Privacy Policy and Personal Data Protection

Kaeyros Analytics' commitment regarding the collection, processing, security and retention of personal data, in connection with its consulting, software engineering, data engineering, business intelligence and artificial intelligence activities.

Version
Version 1.0
Effective date
06/23/2026
Last updated
06/23/2026

01 Preamble and commitment

Kaeyros Analytics SAS (hereinafter “Kaeyros Analytics”, “we”) designs, develops and operates data platforms, cloud infrastructure, artificial intelligence solutions and business intelligence systems on behalf of public and private organisations, across Central Africa and Europe.

Data is our raw material. We accordingly consider that protecting privacy, confidentiality and control over the data entrusted to us is not a peripheral obligation, but a structural part of our profession and of the trust our clients place in us.

This policy transparently describes the categories of data we process, the purposes we pursue, the legal bases relied upon, the security measures implemented, the period for which data is retained, and the rights available to data subjects and how to exercise them.

Guiding principles

Lawfulness, fairness and transparency · Purpose limitation · Data minimisation · Accuracy · Storage limitation · Integrity and confidentiality · Accountability · Privacy by design and by default.

02 Identity of the data controller

The controller of the processing activities described in this policy is Kaeyros Analytics SAS, Av du 27 Août Tsinga, Yaoundé, Cameroon.

For any question relating to this policy or to exercise your rights, you may write to us at [email protected] (see also section 22).

03 Scope

This policy applies to all processing of personal data carried out by Kaeyros Analytics, regardless of the medium or location involved, including in particular:

  • Websites, portals, documentation spaces and forms published by Kaeyros Analytics;
  • Commercial and contractual relationships with our clients, prospects, partners and suppliers;
  • Consulting, engineering, hosting, managed services, data engineering, business intelligence, cybersecurity and artificial intelligence services;
  • Platforms and applications developed, deployed or operated on behalf of our clients;
  • Recruitment, training and skills-transfer activities;
  • Internal processing relating to administrative management and the security of our information systems.

It applies to all employees, interns, consultants and contractors acting on behalf of Kaeyros Analytics, who are bound by a contractual confidentiality obligation.

04 Applicable legal framework

Our processing activities are carried out in compliance with, depending on their territorial and material scope:

  • Law No. 2024/017 of 23 December 2024 on the protection of personal data in Cameroon, whose compliance deadline expired on 23 June 2026, together with its implementing texts and the decisions of the Data Protection Authority (APDP);
  • Law No. 2010/012 of 21 December 2010 on cybersecurity and cybercrime in Cameroon, and Law No. 2010/013 on electronic communications;
  • The General Data Protection Regulation (EU) 2016/679 (GDPR) and, where applicable, the German Federal Data Protection Act (BDSG), for processing governed by European Union law;
  • CEMAC community instruments applicable to electronic communications and data protection;
  • Sector-specific requirements applicable to our clients (insurance, healthcare, finance, international organisations), where these are contractually binding on us.

Where several regimes apply simultaneously to the same processing activity, Kaeyros Analytics applies the standard most protective of the data subject.

05 Definitions

Personal data
Any information relating to an identified or identifiable natural person, directly or indirectly.
Processing
Any operation performed on personal data (collection, recording, structuring, storage, consultation, transmission, erasure, etc.).
Data controller
The entity that determines the purposes and means of the processing.
Data processor
The entity that processes data on behalf of, and under the documented instructions of, the data controller.
Data subject
The natural person to whom the data relates.
Sensitive data
Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, biometric, genetic data or data concerning sex life.
Data breach
Any breach of confidentiality, integrity or availability of data, whether accidental or unlawful.

06 Our two roles: data controller and data processor

Kaeyros Analytics' role varies depending on context, and this distinction governs all of our obligations.

SituationOur roleScope
Website, marketing, responses to calls for tender, commercial relationships, recruitment, HR and supplier managementData controllerWe determine the purposes and means; this policy applies in full.
Development, hosting, managed services, data pipelines, BI dashboards, business platforms operated for a clientData processorWe act exclusively on the client's documented instructions, as data controller, under a data processing agreement (DPA) annexed to the contract.
Security audits and penetration testingData processorScope, engagement window and rules of engagement defined by the client's prior written authorisation; any real data encountered is protected and never extracted.

