Legal
Privacy Policy
Version 1.0 · Effective 12 Sep 2026
Version: 1.0 (draft for legal review) · Last updated: 10 September 2026 · Effective: 10 September 2026
Draft. This document has not yet been reviewed by counsel and contains placeholders in — that must be completed before it takes effect. See §21 for the standard it is written to and why.
1\. Who is responsible for your data
Bizik (“Bizik”, “we”, “us”), RCCM —, registered at —, Republic of Cameroon, decides why and how your personal data is processed when you use the Bizik website, apps, and WhatsApp service (the “Platform”). In data-protection language, we are the controller.
Data-protection contact: privacy@bizik.com Postal: —
Where you use Bizik on WhatsApp, WhatsApp Ireland Ltd / Meta is a separate controller for the messaging layer itself, under its own policy. We control what we do with the content of your messages once they reach us. See §16.
2\. The short version
| What we collect | Who you are, how to reach you, your identity documents and face, your Deals and payments, your messages to us, and technical data about your device |
| Why | To run escrow and payments, to verify identity because the law requires it, to prevent fraud and money laundering, to resolve disputes, and to improve the service |
| The sensitive part | Your face, processed biometrically to check that the person holding the ID is the person on it. §5 explains this in full |
| Who sees it | Your counterparty sees your name and handle. Our staff see what their role requires. Named third parties process on our instructions (§11). Authorities receive what we are legally obliged to give them |
| Where it goes | Outside Cameroon, including to the EU and the United States (§13) |
| How long | Identity and transaction records for 10 years after the relationship ends, because financial-crime law requires it. WhatsApp chat logs for 90 days (§9) |
| Your rights | Access, correction, deletion where the law allows, objection, portability, complaint (§14) |
| We never | Sell your data, or use it for advertising by third parties |
3\. What we collect, and where it comes from
3.1 Data you give us
Account and identity
- Full legal name; phone number; email address (optional for end users); country; preferred language; date of birth where collected; your Bizik handle.
- Password (stored only as a cryptographic hash, never in readable form).
- Transaction PIN (stored only as a hash).
Identity verification — see §4 and §5
- Identity-document type (national ID, passport, driving licence, voter’s card) and number.
- Photographs of the front and back of the document.
- A selfie of you holding the document.
Financial
- Mobile Money numbers and bank or payout details you register.
- The amounts, currencies, counterparties, descriptions and dates of your Deals and transfers.
- The source of funds and source of wealth information we ask for when we are required to.
Content you create
- Deal titles, descriptions, notes, milestone definitions and delivery dates.
- Delivery submissions and any files attached to them.
- Dispute descriptions, evidence files and messages.
- Support tickets and their attachments.
- Reviews and ratings you leave.
Communications
- Messages you send the Bizik assistant on WhatsApp, including voice notes, which are transcribed to text.
- Emails, SMS and in-app messages between you and us.
3.2 Data we generate about you
- Your account status, verification tier and the history of both.
- Your transaction ledger, balances and escrow positions.
- Risk, fraud and sanctions-screening outcomes, and any alert or case they generate.
- The audit log: a record of significant actions on your account, who performed them, when, and whether they succeeded.
- Scores and findings produced by our image analysis (§7).
- Notification and message-delivery records.
3.3 Data collected automatically
- IP address; device type, operating system and app version; browser type.
- Timestamps of access, session identifiers, and authentication events.
- Cookies and similar technologies on the web apps — see the Cookie Policy.
- Approximate location derived from IP address, used for fraud and sanctions purposes. We do not collect precise GPS location.
3.4 Data from others
- Your counterparty, who may enter your phone number and a name of their own choosing when inviting you to a Deal. That name is their reference for you; it does not become your account name.
- Payment providers — Mobile Money operators, banks, and our payment aggregator — who tell us whether a payment succeeded, and may return the name registered to a number.
- Sanctions, politically-exposed-person and adverse-media list providers.
- Identity-verification providers, if and when enabled for your market (§11).
4\. Identity documents
An identity document is sensitive by nature. We handle it as follows.
- Where it is stored. Document images are held in private storage that is not publicly addressable and not served from a public URL. They are retrievable only by an authenticated reviewer with the relevant permission, and every retrieval is recorded in the audit log.
- Your ID number is encrypted at rest with a dedicated key, separately from the rest of your record.
