Privacy Policy

Effective Date: February 10, 2026

At Paydora, we are committed to protecting your privacy and securing your personal data in compliance with the Nigerian Data Protection Regulation (NDPR) 2019.

NDPR 2019 Compliant
GDPR Principles
Data Protection Certified

Important Privacy Notice

This Privacy Policy explains how Paydora Limited collects, uses, discloses, and protects your personal information. As a NIN verification service provider, we handle sensitive personal data and are committed to the highest standards of data protection.

By using our services, you consent to the collection and use of your information as described in this policy. Please read this policy carefully to understand our practices regarding your personal data.

1

Introduction

Paydora Limited ("we", "us", "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy applies to all users of our NIN verification services, website, and mobile applications (collectively, the "Services").

We are registered with the Nigerian Data Protection Commission (NDPC) as a data controller and processor. Our registration number is DPC/NG/2023/12345.

Key Principles

We adhere to the following data protection principles under NDPR 2019:

  • Lawfulness, Fairness & Transparency: We process data lawfully and transparently
  • Purpose Limitation: We collect data for specified, legitimate purposes
  • Data Minimization: We only collect data necessary for our purposes
  • Accuracy: We keep data accurate and up-to-date
  • Storage Limitation: We retain data only as long as necessary
  • Integrity & Confidentiality: We implement appropriate security measures
  • Accountability: We are responsible for compliance with NDPR
2

Definitions

"Personal Data"

Any information relating to an identified or identifiable natural person as defined under NDPR Section 1.3.

"Sensitive Personal Data"

Data relating to racial or ethnic origin, political opinions, religious beliefs, health, genetics, biometrics, NIN, etc. (NDPR Section 1.3(xvii)).

"Data Controller"

Paydora Limited, who determines the purposes and means of processing personal data.

"Data Processor"

Any person who processes personal data on behalf of the Data Controller.

"Processing"

Any operation performed on personal data including collection, recording, storage, etc.

"Data Subject"

The individual to whom personal data relates (you, our user).

3

Data Controller Information

The Data Controller responsible for your personal data is:

Paydora Limited

Abuja, Nigeria

+2348158600270

privacy@paydora.africa

4

Data We Collect

We collect the following categories of personal data:

Data Category Type of Data Purpose Legal Basis
Personal Data
  • • Full Name
  • • Email Address
  • • Phone Number
  • • Date of Birth
Account creation, verification, communication Contract performance, Legitimate interest
Sensitive Data
  • • National Identity Number (NIN)
  • • Biometric data (from NIN database)
  • • Gender
  • • Address information
NIN verification services Explicit consent, Legal obligation
Financial Data
  • • Payment information
  • • Transaction history
  • • Wallet balance
  • • Bank account details (for refunds)
Payment processing, refunds Contract performance, Legal obligation
Technical Data
  • • IP Address
  • • Device information
  • • Browser type
  • • Usage patterns
Security, analytics, service improvement Legitimate interest

Special Note on NIN Data

National Identity Number (NIN) is classified as sensitive personal data under NDPR. We process NIN data only for verification purposes and with your explicit consent. We do not store NIN data longer than necessary for verification completion.

Data Flow Process

1

Data Collection

You provide NIN and personal information through our secure platform

2

Verification Processing

We verify NIN through authorized API channels with encryption

3

Report Generation

We generate verification reports with necessary data only

4

Secure Storage

Data is stored in encrypted databases with access controls

5

Controlled Deletion

Data is deleted according to retention policies

5

How We Use Your Data

We use your personal data for the following purposes:

Primary Purposes

  • Provide NIN verification services
  • Process payments and transactions
  • Generate verification reports
  • Maintain your account and profile

Secondary Purposes

  • Improve our services and platform
  • Prevent fraud and enhance security
  • Comply with legal obligations
  • Communicate important updates

Marketing Communications

We will only send you marketing communications if you have explicitly opted in. You can unsubscribe at any time by clicking the unsubscribe link in our emails or contacting our support team.

7

Data Sharing & Disclosure

We may share your personal data with the following categories of recipients:

Authorized Third Parties

  • Payment Processors: For transaction processing
  • Verification APIs: For NIN verification services
  • Cloud Service Providers: For secure data storage

Legal & Regulatory

  • Law Enforcement: When required by court order
  • Regulatory Bodies: NDPC, CBN, or other authorities
  • Legal Proceedings: To protect our legal rights

Data Processing Agreements

All third-party processors sign Data Processing Agreements (DPAs) that comply with NDPR requirements. These agreements ensure they implement appropriate security measures and only process data for specified purposes.

No Sale of Personal Data

We do not sell, trade, or rent your personal data to third parties for marketing purposes. Your data is only shared as described in this policy or with your explicit consent.

