1. Who we are and what this Policy covers
Broco Technologies, Inc. (“Broco”, “we”, “us”) is a company incorporated in Delaware, United States, with its registered address at 1111B S Governors Avenue, Ste 96387, Dover, DE 19904, United States. For privacy questions or requests, contact support@broco.app, with “Privacy — Senegal” in the subject.
This Policy explains our use of personal information in connection with Broco websites, applications, profiles, dashboards, APIs and services used in Senegal. It covers Personal users and the individuals involved with Pro and Business profiles, including representatives, beneficial owners, administrators, staff, merchants, agents, transporters, senders and recipients. You can have privacy rights even if you do not hold a Broco account.
The country-specific provisions reflect Law No. 2008-12 of 25 January 2008 on the protection of personal data and its applicable implementing rules, where that law applies to the processing. Selecting a country or using English does not change the law that protects you. This is a standalone Policy: you do not need to combine it with the Global Privacy Policy to understand the processing described here. A notice provided at a particular collection point adds details for that operation and cannot reduce mandatory rights.
We are the controller where we determine the purposes and means of processing. Where we process an organisation's information solely on its instructions, the applicable processing arrangement governs that activity. A financial-service entity, merchant or other participant may be independently responsible for its own processing. We remain responsible for the processing that is ours.
This Policy provides information. It is not a blanket consent, a financial-service agreement or a guarantee that every catalogue service is available.
2. Information involved
The information depends on your role and the functions you use.
| Category | Information and context |
|---|---|
| Profile and contact | Name, contact details, address, account identifiers, preferences and profile settings. |
| Identity and eligibility | Date of birth, nationality or residence, identity-document information, photographs, verification results, business registration, ownership, authorised representatives and source-of-funds information required for the relevant checks. |
| Verification images | Selfie or liveness information and, where the actual verification process uses it, biometric information subject to the additional legal requirements. |
| Accounts and transactions | Funding references, balance and ledger entries, instructions, amounts, currencies, fees, transaction status, counterparties, recipients, merchant or bill references, card-related records and subscription records. |
| Professional and delivery activity | Permissions, business activity, agent or transporter references, orders, shipment and delivery evidence, cash handovers and reconciliation records. |
| Device and use | IP address, device and application identifiers, operating-system information, access and security events, and use of enabled functions. Location information is limited to the relevant feature and applicable permissions. |
| Communications and choices | Support correspondence, complaints, privacy requests, consent or objection records and marketing preferences. Cookie or analytics information depends on the technologies actually used and applicable choices. |
A list of possible categories does not mean every category is collected from every person. We do not require sensitive information simply because it appears in an identity document. Collection and access must be limited to what is needed and lawfully permitted.
For services enabled in Senegal, information may include transfer instructions, beneficiary and payout details, local cash receipts, merchant payments and bill or digital-service references. Availability of a transfer route does not mean that all countries, directions or currencies are supported. Recipient information is used for the requested operation and applicable checks, rather than automatically for marketing.
3. Where information comes from and what you must provide
Information comes from you, your authorised representatives, your use of Broco, and the participants involved in an enabled service. Depending on the operation, these may include verification and financial-service entities, your organisation's administrators, merchants, cash agents, delivery participants, billers and lawful public sources. A sender may provide recipient details; a business may provide details of its authorised staff or beneficial owners. Indirect collection remains subject to applicable notice and collection requirements.
If you supply another person's information, provide only what the operation requires and make sure you have authority or another lawful basis to supply it. Where applicable, that person must receive the relevant privacy information. This does not transfer Broco's own notice obligations to you.
Required fields or supporting information relate to the requested function, security or an applicable legal requirement. If necessary information is missing, we may be unable to open the requested profile, verify eligibility or complete that operation. Refusing optional marketing or unrelated analytics does not, by itself, prevent use of the core service.
4. Why we use information and on what basis
We use the relevant information for:
- opening and administering profiles, managing permissions and authenticating access;
- handling requested funding, transfers, payments, purchases, subscriptions, delivery and reconciliation within our role;
- assessing eligibility, supporting identity and business checks, and carrying out financial-crime or sanctions checks where applicable;
- preventing misuse, investigating incidents, handling complaints and establishing or defending legal claims;
- communicating transaction, security, account and service information;
- maintaining the reliability of the platform and understanding permitted usage information;
- optional marketing and measurement where the required choice or other lawful basis exists.
