Nigeria Privacy Notice

Read this Privacy Notice if you want to know how Unlimint Nigeria Limited gathers, processes and stores your personal data.

The purpose of this Notice is to tell you which personal data we process, how, why and for how long we process your personal data. It is important to Unlimint that you know your rights regarding your personal data and how to reach us.

To get a complete understanding of Unlimint and our service offering to you, please read this Notice with the relevant Terms and Conditions and Cookie Policy on our Website.

Who is Unlimint?

Unlimint and its group companies or businesses are part of a global payments and technology organisation.

Unlimint Nigeria Limited (“Unlimint” or “we”) operate as a Payment Solutions Service Provider. This means that Unlimint provides its merchants with payment services and the platforms and applications (“platforms”) through which card payments services and other alternative payment methods are offered (“payment services”) to merchants.

When you use our payment services as a merchant of Unlimint, the merchant is the data controller.

This may change depending on your chosen services and products or when they become available in Unlimint.

When you visit our Website, or you are staff of Unlimint, Unlimint is the controller of your personal data.

Warning: Our Website may contain links to or come from websites or applications with their privacy notices or policies, which Unlimint does not control. These websites will have different privacy notices or statements, and we do not control these websites. Unlimint does not accept any responsibility or liability for such websites.

In this Notice, “personal data” refers to information that identifies you or may identify you (e.g., depending on who you are, a merchant, payer, supplier or business partner) and how you interact with us, we may process different types of personal data. “Processing” of personal data refers to collecting, gathering, handling, storing, transmitting and combining personal data. A “data subject” is a person that can be identified or identifiable from the personal data processed by a controller or processor. A “merchant” is a company or online store that uses our services to enable payments so that you can pay for goods, services or both.

What this Notice tells you

This Notice contains a description of:

  1. When and why do we process personal data:
    • Why do we process personal data,
    • When do we process personal data;
  2. What types of personal data do we process;
  3. How we collect and use personal data;
  4. What are the lawful grounds that we rely on to process your personal data;
  5. What are our purposes for processing your personal data;
  6. Who do we share your personal data with:
    • International Transfers,
    • Marketing and Cookies;
  7. Your rights and how to raise a complaint;
  8. How long we keep your personal data;
  9. How we keep your personal data secure;
  10. How we tell you when we change this Notice.

Why and when do we process personal data?

Why do we process personal data?

Establish a contract with a merchant and provide our services to a merchant. In this scenario, Unlimint needs the following personal data:

  • To meet our legal obligations. We are required to identify you, authenticate your identity and perform due diligence checks on you, and if you are a legal person, we also then have to verify your directors, signatories and ultimate beneficial owners. This is an obligation on Unlimint under payments, anti-money laundering, sanction and anti-bribery and anti-corruption laws, as well as multiple directives, regulations and guidance to combat fraud, money laundering and bribery and corruption. Examples of such laws include: Money Laundering (Prevention and Prohibition) Act, 2022; Terrorism (Prevention and Prohibition) Act, 2022.
  • For contractual purposes. To establish and maintain a business relationship for the provision of our services, to execute (complete) payment transactions and the performance of contractual obligations between both Unlimint and its merchants.
  • For our legitimate interests. We implement online and physical security measures to properly provide our payment services, ensuring personal data and the underlying physical and logical security best practices, access control management and underlying analytics to further protect against cybercrime and fraud.

When do we process personal data?

Personal data is requested before and during the contractual relationship.

For example, when we perform card or online payment processing, Unlimint, in the capacity of a processor, processes personal data received from merchants, which is relevant for processing payments for merchants and reporting transactions to the merchant.

This includes personal data such as transaction details and payment reference identifier and personal data in the context of transactions processing (such as payment instrument and transaction details, identification details, contact details, such as email, telephone, name on card, date of birth), to complete the transaction initiated by the cardholder or payer to the merchant.

Please check your merchants’ privacy notices or statements regarding important information about your personal data processing.

Suppose we cannot process certain categories of personal data. In that case, this can result in Unlimint not being able to enter into a services contract with a merchant or execute a payment instruction without the requested personal data, or we may no longer be able to continue with an existing relationship and provision of our services with a merchant.

What types of personal data do we process?

