DJULAH — Privacy Policy
Platform: Djulah — www.djulah.com
Operator / Data Controller: NGUHS VENTURES SARL, Simbock, Yaoundé, Republic of Cameroon
Trade Register: CM-NSI-01-2025-B12-01432 (23 September 2025)
NIU: M092518075526S
Effective Date: 24 June 2026
Version: 1.0 — June 2026
Table of Contents
- Introduction and Legal Basis
- Identity of the Data Controller
- Categories of Personal Data Collected
- Purposes and Legal Bases of Data Processing
- Access to Messaging and Dispute Management
- Data Sharing and Third Parties
- Technical Security Measures
- Data Retention and Deletion
- User Rights
- Cookies and Tracking Technologies
- Cross-Border Data Transfers
- Minors
- Amendments to the Privacy Policy
- Contact and Complaints
Article 16 — Introduction and Legal Basis
NGUHS VENTURES SARL, operator of the Djulah platform, is committed to the protection of the personal data of all Users. This Privacy Policy describes the personal data Djulah collects, the purposes for which it is processed, the conditions of its retention and deletion, and the rights Users have in respect of their data.
This Privacy Policy has been drafted in compliance with the following laws and regulations of the Republic of Cameroon:
- Law No. 2024/017 of 23 December 2024 relating to Personal Data Protection in Cameroon (the "Data Protection Act"), enforceable from 23 June 2026;
- Law No. 2010/012 of 21 December 2010 on Cybersecurity and Cybercrime in Cameroon;
- Law No. 2010/013 of 21 December 2010 regulating Electronic Communications in Cameroon;
- Law No. 2010/021 of 21 December 2010 regulating Electronic Commerce in Cameroon;
- Law No. 2011/012 of 06 May 2011 on Consumer Protection in Cameroon;
- Law No. 2003/004 of 21 April 2003 on Banking Secrecy;
- The Constitution of the Republic of Cameroon, which enshrines the right to privacy in its Preamble.
Important: The Data Protection Act (Law No. 2024/017) was enacted on 23 December 2024 and is enforceable from 23 June 2026. NGUHS VENTURES SARL is committed to full compliance with this law and with regulations issued by the Personal Data Protection Authority (Autorité de Protection des Données à Caractère Personnel — APDCP) as they are published.
Article 17 — Identity of the Data Controller
| Legal name | NGUHS VENTURES SARL |
| Legal form | Société à Responsabilité Limitée (SARL) |
| Trade Register | CM-NSI-01-2025-B12-01432 (23 September 2025) |
| NIU | M092518075526S |
| Share capital | 500,000 FCFA |
| Registered address | Simbock, Yaoundé, Republic of Cameroon |
| Tax centre | CDI 5 — Biyem Assi Lycée, Yaoundé |
| Phone | +237 650 72 95 92 |
| Platform | Djulah — www.djulah.com |
| Data protection contact | privacy@djulah.com |
| Data Protection Officer (DPO) | Mr. Jean-Baptiste FOUDA MBALLA — privacy@djulah.com |
Article 18 — Categories of Personal Data Collected
18.1 Data Collected from Clients
| Category | Examples |
|---|---|
| Identity and account data | Last name, first name, username, email address, telephone number, profile photo, language preferences. |
| Authentication data | Encrypted password, Google OAuth session data, session tokens, one-time passwords (OTP). |
| Search and browsing data | Category selected, location searched, budget filters, property types, properties viewed. |
| Activity data | Favourites, availability requests, reservations, visit requests, reservation statuses, interaction history. |
| Payment data | Payment account references, payments made or attempted, transaction status, payment references from providers. |
| Communication data | Messages exchanged with Hosts, any attached files, associated notifications. |
| Exceptional identification data | National Identity Card (CNI) or equivalent — collected only in the event of a serious dispute requiring identity verification. |
18.2 Data Collected from Hosts
In addition to account and authentication data, Hosts provide verification documents before publishing any listing:
Owners:
- Front and back of National Identity Card (CNI);
- Photograph holding the CNI.
Agents and agencies:
- Front and back of National Identity Card;
- Photograph holding the CNI;
- Professional documents where available.
Hotel establishments:
- CNI of the manager or authorized representative;
- Trade Register registration number;
- Official establishment authenticity document.
Hosts also provide listing-related data: property photos, location, price, availability schedule, description, and applicable booking conditions.
18.3 Data Generated by Platform Activity
| Activity Source | Generated Data |
|---|---|
| Search and navigation | Categories browsed, filters applied, price ranges, properties viewed, frequency of searches. |
| Reservations and visits | Request creation, Host validation, payment, confirmation, cancellation, closure, full status history. |
| Favourites and views | Properties saved, viewing duration, repeated consultations. |
| Host publications | Listings created, modifications, validation statuses, refusals. |
| Communications | Client-Host messages, attachments, reports submitted by Users. |
| Payment transactions | Payment attempts, confirmations, payouts, refunds, transaction references. |
| Administration actions | Verification decisions, validation, rejection, moderation, dispute intervention, system logs. |
18.4 Financial Data
In connection with payments, Djulah collects or generates the following financial data:
- Amount paid by the Client and base price set by the Host;
- Service fees, reservation fees, visit fees and applicable commissions;
- Payment method used (Mobile Money, bank card or other integrated electronic payment method);
- Transaction references and payment status;
- Refund status and amount paid out to the Host;
- History of payments, refunds and payouts;
- Financial disputes, claims and associated supporting documents;
- Notifications related to payments and transactions.