8

Data Security

We implement comprehensive security measures to protect your personal data:

256-bit SSL Encryption
ISO 27001 Certified
AES-256 Encryption
Multi-Factor Authentication
DDoS Protection
Web Application Firewall

Technical Security Measures

  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access Controls: Role-based access control (RBAC) and principle of least privilege
  • Network Security: Firewalls, intrusion detection systems, regular security audits
  • Physical Security: Data centers with 24/7 surveillance and biometric access

Organizational Security Measures

  • Employee Training: Regular data protection and security awareness training
  • Data Protection Officer: Appointed DPO overseeing compliance
  • Incident Response Plan: Procedures for data breach response and notification
  • Regular Audits: Internal and external security audits and assessments

Data Breach Notification

In the event of a data breach, we will notify the Nigerian Data Protection Commission (NDPC) within 72 hours of becoming aware of the breach, as required by NDPR Section 3.1(10). Affected data subjects will also be notified without undue delay.

9

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

Data Type Retention Period Reason for Retention
Account Information 5 years after account closure Legal requirements, fraud prevention
NIN Verification Records 7 years Regulatory compliance, audit purposes
Transaction Records 7 years Financial regulations, tax compliance
Communication Data 3 years Customer service, dispute resolution
NIN Numbers 30 days after verification Temporary processing, then anonymized
Inactive Accounts 2 years of inactivity Then deleted or anonymized

Data Deletion Process

When data retention periods expire, we securely delete or anonymize the data. Anonymized data may be retained for statistical analysis. You can request earlier deletion of your data by exercising your rights under NDPR.

10

Your Rights Under NDPR

As a data subject under NDPR 2019, you have the following rights regarding your personal data:

Right to Access

You can request a copy of your personal data we hold.

Right to Rectification

You can request correction of inaccurate or incomplete data.

Right to Erasure

You can request deletion of your personal data ("right to be forgotten").

Right to Restrict Processing

You can request restriction of how we process your data.

Right to Data Portability

You can request your data in a structured, commonly used format.

Right to Object

You can object to certain types of processing.

Right to Withdraw Consent

You can withdraw consent at any time, without affecting prior processing.

Right to Lodge Complaint

You can complain to the NDPC if you believe your rights have been violated.

Exercising Your Rights

To exercise any of these rights, please contact our Data Protection Officer at:

dpo@paydora.africa

We will respond to your request within 30 days as required by NDPR Section 3.1(8).

11

Children's Privacy

Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children under 18.

Parental Consent Required

If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately. If we learn that we have collected personal data from a child under 18 without parental consent, we will delete that information promptly.

12

Third-Party Services

Our Services may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party services.

Our Third-Party Processors

  • AWS: Cloud hosting and storage
  • Paystack/Flutterwave: Payment processing
  • Google Analytics: Website analytics
  • Twilio: SMS notifications

Verification Partners

  • KoraPay API: NIN verification services
  • Authorized NIN Databases: Official verification sources

Your Responsibility

We encourage you to review the privacy policies of any third-party services you access through our platform. We are not responsible for the privacy practices or content of third-party services.

13

International Data Transfers

Your personal data is primarily processed and stored in Nigeria. However, some of our service providers may process data in other countries.

Adequacy Decisions & Safeguards

When data is transferred outside Nigeria, we ensure appropriate safeguards are in place:

  • Adequacy decisions by NDPC for recipient countries
  • Standard Contractual Clauses approved by NDPC
  • Binding Corporate Rules for intra-group transfers
  • Explicit consent for specific transfers

Cross-Border Processing Notice

By using our Services, you acknowledge that your personal data may be transferred to, stored, and processed in countries other than Nigeria, subject to the safeguards described above.

14

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, services, or legal requirements.

Update Notification Process

  • Email Notification: For material changes, we'll notify you via email 30 days in advance
  • Website Notice: Updated policy will be posted on our website with new effective date
  • Consent for Major Changes: Significant changes may require renewed consent

Your Continued Use

Your continued use of our Services after any changes to this Privacy Policy constitutes acceptance of those changes. If you do not agree with the updated policy, you must stop using our Services.

15

Contact Information & DPO

Data Protection Officer

Data Protection Officer
Paydora Limited

dpo@paydora.africa

+2348158600270

General Privacy Inquiries

privacy@paydora.africa

support@paydora.africa

Response Time: 48 hours
Business Hours: Mon-Fri, 9am-6pm WAT

Nigerian Data Protection Commission

You have the right to lodge a complaint with the supervisory authority:

Nigerian Data Protection Commission (NDPC)

Plot 1252, Michael Okpara Street, Wuse Zone 5, Abuja, Nigeria

https://ndpc.gov.ng

Privacy Commitment

At Paydora, we are committed to protecting your privacy and securing your personal data. This Privacy Policy, together with our Terms of Service and Cookie Policy, governs our relationship with you regarding data protection.

Last Updated: February 10, 2026