- Uploads are sanitised. Every image you send is decoded and re-encoded before it is stored. This removes embedded metadata — including camera identifiers and any location the camera recorded — and destroys anything concealed in the file by steganography. The stored image is a clean re-rendering of the picture, not the file you sent.
- Who can see it. Only staff whose role includes identity review, and only for as long as that is their role. Access is controlled by permission, not by seniority.
- What we do not do. We do not publish your documents, do not show them to your counterparty, and do not use them for anything other than verification, fraud prevention, and meeting our legal obligations.
5\. Your face: biometric data
⚠ Read this section. It describes the most sensitive processing we carry out.
5.1 What we do
When you submit a selfie holding your identity document, we perform two separate operations:
- Face detection — locating a face in the selfie and in the photograph on your document.
- Face comparison — computing a mathematical representation (an “embedding” or template) of each face and measuring the similarity between the two, to assess whether the person holding the document is the person the document depicts.
The second operation processes biometric data for the purpose of uniquely identifying a natural person. In jurisdictions that recognise the category — including under the GDPR for our European users — that is a special category of personal data and attracts heightened protection.
5.2 Why we do it
Because identity is the control on which every other control depends. Without a face check, a stolen identity document is enough to open a verified account, send money and disappear. We do it to prevent that, and because the anti-money-laundering rules described in the AML / KYC Policy require us to satisfy ourselves that you are who you say you are.
5.3 Our legal basis
- Cameroon and other markets: your explicit consent, given when you begin verification, together with our need to comply with anti-money-laundering and counter-terrorist-financing obligations and to prevent fraud.
- EU / UK users: Article 9(2)(a) GDPR (explicit consent), with Article 9(2)(g) (substantial public interest in preventing financial crime) and Article 9(2)(f) (establishment, exercise or defence of legal claims) relied on where applicable.
You can refuse. If you do not want your face processed biometrically, do not submit a selfie. You may still hold an account, receive money, view your Deals and pay a Deal. You will not be able to create a Deal, send money or withdraw, because those require a verified account. Contact us at privacy@bizik.com to ask about an alternative verification route.
5.4 Where the comparison happens
The face detection and face comparison are performed by software operated by us on our own infrastructure. Your selfie and your document photograph are not sent to an external biometric service for that comparison.
Where a market requires the use of an external identity-verification provider, we will tell you before you submit, and that provider is named in §11.
5.5 What is kept
We keep the result of the comparison — a similarity score and a pass/fail finding — as part of your verification record. The intermediate mathematical templates are not retained as a searchable biometric database, and we do not use your face to search for you across our records or anyone else’s.
5.6 What we do not do
We do not use your face for surveillance, for emotion or demographic inference, for training a general-purpose model, for advertising, or to identify you outside the verification process.
6\. Why we use your data, and our legal basis for each purpose
| # | Purpose | Data used | Legal basis |
|---|---|---|---|
| 1 | Create and run your account | Account, contact, credentials | Performance of our contract with you |
| 2 | Operate escrow, wallets, transfers, withdrawals | Financial, transaction, payout details | Performance of contract |
| 3 | Verify your identity | Identity documents, selfie, biometric comparison | Legal obligation (AML/CFT); explicit consent for the biometric element |
| 4 | Screen against sanctions and PEP lists, monitor for suspicious activity, report to ANIF | Identity, transaction, behavioural | Legal obligation |
| 5 | Prevent, detect and investigate fraud and abuse | Nearly all categories, including device and IP | Legitimate interests — protecting users and the platform; legal obligation |
| 6 | Resolve disputes between users | Deal content, evidence, messages, transaction history | Performance of contract; legitimate interests |
| 7 | Provide support | Tickets, messages, account data | Performance of contract; legitimate interests |
| 8 | Send service messages (a delivery submitted, a payment received, a reminder) | Contact details, Deal state | Performance of contract |
| 9 | Send the weekly summary email | Transaction history, contact details | Legitimate interests; you may opt out |
| 10 | Operate the WhatsApp assistant, including voice transcription | Message content, account context | Performance of contract |
| 11 | Keep the audit log | Action records | Legal obligation; legitimate interests in accountability |
| 12 | Secure the Platform | Technical, authentication, device | Legitimate interests; legal obligation |
| 13 | Analyse and improve the Services | Aggregated and, where possible, anonymised usage | Legitimate interests |
| 14 | Comply with tax, accounting, court orders and regulatory requests | As required | Legal obligation |
| 15 | Establish, exercise or defend legal claims | As relevant | Legitimate interests; legal claims |
| 16 | Marketing about Bizik’s own services | Contact details | Consent, or legitimate interests where the law permits. You may opt out at any time |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded that the processing is proportionate. You may ask us for that assessment, and you may object (§14).
