DAT PAY

Privacy Policy

Last updated: 22 August 2026

Traduction non officielle

Ce document est publié en anglais. Le texte anglais constitue la version officielle et fait foi ; toute traduction est fournie à titre indicatif uniquement et n’a aucune valeur juridique. Consulter la version officielle en anglais

1. Who We Are

DAT PAY is a financial technology and payment infrastructure platform operated by HACHTHER SARL, a company incorporated and registered in the Republic of Cameroon under RCCM No. RC/DLA/2019/B/1809, with Unique Identification Number (UIN) M041914224584L.

DAT PAY provides technology, software, connectivity and infrastructure through which individuals, businesses, merchants and financial institutions may access financial and payment services provided through appropriately authorised financial institutions, payment providers and other regulated or specialised service providers.

HACHTHER SARL does not represent itself as a bank, payment institution, electronic money issuer, money transfer institution, custodian or other regulated financial institution where it does not hold the applicable licence or authorisation.

Where regulated financial services are provided through a regulated partner, that partner may independently determine the purposes and means of processing certain personal data and may have its own privacy notice and data protection obligations.

For the purposes of this Privacy Policy, “DAT PAY”, “we”, “us” and “our” refer to HACHTHER SARL in connection with the DAT PAY platform and services.

2. Purpose of This Privacy Policy

This Privacy Policy explains how DAT PAY collects, uses, stores, protects and shares personal data when you:

  • visit datpay.io;
  • communicate with DAT PAY;
  • request information or a meeting;
  • apply for an account;
  • undergo identity or business verification;
  • access the DAT PAY client console;
  • use DAT PAY products or services;
  • initiate, receive or otherwise participate in a payment or financial transaction through the platform;
  • use APIs or other technical interfaces provided by DAT PAY;
  • interact with our support, compliance or security teams.

This Privacy Policy applies to personal data processed through our website, client console, applications, APIs, communications and related services, unless a separate privacy notice applies to a particular service.

3. Our Data Protection Responsibilities

Depending on the nature of the service and the relationship involved, DAT PAY may act as:

  • a data controller, where DAT PAY determines the purposes and means of processing personal data;
  • a data processor or service provider, where DAT PAY processes personal data on behalf of a client or another organisation;
  • a joint or independent controller with another organisation where applicable law or the structure of a particular service requires it.

Where another financial institution or regulated service provider independently processes your personal data, that organisation may have separate responsibilities as a data controller.

4. Personal Data We Collect

We collect personal data that is necessary for the operation, security, compliance and delivery of DAT PAY services.

Identity and Personal Information

Depending on the service and applicable requirements, this may include:

  • full legal name;
  • date and place of birth;
  • nationality;
  • country of residence;
  • residential or business address;
  • tax residence;
  • tax identification information;
  • government-issued identification information;
  • identification document details;
  • verification information;
  • photographs or other information required for identity verification;
  • information concerning authorised representatives.

Where identity verification requires biometric comparison or similar verification technology, such information may be processed by DAT PAY or by an appropriately appointed verification service provider in accordance with applicable law.

Business and Corporate Information

For business and institutional clients, we may collect:

  • legal entity name;
  • trading name;
  • incorporation details;
  • registration numbers;
  • registered and operating addresses;
  • business activities;
  • licences and regulatory status;
  • directors and authorised representatives;
  • shareholders;
  • ultimate beneficial owners;
  • ownership percentages;
  • corporate structure;
  • tax information;
  • corporate documents;
  • financial information;
  • source of funds and source of wealth information;
  • information required for KYB and enhanced due diligence.

Contact Information

This may include:

  • email address;
  • telephone number;
  • business contact information;
  • correspondence address;
  • professional information;
  • communications with DAT PAY.

Financial and Transaction Information

Depending on the services you use, we may process:

  • bank account information;
  • payment account information;
  • currency balances;
  • transaction amounts;
  • transaction dates and times;
  • payment references;
  • beneficiary information;
  • sender information;
  • recipient information;
  • transaction instructions;
  • payment status;
  • fees and charges;
  • foreign exchange information;
  • source of funds;
  • source of wealth;
  • transaction purpose;
  • transaction history;
  • information required to investigate disputed, failed, unusual or suspicious transactions.