Important: NGUHS VENTURES SARL does not directly retain sensitive bank card data. Where bank card payments are processed, such data is managed exclusively by the specialized payment service provider. Djulah retains only transaction references, statuses and confirmation data necessary for operational, accounting and dispute management purposes.
Article 19 — Purposes and Legal Bases of Data Processing
| Processing Purpose | Legal Basis |
|---|---|
| Account creation and management | Contractual necessity. |
| Identity verification of Hosts before listing publication | Contractual necessity; legitimate interest in platform security and fraud prevention. |
| Enabling search, viewing, reservation and visit request | Contractual necessity. |
| Processing payments, payouts and refunds | Contractual necessity; compliance with financial and accounting obligations. |
| Calculation and application of fees and commissions | Contractual necessity. |
| Verification and moderation of listings | Legitimate interest; compliance with applicable law. |
| Fraud prevention and abuse detection | Legitimate interest; compliance with Law No. 2010/012 on Cybersecurity. |
| Dispute management between Clients and Hosts | Legitimate interest; contractual necessity. |
| Sending transactional notifications | Contractual necessity; User consent. |
| Platform performance analytics and service improvement | Legitimate interest. |
| Compliance with legal, accounting and tax obligations | Legal obligation under applicable Cameroonian law. |
| Data retention for dispute resolution and evidence | Legitimate interest; legal obligation. |
Article 20 — Access to Messaging and Dispute Management
The Platform provides an integrated messaging system enabling communication between Clients and Hosts. These conversations are private exchanges between the parties and are not subject to systematic monitoring by NGUHS VENTURES SARL.
Djulah's authorized team may access conversation data exclusively in the following circumstances:
- To investigate and resolve a dispute formally submitted by one of the parties;
- To detect, prevent or address suspected fraudulent or abusive conduct;
- To verify commitments made between the parties in connection with a reservation, visit or payment;
- To protect the rights and legitimate interests of a Client, Host or the Platform;
- To comply with a valid legal request from a competent authority.
Any access to User conversations is recorded, access-controlled and limited to employees with a specific operational or legal need. NGUHS VENTURES SARL does not use conversation content for commercial profiling or advertising purposes.
Article 21 — Data Sharing and Third Parties
21.1 Authorized Sharing
NGUHS VENTURES SARL may share User data with third parties only in the following circumstances:
- Payment service providers: transaction data shared exclusively for payment processing, fraud prevention and regulatory compliance. These providers are contractually bound to process such data only as instructed by NGUHS VENTURES SARL.
- Technical service providers (including MongoDB/Mongoose, Redis, Cloudinary CDN, OneSignal, Resend/Brevo): data shared under strict contractual data processing agreements ensuring confidentiality and security.
- Competent authorities: personal data may be disclosed where required by a valid court order, legal obligation or request from a supervisory authority such as ANTIC or the APDCP.
21.2 What Djulah Does Not Do
| Commitment | Description |
|---|---|
| Does not sell | NGUHS VENTURES SARL does not sell User personal or financial data to any third party. |
| Does not share identity documents | NGUHS VENTURES SARL does not share identity documents with unauthorized third parties. |
| Does not share financial data | NGUHS VENTURES SARL does not share financial data with unauthorized third parties. |
| Does not divert data | NGUHS VENTURES SARL does not use data for purposes incompatible with those declared in this Policy. |
| Does not publish private information | NGUHS VENTURES SARL does not publish Users' private information. |
| Does not retain beyond purpose | NGUHS VENTURES SARL does not retain data beyond its intended purposes, except where required by applicable legal obligations. |
Article 22 — Technical Security Measures
NGUHS VENTURES SARL implements appropriate technical and organizational measures to protect User data against unauthorized access, loss, alteration, disclosure or destruction.