7\. The image analysis, and what it does not do
When you submit verification documents, an automated analysis runs. It measures things that can be measured:
- whether a face is present in the selfie and in the document photograph, and how similar they are;
- whether the document image is sharp enough, well-enough lit and detailed enough to be read;
- whether the image looks like a photograph of a screen rather than of a document;
- whether text is present where a document would have text.
It produces a set of findings — each with a reason in plain language — and a suggested outcome of approve, reject or take a closer look.
⚠ The analysis does not decide anything. A named reviewer reads the findings and the documents and makes the decision. See §8.
Where the analysis has not run — for example because the service was unavailable — your record says so, rather than showing invented scores.
8\. Automated decision-making
We do not subject you to a decision producing legal effects or similarly significantly affecting you that is based solely on automated processing, except as set out below.
- Identity verification is decided by a person. Automatic approval on passing scores is a setting that is switched off. If we ever switch it on for a market, we will tell you before it applies to you, explain the logic in general terms, and give you the right to obtain human intervention, to express your point of view and to contest the outcome.
- Sanctions screening may automatically place an account on hold pending human review. That hold is a precaution, not a final decision; a person reviews it.
- Fraud rules may automatically decline or delay a transaction, or hold a large withdrawal for review. You can ask us to look again.
- The WhatsApp assistant proposes, it never executes. No money moves without your explicit confirmation and, where enabled, your PIN.
In every case you may contact privacy@bizik.com to ask for human review and to contest the outcome.
9\. How long we keep your data
| Data | Retention | Why |
|---|---|---|
| Identity documents, verification records, biometric comparison results | 10 years after the end of the business relationship | Anti-money-laundering record-keeping obligations |
| Transaction records, ledger, escrow history, Deal records | 10 years after the transaction | AML and accounting/tax obligations |
| Account and contact details | Life of the account, then 10 years | As above |
| Suspicious-activity reports and their supporting records | 10 years, or longer if an investigation is open | Legal obligation; retained even if you close the account |
| Dispute records, evidence and rulings | 10 years, or until any claim is time-barred if longer | Defence of legal claims |
| WhatsApp message logs | 90 days, then automatically purged nightly | Support and compliance need, kept no longer than necessary |
| WhatsApp conversation session context | 30 minutes of inactivity | Operational only |
| Support tickets | 3 years after closure | Service quality; defence of claims |
| Audit log | 10 years | Accountability |
| Technical and security logs | 12 months, unless part of an investigation | Security |
| Marketing preferences | Until you withdraw, plus a record of the withdrawal | To honour your choice |
| Closed-account records | As above; the account itself is deactivated and access removed | — |
⚠ Deleting your account does not delete everything. We are legally required to keep identity and transaction records for ten years, and we cannot delete them on request. What we can do is stop using them for anything other than that legal purpose, and remove your access. See §14.3.
Where a retention period expires, data is deleted or irreversibly anonymised.
10\. Who we share your data with
10.1 Your counterparty
When you enter a Deal, your counterparty sees your account name, your handle, and the Deal’s content and history. When you send money, the recipient sees your name.
Before you send a transfer, we show you the recipient’s account name, so you can check you have the right person. This is a disclosure of their name to you, for fraud prevention.
We do not disclose your phone number, email, identity documents, address or other Deals to your counterparty.
10.2 Our staff
On a need-to-know basis, governed by role-based permissions. Identity documents, compliance cases and dispute evidence are each restricted to the roles that require them, and access is logged.
10.3 Service providers
Named in §11. They process on our written instructions and may not use your data for their own purposes.
10.4 Authorities
We disclose where we are legally required to, including to ANIF, tax authorities, courts, police, financial regulators and their equivalents in other countries where an obligation applies to us.
⚠ Where we file a suspicious-activity report, the law prohibits us from telling you. We will not confirm or deny that a report exists.
