Privacy Policy
This English version is provided for your convenience. The legally binding version is the Portuguese-language master at /legal/privacidade . In case of any discrepancy, the Portuguese version prevails.
About this Notice
This Privacy Policy explains what personal data we collect when you use Ondjango Bay, why we collect it, who we share it with, how long we keep it, and what choices and rights you have. It applies to all users - consumer buyers, business buyers, sellers, registered users, and visitors - and to all our channels: the website, mobile applications, public APIs, and any communications you have with us.
This policy is a summary in plain language; for the full legal text and statutory references, see the master document at /legal/privacidade (Portuguese).
Who We Are
The controller of your personal data is ONDJANGO BAY, S.A., a public limited company organised under Angolan law, registered at Luanda, NIF [to be confirmed]. Our role under Lei n.º 22/11 (Personal Data Protection) is the "Responsável pelo Tratamento".
We have appointed a Data Protection Officer (DPO). The DPO is your privileged contact for any data-protection question or request. You can reach the DPO at dpo@ondjangobay.co.ao or through the Privacy Centre .
What Data We Collect
The data we collect depends on how you use Ondjango Bay. The main categories are:
- Identification data - name, date of birth, nationality, identification document details (when KYC verification is required).
- Contact data - email, phone number, postal and delivery addresses.
- Account credentials - username, password (encrypted, never in plain text), two-factor authentication factors.
- Transaction data - your orders, cart contents, payment preferences, amounts, refunds, chargebacks.
- Payment data - tokenised references to your payment methods; we do not store full card numbers.
- Navigation data - pages you visit, items you view, searches, clicks, time spent - processed in line with our cookie rules.
- Device data - IP address, device identifier, model, operating system, browser, language, time zone.
- Location data - approximate location from your IP; precise location only with your explicit consent.
- Content you post - listings, photos, reviews, comments, questions, messages.
- Support history - messages with our support team, complaints, decisions.
- Compliance data - KYC/KYB elements, sanctions-screening results, suspicious-activity reports (not disclosed to you due to legal secrecy).
We do not knowingly collect sensitive data (e.g. health, religion, political opinions) unless you explicitly provide it (for example, in a message), or unless we need to (for instance, biometric data for optional fingerprint login - which is only processed with your explicit consent).
How We Use Your Data
We use your data for the following purposes:
- To run your account and let you use the platform - authentication, profile, preferences, support.
- To process orders - formation of the contract with the seller, payment, delivery coordination, returns, warranty.
- To comply with legal duties - identity verification (KYC), anti-money-laundering (AML/CFT), tax, consumer protection, regulatory reporting.
- To prevent fraud and keep you safe - risk analysis on transactions, detection of misuse, security monitoring.
- To send you operational communications - order updates, security alerts, policy changes (no consent required).
- To send you marketing - newsletters, recommendations, promotions - only with your consent (or, where allowed, for products similar to those you have already bought, with a clear opt-out).
- To personalise your experience - recommendations, search results, advertising - in line with your preferences.
- To improve our services - analytics, A/B testing, model training - using pseudonymised or aggregated data where possible.
Why We Can Use Your Data (Legal Bases)
Under Article 6 of Lei n.º 22/11, we always need a legal basis to process your data. We rely on:
- Performance of a contract - when you have an account or an order with us, we can process the data needed to deliver that contract.
- Legal obligation - to comply with KYC/AML, tax, consumer-protection and other duties.
- Legitimate interest - to prevent fraud, secure the platform, perform basic analytics, and run non-intrusive marketing for similar products - always weighed against your rights.
- Your consent - for cookies that are not strictly necessary, for marketing communications, for biometric authentication, for precise location, and for some optional features. You can withdraw consent at any time.
- Vital interests - in rare cases where someone's life or safety is at risk.
If you want to know which legal basis applies to a specific processing operation, you can ask us at dpo@ondjangobay.co.ao and we will tell you within the time limits set by law.
Who We Share Your Data With
We share only what is necessary, and only with the following categories of recipients:
- Sellers (when you buy from a seller) - your name, delivery address and contact details, so they can fulfil the order. Sellers act as independent controllers and must respect your rights.
- Buyers (when you sell) - your seller identity and ratings, so buyers can decide.
- Payment processors - EMIS (Multicaixa Express), PayPal, Stripe and other PSPs we integrate, for the strict purpose of processing your payment.
- Carriers - DHL Express and other logistics partners, for delivery of your orders.
- Public authorities - APD, BNA, AGT, INADEC, UIF, courts and security forces - only when required by law.
- Service providers - cloud hosting, analytics, fraud detection, identity verification, customer support - all bound by written contracts that require them to protect your data.
We do not sell your personal data to third parties for their own marketing. A public, updated list of our main service providers (sub-processors) is available on request to the DPO and is also referenced in our Third-Party Services Disclosure .