As a data processor, we undertake to process data only for the performance of the service, not to use it for our own purposes, not to engage a sub-processor without authorisation, to assist the client in the exercise of data subject rights and in its impact assessments, and to return or delete the data at the end of the contract.

07 Data collected

7.1 Data we collect as controller

  • • Identification and contact data: first and last name, role, organisation, business address, email address, phone number.
  • • Business relationship data: correspondence, meeting minutes, stated needs, proposals, contracts, billing history.
  • • Application data: curriculum vitae, academic and professional background, references, interview and technical assessment results.
  • • Training data: enrolments, attendance, submitted work, progress and certificates, in connection with our skills-transfer programmes.
  • • Technical and logging data: IP address, timestamp, session identifier, browser and device type, pages visited, system access logs.

7.2 Data processed as data processor

In connection with the platforms we build or operate for our clients, we may be exposed to end-user data: account identifiers, contact details, phone numbers and messaging identifiers, conversation content, subscription or case data, geolocation data, transaction data, and, in certain sectors, sensitive data. This data belongs to the client, is processed on the client's instructions, and its exact categories are set out in the data processing agreement specific to each project.

7.3 Data we do not collect

For our own purposes, we never collect sensitive data that is not necessary for the performance of a contract, payment data (see section 09), or data obtained through unauthorised or unfair means.

08 Purposes and legal bases

PurposeLegal basisData concerned
Managing the pre-contractual and contractual relationshipPerformance of the contract or pre-contractual measuresIdentification, contact, business relationship
Invoicing, accounting, tax and social obligationsLegal obligationIdentification, billing data
Prospecting and institutional communicationConsent or legitimate interest (B2B clientele), with a permanent right to objectProfessional contact details
Recruitment and application managementPre-contractual measures and consentApplication data
Provision, supervision and maintenance of servicesPerformance of the contractTechnical data, logs
System security, incident prevention and detectionLegitimate interest and legal obligationLogs, telemetry, security events
Service improvement and audience measurementConsent (non-essential trackers) or legitimate interest (aggregated measurement)Aggregated browsing data
Defending our rights and managing disputesLegitimate interestContractual documents and correspondence

09 Payments and means of payment

Important notice

Kaeyros Analytics is not a payment aggregator. We are neither a payment institution, nor an electronic money institution, nor an aggregator, nor an acquirer. We do not collect funds on behalf of third parties and we do not operate any payment acceptance platform in our own name.

9.1 Our positioning

When a project has a payment dimension, Kaeyros Analytics acts exclusively as a technical integrator, in one of two ways:

  • • The client brings its own aggregator. The client already has a contract with a payment aggregator, a banking institution, a mobile money operator or a payment service provider. We technically integrate this solution into the platform, in line with the retained provider's documentation and requirements.
  • • We facilitate the process. Where the client does not yet have a solution, we support it in its dealings with aggregators and payment providers: defining requirements, comparing offers, preparing the onboarding file, technical discussions, and qualification and acceptance testing of the integration. This support is an assistance and engineering service; the payment service contract is entered into directly between the client and the payment provider, which remains solely responsible for it.

9.2 Consequences for data

Payment flows are processed directly between the paying party and the payment provider, via redirection, hosted page, dedicated interface or the provider's API.

Kaeyros Analytics does not collect, store, log or transmit any payment authentication data: full card number, expiry date, security code, PIN, one-time confirmation code, or e-wallet credentials.

Only non-sensitive data necessary for functional reconciliation may pass through the systems we operate for the client: transaction identifier, order reference, amount, currency, timestamp, status, non-reversible token and, where applicable, the last four digits of a masked instrument provided by the payment provider.

The processing of payment data is governed by the privacy policy of the payment provider used, which acts as a separate data controller. We invite users to review it.

