LEGAL · SBCGrow/POL/PDP-CLI/2026/v1.0

Privacy Policy — Protection of Personal Data

Last updated: April 2026 · Next review: April 2027

The French version is the authoritative legal text (Senegalese jurisdiction, Law No. 2008-12). This English version is provided for convenience.

1. Data Controller

Company
SBCGrow SARL
RCCM
SN.DKR.2024.B.1836
NINEA
010940676 2V2
Registered address
Lot No. 130 Liberty 6 extension, Dakar, Senegal
Legal representative
Mame Michele Laye Diop — Manager
Data protection contact
admin@sbcgrow.com

2. Purpose and Scope

This policy informs clients of SBCGrow SARL (current and prospective) about the conditions under which their personal data is collected, processed, and protected.

It applies to all interactions between the client and SBCGrow: initial contact, contracting, service delivery, commercial prospecting, and communication.

In accordance with Senegalese law (Law No. 2008-12 of January 25, 2008 on the protection of personal data) and international standards (GDPR as a best-practice reference, ISO 27701), SBCGrow is committed to processing its clients' personal data with the highest diligence.

This policy forms part of SBCGrow's General Data Protection Policy (SBCGrow/POL/PDP/2026/v1.0).

3. Data Collected and Purposes

3. Data Collected and Purposes
DataPurposeNature
Last name, first nameIdentification of the contracting partyMandatory
Email addressCommunication, document deliveryMandatory
Phone numberOperational contactMandatory
Company name, business addressB2B client relationship managementMandatory (B2B)
Industry sectorService personalizationOptional
Exchange historyContractual relationship trackingAutomatic
Billing dataAccounting and tax obligationsMandatory
Browsing data (cookies)Website improvementConsent

No sensitive data (health, political opinions, religion, biometrics, criminal records) is collected. Any accidental receipt of sensitive data is immediately deleted with notification to the sender.

4. Legal Basis

4. Legal Basis
ProcessingLegal basis
Service deliveryContract execution
Invoicing and accountingLegal obligation (tax law)
Commercial prospecting (B2B)Legitimate interest
NewsletterConsent (opt-in)
Cookies (analytics/marketing)Consent (opt-in)
Response to legal requestsLegal obligation

5. Data Retention

5. Data Retention
Data typeRetention period
Contractual data (contracts, deliverables)Duration of contract + 5 years
Accounting data (invoices, payments)10 years (tax obligations)
Prospecting data (non-clients)2 years after last contact
Cookies and browsing data13 months

Data is permanently deleted within 30 days after the retention period expires.

6. Data Recipients

Personal data is accessible only to:

  • Authorized SBCGrow personnel — on a strict need-to-know basis (principle of least privilege)
  • Microsoft Ireland Operations Limited — data processor (cloud hosting), bound by a Data Processing Agreement (DPA)
  • Competent authorities — in case of legal obligation (CDP, judicial authority, tax administration)

SBCGrow never sells, rents, or transfers client data to third parties for commercial purposes.

7. International Transfers

Client data is hosted on Microsoft Cloud (data centers in Ireland and/or the Netherlands, European Union). This transfer is governed by:

  • A Data Processing Agreement (DPA) with Microsoft Ireland Operations Limited
  • Standard Contractual Clauses (SCCs) in accordance with European Commission decisions
  • An Authorization Request filed with the CDP (Articles 49–51, Law 2008-12)
  • Microsoft certifications: ISO 27001, ISO 27017, ISO 27018, SOC 1, SOC 2, SOC 3
  • Data encryption at rest (AES-256) and in transit (TLS 1.2+)
  • Data residency in Europe (EMEA region) — no transfer outside the EU

8. Security Measures

SBCGrow implements the following measures to protect client data:

8. Security Measures
MeasureDescription
EncryptionAES-256 at rest, TLS 1.2+ in transit
AuthenticationAccess by unique identifier and password (12 characters min., renewal every 90 days)
LoggingAccess traceability via Microsoft 365 Audit Log
Access controlPrinciple of least privilege — access limited to authorized personnel
BackupContinuous automatic backup on Microsoft Cloud
Physical securitySecured premises; Microsoft data centers certified ISO 27001

9. Your Rights

In accordance with Articles 58 to 68 of Law No. 2008-12 and GDPR principles, every client has the following rights:

9. Your Rights
RightDescriptionResponse time
InformationKnow what data is collected and whyImmediate (at collection)
AccessObtain a copy of your data in a readable format15 business days
RectificationCorrect inaccurate or incomplete data15 business days
OppositionObject to processing on legitimate grounds15 business days
DeletionRequest erasure of your data30 business days
PortabilityReceive your data in a structured, reusable format30 business days
RestrictionFreeze processing pending verification15 business days

How to exercise your rights: send an email to admin@sbcgrow.com with a copy of your ID document. In case of a reasoned refusal, you may file a complaint with the Commission des Données Personnelles (CDP): www.cdp.sn — contact.cdp@cdp.sn.

10. Cookies

The website www.sbcgrow.com may use the following cookies:

10. Cookies
TypePurposeConsent
Essential cookiesWebsite functionalityNot required (strictly necessary)
Analytics cookiesAudience measurement, improvementConsent required (opt-in)
Marketing cookiesTargeted advertisingConsent required (opt-in)

You can manage your cookie preferences via the consent banner or your browser settings. Consent is valid for 13 months.

11. Policy Changes

SBCGrow reserves the right to modify this policy to maintain compliance with legislative changes or operational needs. Any substantive change will be communicated to clients by email and/or publication on the website, with 30 days' prior notice before taking effect.

12. Contact and Complaints

Data protection contact
admin@sbcgrow.com
Postal address
SBCGrow SARL — Lot No. 130 Liberty 6 extension, Dakar, Senegal
Supervisory authority
Commission des Données Personnelles (CDP) — 76, Mermoz Pyrotechnie, VDN-Dakar — www.cdp.sn — contact.cdp@cdp.sn

Applicable law: Law No. 2008-12 of January 25, 2008 on the protection of personal data and its implementing Decree No. 2008-721 of June 30, 2008.