| Measure | Description |
|---|---|
| Password storage | Passwords are hashed using bcrypt and are never stored in plain text. |
| Authentication | Single-use OTP with limited validity; secure access and refresh tokens; session revocation mechanism. |
| Encryption in transit | All communications between Users and the Platform use HTTPS/TLS encryption. |
| Encryption at rest | Sensitive messages may be protected by AES-256-GCM encryption. |
| Media and file storage | Files validated, optimized and stored on secure cloud services (Cloudinary CDN). No permanent local storage on the application server. |
| Database | Business data managed in a structured MongoDB/Mongoose database with access controls and integrity constraints. |
| Sessions and caching | Redis used for session management, caching and request rate limiting. |
| Network protection | Rate limiting, input validation and network protection mechanisms applied at infrastructure level. |
| Payment security | Payments processed through specialized providers with webhook validation, anti-duplication and idempotency mechanisms. |
Article 23 — Data Retention and Deletion
| Data Category | Retention Principle |
|---|---|
| Reservations and visit records | Retained for operational, evidence and dispute management purposes for a period to be determined by applicable APDCP regulations. |
| Transaction and financial data | Retained for the duration required by Cameroonian accounting, tax and financial law — generally a minimum of ten (10) years under CEMAC/OHADA accounting standards. |
| Identity verification documents (CNI) | Retained for the duration necessary for identity verification and any pending disputes; subject to retention periods specified by APDCP regulations. |
| Authentication data (OTP, sessions) | OTPs deleted upon validation or expiration. Expired sessions deleted automatically by technical mechanisms. |
| User accounts | Retained until account deletion is requested or carried out by the User, subject to data NGUHS VENTURES SARL is required to retain by law. |
| Communication data (messages) | Retained for dispute resolution purposes and in accordance with applicable legal obligations. |
| Activity and navigation data | Retained for platform improvement, analytics and fraud detection, for a period not exceeding what is necessary for these purposes. |
Users may request the deletion of their account directly from the Platform settings. Deletion covers account data, associated media, conversation history and profile information, subject to data that NGUHS VENTURES SARL is required to retain for legal, accounting, security or dispute resolution purposes.
Article 24 — User Rights
In accordance with the Data Protection Act (Law No. 2024/017 of 23 December 2024), all Users have the following rights in respect of their personal data:
| Right | Description |
|---|---|
| Right of access | The right to obtain confirmation of whether NGUHS VENTURES SARL processes personal data about you and, if so, to access a copy of such data. |
| Right of rectification | The right to request correction of inaccurate or incomplete personal data. |
| Right of deletion (erasure) | The right to request deletion of your personal data, subject to NGUHS VENTURES SARL's legal retention obligations. |
| Right to portability | The right to receive your personal data in a structured, commonly used format, where technically applicable. |
| Right to object | The right to object to the processing of your personal data based on legitimate interests, in particular for profiling. |
| Right to withdraw consent | Where processing is based on consent, the right to withdraw your consent at any time without affecting the lawfulness of prior processing. |
To exercise any of these rights, Users may submit a request by:
- Email: privacy@djulah.com
- In-application: through the account settings section of the Platform.
NGUHS VENTURES SARL will acknowledge receipt of requests and respond within the timeframes specified by applicable regulations. NGUHS VENTURES SARL may ask the requesting User to verify their identity before processing the request.
If a User considers that NGUHS VENTURES SARL has violated their data protection rights, they have the right to submit a complaint to the Personal Data Protection Authority (APDCP) once established, or to the relevant competent court.
Article 25 — Cookies and Tracking Technologies
The Platform may use cookies and similar tracking technologies for purposes including authentication, session management, security, and analytics. Users will be informed of and may consent to non-essential cookies through a cookie consent mechanism implemented on the Platform.
Essential cookies necessary for the functioning of the Platform do not require prior consent. Users may configure their device settings to refuse or delete cookies, though this may affect the functioning of certain Platform features.
Article 26 — Cross-Border Data Transfers
Due to the international nature of certain technical service providers used by the Platform (including cloud storage and communication services), certain personal data may be transferred to or processed in countries outside the Republic of Cameroon.
Any such transfer is carried out in accordance with the Data Protection Act (Law No. 2024/017) and applicable APDCP requirements, including by ensuring that recipient countries provide an adequate level of protection or that appropriate safeguards (such as contractual clauses) are in place. NGUHS VENTURES SARL will obtain any required authorization from the APDCP for cross-border data transfers as required by applicable law.
Article 27 — Minors
The Platform is not intended for use by persons under eighteen (18) years of age. NGUHS VENTURES SARL does not knowingly collect personal data from minors. If NGUHS VENTURES SARL becomes aware that personal data of a minor has been collected, it will take immediate steps to delete such data.
Parents or guardians who become aware that their child has provided personal data to Djulah should contact privacy@djulah.com immediately.
Article 28 — Amendments to the Privacy Policy
NGUHS VENTURES SARL reserves the right to modify this Privacy Policy at any time to reflect changes in applicable law, regulatory requirements or Platform functionality. Users will be informed of material changes by push notification, in-application notice, or email, no later than thirty (30) days before the changes take effect.
The current version of this Privacy Policy is always accessible at www.djulah.com/privacy. Continued use of the Platform after the effective date of the updated Privacy Policy constitutes acceptance of the changes.
Article 29 — Contact and Complaints
| Legal name | NGUHS VENTURES SARL |
| Trade Register | CM-NSI-01-2025-B12-01432 |
| NIU | M092518075526S |
| Address | Simbock, Yaoundé, Republic of Cameroon |
| Phone | +237 650 72 95 92 |
| Data protection contact | privacy@djulah.com |
| General support | support@djulah.com |
| Privacy Policy URL | www.djulah.com/privacy |
Users who believe their rights have been violated may also submit a complaint to:
- The Personal Data Protection Authority (APDCP) once established under Law No. 2024/017;
- The Agence Nationale des Technologies de l'Information et de la Communication (ANTIC);
- The competent courts of the Republic of Cameroon.
© 2026 NGUHS VENTURES SARL — Djulah Platform — All rights reserved.
www.djulah.com