Digital Asset and Blockchain Information

Where digital asset functionality is involved, we may process information such as:

  • blockchain wallet addresses;
  • blockchain network information;
  • transaction hashes;
  • digital asset amounts;
  • token or asset information;
  • blockchain transaction timestamps;
  • deposit and withdrawal information;
  • blockchain transaction status;
  • information linking a blockchain transaction to an account or transaction.

Blockchain information may be publicly visible on the relevant network and may remain permanently recorded on that network.

Compliance and Risk Information

To meet legal, regulatory and contractual obligations, we may process information relating to:

  • customer due diligence;
  • enhanced due diligence;
  • sanctions screening;
  • politically exposed person screening;
  • adverse media screening;
  • fraud prevention;
  • transaction monitoring;
  • financial crime risk;
  • source of funds;
  • source of wealth;
  • transaction purpose;
  • risk classifications;
  • regulatory investigations;
  • suspicious or unusual activity;
  • information received from competent authorities or other authorised sources.

We process such information only for legitimate and lawful purposes, including financial crime prevention, regulatory compliance, security and risk management.

Technical and Security Information

When you access our website, applications or client console, we may collect:

  • IP address;
  • device information;
  • browser type;
  • operating system;
  • device identifiers;
  • session information;
  • authentication events;
  • login history;
  • security events;
  • access logs;
  • API activity;
  • approximate location derived from technical information where necessary for security;
  • information relating to attempted or successful authentication.

We use technical information to operate, secure and improve our systems and to detect unauthorised access, fraud and abuse.

Communications

We may retain information contained in:

  • emails;
  • support requests;
  • sales enquiries;
  • meeting requests;
  • telephone or other communications where legally permitted;
  • complaints;
  • compliance correspondence;
  • account-related communications.

5. How We Use Personal Data

We use personal data for purposes including:

Account and Service Provision

  • creating and administering accounts;
  • providing access to the DAT PAY platform;
  • processing service requests;
  • facilitating payment and financial service instructions;
  • maintaining account information;
  • providing customer support.

Customer Due Diligence

  • verifying customers and authorised representatives;
  • conducting KYC and KYB;
  • identifying beneficial owners;
  • assessing customer risk;
  • conducting enhanced due diligence where required.

Financial Crime Prevention

  • preventing money laundering;
  • preventing terrorist financing;
  • preventing proliferation financing;
  • sanctions screening;
  • fraud detection and prevention;
  • transaction monitoring;
  • detecting unusual or suspicious activity;
  • investigating financial crime;
  • protecting DAT PAY and its partners from financial crime risks.

Regulatory and Legal Compliance

We may process personal data to comply with applicable:

  • laws and regulations;
  • court orders;
  • regulatory requirements;
  • tax obligations;
  • accounting requirements;
  • AML and CFT requirements;
  • sanctions requirements;
  • reporting obligations;
  • lawful requests from competent authorities.

Security

We process data to:

  • protect accounts;
  • authenticate users;
  • detect unauthorised access;
  • investigate security incidents;
  • prevent cyberattacks;
  • prevent abuse of our services;
  • maintain audit trails;
  • protect the integrity of transactions and systems.

Business Operations

We may also process information to:

  • maintain and improve our services;
  • manage our technology infrastructure;
  • conduct internal audits;
  • manage operational risks;
  • perform analytics;
  • maintain business records;
  • enforce contractual rights;
  • resolve disputes;
  • protect our legal interests.

Communications and Marketing

Where permitted by applicable law, we may send service-related communications.

Marketing communications will be sent where permitted by law and, where consent is required, only after obtaining the required consent.

You may opt out of marketing communications at any time.

7. Financial Crime, Compliance and Screening

DAT PAY operates within an environment where financial crime prevention and regulatory compliance are fundamental requirements.

We may therefore conduct or facilitate:

  • identity verification;
  • business verification;
  • sanctions screening;
  • PEP screening;
  • adverse media screening;
  • fraud screening;
  • transaction monitoring;
  • source of funds checks;
  • source of wealth checks;
  • enhanced due diligence;
  • ongoing customer risk assessment.

We may use internal systems and appropriately appointed third-party systems to perform these activities.

