Baobab — by Bridge Corporation
Bridge Corporation operates Baobab, a Banking-as-a-Service (BaaS) platform licensed under COBAC (PSP/2024/001) in the CEMAC region and registered with BaFin (DE-12345678) in Germany. Our registered address is available at baobab-bridge.org.
For GDPR purposes, Bridge Corporation is the data controller. Our Data Protection Officer can be reached at dpo@baobab-bridge.org.
| Category | What we collect | Why |
|---|---|---|
| Identity | Full name, date of birth, nationality, government ID | KYC / AML / regulatory compliance |
| Contact | Phone number, email address, residential address | Account creation, notifications, security alerts |
| Financial | Wallet balance, transaction history, bank account details | Core payment services |
| Device | Device fingerprint, IP address, browser/OS info | Fraud prevention, security alerts |
| Location | Country detected from IP (not GPS) | Regulatory compliance, currency routing |
| Usage | Features used, screens viewed, interaction patterns | Service improvement, fraud detection |
| Communications | Chat messages sent within Baobab Chat & Pay | Delivering the messaging service |
| Biometric (optional) | Face photo (selfie for KYC only) | Identity verification — not stored beyond verification |
We never sell your data. We share it only with:
Your data may be processed in countries outside your residence. Where we transfer data from the EEA, we use Standard Contractual Clauses (SCCs) approved by the European Commission. For transfers from Cameroon and CEMAC countries, we follow COBAC data localisation requirements.
| Data type | Retention period |
|---|---|
| Transaction records | 10 years (regulatory requirement) |
| KYC documents | 5 years after account closure |
| Account data | Duration of account + 5 years |
| Security/device logs | 2 years |
| Marketing preferences | Until consent withdrawn |
| KYC selfie photos | Deleted after verification (max 90 days) |
Depending on your jurisdiction, you have the right to:
Exercise your rights from Profile → Privacy & Data Rights inside the app, or email privacy@baobab-bridge.org. We respond within 30 days as required by GDPR.
The Baobab web app uses only strictly necessary cookies for session management. We do not use third-party advertising trackers. We use anonymous usage analytics to improve the app experience. You can manage cookie preferences in the cookie banner on first visit.
Baobab is not intended for users under 18 years of age. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact us immediately at privacy@baobab-bridge.org.
We will notify you of material changes via email and in-app notification at least 30 days before they take effect. Continued use of Baobab after that date constitutes acceptance.
Baobab operates under the supervision of:
If you are unsatisfied with our response to a privacy complaint, you have the right to lodge a complaint with your national data protection authority (e.g. CNIL in France, ICO in the UK, BfDI in Germany).
Data Protection Officer: dpo@baobab-bridge.org
Privacy requests: privacy@baobab-bridge.org
General support: support@baobab-bridge.org
Website: https://baobab-bridge.org
Bridge Corporation · License COBAC/PSP/2024/001 · BaFin Reg. DE-12345678