Data controller and contact
The data controller is SM SARL, a Cameroonian limited liability company (SARL), registered with the Trade and Personal Property Credit Register under RCCM CM-DLA-03-2025-B12-00362, taxpayer identification number (NIU) M052517777217E, with registered office at Terminus Bonamoussadi, Douala, Cameroon. Share capital: 900,000 FCFA. Bumxpress is a brand and service operated by SM SARL.
For privacy requests, contact privacy@bumxpress.com. For general support, contact support@bumxpress.com. Company contact: contact@sm-sarl.com. Phone: +237 690 702 142. Postal address: SM SARL, Terminus Bonamoussadi, Douala, Cameroon.
Scope and applicable law
This policy applies to personal data processed through bumxpress.com, the Bumxpress mobile applications, Business / merchant portals, APIs and related customer-support channels when SM SARL acts as data controller.
Processing is governed primarily by Law No. 2024/017 of 23 December 2024 on the protection of personal data in Cameroon, and, where relevant, Law No. 2010/012 of 21 December 2010 on cybersecurity and cybercrime, Law No. 2010/013 of 21 December 2010 governing electronic communications (as amended), applicable OHADA commercial rules, CEMAC / AML-CFT obligations and SM SARL’s ART prior-declaration framework for value-added mobile financial services (mobile payment services).
Categories of personal data we collect
Identity and contact data: full name, date of birth where required, nationality, phone number, email address, postal or residential details, national identity document or passport details, selfie or biometric comparison data where a product implements identity verification, and account credentials.
Transaction and payment data: transfer amounts, fees, currencies, quotes, sender and recipient mobile-money identifiers, operator corridors, transaction references, timestamps, status, and information needed to investigate failed, disputed or suspicious payments.
KYC / AML and compliance data: identity verification results, source-of-funds or purpose-of-payment explanations, beneficial-owner and authorised-representative details for businesses, screening outcomes against sanctions or politically exposed person lists, and records required for anti-money-laundering and counter-terrorist-financing controls.
Technical and usage data: IP address, device type, operating system, application or browser version, language preference, pages or screens visited, crash or diagnostic logs, cookies and similar technologies, and security logs (access, authentication attempts, anomaly alerts).
Support and communication data: messages you send to support or sales, complaint files, call or chat notes where recorded, and records of our responses.
How we collect data
We collect data directly from you when you create an account, complete KYC, request a quote, initiate a transfer, contact support, submit a Business inquiry, or configure a merchant integration.
We also receive data from mobile-money operators and payment partners involved in a requested movement of money, from identity-verification or screening providers, from fraud and security tooling, and automatically from your device when you use the website or applications.
Purposes of processing
We process personal data to: create and manage accounts; generate and confirm quotes; execute and reconcile transfers and merchant payments; verify identity and eligibility; prevent fraud, abuse, money laundering and terrorist financing; meet ART, tax, accounting and other legal obligations; provide customer support and handle complaints; send service notices (including transaction status); improve reliability, security and product quality; and, only with a valid legal basis and where required with consent, send commercial communications.
Legal bases under Cameroon law
Depending on the processing, SM SARL relies on: (i) your consent where required by Law No. 2024/017; (ii) performance of a contract or pre-contractual steps you request (for example creating an account or executing a transfer); (iii) compliance with a legal obligation (KYC/AML, record-keeping, responses to competent authorities, ART obligations); and (iv) legitimate interests pursued by SM SARL or a third party, provided your fundamental rights and freedoms are not overridden (for example securing systems, preventing fraud and improving service reliability).
Where consent is the legal basis, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Withdrawal may limit certain optional features (for example marketing) but does not erase records that SM SARL must keep under law.
Recipients and sharing
We share personal data only when necessary for the purposes above, with: mobile-money operators and payment partners (including MTN Mobile Money, Orange Money and other corridor operators where used); identity, KYC and screening providers; hosting, cloud, messaging, analytics and customer-support processors acting on our instructions; professional advisers under confidentiality; and courts, ART, tax authorities, financial-intelligence or law-enforcement bodies when a valid legal obligation or request so requires.
SM SARL does not sell personal data. Processors are bound by contractual or legal obligations to process data only for authorised purposes and to apply appropriate security measures, consistent with SM SARL’s internal security and internal-control policies.
Retention periods
We keep personal data only for as long as needed for the purpose of collection, then archive or delete it, unless a longer period is required or permitted by law.
Indicative periods: account and profile data — for the life of the account plus up to five (5) years after closure; transaction, KYC/AML and accounting records — generally five (5) to ten (10) years from the transaction or end of the business relationship, in line with applicable AML-CFT, tax and commercial obligations; support tickets — up to three (3) years after closure unless linked to a longer retention duty; cookie and technical logs — from session length up to thirteen (13) months unless security needs justify a longer period; marketing consent records — until withdrawal plus evidence of consent for the applicable limitation period.
Security measures
SM SARL applies organisational and technical measures aligned with its Security Policy and Internal Control Policy, based on confidentiality, integrity, availability, authentication and authorisation. Measures may include encryption in transit and at rest where appropriate, strong authentication and access control based on least privilege, transaction monitoring and anomaly detection, regular internal audits, staff awareness, backup and continuity arrangements, and incident-response procedures.
No method of transmission or storage is perfectly secure. If we become aware of a personal-data breach likely to create a risk to your rights, we will take containment measures and notify competent authorities and affected persons when Cameroon law requires it.
International transfers
Primary service operations are organised from Cameroon. Some processors (for example cloud hosting, messaging or screening tools) may process data in other countries. Where a transfer outside Cameroon occurs, SM SARL implements appropriate safeguards required by Law No. 2024/017 and related implementing rules, such as contractual clauses, security assessments and transfers only to recipients offering an adequate level of protection or an approved derogation.
Your rights
Subject to Law No. 2024/017 and applicable exceptions, you may request: access to your personal data; rectification of inaccurate or incomplete data; erasure; restriction of processing; objection to processing based on legitimate interests or to direct marketing; withdrawal of consent; and, where technically feasible and legally required, portability of data you provided.
To exercise a right, email privacy@bumxpress.com with enough detail to identify your request. We may ask for identity verification. We aim to respond within a reasonable period and, in any event, within the timelines set by Cameroon law once the supervisory authority’s procedures are fully operational. Some data cannot be erased while retention is mandatory for AML-CFT, accounting, dispute or security reasons.
Complaints to the supervisory authority
If you believe your personal data is not processed in accordance with Cameroon law, you may first contact privacy@bumxpress.com. You may also lodge a complaint with the Personal Data Protection Authority created by Law No. 2024/017 (Autorité de protection des données à caractère personnel), once that Authority is organised and receives complaints, or with any other competent Cameroonian authority.
Cookies and similar technologies
The website may use strictly necessary cookies or local storage to remember language and keep the site functioning. Optional analytics or measurement technologies, if used, are described in the Cookie notice and activated only with any consent or choice mechanism required by law. See the Cookie notice for details and browser controls.
Minors
Bumxpress services are intended for persons aged eighteen (18) years or older, corresponding to the age of majority under Cameroon civil law, or for legal entities acting through duly authorised representatives. We do not knowingly collect personal data from children acting independently. If you believe a minor has provided data without valid authority, contact privacy@bumxpress.com so we can delete or restrict the data as required.
Changes to this policy
We may update this policy to reflect legal, technical or operational changes. The updated version is published on this page with a revised effective date. Where Cameroon law requires specific notice or renewed consent, we will provide it. Continued use of the services after the effective date constitutes acknowledgement of the updated policy, without prejudice to rights that cannot be waived.