Where required, information may be shared with regulated financial institutions, payment providers, compliance service providers, regulators, law enforcement authorities and other competent authorities.

We may restrict, suspend, reject or delay a transaction or account activity where necessary to comply with applicable law, regulatory requirements, sanctions obligations, fraud controls, risk management procedures or contractual requirements.

Where permitted by law, we may be unable to disclose certain information concerning investigations, suspicious activity reports, sanctions screening or other confidential compliance processes.

8. Automated Processing

DAT PAY may use automated technologies to assist with:

  • identity verification;
  • sanctions screening;
  • fraud detection;
  • transaction monitoring;
  • security monitoring;
  • risk assessment;
  • account protection.

Automated processing may generate alerts or require additional verification or human review.

Where applicable law gives you rights concerning decisions based solely on automated processing, we will respect those rights.

DAT PAY does not intend to use solely automated processing to produce legal or similarly significant effects where such processing is prohibited by applicable law.

9. Who We Share Personal Data With

We do not sell personal data.

We may disclose personal data where necessary and lawful to:

  • regulated banks and financial institutions;
  • payment institutions and payment service providers;
  • correspondent institutions;
  • settlement and payment networks;
  • foreign exchange and treasury service providers;
  • digital asset and blockchain service providers;
  • identity verification providers;
  • KYB and KYC service providers;
  • sanctions and PEP screening providers;
  • fraud prevention and transaction monitoring providers;
  • technology and infrastructure providers;
  • cloud hosting and database providers;
  • cybersecurity providers;
  • communications and email service providers;
  • professional advisers;
  • auditors;
  • insurers;
  • legal advisers;
  • competent regulators;
  • courts;
  • law enforcement authorities;
  • tax authorities;
  • other competent public authorities where legally required.

We require service providers that process personal data on our behalf to maintain appropriate contractual, organisational and technical safeguards consistent with their role and applicable law.

10. Regulatory and Law Enforcement Disclosures

We may disclose personal data where required or permitted by applicable law, including in response to:

  • court orders;
  • regulatory requests;
  • lawful requests from law enforcement;
  • tax authority requests;
  • sanctions requirements;
  • AML and CFT obligations;
  • fraud investigations;
  • requests from competent public authorities.

We may also disclose information where reasonably necessary to establish, exercise or defend legal rights.

11. International Data Transfers

DAT PAY operates in an international financial environment.

Your personal data may therefore be processed or accessed in countries other than the country in which you reside.

International transfers may be necessary to:

  • execute cross-border transactions;
  • provide financial services;
  • conduct identity and business verification;
  • conduct sanctions and fraud screening;
  • operate our technology infrastructure;
  • provide customer support;
  • comply with legal and regulatory obligations.

Where personal data is transferred internationally, DAT PAY will apply safeguards required by applicable law.

Depending on the applicable jurisdiction and circumstances, these safeguards may include:

  • adequacy mechanisms;
  • contractual protections;
  • standard contractual clauses where applicable;
  • regulatory authorisations or approvals where required;
  • appropriate technical and organisational safeguards.

Where applicable under Cameroonian law, international transfers of personal data will be subject to the required regulatory framework and authorisations.

Where the GDPR applies, international transfers will be handled in accordance with applicable GDPR requirements.

12. Data Security

DAT PAY maintains technical and organisational measures designed to protect personal data against:

  • unauthorised access;
  • unauthorised disclosure;
  • alteration;
  • loss;
  • destruction;
  • misuse;
  • accidental or unlawful processing.

Depending on the system and service, security measures may include:

  • encryption in transit;
  • encryption or other protection of sensitive information at rest;
  • access controls;
  • authentication controls;
  • multi-factor authentication where available;
  • role-based access;
  • privileged access controls;
  • logging and audit trails;
  • security monitoring;
  • vulnerability management;
  • backup and recovery controls;
  • incident response procedures;
  • segregation of duties;
  • personnel confidentiality obligations.

Access to personal data is limited to persons and service providers who require access for legitimate business, operational, security, legal or regulatory purposes.

No internet-based system can be guaranteed to be completely secure. You are responsible for protecting your authentication credentials and promptly notifying DAT PAY of suspected unauthorised access to your account.

13. Personal Data Breaches

DAT PAY maintains procedures for identifying, investigating, containing and responding to personal data breaches.

