the competent data-protection authority where applicable without first waiving or exhausting that right through Broco support.

9. Security

We use technical and organisational measures designed to protect information against unauthorised access, misuse, alteration, loss and disclosure. Appropriate measures may include access controls, authentication, secure transmission, monitoring and restrictions on personnel and provider access.

No storage or transmission system can be guaranteed completely secure. If an incident triggers a notification duty, the required authorities and individuals must be notified under the applicable rules. This Policy does not claim a security certification, fixed universal incident deadline or particular hosting location.

10. Marketing, cookies and permissions

You may opt out of optional marketing at any time through the channel's control or support. Necessary account, transaction, security and legal messages may continue.

The Cookie Policy describes the approach to cookies, SDKs and similar technologies. Where consent is required, optional technologies must remain inactive until a valid choice authorises them. Where available, you can change your choice through the relevant preferences control. App permissions and device settings may provide additional controls.

11. Age, other services and updates

Individual Broco accounts are intended for adults with the capacity required to contract. The minimum for residents of Algeria is 19; elsewhere the minimum is 18 and any higher applicable age of contractual capacity. We do not offer a minor-account service under these documents.

If information about a child is supplied in another workflow, its treatment must follow the applicable law; the account age restriction does not remove that responsibility.

Third-party services may have their own notices. Broco remains responsible for its own processing when an integration is used.

We may update this Policy as processing or law changes. The approved version will show its effective date, and changes will be communicated where required. Updating wording does not supply a missing legal basis or retroactive consent.

Privacy questions and complaints: support@broco.app.