Compliance obligations specific to the payment activity — licensing, anti-money laundering, know-your-customer checks, PCI DSS certification, strong authentication — rest with the client and the payment provider. Kaeyros Analytics designs its integrations to keep its own infrastructure outside the scope of payment data.

10 Recipients and further sub-processors

Data is accessible only to authorised personnel, on a need-to-know basis. It may be disclosed:

  • • To internal teams strictly involved in the service;
  • • To our infrastructure and hosting providers, bound by contract and by confidentiality and security undertakings;
  • • To electronic communication and messaging providers used by client platforms, where the client has expressly decided to do so;
  • • To payment providers, under the conditions described in section 09;
  • • To our advisers (lawyers, accountants, auditors, insurers);
  • • To administrative or judicial authorities, upon lawful request and within the limits of the law.

We do not sell, rent or exchange any personal data. Any further sub-processing is subject to a prior assessment, to a contractual commitment equivalent to our own and, as a data processor, to the client's information or authorisation in accordance with the DPA.

Register of sub-processors available upon request

11 International transfers

Kaeyros Analytics operates between Central Africa and Europe. Certain processing activities may therefore involve a transfer of data outside Cameroonian territory or outside the European Economic Area.

Any transfer outside Cameroon is carried out in compliance with Law No. 2024/017, including, where required by the regulations, following prior authorisation from the data protection authority.

Any transfer from the European Union to a third country is governed by an adequacy decision or, failing that, by the European Commission's standard contractual clauses, supplemented by a transfer impact assessment and additional technical measures (encryption, pseudonymisation, segregation).

At the client's request, data location may be contractually restricted to a specific hosting region, including on-premises or sovereign cloud deployment.

12 Retention periods

CategoryRetention period
Prospects with no contractual relationship3 years from the last contact
Clients — business relationship dataDuration of the contract, then 5 years
Accounting and tax records10 years, in accordance with legal obligations
Unsuccessful applications2 years from the last exchange, unless objection is raised
Technical and security logs6 to 12 months, unless an incident is under investigation
Trackers and audience measurement13 months maximum
Data processed on behalf of a clientPeriod set by the client in the DPA; returned or deleted at the end of the contract
Encrypted backupsAccording to the agreed retention cycle, with automatic purging

Once these periods expire, data is either securely deleted or irreversibly anonymised for statistical purposes.

13 Information security

Kaeyros Analytics implements technical and organisational measures proportionate to the risk, reviewed periodically:

Technical measures

  • • Encryption of data in transit (TLS) and at rest, centralised secrets management and key rotation.
  • • Segregation of development, staging and production environments, with isolation by client and by namespace on our clusters.
  • • Role-based access control (RBAC), row-level security (RLS) where the data model allows for it, multi-factor authentication and encrypted remote-access tunnels.
  • • Centralised logging, continuous monitoring, alerting and traceability of data access.
  • • Encrypted, tested backups, and documented business continuity and disaster recovery plans.
  • • Vulnerability scanning, patch management and systematic hardening of exposed services.

Organisational measures

  • • Confidentiality undertakings signed by all personnel involved.
  • • Named access rights, periodic access reviews and immediate revocation upon departure or end of assignment.
  • • Standardised penetration testing and audit reporting process, applied to the applications we deliver.
  • • Regular staff awareness training on data protection and digital hygiene.
  • • Formalised incident management and notification procedure.
  • • Data protection considered from the design stage of architectures and applied by default in delivered configurations.

As no measure can guarantee absolute security, we commit to a reinforced obligation of means and to full transparency in the event of an incident.

14 Internal governance of client data

Our clients' data does not leave its authorised perimeter. Our governance model is based on the following principles:

  • • Access rather than extraction: as far as technically possible, our analysts and engineers work through direct, governed connections to source systems rather than by downloading local copies.
  • • Mapping and inventory: each dataset is linked to a client, a purpose, an environment and an internal owner.
  • • Least privilege: access rights are granted by role and by project, time-limited, and revoked when the assignment ends.
  • • Traceability: consultation, export and transfer of client data are logged and auditable.
  • • Control over copies: ad hoc exports are controlled, justified, encrypted and deleted once their purpose has been fulfilled.

