Compliance & Privacy

Data Privacy & Sovereignty Policy

Last structural review and data protection alignment: August 27, 2026

1. Information We Collect & Route

To operate our communications gateway, Sendit AFRICA collects data in two profiles: information regarding your corporate merchant profile (such as contact logs, billing details, and developer keys), and metadata required to route transaction intents.

We act as a **Data Processor** for end-user numbers, mobile money destination keys, and survey responses passed through our infrastructure. Your enterprise remains the **Data Controller** under continental legislation.

2. Message Payload Data Logs

When triggering Bulk SMS or interactive USSD nodes, text strings are captured inside transient buffers exclusively for direct telco delivery pipeline validation.

To maintain financial security and debug transaction histories, raw delivery receipts (DLR) and logs containing hashed destination targets are cached for a baseline of 90 days. After this operational cycle window passes, text bodies are structurally scrubbed or permanently anonymized.

3. Financial & Payout Metadata

Mobile money collection push intents (STK prompts) and bulk B2C disbursement clearings ingest recipient identities, transaction totals, and network operator names.

This transaction metadata is kept separately from our standard communication cache files to comply with pan-African anti-money laundering (AML) laws and central banking balance audit procedures. We do not store or process end-user mobile money PIN parameters under any system rules.

4. Sovereign Cloud Data Residency

Sendit AFRICA enforces cross-border compliance framework restrictions natively. To follow the rules set by data regulators (like Kenya's ODPC, Nigeria's NDPC, and South Africa's Regulator), your message packets are processed within local cloud nodes.

Data originating from West African operator tunnels remains located inside West African data silos, while East African communication vectors route locally inside East African regions. We strictly block unencrypted cross-border exports of consumer personally identifiable information (PII).

5. Security, Token & API Controls

All infrastructure connections require TLS 1.3 payload encryption. Access to API gateways is restricted using cryptographically signed authorization tokens passed inside transaction request blocks.

Your system administrators bear total liability for isolating secret production tokens. If a token leaks, use your central corporate web portal to rotate credentials instantly and cancel existing active threads.

6. Your Rights & Statutory Contacts

Under regional laws, your African consumer base has the right to access records, correct input variables, or demand data erasure profiles from active log tables (where AML laws do not apply).

For legal compliance escalations or data request processing, reach out to our dedicated corporate protection division directly: privacy@sendit.africa.