CBE Super App
How the Commercial Bank of Ethiopia collects, uses, stores, shares, and protects your personal data across the CBE SuperApp and all integrated Mini Apps.
This Privacy Policy establishes how the Commercial Bank of Ethiopia CBE collects, uses, stores, shares, and protects the Personal Data of customers who use the CBE SuperApp.
Personal Data: Any information relating to an identified or identifiable individual as per defined under Personal Data Protection Proclamation No. 1321/2024.
Sensitive Personal Data: Biometrics, health data, criminal records, or other categories defined under Ethiopian law.
Processing: Any operation performed on Personal Data, including collection, storage, use, sharing, or deletion.
Controller: The entity that determines why and how data is processed (CBE).
Processor: Any third party processing data on behalf of CBE.
Mini-Apps: Third-party or CBE-owned functional applications integrated within the SuperApp.
All users of the SuperApp and Mini-Apps, all digital services linked to the SuperApp, all data processed through the SuperApp, including payments, onboarding, customer support, and third-party integrations.
Contact Information: Name, address, phone numbers, and email addresses.
Financial Information: Account numbers, card numbers, transaction records, loan data, repayment history, income information.
Identification Information: Fayda ID, passport, driver's license, date of birth, nationality, biometrics (fingerprint/face ID), account verification details.
Sensitive Personal Data: Health information, disability data, criminal records only where required by law or for regulated banking services.
Technical & Device Information: Device ID, IMEI, MAC address, IP address, geolocation, app usage logs, browser type, cookies.
Demographic & Professional Data: Occupation, employer, marital status, etc.
Mini-App Transactional Data: Data generated through the use of integrated Mini-Apps.
Contract performance: To provide banking and digital financial services.
Legal obligations: As required by NBE directives, AML/CFT laws, KYC requirements, and other regulatory mandates.
Legitimate interest: Fraud prevention, service enhancement, security monitoring.
Consent: For marketing communications, location tracking, and optional features.
Public interest: Where required for financial sector stability or regulatory reporting.
Service Delivery: Opening and managing accounts, processing payments, transfers, deposits, and withdrawals. Supporting Mini-App functions.
Service Improvement: Customer analytics and product development, performance monitoring.
Marketing & Communication: Sending promotional offers with your consent, service alerts and important notifications.
Security & Fraud Prevention: Preventing unauthorized access and monitoring suspicious activity.
Risk Management & Regulatory Compliance: KYC/AML checks, fraud monitoring, credit scoring and loan assessment, and reporting to NBE and other regulators.
Internal Sharing within CBE: Data is shared only with authorized departments that require the information to deliver services.
Third-party service providers: To assist in providing our services, such as data processing, marketing, and customer support, for the limited purpose needed.
Financial institutions: Shared only for transaction processing, settlement, and regulatory compliance.
Law enforcement & regulatory authorities: Shared only where legally required by law.
Corporate Transactions: In the event of a merger, acquisition, or sale of assets, information may be disclosed subject to confidentiality agreements.
Encryption: Strong encryption technologies to protect data in transit and at rest.
Access controls: Strict access controls limiting access to authorized personnel only.
Regular security assessments: Periodic security audits and vulnerability assessments to identify and address potential risks.
CBE retains Personal Data only for as long as required by law or business needs. After expiry, data is securely deleted or anonymized.
KYC documents: 10 years (NBE requirement)
Transaction data: 10 years
Log files: 2 years
Marketing data: Until consent is withdrawn
Right to Access: Request access to your Personal Data.
Right to Rectification: Request correction of inaccurate or incomplete Personal Data.
Right to Erasure: Request deletion of your Personal Data, subject to legal and regulatory retention obligations.
Right to Object: Object to the processing of your Personal Data in certain circumstances.
Right to Restriction: Request restriction of processing of your Personal Data in certain circumstances.
Right to Data Portability: Request transfer of your Personal Data to another organization or to you directly.
Right to Withdraw Consent: Withdraw consent to processing at any time without affecting prior lawful processing.
The SuperApp may link to external services. CBE is not responsible for external privacy practices, and users are encouraged to review those policies independently.
If you have any questions or concerns about this Privacy Policy, please contact us by calling 951 or visiting your nearest CBE branch.
CBE may update this policy from time to time. Material changes will be communicated through the SuperApp or official channels.
This Policy enters into force effective from May 01, 2026.