Privacy Policy
This Privacy Policy explains how lomi. Technologies Africa S.A. (lomi., we, us), registered office at Cocody, Les Perles, Rue 01012 L82/375, Abidjan, Côte d'Ivoire, collects, uses, shares and protects personal data when you visit lomi.africa, create or use a lomi. account, pay a business that uses lomi., or otherwise interact with us. It applies to the businesses that use our payment services and their representatives (Merchants), to the people who pay them (Customers), and to visitors of our websites and documentation.
We process personal data in accordance with Côte d'Ivoire Law No. 2013-450 of 19 June 2013 on the protection of personal data, the ECOWAS Supplementary Act on personal data protection, and, where it applies to a data subject, the EU General Data Protection Regulation (GDPR). This Policy is part of our Terms and Conditions. It is drafted in French; the English, Spanish and Chinese versions are convenience translations and the French version prevails in case of conflict.
1. Who we are and our roles
Controller or processor, depending on the data
lomi. is a payment processor. We provide payment collection, checkout, payment-link, subscription and disbursement services to Merchants through licensed partner banks, electronic-money issuers, card acquirers and mobile-money operators (Payment Channel Partners). We are not a party to the sale between a Merchant and its Customers. lomi. Technologies Africa S.A. has applied to the BCEAO for authorisation as a payment institution; the application is under review.
lomi. as controller. We decide how and why personal data is processed, and are therefore the controller, when we: verify the identity of Merchants, their owners and representatives (KYC and KYB); process payments, refunds, Chargebacks and Payouts; prevent and detect fraud; comply with anti-money-laundering, counter-terrorist-financing, sanctions, tax and Card Network obligations; operate and secure our websites, dashboard, API and support channels; and send our own communications. For Customer data needed to complete a payment (for example name, email, phone number, payment instrument and transaction details), we act as an independent controller alongside the Merchant.
lomi. as processor. When a Merchant configures our services to collect or store additional Customer data on its behalf (for example custom checkout fields, delivery addresses, customer notes or catalog data), we process that data as the Merchant's processor, only on its documented instructions. The Merchant is the controller of that data and is responsible for informing its Customers and for answering their requests; we assist it as described in our Terms.
Merchants' own obligations. Each Merchant is responsible for its own compliance with data-protection law in its relationship with its Customers, including telling them that payments are processed by lomi. and its Payment Channel Partners.
2. Personal data we collect
What we collect, from whom, and where it comes from
Personal data means any information that identifies, or could reasonably be used to identify, a natural person. Data that has been aggregated or anonymized so that it can no longer be associated with a person is not personal data. What we collect depends on how you interact with us.
2.1 Merchants and their representatives
- Account and identity data: name, email address, phone number, role, login credentials, language and preferences.
- Business verification (KYC and KYB): legal and trade name, registration number (such as RCCM), tax identification (such as NINEA or DFE), address, business description and websites, identity documents of owners, directors and signatories (including document number, date and place of birth, nationality and photograph), proof of address, beneficial-ownership information, bank account or mobile-money details for Payouts, and the results of sanctions, politically-exposed-person and registry checks.
- Financial and transaction data: Balance, Payouts, Fees, invoices, refunds, Chargebacks, Reserves and Holds, and the transactions you process.
- Usage and technical data: dashboard actions, API calls and keys, webhook endpoints, connected applications and AI agents authorized through OAuth, IP address, device and browser information, and security logs.
- Communications: support requests, emails, WhatsApp or SMS messages, survey answers and feedback.
- lomi. Pos and in-person payments: device model, operating-system version, app version, device integrity and attestation results and, where the Tap to Pay provider or the device platform requires it for fraud prevention, the approximate location of the device at the time of a transaction; staff user profiles and hashed PINs; and the in-person transactions you process.
2.2 Customers who pay a Merchant
- Payment data: name, email address, phone number, mobile-money number, card details (processed through our PCI DSS compliant partners; we do not store full card numbers or CVV on our own systems), bank account or instant-payment identifiers, billing and, where the Merchant requests it, delivery address.
- Transaction data: amount, currency, date, payment method, Merchant, product or service description, status, refunds and disputes.
- Fraud and device data: IP address, device and browser fingerprint, approximate location derived from IP, authentication results (for example 3-D Secure or mobile-money confirmation) and risk signals from our Payment Channel Partners.
- Additional data configured by the Merchant, which we process as the Merchant's processor.
2.3 Website and documentation visitors
Technical data such as IP address, browser and device type, pages viewed, referrer and approximate country, collected through essential cookies and our cookieless analytics (see Section 9), and any information you send us through a contact form, a newsletter sign-up or an email.