Where a breach occurs, DAT PAY will assess its nature, scope, potential impact and applicable legal reporting requirements.

Where notification is required, we will notify the competent authority and affected individuals in accordance with applicable law and within the applicable statutory timeframe.

We may also take measures including:

  • containment;
  • investigation;
  • remediation;
  • security improvements;
  • preservation of evidence;
  • engagement of specialist advisers;
  • notification of relevant financial or regulatory partners where required.

14. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required or permitted by law.

Retention periods may be determined by:

  • AML and CFT requirements;
  • sanctions obligations;
  • financial and payment regulations;
  • tax requirements;
  • accounting requirements;
  • contractual obligations;
  • legal claims;
  • regulatory investigations;
  • fraud investigations;
  • dispute resolution;
  • security requirements;
  • legal holds.

Customer identification, transaction and compliance records may therefore be retained after an account is closed where required by applicable law or regulatory requirements.

Where no legal, regulatory, contractual or legitimate business reason requires continued retention, personal data will be deleted, anonymised or otherwise securely disposed of in accordance with our retention procedures.

A request to delete an account does not override mandatory legal or regulatory record-keeping obligations.

15. Your Privacy Rights

Subject to applicable law and legitimate legal, regulatory and security requirements, you may have the right to:

  • request access to personal data we hold about you;
  • request correction of inaccurate or incomplete information;
  • request deletion of personal data;
  • request restriction of processing;
  • object to certain processing;
  • request portability of certain personal data;
  • withdraw consent where processing relies on consent;
  • obtain information about how your personal data is processed;
  • exercise rights relating to automated decision-making where applicable;
  • lodge a complaint with the competent data protection authority.

These rights are not absolute.

For example, DAT PAY may be required to retain information to comply with AML, sanctions, tax, accounting, regulatory, legal or other mandatory obligations.

16. Exercising Your Rights

Requests concerning your personal data should be submitted through the privacy contact channel published by DAT PAY.

To protect your account and personal information, we may need to verify your identity before responding to a request.

We will respond within the period required by applicable law.

Where we cannot fulfil a request because of a legal, regulatory or other permitted restriction, we will explain the applicable limitation where legally permitted to do so.

17. Complaints

If you believe that DAT PAY has processed your personal data unlawfully or has failed to respect your applicable data protection rights, you may contact us first so that we can investigate the matter.

You may also have the right to lodge a complaint with the competent data protection authority in the jurisdiction applicable to you.

18. Cookies and Similar Technologies

DAT PAY uses cookies and similar technologies on its website and, where applicable, within its digital services.

These technologies may be used for:

  • essential website functionality;
  • security;
  • authentication;
  • preferences;
  • performance;
  • analytics;
  • service improvement;
  • marketing where permitted.

Where consent is required for non-essential cookies, we will request consent through the applicable cookie management mechanism.

You may manage your cookie preferences through the cookie settings available on the website.

Further information is provided in our Cookie Policy.

19. Children’s Privacy

DAT PAY services are intended for persons and organisations that are legally capable of entering into the relevant relationship or otherwise permitted to use the applicable service.

We do not knowingly collect personal data from children in circumstances where such collection is prohibited by applicable law.

Where a service is subject to minimum age or legal capacity requirements, those requirements apply.

21. Corporate and Business Changes

If DAT PAY or HACHTHER SARL is involved in a merger, acquisition, restructuring, financing, transfer of assets, sale of a business line or similar corporate transaction, personal data may be transferred as part of that transaction where permitted by applicable law.

Any such transfer will remain subject to applicable confidentiality, security and data protection requirements.

22. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • changes in our services;
  • changes in our technology;
  • changes in applicable laws or regulations;
  • regulatory guidance;
  • changes in our data processing activities;
  • security or operational developments.

The updated version will be published on this page with a revised “Last updated” date.

Where required by law, we will provide additional notice or obtain consent for material changes.

23. Contact

Questions, requests or complaints concerning this Privacy Policy or the processing of personal data may be submitted through the privacy contact address published on the DAT PAY website.

Postal correspondence may be addressed to:

HACHTHER SARL For the attention of the Data Protection Contact Republic of Cameroon

Privacy Policy | DAT PAY