Various types of personal data are processed in the context of the relationship between you and Unlimint, depending on the service and product you are using. These may include:

Your personal data Name, previous names, data and place of birth, language, if you hold prominent public functions (Peps), residence permit.
Your personal contact details Work address, home address, email address, telephone number, and other contact details.
Your identity information Passport, National ID card, Nationality, Utility bill, tax residence and tax ID.
Relevant financial information Personal bank details, professional status, employment field, employer details (including, for example, information such as certificates of directors).
Specific authentication personal data A signature or your user login to access our service dashboards.
Communications Personal data that you may provide by filling in forms or by communicating with us (e.g. directed to us in letters, emails, via our electronic channels).
Transactional and other/documents information Personal Data arising for the execution of payment transactions (including data such as date, time, amount, currencies, beneficiary details, location information and merchant details), supplementary/supporting documentary evidence related to transactions, and further information arising from contractual obligations between Unlimint and Merchants.
Location and technical information Location data (for example, at the time of login or a transaction); IP addresses and device information, visitor’s information and similar information subject to our Cookie Policy.
Publicly available Personal Data Details about you from public records and available in publicly accessible databases.
Investigations data/results of due diligence and enhanced due diligence Personal data regarding criminal convictions and offences (special category of data), as part of its compliance measures with regulatory obligations, as well as other supporting documents and personal data related to the categories above.
CCTV Closed circuit television (CCTV) at our offices (which may collect videos of you).
Consents Personal Data that you agree to give us by your active consent when you use our services or visit our Website.

How do we collect your personal data?

1. Personal Data you submit to us

This can happen in different ways:

  • When you have agreed to give to the merchant your personal data who has a contract with us so we can provide our services to them. We take all reasonable steps to collect the personal data of payers only what is needed to process the transaction for the Merchant.
  • When you actively opt-in to accept our Privacy Notice, receive communications from us, via email or forms available on our Website or any other means of communication. When you consent to us collecting such Personal Data, you have the right to opt out of such collection at any time. To do so, please go to our Website to choose what Personal Data we may collect from you.

2. Personal Data we collect when you use our services

This personal data may include the following:

  • Payment and Transactions data.
  • Profile and usage data (such as data when you connect to internet banking, or SMS services (if applicable), and may include Personal Data on how you use the services. We may collect data from devices you use to connect to the services, such as computers and mobile phones, such as your IP address and use cookies (go to our Cookie Notice).
  • Third-party data. Personal data we lawfully obtain from other entities such as service providers, fraud prevention aggregation agencies, public authorities, persons that refer you to us, our Group companies, and companies processing payments.
  • Public Data. Databases and publicly accessible sources or other sources accessible to relevant payment institutions, such as Unlimint, due to the nature of Unlimints’ services (e.g., this includes Registrars of Companies, Commercial Registries, AML and sanction screening databases).

What are the lawful grounds we rely on to process your personal data?

When we process your personal data, we rely on one of the processing legal bases below. We may process your personal data for different purposes, and in such cases, the same personal data will be processed under another legal basis.

1. Conclusion and performance of a contract

We process personal data to conclude a services contract with a merchant and to perform our obligations under a contract to provide our payment services with our merchants in compliance with applicable laws and regulations.

2. Legal obligation or public interest

Unlimint is subject to various legal obligations and legal and regulatory requirements to provide payment services. We are also required to implement regulations and directives of multiple authorities to ensure compliance. The purposes of processing include verification controls of identity, money laundering and fraud prevention, compliance with our record reporting obligations, tax obligations, risk control measures, and providing information to a competent authority, public body or law enforcement agency.

3. Legitimate interests

Where necessary, we may process personal data where there is a legitimate interest for us or a third party in pursuing commercial and business interests, except where your interests, fundamental rights and freedoms override such interests.

4. Your consent

Your personal data will be processed in this way if you agree to this. Where the legal basis is the consent you provided, you may withdraw your consent at any time. The revocation of your consent will not affect the legality of the data processed before the revocation.

Purposes for which we use your personal data

We process your personal data for the following purposes:

 

1. Authenticate, Verify and Authorise you

  • To verify your identity (e.g., for authentication, purposes and fraud prevention purposes);
  • To provide our payment services requested (e.g., conduct merchant acceptance procedures to enter into a contract);
  • To execute transactions;
  • To execute merchant payment requests, act upon instructions;
  • To perform our contractual obligations.

2. Ensure we comply with the law and applicable regulations, directives

  • To perform anti-money laundering checks and evaluations;
  • For crime prevention purposes and, when required, to co-operation with authorities;
  • Statistics and analytics for internal purposes and improvement of services and website;
  • Enforce or defend the rights of Unlimint or Unlimint group/affiliates;
  • Ensure physical and technical security and business continuity;
  • For internal operational support and administrative purposes (e.g. product development, audit, risk management);
  • General administrative functions (e.g. maintenance of our internal records necessary for keeping up-to-date information in our systems, general record-keeping).

