Baobab logo

Privacy Policy

Baobab — by Bridge Corporation

Effective: 1 January 2025 Last updated: 25 April 2026 Version: 3.0 Governed by: COBAC · BaFin · GDPR · CCPA
Baobab is a global financial superapp operated by Bridge Corporation. We take your privacy seriously. This policy explains exactly what data we collect, why we collect it, and how you can control it.

1. Who We Are

Bridge Corporation operates Baobab, a Banking-as-a-Service (BaaS) platform licensed under COBAC (PSP/2024/001) in the CEMAC region and registered with BaFin (DE-12345678) in Germany. Our registered address is available at baobab-bridge.org.

For GDPR purposes, Bridge Corporation is the data controller. Our Data Protection Officer can be reached at dpo@baobab-bridge.org.

2. Data We Collect

CategoryWhat we collectWhy
IdentityFull name, date of birth, nationality, government IDKYC / AML / regulatory compliance
ContactPhone number, email address, residential addressAccount creation, notifications, security alerts
FinancialWallet balance, transaction history, bank account detailsCore payment services
DeviceDevice fingerprint, IP address, browser/OS infoFraud prevention, security alerts
LocationCountry detected from IP (not GPS)Regulatory compliance, currency routing
UsageFeatures used, screens viewed, interaction patternsService improvement, fraud detection
CommunicationsChat messages sent within Baobab Chat & PayDelivering the messaging service
Biometric (optional)Face photo (selfie for KYC only)Identity verification — not stored beyond verification

3. Legal Basis for Processing (GDPR)

4. How We Use Your Data

5. Data Sharing

We never sell your data. We share it only with:

6. International Transfers

Your data may be processed in countries outside your residence. Where we transfer data from the EEA, we use Standard Contractual Clauses (SCCs) approved by the European Commission. For transfers from Cameroon and CEMAC countries, we follow COBAC data localisation requirements.

7. Data Retention

Data typeRetention period
Transaction records10 years (regulatory requirement)
KYC documents5 years after account closure
Account dataDuration of account + 5 years
Security/device logs2 years
Marketing preferencesUntil consent withdrawn
KYC selfie photosDeleted after verification (max 90 days)

8. Your Rights

Depending on your jurisdiction, you have the right to:

Exercise your rights from Profile → Privacy & Data Rights inside the app, or email privacy@baobab-bridge.org. We respond within 30 days as required by GDPR.

9. Security

10. Cookies & Tracking

The Baobab web app uses only strictly necessary cookies for session management. We do not use third-party advertising trackers. We use anonymous usage analytics to improve the app experience. You can manage cookie preferences in the cookie banner on first visit.

11. Children's Privacy

Baobab is not intended for users under 18 years of age. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact us immediately at privacy@baobab-bridge.org.

12. Changes to This Policy

We will notify you of material changes via email and in-app notification at least 30 days before they take effect. Continued use of Baobab after that date constitutes acceptance.

13. Regulatory Supervision & Complaints

Baobab operates under the supervision of:

If you are unsatisfied with our response to a privacy complaint, you have the right to lodge a complaint with your national data protection authority (e.g. CNIL in France, ICO in the UK, BfDI in Germany).

Contact Us

Data Protection Officer: dpo@baobab-bridge.org

Privacy requests: privacy@baobab-bridge.org

General support: support@baobab-bridge.org

Website: https://baobab-bridge.org

Bridge Corporation · License COBAC/PSP/2024/001 · BaFin Reg. DE-12345678