Privacy policy
Last updated: 30/09/2026. This policy explains what personal data the SIDRAT application and platform process, why, and how you can exercise your rights.
1. Who we are
SIDRAT is a platform used by a professional network (central office, agents and distributors) to manage money-transfer requests, liquidity and commissions. Data controller:
Neokraal
Contact : from the app (Menu → My profile)
2. Data we process
- Account: first and last name, e-mail and/or phone number, password (stored only as a one-way hash), optional PIN (hashed), two-factor authentication secret (encrypted), language.
- Network role: the actor(s) you belong to (agent, distributor…), your role and permissions.
- Transfers: amounts, currencies, countries, sender and beneficiary (name, phone, and — when required by law — ID type and number, stored encrypted), payout details (mobile-money number, bank account), status history.
- Proof documents: photos or PDFs you choose to attach (receipts, transfer slips).
- Device and security: device identifier and model, push-notification token, IP address, user agent, sign-in sessions and an audit log of sensitive actions.
We do not collect your location, your contacts, your advertising identifier, and we do not use advertising or tracking SDKs.
3. Why
- Provide the service (create, route, approve and settle transfers; manage balances) — performance of a contract.
- Security and fraud prevention (authentication, device checks, audit log, anomaly detection) — legitimate interest.
- Compliance with financial regulations (record keeping, anti-money-laundering obligations) — legal obligation.
- Service notifications (new request, payment sent, low balance…).
4. Sharing
Transfer data is visible only to the network actors involved in that transfer and to the central office, according to their permissions. We use technical providers acting on our instructions: hosting, file storage (S3-compatible) and Google Firebase Cloud Messaging for push notifications. We never sell your data. Data may be disclosed to authorities when required by law.
5. Retention
- Account data: as long as your account is active.
- Financial records, proof documents and audit log: for the legal retention period applicable to financial operations (generally 5 to 10 years depending on the country), even after account deletion.
- Notifications and push tokens: deleted with the account.
6. Security
Encrypted connections (HTTPS), passwords and PINs hashed with bcrypt, sensitive fields encrypted with AES-256-GCM, server-side authorization on every request, immutable ledger and audit log, session revocation and optional two-factor authentication.
7. Your rights
You can access, rectify or delete your data, object to processing or ask for portability. You can delete your account in the app (Menu → My profile → Delete my account) or on this page. You may also lodge a complaint with your data-protection authority.
8. Children
SIDRAT is reserved for professionals aged 18 or over.
9. Changes
We will inform you in the app of any significant change to this policy.