2.4 Sources
We receive personal data directly from you, from the Merchant you pay or work for, from our Payment Channel Partners (for example authorization results, dispute notices and account details), from identity-verification and fraud-prevention providers, from public registries (including a greffe, RCCM or NINEA records), from sanctions and PEP lists, and from your interactions with our websites, dashboard and API.
3. Why we use personal data and on what legal basis
Purposes and legal bases
Law 2013-450 and the GDPR require a legal basis for each processing. We rely on the following:
- Performance of a contract (our Terms with Merchants, and the payment you ask us to process): to open and manage accounts, process payments, refunds, Payouts and disbursements, send receipts and transactional notices, provide support and operate the dashboard, API, MCP server and plugins.
- Compliance with legal obligations: to verify identities and beneficial owners, screen sanctions and PEP lists, keep records, detect and report suspicious transactions to the CENTIF and other competent authorities, respond to lawful requests from courts, regulators and law enforcement, comply with the BCEAO, UEMOA and tax rules and with the Card Network Rules.
- Legitimate interests of lomi., Merchants, Customers and Payment Channel Partners, where not overridden by your rights: to prevent fraud and abuse, manage Chargebacks, Holds and Reserves, secure our systems, analyze and improve our products, enforce our Terms, manage our business and defend our rights.
- Consent, where the law requires it: for marketing messages to people who are not yet our customers, for non-essential cookies if we ever use them, and for certain international transfers. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
Providing the data marked as required at sign-up or checkout is necessary to open an account or to complete a payment; without it we cannot provide the service. Other data is optional and is indicated as such when we ask for it.
In line with Article 50 of BCEAO Instruction No. 001-01-2024, we access only the personal data necessary to provide the payment services and to meet our legal obligations, we may process personal data to prevent, investigate and detect payment fraud, and we ask for your explicit consent before any other use, processing or retention of your data.
4. Automated decisions, fraud scoring and AI-assisted review
How automation is used and how you can contest it
We use automated tools to keep payments safe and to meet our compliance obligations: transaction risk scoring (including tools provided by our Payment Channel Partners such as Stripe Radar), velocity and pattern checks, sanctions and PEP screening, document authenticity checks, and AI-assisted review of onboarding files and support requests.
These tools may block or delay a payment, place a Hold or Reserve, or flag an account for review. In line with Article 25 of Law 2013-450 and Article 22 of the GDPR, no decision that produces legal effects or similarly significantly affects you (for example refusing an account, terminating a Merchant, or reporting to an authority) is based solely on automated processing: such decisions are reviewed by a trained member of our team, who considers the documents and explanations you provide.
You have the right to obtain meaningful information about the logic involved, to express your point of view, and to contest an automated decision by writing to hello@lomi.africa. We will review it and answer within thirty (30) days. We may not disclose details that would reveal a Payment Channel Partner's confidential risk criteria or compromise an investigation.
6. International transfers
Where personal data is stored and processed
We are established in Côte d'Ivoire and our Payment Channel Partners are mainly in the UEMOA zone. Some of our service providers and partners, including cloud hosting, analytics, email delivery, identity verification and card acquiring (for example Stripe), process data in the United States or in the European Union.
Transfers within the ECOWAS area are permitted under Law 2013-450 and the ECOWAS Supplementary Act. Transfers to countries outside ECOWAS are made only where the destination provides an adequate level of protection or with appropriate safeguards, including contractual data-protection clauses with the recipient, the recipient's binding security and confidentiality commitments, and, where required, the prior authorization of the ARTCI. We limit transferred data to what is necessary for the purpose. You may ask us for information about the safeguards that apply to a specific transfer.
Authorities of the countries where data is processed may, in some cases, be entitled to access it under their own laws.
7. How long we keep personal data
Retention periods
We keep personal data only for as long as needed for the purposes described in this Policy and to meet our legal obligations, then delete or anonymize it. The main periods are:
- Identity, KYC, KYB and transaction records: ten (10) years after the end of the business relationship or the date of the transaction, as required by the anti-money-laundering and counter-terrorist-financing law applicable in Côte d'Ivoire and the UEMOA (uniform law implemented by Ordinance No. 2023-875) and by our Payment Channel Partners.
- Dispute, refund and fraud evidence (including Payment Link descriptions, receipts and Customer communications): for the applicable card-scheme dispute window and any ongoing investigation, and in any case within the ten-year period above.
- Accounting and tax records: ten (10) years under OHADA accounting law and the Ivorian tax code.
- Account, usage and security logs: for the life of the account and up to two (2) years after closure, unless needed longer for security investigations or legal claims.
- Marketing data and cookies: until you opt out or, for prospects, three (3) years after your last interaction; analytics data is aggregated and does not identify you.
- Support communications: three (3) years after the last exchange.
When a Merchant closes its account we stop active processing but keep the records above for the periods indicated. Residual copies may remain in encrypted backups for a limited time before they are overwritten. Anonymized data may be kept indefinitely.