3. To communicate, establish and maintain our services relationship with you

  • To provide ongoing support and handle inquiries, complaints and similar issues;
  • To provide information about our products, services or both when you request it;
  • To ensure that our internal procedures and protective measures against fraud, risk and financial crime are followed and that you are kept informed of this;
  • To obtain reports of an online problem (e.g. with our website or payment services);
  • To notify you of any quality management change, important product or service improvement, update or upgrade.

4. To market our product and services

  • To provide information about our products, services or both;
  • To improve and customise the content of our advertisements, promotions, and advertising that you may be interested in.

The provision of marketing activities is subject to the applicable laws of the country in which the marketing and communication activity occurs. This means that you can in Nigeria actively opt-in to receive such marketing communications. You are entitled to opt-out from receiving such marketing by clicking on the opt-out or unsubscribe link(s) provided in Unlimint marketing communications.

Who do we share your personal data with?

Internally

Unlimint shares your personal data in the context of Unlimint operations internally. This means that Unlimint Nigeria may share personal data with third parties from within the same group of companies to which Unlimint belongs. We may disclose your personal information to those companies to:

  • provide support services and technical services to these internal third parties and receive some of these services from them;
  • contribute to research, data analytics and studies to improve our products and services.

Externally

We will not share personal data with third parties unless this is necessary for our legitimate business needs to carry out requests, provide services or as required or permitted by law. Third parties under these circumstances include:

1. Merchants

Unlimint share your personal data with merchants to process a card payment transaction. When you buy products or services using Unlimint payment services, we may provide the merchant with your credit card billing address to help complete an individual’s payment transaction.

2. Service providers

We will disclose personal data to alternative payment providers (where applicable) and service providers (processors), so they can process it on our behalf where required. These service providers must provide assurances in accordance with applicable data protection laws and associated requirements. (e.g., being bound contractually to data protection, privacy, security and confidentiality obligations). We will only share personal data as is strictly necessary for them to provide their services to us.

3. Auditors, advisors and consultants

We may disclose personal data for purposes and in the context of audits (e.g., external card scheme audits, regulatory authority audits (like the Central Bank of Nigeria), security audits – such as Quality Security Assessors for PCI DSS Level 1, to legal and other compliance advisors who investigate security issues, risks, complaints.

This means that your personal data may be transferred and disclosed to:

  • Money laundering and fraud prevention aggregation or agencies, compliance and verification services and risk prevention services. This is required to verify your identity, ensure protection against fraud, and confirm eligibility for our services/products;
  • Banks (other credit and financial service institutions) and similar institutions. These enable us to provide our payment services and include correspondent banks such as intermediary banks;
  • Payment Card Brands or Systems (SWIFT, Visa, Mastercard, Verve). These enable us to provide our card processing services;
  • Companies assisting us with the provision of our services (e.g., technological services, solutions, support such as support/maintenance/development of IT applications, technology, website management, telephony/SMS services);
  • Customer support service providers and marketing service providers;
  • Entities of Unlimint Group which are affiliated/related to us, acting as processors or controllers to provide services, streamlined services, ensure quality and effectiveness across the group;
  • Administrative service providers;
  • Auditing and accounting services and consultants;
  • External legal advisors.

Unlimint takes all reasonable measures to ensure that every third party involved in processing your personal data has the required organisational and technical protections, including the required data processing and transfer agreements where necessary. When required under applicable law, we may provide you with a list of our sub-processors or suppliers upon request by contacting us at [email protected].

Regulatory authorities, law enforcement, courts

We may disclose personal data to comply with applicable legislation and regulatory obligations, to respond to requests of regulatory authorities, government and law enforcement agencies, courts and court orders in the Republic of Nigeria, such as:

  • Central Banks;
  • Financial Investigative authorities and the Police (subject to the receipt of a subpoena, court order or similar lawful request or procedure);
  • Tax Authorities;
  • Other regulators, authorities and public bodies where applicable under Nigerian legislation.

Other recipients may be any person/legal entity/organisation for which you ask your data to be transferred (e.g. reference etc.) or give your consent to transfer personal data.

We may also disclose your personal data if

  • If we are under a duty to disclose or share your personal data to comply with any legal or regulatory obligation or request;
  • To apply or enforce the Terms and Conditions or any other agreement in place in the context of our relationship and to investigate potential breaches;
  • To protect Unlimint’s rights, safety or property, or that of our customers or third parties/ the public. This includes exchanging information with other companies and organisations for the purposes of money laundering, fraud prevention and equivalent risks;
  • If Unlimint or substantially all of its assets are acquired by a third party, in which case personal data held by it about its merchants will be one of the transferred assets.