10.5 Partners in the payment chain
Mobile Money operators, banks and our aggregator receive the data needed to execute your payment, which will typically include your name, the number or account, the amount and a reference.
10.6 Professional advisers, insurers and auditors
Under duties of confidentiality.
10.7 Corporate transactions
If our business is sold or reorganised, data may transfer to the acquirer, subject to this policy or a policy no less protective. We will tell you.
10.8 What we never do
We do not sell your personal data. We do not share it with third parties for their own advertising. We do not disclose your identity documents to other users.
11\. Service providers who process data for us
| Provider | What they do | Data they see | Where |
|---|---|---|---|
| WhatsApp / Meta | Delivers messages to and from you | Your phone number and the content of the messages | Ireland, United States |
| Anthropic | Provides the AI model behind the assistant | The content of your conversation and the account context needed to answer | United States |
| OpenAI | Transcribes voice notes; fallback model | Audio of your voice notes; message content | United States |
| Cloudinary | Stores images you attach to deliveries and dispute evidence | Those images | United States / EU |
| Twilio | Sends SMS and one-time codes | Your phone number, message content | United States |
| Sends email | Your email address, message content | ||
| Fapshi | Mobile Money aggregation | Name, number, amount, reference | Cameroon |
| MTN Mobile Money, Orange Money | Execute mobile payments | As above | Cameroon / regional |
| Hosts the Platform and databases | All data at rest | ||
| Smile Identity (if enabled) | Identity verification, African markets | Identity documents, selfie | Africa / United States |
| Stripe Identity (if enabled) | Identity verification, other markets | Identity documents, selfie | United States / EU |
| Sanctions and PEP screening | Name, date of birth, country |
⚠ Note on identity providers. Smile Identity and Stripe Identity are configured in the Platform but are enabled per market. Where neither is enabled, document analysis is performed on our own infrastructure (§5.4). We will name the provider actually used in your case on request.
⚠ Note on the AI assistant. Your conversation is sent to the model provider to generate a reply. Do not send information in chat that you would not want processed this way. We do not send your identity documents or your PIN to a model provider.
We keep an up-to-date register of these providers. Ask privacy@bizik.com for the current version.
12\. What we do not do with your data
- We do not use your Deal content, your identity documents or your face to train general-purpose artificial-intelligence models, and we do not permit our providers to do so with data we send them.
- We do not profile you for advertising.
- We do not make your data available for credit scoring by third parties.
13\. International transfers
Your data is processed in Cameroon and transferred outside it, in particular to the European Union and the United States, because the providers in §11 operate there.
Where we transfer personal data internationally we rely on:
- an adequacy decision, where one applies to the destination;
- standard contractual clauses or equivalent contractual safeguards with the recipient;
- technical measures — encryption in transit and at rest, and minimisation of what is sent;
- your explicit consent, where no other mechanism is available and the transfer is necessary.
⚠ Some destination countries do not give the same protection as your own, and their authorities may be able to access data in circumstances that would not be permitted at home. You may ask privacy@bizik.com for a copy of the safeguards we rely on.
If you are in the EU, the EEA or the United Kingdom, we apply the GDPR / UK GDPR transfer rules to your data and rely on standard contractual clauses with the addendum applicable to your jurisdiction. —
14\. Your rights
14.1 The rights
Subject to the conditions and exceptions in the applicable law, you may:
| Right | What it means |
|---|---|
| Access | Obtain confirmation that we process your data, a copy of it, and information about how we use it |
| Rectification | Have inaccurate data corrected and incomplete data completed |
| Erasure | Have data deleted where we no longer have a lawful reason to keep it — see §14.3 |
| Restriction | Have us stop using data, while keeping it, in defined circumstances |
| Objection | Object to processing based on our legitimate interests, and to direct marketing at any time and without reason |
| Portability | Receive data you gave us, in a structured machine-readable format, and have it sent to another controller where technically feasible |
| Withdraw consent | Where we rely on consent, withdraw it at any time. This does not affect processing already carried out |
| Human review | Obtain human intervention in relation to an automated decision, express your view and contest it (§8) |
| Complain | To us, and to a supervisory authority (§17) |
14.2 How to exercise them
Write to privacy@bizik.com. Much of your data — your Deals, transactions, records and profile — you can already see and download in the Platform.
