This Privacy Policy describes how MicroLink, a company registered at BP 521,
Libreville, Gabon (Statistical ID No. 085332F β RCS No. 2006B04993 β License No. 001-8073GU1 dated
03/06/2006), publisher of the xFin solution, collects, uses and protects the
personal data of visitors to the xfin.pro website, users of the Merchant Portal and the xFin Portal
Android app.
Article 1 β Data controller
MicroLink acts as data controller for data collected via the xfin.pro website, the contact form,
the Merchant Portal and the associated Android app. For any question relating to this Policy,
MicroLink can be contacted using the details set out in Article 12.
Article 2 β Data we collect
Depending on your use of the Services, we may collect:
- Data submitted via the contact form: name, email address, subject and message content;
- Merchant account data: identity, contact details, business information, and payout bank details, provided when opening access to the API or the Portal;
- Transaction data: payment references, amounts, statuses and timestamps, required for tracking and reconciling operations;
- Technical browsing data: IP address, browser type, pages viewed, collected automatically when visiting the site;
- Android app usage data: see Article 4.
Article 3 β Purposes and legal bases
Your data is processed for the following purposes:
- Responding to your requests submitted via the contact form (legal basis: pre-contractual measures or legitimate interest);
- Providing and securing the Services (API, Sandbox, Merchant Portal, Android app), including fraud prevention and compliance with AML/CFT obligations (legal basis: performance of the contract and legal obligations);
- Ensuring accounting oversight and disbursement of funds (legal basis: performance of the contract);
- Measuring website traffic for continuous improvement (legal basis: consent, collected via the cookie banner);
- Complying with our legal and regulatory obligations applicable within the CEMAC region.
Article 4 β xFin Portal Android app
The xFin Portal Android app, currently offered in early access via direct APK
download, allows users to configure their applications, manage their access and track their
accounts and transactions from their mobile device. It accesses the same merchant account and
transaction data as the browser-based Merchant Portal, through an authenticated connection to the
xFin API. No device data (contacts, photos, precise location) is collected by the app beyond what
is strictly necessary for its operation and security (session identifiers, technical connection
logs).
Article 5 β Data recipients
The data collected may be shared, to the extent necessary, with:
- Authorized internal MicroLink teams (support, technical, compliance);
- Payment Partners (banking institutions, Mobile Money operators) for the execution of transactions;
- FormSubmit, the technical provider used to route messages from the contact form to our mailbox;
- Google Analytics (Google Ireland Limited), used for website traffic measurement, subject to your cookie consent;
- Competent authorities, where required by law, notably in connection with AML/CFT obligations.
Article 6 β Transfers outside the CEMAC region
Certain technical service providers (hosting, traffic measurement, routing of contact form emails)
may process data outside the CEMAC region. In such cases, MicroLink ensures that these providers
offer appropriate data-protection safeguards, consistent with standards generally recognized in
this area (contractual clauses, confidentiality commitments).
Article 7 β Retention periods
- Contact form messages: kept for as long as necessary to process the request, then archived for a reasonable period for evidentiary purposes;
- Merchant account and transaction data: kept for the entire duration of the contractual relationship, then archived for the period required by applicable accounting, tax and AML/CFT obligations;
- Browsing data and audience-measurement cookies: kept in accordance with the periods set out on the Cookie Settings page.
Article 8 β Data security
MicroLink implements reasonable technical and organizational measures (encryption of exchanges,
access controls, logging) to protect data against loss, unauthorized access, disclosure or
alteration. The Client remains responsible for keeping their own Merchant Portal and Android app
login credentials confidential.
Article 9 β Cookies and trackers
The xfin.pro website places cookies, notably for traffic measurement purposes. The categories of
cookies used, their purpose, retention periods and how you can manage your consent are detailed on
our dedicated page: Cookie Settings.
Article 10 β Your rights
In accordance with Gabonese Law No. 001/2011 on the protection of personal data, you have the
right to access, rectify, erase and object to the data concerning you, as well as the right to
request that its processing be restricted. These rights may be exercised by writing to the address
given in Article 12, together with proof of identity. MicroLink undertakes to respond within a
reasonable timeframe.
Article 11 β Changes to this Policy
MicroLink may amend this Privacy Policy, notably to reflect regulatory or technical developments,
or the rollout of new features such as the xFin Portal Android app. The date of the last update is
shown at the top of this page.
Article 12 β Contact
For any question relating to this Policy, or to exercise your rights, you can contact MicroLink: