Version 1.0 · effective 26 September 2026 · Required by Article 30 of Loi n° 2024/017
This agreement is between Astra Digital CM, operator of Proxim ("Proxim", "we"), and the merchant using the platform ("you"). Under Cameroon's Law No. 2024/017 of 23 December 2024 on the protection of personal data, you are the controller of the personal data of your own customers, and Proxim is your processor. Article 30 requires that this relationship be governed by a contract, which is what this document is.
Proxim processes personal data only on your documented instructions, and only for these purposes:
We do not use your customers' data for our own purposes, and we do not sell or rent it.
| Data subjects | Categories of data |
|---|---|
| Your customers and leads | Name, phone number, email address, notes, status, conversation history, messages, photographs, voice notes, order history, delivery address and city |
| Your staff | Name, email address, phone number, role, locale, assignment of leads |
| Your business | Business name, storefront URL, product catalogue, prices, stock, coupons, shipping zones, order records, payment references, subscription and invoice history |
| Technical contacts | Channel credentials (WhatsApp, Telegram), payment provider keys, push notification device tokens, access and deletion logs |
Proxim does not ask for and does not intend to process special categories of data (health, biometrics, political or religious opinions, or criminal data). Do not send such data through the assistant or a customer record.
Article 25 and 26 of the Law require technical and organisational measures proportionate to the risk, including preventing unauthorised reading, copying, transmission or erasure, restricting access to each person's own scope, and being able to verify after the fact who accessed or changed what, and when. We apply, among others:
These providers process data on our instructions so the service can work. Each is bound by its own contract with us.
| Provider | Purpose | What it receives |
|---|---|---|
| Meta (WhatsApp Business Cloud API) | Sending and receiving WhatsApp messages | Message content, phone numbers, media |
| Telegram (Bot API) | Sending and receiving Telegram messages | Message content, chat ids, media |
| Anthropic or DeepSeek | Generating the assistant's replies | Conversation context, your products, your persona |
| OpenAI | Voice-note transcription, text-to-speech | Audio or text to be converted |
| NotchPay | Taking payment from your buyers, and your subscription | Amounts, references, buyer contact for payment |
| Resend | Transactional email | Email addresses |
| Hosting and email provider | Running the platform | All of the above, at rest |
If we add or replace a sub-processor we will tell you at least thirty days before your data starts going to them, and you may object in writing. If we cannot resolve the objection you may close your account and export your data, and we will delete it as described in section 8.
Data is kept only as long as the processing needs it, as required by Article 13 of the Law. The current schedule is published in our Privacy Policy and is enforced automatically.
When one of your customers asks to be forgotten, you action it in Proxim by deleting that customer:
When you close your business, everything without a legal retention duty is deleted immediately, your channel credentials included, and your financial records are kept for ten years with buyer identity removed. We will never quietly retain data we are required to keep: when we do, we tell you, and tell you for how long.
Article 22(1) of the Law requires that, as soon as we become aware of a breach, the processor — which is us, not only you — informs the data protection authority and the affected person, without delay. The Law sets no deadline in days. We will notify you at the same time, with what we know, what it affects, and what we are doing about it. Because the supervisory authority has not yet been established and has no published contact point, please report anything you suspect to support@astradigitalcm.com.
Article 32 of the Law requires prior authorisation from the data protection authority before personal data is transferred to another country, together with standard contractual clauses published by that authority. The authority was created by Article 53 of the Law but has not yet been put in place, so no such authorisation or clauses exist today, and our providers — several of which are outside Cameroon — operate in that gap. We are not treating the absence as permission: we minimise what leaves the platform, we publish the list rather than hide it, and we will complete the authorisation as soon as there is an authority to file it with. This paragraph will be updated when that happens.
You may ask us for evidence that we are meeting this agreement — a report on the processing we perform for you, a copy of the deletion log for your business, or confirmation of the sub-processors in use. We will answer within thirty days. An on-site audit is possible on reasonable written notice, at your cost, once a year, and only where an account of our measures is not sufficient.
This agreement is governed by the laws of the Republic of Cameroon. Each party is liable for its own breaches. Where our breach causes you a loss that is not covered by the refund or service credits in our Terms of Service, our aggregate liability is limited to the fees you paid in the twelve months before the loss. Nothing here limits liability that cannot be limited by law, including for the wilful or reckless mishandling of personal data.
If we change this agreement in a way that affects your obligations, we will tell you before the change takes effect and ask you to accept the new version. Your acceptance is recorded with the version number, the date, and the locale you read it in. Continuing to use the platform after the change takes effect means you accept it.
| Detail | Value |
|---|---|
| Processor | Astra Digital CM — Ahala Barrière, Yaoundé, Cameroon |
| support@astradigitalcm.com | |
| Phone | +237 698262989 |