Compagnie Fiduciaire de Management et d'Audit (COFIMA), founded in 2000 and registered with the Order of Chartered and Certified Accountants of Benin (OECCA-Bénin) under registration number 008-SE, and authorised to process personal data by the Data Protection Authority (Autorité de Protection des Données Personnelles, APDP) under reference number [TO BE COMPLETED], is a limited liability company specialising in audit, accounting services, management consulting and fiduciary management, with its registered office in Cotonou, C/2197 Immeuble Luca Pacioli, Kouhounou, Benin, Tel: +229 01 21 38 26 24; represented by its Managing Director Jean-Claude AVANDE, collects and processes personal data as part of its professional engagements, which includes the personal data of individuals who visit the website www.cofima.cc (the "Site").
The collection and processing of your personal data is carried out in compliance with Book Five of the Digital Code, in order to meet your expectations and requests.
This document is provided for information purposes and aims to clarify the rules and commitments of COFIMA regarding the protection of personal data.
In particular, it is intended to inform you about:
This policy applies to all of COFIMA's digital tools, regardless of their form (website, mobile application and secure areas).
It should be noted that COFIMA does not handle data classified as sensitive, such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, sex life or sexual orientation, or personal data relating to criminal convictions and offences, as these do not correspond to COFIMA's activity and serve no purpose in the company's processing operations.
Each capitalised term has the meaning assigned to it below:
In accordance with Article 1 of the Digital Code, Compagnie Fiduciaire de Management et d'Audit (hereinafter "COFIMA", located in Cotonou, C/2197 Immeuble Luca Pacioli, Kouhounou, Tel: +229 01 21 38 26 24; represented by its Managing Director Jean-Claude AVANDE) is designated as the data controller.
COFIMA has appointed and notified the Data Protection Authority (APDP) of a Data Protection Officer (hereinafter "DPO").
For any question relating to the processing of your personal data or to exercise your rights, you may contact our DPO at the following email address: dpo@cofima.cc.
The personal data that may be collected and processed under this policy are:
| Data category | Data collected |
|---|---|
| Civil status; identification data | Surname, first name, postal address, email address, phone number, copy of identity document (where required), signature. |
| Professional life | Company name, email address, professional status, social security (CNSS) affiliation number, salary, number of working days, qualifications, CV, personnel file, data relating to assigned engagements. |
| Financial data | Contract number, service terms, billing, payment history, salary and fees. |
| Location data | Physical address |
| Connection data | IP address, connection logs |
Certain personal data will be processed on a case-by-case basis.
If COFIMA requests additional data from you, it will explicitly indicate the need to collect this personal data for the completion of the service. Personal data is collected directly from you and is only used for the purposes explicitly indicated to you.
Indeed, should you provide us with additional data beyond that listed above, on an optional basis, COFIMA undertakes to use it only to the extent that it is absolutely necessary for the performance of the requested service.
Some services may be accessible to minors. In this case, minors under the age of 16 must obtain the consent of their parents or legal guardians.
COFIMA's digital and physical tools incorporate the protection of personal data from the initial phases of projects.
The firm undertakes to build in the protection of your personal data and privacy from the design stage of the services offered to you, thereby helping to reduce risks related to non-compliance in personal data processing.
As a result, technical and organisational measures suited to the personal data processing operation are adopted according to the purpose pursued by the firm in the intended processing operation.
Applying this principle therefore makes it possible to deploy anticipatory measures aimed at limiting risks to personal data.
COFIMA's digital and physical tools guarantee, by default, the optimal level of personal data protection.
COFIMA deploys appropriate technical and organisational measures to ensure that, by default, only the personal data necessary for the intended purpose is processed.
Personal data is collected for the requirements of COFIMA's activities, such as audit engagements, accounting expertise, management advisory services, optimising the firm's prospecting and communication activities and fine-tuning the firm's services to client expectations, complying with legal reporting requirements, and other similar activities.
In any event, COFIMA undertakes to collect only data that is strictly necessary when:
COFIMA relies on the following legal bases to process personal data
The legal basis for the processing of clients' personal data collected is the performance of a service contract between the parties.