International Transfers
Some of our service providers and payment partners operate internationally, which means your data may be transferred outside Angola - typically to the European Union, the United States, the United Kingdom, South Africa, China, or Southeast Asia. We only do this when we have appropriate safeguards in place:
- Authorisation from the Agência de Proteção de Dados (APD) where the law requires it.
- Contractual clauses with the recipient that ensure a level of protection equivalent to Angolan law.
- Recognition by competent authorities that the destination country provides adequate protection.
- Your explicit consent, for specific transfers we cannot otherwise justify.
If you want details about a specific transfer, ask the DPO. You can also object to a transfer based on legitimate interest. See the full International Transfers Policy .
How Long We Keep Your Data
We keep your data only as long as we need it, plus any extra time required by law. As a guide:
- Account data - for as long as your account is open.
- Transaction and tax data - 10 years from the order, as required by tax law and AML/CFT rules.
- KYC/KYB records - 10 years after the end of our relationship, under Lei n.º 5/20.
- Marketing data - until you withdraw consent, plus a short period for proof.
- Cookies - periods specific to each cookie, listed in the Cookie Policy .
- Navigation logs - pseudonymised or aggregated whenever possible; identifiable logs for limited periods.
- Support messages - 3 years after case closure, unless a dispute is open.
When we no longer need your data, we either securely erase it or anonymise it (so it can no longer be linked to you). In some cases we keep data longer for legal reasons (e.g. ongoing litigation, regulatory orders).
Your Privacy Rights
Under Lei n.º 22/11 you have the following rights, free of charge:
- Right of access - to know what data we hold about you, and to receive a copy.
- Right of rectification - to correct inaccurate or incomplete data.
- Right of erasure - to have your data deleted, in the cases the law allows.
- Right to object - to processing based on legitimate interest, or to direct marketing.
- Right of restriction - to limit how we use your data while we resolve a dispute about it.
- Right of portability - to receive your data in a structured format and send it to another controller.
- Right not to be subject to fully automated decisions - to ask for human review of automated decisions that affect you significantly.
To exercise any right, go to the Privacy Centre or email dpo@ondjangobay.co.ao. We will respond within 30 days, extendable by 60 days for complex requests. If you are not satisfied, you can complain to the Agência de Proteção de Dados (APD) and take judicial action.
How We Keep Your Data Safe
We protect your data with technical and organisational measures appropriate to the risk, including:
- Encryption - in transit (TLS) and at rest for sensitive data.
- Access control - multi-factor authentication for administrators, principle of least privilege, prompt revocation.
- Network security - segmentation, firewalls, intrusion detection, DDoS protection.
- Monitoring - centralised security logging and alerting (SIEM).
- Vulnerability management - periodic scanning, penetration testing, responsible disclosure programme.
- Backups and continuity - encrypted backups, disaster-recovery plans.
- Incident response - a dedicated team and a written response plan.
- Vendor management - due diligence and contracts with all service providers.
- Privacy by design - protection considered from the start of every new product and feature.
If despite our measures there is a breach of your personal data that poses a risk to your rights and freedoms, we will notify the APD within 72 hours and, when the risk is high, communicate with you individually.
Cookies and Similar Technologies
We use cookies and similar technologies to operate the platform, remember your preferences, analyse usage, and (with your consent) personalise content and advertising. For the full list of cookies and your control options, see the Cookie Policy and use the Cookie Preferences button at any time.
Children
Ondjango Bay is not intended for people under 18. We do not knowingly collect personal data of minors. If you are a parent or legal representative and believe we may have collected data about your child, contact dpo@ondjangobay.co.ao and we will take immediate steps to remove it. See the Minors Data Processing document for the full regime.
Automated Decisions
Some decisions on the platform are taken with the help of automated systems - for example, blocking a suspicious transaction, preventively suspending an account, or refusing an order on anti-fraud grounds. We always offer:
- The right to know that an automated decision was taken and to understand its logic in plain language.
- The right to request human review of the decision.
- The right to express your point of view and contest the decision.
See the Automated Decisions Policy for details. Material Remedies always involve human review before they are applied (with limited emergency exceptions for fraud, sanctions, or risk to minors).
Changes to This Notice
We may update this Privacy Policy from time to time. For material changes - for example, adding a new data category, a new purpose, or a new recipient - we will notify you at least 30 days in advance by email or in-app notification, with a summary of the changes and the effective date. Where the change affects a consent-based processing, we will ask for your fresh consent.
Prior versions are archived at /legal/archive/DPP-01.
How to Contact Us
For any privacy question or request:
- Email the DPO: dpo@ondjangobay.co.ao
- Use the Privacy Centre for structured rights requests.
- Write to: ONDJANGO BAY, S.A., [registered office address], Luanda, Republic of Angola - marked "To the attention of the DPO - Confidential".
- Reach our Information Security Team at security@ondjangobay.co.ao for security incidents involving personal data.
You also have the right to file a complaint with the Agência de Proteção de Dados (APD) and to seek judicial remedy.


