Privacy policy
This policy describes how Black Mobile (Pty) Ltd collects, uses, and protects personal data when you visit blackmobile.io, when you use our APIs as a customer, and when our customers send messages through our platform to you as a recipient. We comply with the Botswana Data Protection Act and adopt GDPR-equivalent safeguards for customers and recipients in the European Economic Area and the United Kingdom.
1. Who we are
Black Mobile (Pty) Ltd is the data controller responsible for the data described in this policy. Our head office is at Plot 32602, Phakalane, Gaborone, Botswana. You can contact our Data Protection Officer at dpo@blackmobile.io.
2. What data we process
2.1 Account & billing data (you, as a customer)
- Name, email, phone, company name, VAT/tax number, billing address.
- Payment method details (we use a PCI-compliant payment processor; we do not store full card numbers).
- Login credentials, API keys, and webhook signing secrets you create.
2.2 Usage data
- API request logs, IP addresses, user-agent strings, timestamps.
- Performance and error telemetry from the dashboards.
- Aggregated traffic statistics (messages sent, delivery rates, latency).
2.3 Message and session data (recipients of our customers' messages)
When our customers use the platform to communicate with their end-users, we process on their behalf:
- Recipient phone numbers, email addresses, and any other contact identifiers.
- Message bodies, USSD session inputs, voice-call audio metadata, email subjects and bodies.
- Delivery receipts (DLRs), bounces, opens (for email), opt-out signals.
For this category, our customer is the data controller and Black Mobile is a data processor acting on their documented instructions. Recipients should direct any privacy queries first to the customer whose name appears on the message; if that customer cannot resolve the query, we will assist on request.
3. How we use it
We process personal data for the following purposes:
- Delivering the service — routing messages, completing USSD sessions, placing voice calls, generating delivery receipts.
- Billing — calculating fees, issuing invoices, collecting payments.
- Support — investigating customer-reported issues, identifying delivery problems.
- Security & fraud prevention — detecting and blocking spam, abuse, and unauthorised access.
- Service improvement — anonymised analytics on platform usage, delivery quality, and feature adoption.
- Legal & regulatory compliance — responding to lawful requests from regulators and courts.
Our legal bases under GDPR-equivalent frameworks: contract performance, legitimate interest (security and analytics), legal obligation (tax and regulatory records), and the customer's instructions where we act as a processor.
4. Who we share it with
- Mobile network operators — recipient numbers, message content, and routing metadata are shared with the appropriate MNO in the destination country in order to deliver the message. We hold direct termination agreements with 30+ MNOs.
- WhatsApp Business / Meta — when sending via WhatsApp, the message content and recipient number are transmitted to Meta as required by the WhatsApp Business Solution Provider model.
- Payment processors and tax authorities — to handle invoicing and collection.
- Sub-processors — vetted cloud-infrastructure providers, log-storage services, and observability vendors operating under written data-processing agreements. A current list is available at dpo@blackmobile.io.
- Law enforcement — only on receipt of a valid legal request that we have verified and, where possible, notified the affected customer of in advance.
We do not sell personal data, and we do not share it with advertising networks.
5. International transfers
Our infrastructure is operated primarily in Africa and Europe. When personal data is transferred outside Botswana — for example to the EU, the UK, or to MNOs in other African countries — we rely on Standard Contractual Clauses, equivalent country adequacy decisions, or specific consent from the data subject, as applicable.
6. How long we keep it
- Account & billing data — for the duration of your subscription, plus 7 years after termination for tax and accounting purposes.
- Message content and delivery receipts — retained for up to 90 days for delivery troubleshooting and fraud investigation, then deleted. Customers on Enterprise plans may configure shorter or longer retention windows by written agreement.
- API request logs — 30 days, then aggregated and personal identifiers removed.
- Marketing communications — until you unsubscribe.
7. Security
We protect personal data with industry-standard measures, including:
- TLS 1.2+ for all API traffic and admin access.
- Encryption at rest for stored message content and credentials.
- Hashed and salted account passwords; HMAC-signed webhooks.
- Role-based access controls and audit logging for staff who touch customer data.
- Regular penetration testing and vulnerability scanning.
- Documented incident-response procedures with breach-notification timelines aligned to Botswana law and GDPR (72 hours where applicable).
8. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccuracies.
- Request deletion (subject to our retention obligations).
- Object to or restrict certain processing.
- Receive a portable copy of your data.
- Withdraw any consent you have given.
- Lodge a complaint with a supervisory authority — the Information and Data Protection Commission in Botswana, or your local data-protection authority.
To exercise these rights, email dpo@blackmobile.io with enough information for us to verify your identity. We respond within 30 days.
9. Cookies
Our marketing site uses only essential cookies needed for the site to function (session, security, preferences). The customer portal additionally uses authentication and analytics cookies — a banner offers consent for non-essential categories. You can adjust cookie preferences at any time from the portal's account settings.
10. Children
Our service is not directed to anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact dpo@blackmobile.io and we will delete it.
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email to registered customers at least 30 days before they take effect. The "Effective" date at the top of this page reflects the most recent update.
Contact
Data Protection Officer · dpo@blackmobile.io
Black Mobile (Pty) Ltd · Plot 32602, Phakalane, Gaborone, Botswana.