1. Privacy Policy
1.1 Introduction
Porsa Sarl ("Porsa", "we", "us", "our") operates the Porsa commerce platform that enables merchants to sell goods and digital services across multiple markets. Protecting personal data is central to our mission. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use our Services.
This single policy includes provisions that apply generally (International) and specific references where local/regional law (CEMAC / UEMOA) requires adjustments.
1.2 Scope & Applicability
This policy applies to:
- All users of Porsa Services (merchants, customers, visitors).
- Data processed by Porsa Sarl and its subsidiaries, affiliates, and service providers.
- Processing in jurisdictions where Porsa operates, including but not limited to countries in CEMAC and UEMOA.
1.3 Types of Data We Collect
a) Information you provide:
Account registration (name, email, phone), business details (company name, RCCM/NIU), payment credentials for settlement (bank account, Mobile Money IDs), identity documents for KYC (ID card, passport), product data (descriptions, images), and communications with support.
b) Information we collect automatically:
IP address, device and browser type, cookies and similar technologies, pages visited, session duration, referral URL, performance logs, and transaction metadata (order amount, currency, timestamps, status).
c) Information from third parties:
Payment service providers (payment status, fraud scores), logistics partners (tracking status), KYC providers (identity verification results), public databases and law enforcement when required.
1.4 Purposes of Processing
We process personal data for the following primary purposes:
- To provide and operate the Services (account management, payment processing, settlement, order routing, digital delivery).
- To conduct KYC/AML checks and comply with applicable law (CEMAC / COBAC / UEMOA rules where applicable).
- To detect, prevent and investigate fraud, abuse or other unlawful activity.
- To communicate with users (service messages, transactional emails, legal notices, marketing with consent).
- To improve the Services and perform analytics and research.
- To comply with legal obligations, enforce our Terms, and protect rights and property.
1.5 Legal Bases for Processing
Where required by law, Porsa relies on one or more of the following legal bases:
- Performance of a contract (to provide Services you requested).
- Compliance with a legal obligation (KYC/AML, tax, recordkeeping).
- Legitimate interests (fraud prevention, platform security, analytics) — balanced against your rights.
- Consent (for marketing communications and non-essential cookies).
1.6 Specific Rules for CEMAC / UEMOA
- KYC and financial recordkeeping: Under regional financial regulation, Porsa must retain certain transaction and identity records for defined retention periods and share them with competent authorities upon lawful request.
- Cross-border payments and currency controls: Porsa may process and transfer payment-related data to partners outside the jurisdiction to facilitate settlements; such transfers will observe contractual safeguards.
- Consumer protections: For consumers within UEMOA member states, Porsa will respect local consumer rights regarding returns and refunds and will cooperate with regulators in those territories.
1.7 Data Sharing & Recipients
We may disclose personal data to:
- Payment processors and banks to authorize and settle transactions.
- Logistics and fulfillment partners to dispatch and deliver goods.
- KYC and fraud prevention vendors for identity checks and risk scoring.
- Service providers (hosting, email, analytics) acting as processors under contract.
- Law enforcement, tax or regulatory authorities when required by law or in response to legal processes.
Porsa does not sell personal data to data brokers or advertisers.
1.8 International Transfers
Your data may be transferred and stored in countries other than your country of residence (including servers in Europe, Africa, and North America). We will apply appropriate safeguards such as data processing agreements and standard contractual clauses where required by law.
1.9 Data Retention
We retain personal data only as long as necessary for the purposes described and to comply with legal obligations. Typical retention windows:
- Transaction and accounting records: 5–10 years (per regional rules).
- KYC records: as required by local law (often 5 years after account closure).
- Marketing consents: until withdrawn.
1.10 Security Measures
We implement administrative, technical and organizational measures including encryption in transit and at rest, access controls, logging and monitoring, vulnerability management, and regular security testing. We follow PCI-DSS standards for card data (when applicable).
1.11 Your Rights & How to Exercise Them
Depending on your jurisdiction, you may have rights to:
- Access and obtain a copy of personal data.
- Correct inaccurate or incomplete personal data.
- Delete or request deletion ("right to be forgotten"), subject to legal retention requirements.
- Restrict or object to certain processing.
- Data portability (receive a machine-readable copy).
- Withdraw consent where processing is based on consent.
To exercise rights, contact: privacy@porsa.io. We will respond within applicable legal timelines.
1.12 Cookies & Tracking
We use cookies for authentication, security, preferences, analytics, and advertising (optional). You can manage cookie preferences via your browser and via the cookie banner on our site.
1.13 Children
Porsa Services are not directed to children under 18. We do not knowingly collect personal data from minors.
1.14 Contact
If you have questions or complaints about this policy, contact: privacy@porsa.io or write to Porsa Sarl, Legal Department.
1.15 Changes to this Policy
We may update this Privacy Policy. Where required by law we will provide notice or obtain consent for material changes.