We will verify your identity before acting, because acting on an impostor’s request would be the greater harm. We respond within one month, extendable by two further months for complex requests, and we will tell you if we extend. There is no charge, unless a request is manifestly unfounded or excessive.
14.3 Limits, stated plainly
⚠ We cannot delete everything on request.
- Identity and transaction records are kept for ten years because financial-crime law requires it. A deletion request does not override that.
- Records relating to a suspicious-activity report are kept and cannot be deleted, and we cannot tell you they exist.
- Data needed to establish, exercise or defend a legal claim is kept until the claim is resolved or time-barred.
- Data in the audit log is not editable, by design. That is the point of an audit log.
- We may keep a minimal record of a closed or refused account to prevent it being re-opened in breach of a restriction.
Where we refuse a request, we will tell you why and how to challenge it.
15\. Security
We take measures appropriate to the risk, including:
- encryption of data in transit, and encryption of your identity number at rest under a dedicated key;
- identity documents stored outside publicly-addressable storage, retrievable only by an authenticated and permissioned reviewer;
- re-encoding of every uploaded image to strip metadata and any concealed payload;
- role-based access control, so that access follows the job and not the person;
- an append-only audit log of significant actions;
- multi-factor authentication for staff, and a transaction PIN for money actions on WhatsApp;
- verification of the authenticity of incoming webhooks from payment and messaging partners;
- rate limiting, hardened HTTP headers, and controls against automated abuse;
- separation of client funds from operating funds;
- vetting of staff with access to sensitive data.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the competent authority where required and, where the risk to you is high, notify you directly and tell you what to do.
Your part: use a strong and unique password, keep your PIN secret, never share a one-time code, and remember that we will never ask you for your password, your Bizik PIN, your Mobile Money PIN or a code.
16\. Bizik on WhatsApp
- Two controllers. Meta controls the messaging service; we control what we do with your messages once received. Meta’s own policy applies to the transport layer.
- What we store. The content of inbound and outbound messages, in a log kept for 90 days and then purged automatically, and a short-lived conversation context kept for 30 minutes of inactivity.
- Voice notes are transcribed to text by a third-party provider (§11). The transcript is treated as a message.
- AI processing. Message content is sent to a model provider to generate the reply.
- Delivery. Messaging rules outside our control restrict when we may message you. Where we cannot reach you on WhatsApp we may send an SMS instead.
- Your controls. You may lock the channel, reset the chat PIN, or opt out of WhatsApp entirely, from Settings → Security → WhatsApp in the app. Unlocking is possible only in the app, deliberately.
- Do not send identity documents, passwords or PINs in chat except where the verification flow explicitly asks you for a document photograph.
17\. Complaints and supervisory authorities
Please raise a concern with privacy@bizik.com first — most are resolved quickly.
You may also complain to a competent authority. Depending on where you are, that may be:
- Cameroon: — — and, for matters concerning electronic communications and cybersecurity, ANTIC or ART; for consumer matters, the Ministry in charge of commerce.
- EU / EEA: the data-protection supervisory authority of your habitual residence, place of work, or the place of the alleged infringement.
- United Kingdom: the Information Commissioner’s Office.
Complaining to an authority does not affect any other remedy you may have.
18\. Children
The Services are not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, tell privacy@bizik.com and we will delete it, except where we are required to keep records of a closed account.
19\. Cookies
The web apps use cookies and similar technologies. See the Cookie Policy.
20\. Changes to this policy
We may update this policy. We will publish the new version with a new date, and where a change is material we will tell you before it takes effect, by email, in the Platform, or on WhatsApp. Where a change requires your consent, we will ask for it.
Past versions are available from privacy@bizik.com.
21\. A note on the legal standard applied
Cameroonian law does not currently provide a single comprehensive personal-data statute equivalent to the European General Data Protection Regulation; protection derives from Law No. 2010/012 of 21 December 2010 on cybersecurity and cybercrime, sectoral rules, banking secrecy and constitutional principles, with further legislation under consideration.
We have chosen to write and operate this policy to a GDPR-grade standard regardless. We do so because it is a defensible standard in Cameroon, because it is required for our users in the European Union and the United Kingdom, and because it will not need rewriting when Cameroonian legislation develops.
Where the law that applies to you gives you more than this policy, the law prevails.
_Bizik — RCCM — — —, Republic of Cameroon._