Privacy Policy
This English version is provided for convenience. In case of any discrepancy, the French version prevails.
Last updated: August 11, 2026 Version: 2.4
Completion note: only one field depending on a real-world event that has not yet occurred remains unfilled (IPDCP acknowledgment number, since the declaration has not yet been sent). Everything that could be inferred from discussions with the project owner has been filled in.
1. Who we are
SANZA is a business management application (invoicing, mobile money collection, accounting) published and operated by BAHINIBA, a single-member limited liability company (SARLU) with share capital of 1,000,000 FCFA, registered in the trade register under number TG-LFW-01-2024-B13-00256, tax ID (NIF) 11001918218, whose registered office is located at Adidogomé, Lomé, Togo (hereinafter "BAHINIBA" or "we"). SANZA is a brand and a product of BAHINIBA.
BAHINIBA is the controller of the data described in this policy, except where it acts as a processor as specified in section 3.
This policy applies to the public website sanza.cloud and the application app.sanza.cloud.
2. Legal framework
We process personal data in accordance with the laws applicable in our markets, in particular:
- Togolese law no. 2019-014 of 29 October 2019 on the protection of personal data, under the supervision of the IPDCP (Personal Data Protection Authority), Togo being BAHINIBA's country of establishment;
- Ivorian law no. 2013-450 of 19 June 2013 on the protection of personal data, under the supervision of the ARTCI;
- ECOWAS Supplementary Act A/SA.1/01/10 of 16 February 2010 on the protection of personal data;
- the African Union Convention on Cybersecurity and Personal Data Protection (Malabo Convention, 2014), ratified by Togo.
BAHINIBA completes the formalities required with the IPDCP in Togo, BAHINIBA's country of establishment. [[ TO COMPLETE: the preliminary referral letter has not yet been sent as of this writing — no acknowledgment can therefore exist yet. To be filled in once the process has been initiated and the acknowledgment obtained. ]]
Policy applicable to countries where BAHINIBA operates without a stable establishment. For any country other than Togo, BAHINIBA applies a policy of substantive compliance without a formal prior declaration to the local authority: a register of processing activities extended to that country, a single data protection correspondent (section 9) competent for all countries, exercise of rights under the same procedures as in Togo (section 9), breach notification under the same protocol (section 8). Formal declaration to the local authority becomes mandatory, country by country, upon the first of the following two events: the opening of a local legal entity in that country, or reaching a threshold of 50 active clients in that country. The table of authorities and applicable legal references by country appears in the annex to this document and is kept up to date as countries are activated.
3. Two distinct roles, one clear rule
a) Your account data: BAHINIBA is the controller. When you create an account, subscribe or contact us, we determine the purposes and means of processing.
b) Data entered by your company: BAHINIBA is the processor. Your customer records, invoices, employees and accounting entries belong to your company, which is the controller. We host and process them solely to provide the service, on your instructions, under the terms of the Data Processing Agreement annexed to the Terms. We never sell them, never rent them and never use them for advertising purposes.
4. Data we collect
| Category | Examples | Legal basis |
|---|---|---|
| Account data | Name, phone number, email, associated company, role | Performance of the contract (art. 14 §3) |
| Company data | Business name, RCCM, NCC/NIF, logo, tax settings | Performance of the contract |
| Subscription data | Plan subscribed, payment history, mobile money number used to pay | Performance of the contract and accounting obligations (art. 22 §8) |
| Data entered in the application | Customers, products, invoices, payments, employees, entries | Processing on behalf of your company |
| Health data (payroll only) | Sick leave of employees in the payroll module | Art. 22 §7 and §8 (performance of employment contract, statutory social obligation) |
| Technical data | Connection logs, device type, error logs | Legitimate interest (security, service improvement) |
| Documents sent to the AI assistant | Invoice photos and questions asked | Performance of the contract, on the user's voluntary action |
We collect no biometric data, no genetic data, and no data relating to criminal offences or convictions. The only sensitive data within the meaning of the Law that may be processed are health data strictly limited to sick leave in the payroll module, on the basis of article 22 paragraphs 7 and 8 (performance of employment contract, statutory social obligation): these data are processed on behalf of the employer company, under restricted access. We do not use any advertising cookies. On the public website, audience measurement is provided by Vercel Analytics, which places no cookies and does not allow you to be identified individually. Within the application, usage statistics are calculated from your account data, with no third-party tracker.
5. Purposes
We use this data to: provide the service and its features (invoicing, collection, reminders, AI-assisted accounting), manage your subscription and its billing, ensure platform security and the traceability of sensitive actions (audit log), assist you via support, comply with our legal and tax obligations, and improve the service using aggregated and anonymized data.
Transmission to national tax platforms (legal obligation). In countries where certified electronic invoicing is activated for SANZA (list and status published on the website), the data of invoices issued by your company are automatically transmitted to the national tax platform of the relevant country. In particular, in Côte d'Ivoire, these data are transmitted to the Directorate General of Taxes (DGI) via the FNE platform, in accordance with articles 384-385 of the General Tax Code and the decree 0337/MFB/DGI of 9 May 2025. This transmission arises from a legal obligation to which your company is subject as a taxpayer, and with which BAHINIBA complies as technical provider of the integration, on the basis of article 22 paragraph 8 of Law 2019-014. For countries whose certified invoicing regime has not yet been confirmed by the competent authorities, no such transmission takes place.