8. Security and breach notification
How we protect personal data
We apply organizational, technical and physical measures appropriate to the risk, including encryption of data in transit and at rest, network and application access controls, least-privilege and multi-factor authentication for our staff, segregation of environments, logging and monitoring, secure development practices, vulnerability management, vendor due diligence and staff training. Card data is handled through PCI DSS compliant Payment Channel Partners and never stored in full on our systems. Secret API keys are shown once and stored hashed.
No system is perfectly secure. Merchants remain responsible for protecting their own credentials, API keys and systems, and Customers for their payment instruments and devices.
If we become aware of a personal-data breach likely to result in a risk to your rights, we will notify the ARTCI and, where required, the affected persons and Merchants without undue delay and in any case within seventy-two (72) hours of becoming aware of it, with the information available at that time, and we will cooperate with the Merchant in its own notifications. If you believe your data or account is no longer secure, contact us immediately at hello@lomi.africa.
10. Marketing communications
What we send and how to opt out
If you are a Merchant or have asked to hear from us, we may send you product news, changelog updates, educational content and event invitations by email and, where you have given us the number for that purpose, by WhatsApp or SMS. We do not send marketing to Customers based on the payments they make to Merchants, and we do not share your contact details with third parties for their own marketing.
You can opt out at any time through the unsubscribe link in each email, by replying STOP to a WhatsApp or SMS message, in your dashboard notification settings, or by writing to hello@lomi.africa. We will act on your request within ten (10) business days. Opting out of marketing does not stop transactional and service messages (receipts, security alerts, dispute notices, changes to our Terms), which we must send to operate your account.
11. Your rights
What you can ask and how we answer
Subject to the conditions and exceptions set by applicable law, you have the right to:
- Information and access: know whether we process your personal data and obtain a copy of it and of the related information.
- Rectification: have inaccurate or incomplete data corrected or completed.
- Erasure: have your data deleted where it is no longer necessary, where you withdraw consent, or where it was processed unlawfully. Records we must keep by law (Section 7) are exempt.
- Objection and restriction: object to processing based on legitimate interests, object at any time to direct marketing, and ask us to restrict processing while a request is being examined.
- Portability: receive the data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another provider where technically feasible.
- Automated decisions: not be subject to a decision based solely on automated processing, and obtain human review (Section 4).
- Withdraw consent at any time where processing is based on consent.
To exercise a right, write to hello@lomi.africa from the email address linked to your account, or by post to the address in Section 15, stating which right you exercise and which data is concerned. We may ask for information to verify your identity. We answer within thirty (30) days, extendable by a further sixty (60) days for complex requests with notice to you. Requests are free unless manifestly unfounded or excessive. If you are a Customer and your request concerns data controlled by a Merchant, we will direct you to the Merchant and assist it where we act as its processor.
Complaints. You may lodge a complaint with the Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI), the Ivorian data-protection authority (artci.ci), or with the competent authority of your country of residence. We would appreciate the chance to address your concern first.
12. Children
Our services are for adults and businesses
Our services are intended for businesses and for adults aged eighteen (18) or over. We do not knowingly collect personal data from children under eighteen (18). Merchants selling to minors must comply with the law applicable to them and may not submit a minor's personal data to us beyond what a payment requires. If you believe a child has provided us with personal data, contact us at hello@lomi.africa and we will delete it.
13. If you pay a business that uses lomi.
What Customers should know
When you pay a Merchant through a lomi. checkout, Payment Link or plugin, the Merchant is responsible for your order and for its own privacy policy. We process your payment data as described in this Policy to complete the payment, prevent fraud, handle refunds and disputes and meet our legal obligations, and we share with the Merchant what it needs to fulfil your order.
We may show you a receipt, save your email or phone number to send it, and, if you choose, remember your payment method for future payments to Merchants using lomi. You can ask us to forget a saved method at any time. For questions about an order, contact the Merchant first; for questions about how lomi. processes your data, contact us at hello@lomi.africa.
14. Changes to this Policy
How we tell you about updates
We may update this Policy when our services, partners or legal obligations change. The Last updated date at the bottom of this page shows the latest revision. For material changes in how we use personal data, we will give Merchants at least two (2) months' notice by email and in the dashboard before the change takes effect, and will inform Customers through the checkout or our website where appropriate. Changes required by law may take effect on the date the law requires. Continued use of our services after the effective date means you have read the updated Policy.
15. Contact
How to reach us about privacy
For any question, request or complaint about this Policy or about your personal data, contact our privacy team at hello@lomi.africa or by post at lomi. Technologies Africa S.A., Privacy, Cocody, Les Perles, Rue 01012 L82/375, Abidjan, Côte d'Ivoire. We acknowledge requests within five (5) business days.
Last updated: September 8, 2026