COFIMA is bound by the legal obligations set out in the Digital Code and other applicable legislation. In this context, the processing, retention and possible transmission of your personal data to the competent Authority comply with legal and regulatory obligations and enable the firm to fulfil its duties in this regard.
For the following purposes, the legal basis for processing the user's personal data will be the user's consent, where it has been given:
Withdrawal of consent for these processing operations by the user will not affect the performance of agreements entered into by the data subject directly with COFIMA or via a legal entity under a mandatory or optional collective agreement.
For the following purposes, the legal basis for processing the user's personal data will be COFIMA's legitimate interest:
The retention period for your personal data depends on the service in question. It is as follows:
COFIMA undertakes not to retain your personal data beyond the period necessary for the provision of the service, and therefore for your use of the service, plus the retention period required by applicable statute-of-limitations rules.
COFIMA undertakes to adopt all measures to guarantee the security and confidentiality of personal data, and in particular to prevent it from being altered, deleted or accessed by unauthorised third parties.
COFIMA continuously improves its security protocols in line with technological developments in order to maintain a maximum level of protection. Our team and that of our external service providers with access to personal data are contractually bound by a confidentiality obligation.
Furthermore, in the event of a security incident affecting your personal data (destruction, loss, alteration or disclosure), COFIMA will ensure that it meets its obligation to notify personal data security incidents, in particular to the Data Protection Authority (APDP).
The personal data collected is primarily intended for COFIMA, strictly within the scope of its professional engagements.
Depending on the purposes of the processing, your data may also be shared:
In all cases, COFIMA ensures that only strictly necessary data is shared, and makes sure that each recipient maintains a level of protection appropriate to the nature of the data transmitted.
COFIMA carries out all processing operations on your personal data within the territory of Benin.
However, for certain specific engagements, in particular international audits, cross-border expert assignments or exchanges with international correspondents, it may use external service providers established outside Benin and ECOWAS that do not offer adequate protection guarantees.
Certain personal data may then be disclosed to them for the strict purposes of their engagements. In such cases, in accordance with applicable regulations, COFIMA obtains authorisation for the transfer from the Data Protection Authority and/or requires its sub-processors to provide the necessary guarantees to frame and secure these transfers, in particular through the signing of standard contractual clauses or the production of Binding Corporate Rules.
You may at any time exercise with COFIMA the rights provided for by applicable personal data regulations, subject to meeting the relevant conditions:
When registering for a service or when your personal data is collected, you are informed of the address (postal and/or email) to which to send your request to exercise your rights, a template for which is attached as an annex to this policy.
Any request must be dated, signed and accompanied by proof of identity.
COFIMA undertakes to respond to your requests to exercise your rights as promptly as possible and, in any event, within the legal time limits. It should be noted that the exercise of the requested right must not undermine the performance of your contract or compliance with applicable legal and regulatory obligations.
COFIMA complies with its obligations regarding the protection, security and confidentiality of its members' personal data and has appointed a Data Protection Officer.
You may contact the Data Protection Officer as follows:
COFIMA undertakes to respond to your request for access, rectification, erasure, restriction, portability and objection, or any other request for additional information, within a reasonable time not exceeding two months from receipt of your request. If necessary, this period may be extended by two months in the event of complexity and/or a high volume of requests.
You also retain the option of lodging a complaint with the APDP by submitting your requests on the website: https://service.apdp.bj/mise_en_conformite/procedures
In accordance with the provisions of Book 5 of the Digital Code, you have several rights over your personal data and its processing. Here is how to exercise all the rights granted to you:
For your request for access to your personal data and your request for rectification of your personal data to be taken into account, you must provide the elements necessary to prove your identity, namely a valid proof of identity.
To exercise any of the rights above, contact our Data Protection Officer, specifying your name, contact details, the right concerned and, where applicable, the data covered by your request.
Contact the DPOA cookie is a small file placed on your device when you visit a website. It notably enables the website to function properly, remembers your preferences, or measures traffic.
You can change your choice at any time from this website, or configure your browser to block or delete cookies (settings vary depending on the browser used).
Let's talk about your project