For processing governed by Senegalese law, we use consent or an applicable statutory ground for necessary processing, such as a legal obligation, the contract or requested pre-contractual steps, protection of vital interests, or a legitimate interest subject to the individual's protected rights. A financial-service entity's legal obligation is not automatically an obligation binding Broco.
Direct marketing using personal information requires the prior consent prescribed by Article 47. Sensitive information, biometrics and processing requiring specific authorisation remain subject to their additional conditions. Permission to make one payment is not permission to add its recipient to a marketing list.
Processing necessary for a service is limited to that purpose. Broco does not rely on another entity's regulatory duties as an automatic justification for unrelated collection or indefinite retention. A new, incompatible purpose requires a separate lawful basis and the information or consent required before that use.
5. Verification and decisions
Checks may use automated tools to compare submitted information, identify unusual activity or assist eligibility and security decisions. Broco may access information through the verification interface for its permitted functions. That access does not mean that Broco stores a separate copy of every document held by a verification entity.
The relevant verification notice explains additional sensitive-data processing, its purpose and the applicable choice or legal condition. An operating-system camera permission is not blanket consent to every use of an image.
If a decision affects your access to a service or a transaction, you may contact support to challenge inaccurate information, explain your circumstances and request human review where provided or required. We handle the request within our role and direct you to the responsible decision-maker where another entity makes the decision. Applicable restrictions on decisions based solely on automated processing, and rights to the required explanation and review, remain effective. A review does not guarantee eligibility.
6. Who receives information
Information may be disclosed, only to the extent needed for the relevant purpose and legally permitted, to:
- financial-service and payment entities for account functions, card-related operations, execution, settlement, checks and disputes;
- identity and business-verification providers for the requested checks;
- merchants, recipients, agents, billers and delivery participants for their part of an instruction, sale, cash operation or delivery;
- cloud, communications, security and technical-service providers supporting the platform;
- analytics or marketing providers where that processing is permitted by the applicable choice and law;
- authorised administrators of the organisation whose profile you use;
- advisers, courts, regulators and public authorities where disclosure has a lawful basis;
- a person you validly authorise to receive specified information.
An agent, merchant or transporter does not need unrelated identity or financial records merely because they participate in one operation. Business administrators' access is limited by their role and the legitimate needs of that organisation.
Entities acting on our instructions are subject to the applicable confidentiality, security and processing requirements. Independent controllers remain responsible for their own notices and uses. Where a recipient's identity, address or other specific information must be disclosed, that information must accompany the relevant operation or collection notice; a generic category does not replace a mandatory disclosure.
7. Processing outside Senegal
Broco is based in the United States. An enabled service may involve foreign financial, verification, technical or support infrastructure and cross-border access. Your country selection does not guarantee that every record stays in Senegal. The actual destinations depend on the operation and infrastructure; incorporation alone does not establish the storage location of every record.
Transfers subject to Senegalese law are governed by Articles 49–51 of Law No. 2008-12. These include prior information to the CDP and the required level of protection. The statutory exceptions for a transfer that is occasional and non-massive cannot be treated as a blanket basis for routine foreign hosting. Where the destination does not provide the required protection, an applicable exception or CDP authorisation supported by sufficient safeguards is necessary.
You may request information about the destinations, recipient roles and safeguards relevant to your information by contacting support. Information legally required before collection or transfer must be provided at that stage, rather than only after a request. Neither a privacy notice nor your acceptance of terms establishes that a regulatory formality has been completed.