6. Recipients and processors
Your data is accessible only to our authorized team and to the technical providers strictly necessary for the service:
| Provider | Role | Location |
|---|---|---|
| Supabase Pte. Ltd. | Database, authentication, storage | Singapore (contracting entity) / data hosted in Europe, Paris (eu-west-3) |
| Vercel Inc. | Application hosting and public website audience measurement (Vercel Analytics) | United States / global network |
| Anthropic PBC | AI processing (document reading, assistant) | United States |
| Meta Platforms (WhatsApp Business) | Sending invoices, reminders and notifications | United States / Ireland |
| 360dialog GmbH | Technical intermediary for WhatsApp Business API (Meta) access, transits the same messages | Germany (European Union) |
| Twilio Inc. | Backup SMS in case of WhatsApp delivery failure | United States |
| CinetPay | Mobile money and card payment collection, primary aggregator retained, UEMOA coverage | Côte d'Ivoire |
Directorate General of Taxes of Côte d'Ivoire (DGI-CI, FNE platform fne.dgi.gouv.ci) | Certification of invoices issued by Ivorian client companies (legal obligation) | Côte d'Ivoire |
| Sentry | Technical error logs | United States |
| Referenced accounting partner (with the client's explicit authorization) | Advisory access to the data of the client company that engaged them, within the limits that company has authorized | Partner's country of practice |
Some of these providers are located outside ECOWAS. These transfers are governed by contractual data protection commitments at least equivalent to those of this policy, under the conditions of articles 28 to 31 of Law 2019-014. Access by our support team, or by a referenced accounting partner, to a client account is only possible with the client's explicit authorization, recorded in the audit log.
We disclose your data to authorities only upon valid legal request.
7. Retention periods
- Account data and company data: for the entire duration of the subscription.
- After termination or suspension: data is kept for 12 months, to allow you to reactivate your account or obtain an export of your data, then permanently deleted. Three prior notices are sent to you before any deletion: at D-90 (three months before), at D-30 with a one-click export offer, and at D-7. No deletion occurs until these three notices have been effectively delivered.
- Subscription billing data: 10 years, in accordance with OHADA accounting obligations.
- Technical and security logs: 12 months.
- Register of rights-exercise requests: kept indefinitely for evidential purposes in the event of a control by the IPDCP or ARTCI.
8. Security
We apply technical and organizational measures proportionate to the sensitivity of the data, pursuant to article 52 of Law 2019-014: encryption in transit (TLS) and at rest, strict data isolation between companies (database-level security policies, automatically tested), available reinforced authentication, audit log of sensitive actions, regular backups with restoration tests, access restrictions by role matrix.
In the event of a data breach likely to create a risk to your rights, we notify the competent authority and the affected clients within a maximum of 72 hours after becoming aware of it.
9. Your rights
In accordance with applicable laws, you have the rights of access (art. 39), rectification (art. 46), deletion and erasure (art. 47), objection (art. 45) and portability of your data. The application directly integrates: full export of your company's data (JSON and CSV formats) and the request for permanent account deletion.
These rights remain available to you whatever the status of your account. Where the application's automatic export function is temporarily disabled, in particular in the event of non-payment, an export request sent to support is honoured within the same timeframes.
Rights over data after death (art. 50). The heirs of a deceased person who justify their identity may contact us so that the death is taken into account and the necessary updates are made, at no cost.
Data protection correspondent. BAHINIBA has appointed, pursuant to articles 75 to 78 of Law 2019-014, Mr KOUASSI N. Emmanuel, Manager, as data protection correspondent.
To exercise your rights or to contact the correspondent: dpo@bahiniba.com. We respond within a maximum of 30 days pursuant to article 46 paragraph 2.
If you believe your rights are not being respected, you may refer the matter to the competent supervisory authority: the IPDCP in Togo (contact@ipdcp.tg, Agoè 2 Lions, Lomé, +228 22 25 13 34) or ARTCI in Côte d'Ivoire (artci.ci).
10. Service notifications and commercial communications
We distinguish two categories of messages, sent by WhatsApp, SMS or email:
- Service notifications, inseparable from the contract: reminders before the due date, non-payment follow-ups, suspension notices, security alerts, notifications before permanent data deletion, and information about service changes. These cannot be unsubscribed from while the account is active, as they are essential to the proper performance of the contract.
- Commercial communications (offers, news, content, invitations): these are sent only with your consent and you may unsubscribe at any time, from your settings or via the unsubscribe link, without this affecting service notifications or the quality of the service provided. This prior consent requirement is pursuant to article 26 of Law 2019-014.
11. Minors
The service is intended exclusively for professionals. It is not intended for persons under 18 years of age.
12. Changes to this policy
Any substantial change is notified in the application and by WhatsApp or email at least 30 days before it takes effect. The version in force and its date appear at the top of this document.
13. Contact
BAHINIBA, Adidogomé, Lomé, Togo. Data protection correspondent email: dpo@bahiniba.com. WhatsApp: +228 71675944.
Technical annex — authorities and legal references by country
Table kept up to date as countries are activated (section 2). A confidence level of "to be verified" or "uncertain" means the authority or legal reference indicated has not yet been confirmed by a primary official source; it does not affect the substantive compliance commitments described in section 2, which apply from the country's activation regardless of this level.
| Country | Authority | Legal reference | Confidence level |
|---|---|---|---|
| Togo | IPDCP | Law no. 2019-014 of 21 May 2019 | Confirmed — BAHINIBA's country of establishment |
| Côte d'Ivoire | ARTCI | Law no. 2013-450 of 19 June 2013 | Confirmed |
| Senegal | CDP | Law no. 2008-12 of 25 January 2008 | Confirmed |
| Benin | APDP | Precise legal reference to be confirmed | To be verified |
| Niger | HAPDP | Precise legal reference to be confirmed | To be verified |
| Mali | APDP | 2013 law (precise reference to be confirmed) | To be verified |
| Burkina Faso | CIL | Precise legal reference to be confirmed | To be verified |
| Cameroon | Authority not identified with certainty | Not confirmed | Uncertain |
| Guinea-Conakry | Authority not confirmed with certainty | Not identified | Uncertain |