This framework is subject to a continuous improvement process, the progress of which may be presented to our clients as part of their own audits.

15 Artificial intelligence and analytics

Data entrusted by a client is not used to train models for Kaeyros Analytics' own purposes, nor shared with other clients, except with the client's written, express and revocable agreement.

The use of third-party artificial intelligence services within a project is subject to the client's information and agreement, and we favour offers that are contractually exempt from data reuse for training purposes.

Development and demonstration datasets are anonymised, pseudonymised or synthetic.

No decision producing legal or otherwise significant effects on a person is taken solely on the basis of automated processing unless the client has provided for human intervention, adequate information and a means of contesting the decision.

16 Data breaches

In the event of a personal data breach, Kaeyros Analytics activates its incident procedure: assessment, containment, eradication, restoration, followed by a post-incident review.

As a data processor, we inform the client without undue delay after becoming aware of it, providing the information necessary for the client's own notifications.

As data controller, we notify the competent authority within the applicable legal deadlines and, where the breach is likely to result in a high risk, we inform the data subjects concerned.

A register of breaches is maintained and retained.

17 Rights of data subjects

Every data subject has, under the conditions provided for by the applicable regulations, the following rights:

  • • Right to information and access to their data and to how it is processed;
  • • Right to rectification of inaccurate or incomplete data;
  • • Right to erasure, where retention is no longer justified;
  • • Right to restriction of processing;
  • • Right to object, in particular to prospecting;
  • • Right to data portability, in a structured, machine-readable format;
  • • Right to withdraw consent at any time, without affecting the lawfulness of processing based on consent prior to its withdrawal;
  • • Right to define directives concerning the fate of their data after death;
  • • Right to lodge a complaint with the competent supervisory authority.

How to exercise these rights

Requests should be sent to [email protected] or by post to our registered office. Proof of identity may be requested where reasonable doubt exists. We respond within a maximum of one month, extendable by two months in complex cases, with the data subject being informed accordingly.

Where a request concerns data processed on behalf of a client (with Kaeyros Analytics acting as data processor), we forward it without delay to the client, as data controller, and assist the client in handling it, without responding to it ourselves.

18 Cookies and trackers

Our sites use trackers classified as follows:

CategoryPurposeConsent
Strictly necessarySecurity, session, load balancing, remembering consent choicesNot required
Audience measurementTraffic statistics, content improvementRequired, unless an exempt configuration is used
FunctionalDisplay preferences, language, embedded contentRequired
MarketingMeasurement of institutional campaignsRequired

Consent is collected via a dedicated banner, which can be declined as easily as accepted, and may be changed at any time. Trackers and the information collected are retained for no more than thirteen months.

19 Reversibility and end of contract

Upon expiry or termination of a contract, and in accordance with the client's written instructions, Kaeyros Analytics carries out the full return of data in a usable, documented format, followed by its secure deletion from our environments, including backups, at the end of the agreed retention cycle. A deletion certificate is issued upon request. The only data retained beyond that point is data required by a legal retention obligation.

20 Minors

Our services are aimed at professionals and are not directly intended for minors. Where a platform developed for a client may process data relating to minors, specific safeguards are defined with the client: obtaining authorisation from the holder of parental authority, enhanced data minimisation, age-appropriate information, and shorter retention periods.

21 Changes to this policy

This policy may be amended to reflect changes in our activities, our technologies or the regulatory framework. The version in force is the one published on our website, identified by its version number and last-updated date. Any material change will be notified to data subjects in advance and, in the case of our clients, through contractual communication channels.

22 Contact and complaints

Data Protection Officer

Kaeyros Analytics SAS — Av du 27 Août Tsinga, Yaoundé, Cameroon

[email protected]

Supervisory authorities

Cameroon: Data Protection Authority (APDP), established by Law No. 2024/017.
European Union: the supervisory authority of the Member State of residence, place of work, or place of the alleged infringement.

Privacy Policy | Kaeyros Analytics