8. How long information is kept
Retention follows the purpose, applicable legal requirements and any justified dispute or preservation need. Different records can have different starting events and periods.
| Records | Retention approach |
|---|---|
| Account and profile records | While needed for the relationship, then for necessary closure, outstanding obligations and applicable claims or recordkeeping. |
| Identity and verification information | For the check and the legal or justified compliance purpose applying to that record; not automatically for as long as any transaction record. |
| Transaction, invoice and reconciliation records | For the accounting, financial, contractual or dispute period applicable to the entity and operation concerned. |
| Support, complaints and privacy requests | For handling the matter and justified follow-up, rights enforcement or evidence of the response. |
| Technical and security records | For proportionate maintenance, detection and investigation needs, with longer preservation limited to a justified incident or obligation. |
| Consent and marketing choices | For the relevant choice and necessary evidence; a limited suppression record may be retained to respect an opt-out. |
The applicable collection or service notice supplies a specific retention period where the law requires one. You may ask for the period and trigger relevant to a particular record. These criteria do not permit unlimited retention or replace a mandatory disclosure of duration.
When information is no longer required, it is deleted or effectively anonymised, subject to lawful preservation and destruction procedures. Closing an account does not remove a record that must legally be kept, and is not a reason to retain every record indefinitely. An independent controller may have its own lawful retention obligations.
9. Your rights in Senegal
Under Senegalese law, you may request confirmation of processing, accessible copies of your information, its available origin, purposes, recipients and relevant foreign-transfer information. You may request correction, completion, updating, blocking or deletion of information that is inaccurate, incomplete, ambiguous, outdated or unlawfully collected, used, disclosed or retained.
For a written request under Article 69, the controller must demonstrate that the required corrective action has been taken, without charge, within one month after registration of the request. Where relevant, recipients must be notified of the corrective action. You may object on legitimate grounds, subject to the legal-obligation exception, and oppose use or disclosure for direct marketing. Consent-based processing remains subject to withdrawal.
Rights can be subject to conditions that protect other individuals, an applicable legal obligation or a legally protected investigation. We explain a limitation or refusal and the available next steps to the extent permitted. A request is not rejected simply because you no longer have an active account. Any additional right arising under another applicable law remains available.
10. How to make a request or complaint
Email support@broco.app and identify the right or concern, the relevant country and enough information to locate the record. You can also write to Broco at the registered address in section 1. Do not include your password, authentication codes or unnecessary complete identity documents.
We may ask for proportionate information to verify identity or representative authority and protect another person's information. A guardian, authorised representative or other person entitled by law may act within that authority. Verification is not used to frustrate a valid request.
Requests follow the applicable legal deadline and procedure, including the country-specific rules above. Where correction must be notified to recipients, we take the action required by law. Contact support promptly if a matter remains unresolved; an internal escalation does not suspend a statutory complaint deadline.
You may contact Commission de Protection des Données Personnelles (CDP) through its official website. You do not have to waive a right or exhaust Broco support before using an available regulatory or judicial remedy.
11. Security and incidents
We use technical and organisational measures designed to protect information against unauthorised access, loss, misuse, alteration and disclosure. Access must be appropriate to a person's responsibilities, and personnel and service providers must respect applicable confidentiality duties.
No method of transmission or storage can be guaranteed completely secure. Report suspected account compromise or exposure to support promptly. Where an incident requires notification, Broco must notify the competent authority and affected individuals in accordance with the applicable thresholds, timing and content requirements. This Policy does not claim a certification, a particular hosting region or an absolute security guarantee.
12. Cookies, marketing and device choices
The Cookie Policy explains cookies and similar technologies. Necessary technologies support requested functions such as session security. Optional technologies are subject to the applicable notice and choice requirements; consent is obtained where required before activation. Browser or device controls may affect how a function works.
You may stop optional marketing through the message's available unsubscribe control or by contacting support. Necessary account, transaction, security and legal communications may continue. Refusing optional marketing does not remove access to mandatory support or privacy rights. Device permissions can be reviewed in device settings; withdrawing a permission may prevent the specific feature that requires it.
13. Age, other notices and changes
Broco individual accounts are intended for people aged at least 18 who have the contractual capacity and eligibility required for the service.
Information about a child supplied in another context remains protected by the applicable law. Contact support if you believe it has been collected improperly.
An external website or independent service may provide its own privacy information. An integration does not remove Broco's responsibilities for its own processing. A profile held by a company can still contain protected information about natural persons.
We update this Policy when the relevant processing or requirements change. The published version identifies its applicable date, and we communicate changes where required. An update does not retroactively authorise incompatible processing or replace a consent or authorisation that must be obtained separately.
Privacy contact: support@broco.app.
