Effective Date: January 1, 2026
Last Updated: April 2026
At Opesware, we recognize that in the modern enterprise landscape, data is your most critical asset. We take the confidentiality, integrity, and security of your corporate data with absolute seriousness. This comprehensive Privacy Policy outlines our data governance practices, meticulously adhering to the guidelines set forth by the National Agency for Information and Communication Technologies (ANTIC) in Cameroon, as well as broader international standards like the GDPR, appropriately localized for the CEMAC digital framework.
1. Information Collection and Processing
We do not collect data arbitrarily. Opesware collects business and personal information strictly when necessary to provide our IT consultancy, software engineering, and technical support services. This includes:
- Corporate Identity Data: Names, operational addresses, emails, and commercial registry (RCCM) numbers provided during the quotation and contract phases.
- Diagnostic & Telemetry Data: When deploying custom ERPs, Hospital Management Systems, or POS software, we collect anonymized server telemetry, bandwidth usage metrics, and error logs to proactively optimize system performance against the local ENEO/Camtel infrastructure.
- Financial Data: Transaction metadata related to recurring software subscriptions or enterprise API integrations (e.g., MTN Mobile Money, Orange Money webhook confirmations). We do not store PINs or core cryptographic banking keys.
2. Data Sovereignty, Hosting, and Storage Hubs
Opesware believes in digital sovereignty. In strict accordance with national directives regarding the protection of sensitive biometric and financial data, we heavily prioritize hosting localized data within tier-secured data centers located physically within the Republic of Cameroon (primarily in Douala and Yaoundé).
By preventing sensitive medical and financial data from leaving the CEMAC jurisdiction, we ensure that your enterprise is insulated from foreign data surveillance and international cloud latency issues. For non-sensitive static assets, we utilize highly encrypted, globally redundant CDNs.
3. Confidentiality of Proprietary Code (NDAs)
The logic that runs your business is your intellectual property. Any proprietary business processes discussed during technical discovery sessions, or engineered into custom logic loops within your SaaS/ERP solutions, remain strictly confidential.
It is standard Opesware protocol to execute mutually binding Non-Disclosure Agreements (NDAs) and Data Processing Agreements (DPAs) with all enterprise clients prior to reviewing infrastructural specifications or legacy databases.
4. Third-Party Sharing and Subprocessors
Opesware does not—and will never—sell corporate data, user metrics, or operational logs to data brokers or advertising conglomerates. Information is only shared with vetted, trusted infrastructure sub-processors when strictly necessary to execute the contracted service. Examples include:
- Telecommunication APIs (MTN, Orange) for SMS gateway delivery.
- Secure Banking APIs (Afriland, CCA) for automated payroll distribution.
- State-approved bare-metal server providers for high-availability database clustering.
5. Security Protocols and Incident Response
To protect your data against unauthorized access, Opesware implements rigorous technical and organizational measures. All data stored is encrypted at rest using AES-256 encryption. All data in transit utilizes TLS 1.3 cryptographic protocols. We employ strict Role-Based Access Control (RBAC) internally, meaning our engineers only access the specific server clusters required for their immediate deployment tasks.
In the highly unlikely event of a security breach, our incident response protocol mandates notifying the affected client and relevant legal authorities within 72 hours of detection, providing a full audit trail and remediation roadmap.
6. Your Rights Regarding Your Data
As an enterprise client, you retain absolute ownership of the data uploaded into your custom systems. At any point during or after our contract, you retain the right to:
- Request a comprehensive audit log of all data processed.
- Demand the complete structural deletion (digital shredding) of your corporate data from our staging servers upon contract termination.
- Request the export of your database matrices in standard readable formats (SQL, CSV, JSON) for internal archiving.
7. Contact the Data Protection Officer (DPO)
We believe in transparent accountability. If you have any questions regarding our data storage practices, encryption schemas, or wish to invoke your data rights, please contact our administrative team directly at our headquarters in Douala.
Opesware Data Protection Office
Petite Terrain, Bonamoussadi
Douala, Littoral Region, Cameroon
Email: contact@opesware.com
Phone: +(237) 670 416 238