Transfers outside the EEA or to international organisations

We are a company with a global reach. Your personal data may be processed locally in Nigeria, in the EEA, or worldwide as permitted by law.

Your personal data may be transferred to international organisations if the transfer is necessary and has a legal basis as described in this Notice. Such transfers take place, for example:

  • When necessary to carry out and in the context of transactions (e.g. card transactions, payment orders to third countries, through a correspondent bank in the third country);
  • Under applicable law (e.g. tax legislation);
  • On the basis of your instructions or consent;
  • In the context of data processing undertaken by third parties on our behalf (e.g., the data may also be processed by staff operating outside of the EU/EEA or the relevant country who work for Unlimint or one of our third-party service providers or our Group. Such staff may be performing technical duties and support, duties related to the processing of your orders, provision of support services etc.).

We aim to take all steps reasonably necessary to ensure that your personal data is treated securely and under this Privacy Notice (e.g. requirement to observe privacy standards equivalent to ours, maintaining security standards and procedures to prevent unauthorised access, use of technology such as encryption and firewalls) to protect the security of data in transit and at rest.)

Automated decision-making and profiling

Automated decision-making means making decisions through automated means of processing personal data without human intervention. We do not generally use automated decision-making in establishing and carrying out a business relationship.

We may process some specific data automatically by using systems to make automated suggestions or decisions, including profiling, based on information we have or collect from other authorised sources. This helps us ensure we can react quickly and efficiently, with an aim also to protect our Merchants and payers. Automated decisions we may make include:

Detecting fraud: We are required to take anti-money laundering and anti-fraud measures. We may use your personal data to help us decide if an account/payment instrument is potentially being used for purposes of fraud or money-laundering/terrorist financing, or sanctions contraventions. Such assessments are carried out to help us detect if an account/payment instrument is being used in ways fraudsters work or in a way unusual for you or the business of our Merchant. If we determine a risk of fraud or unauthorised activity, we may stop activity on the account/block the payment instrument, or refuse access to them.

Website and Automatic collection — Cookies, IP addresses and other Tracking

Unlimint’s Website contains forms which website visitors may use. When website visitors send us information online via forms on the website, in the context of the provision of services, the information will be used for purposes and in ways set out in the Privacy Notice.

In some instances, Unlimint and other entities (such as service providers) may use cookies and other technologies to collect certain types of data automatically when you visit Unlimint websites and online platforms. The collection of this data enables Unlimint to improve the security, and usability of Unlimint’s websites and online resources and to measure the effectiveness of marketing activities. We may collect information about your computer or mobile device (including, for example type of operating system and browser) for system administration.

For detailed information on cookies and the purposes for which we use them, please refer to our Cookie Notice.

An IP address is a number assigned to your computer when you access the internet from your browser, which allows computers and servers to recognise and communicate with one another. IP addresses of website visitors may be recorded for IT security and diagnostic purposes. This information may also be used in aggregate form to conduct website trends and performance analysis. In the context of the provision of services, IP addresses may also be used for the purposes and in ways set out in with the Privacy Notice including fraud prevention.

How we keep your personal data secure?

Unlimint has established and regularly reviews its security internal policies and procedures for secure processing of personal data in order to protect personal data from unauthorised access, loss, misuse, alteration or destruction.

We ensure to the best of our abilities that access to personal data is limited to persons on a need-to-know basis, and that persons who have access are required to maintain its confidentiality. We utilise a series of technology and security solutions to protect personal data (such as storage of information you provide us on secure servers, perimeter security mechanisms, such as encryption etc.).

Transmission of information via the internet is not completely secure. We cannot guarantee the security of data transmitted to us via email, to our website or online resources; such transmissions are at your own risk.

Unlimint follows the payments industry standards regarding the protection of payment card information. Unlimint’s payment card infrastructure is regularly audited to maintain the highest level of security certification with the Payments Card Information Security Standard Council (PCI) in respect of protecting card data.

Your Rights

Depending on the applicable law, you may have rights as afforded under applicable data protection law — these rights are afforded to natural persons who are data subjects of personal data which we hold as a controller.

We ensure that you may exercise your rights under applicable privacy and data protection laws, which means that Unlimint endeavours to provide reasonable assistance in respect to requests from individuals regarding processing of personal data, rights to access, deletion, amendment etc. Please note that your rights are not absolute and may be limited due to a legal basis replied upon by us to process your data.

As the majority of processing we perform is a consequence of legal obligations, some of the rights may be limited by our legal and regulatory requirements or legitimate interests.

Depending on the applicable laws, you may have certain rights under data protection law. For example, in Nigeria under the NDPR and its corresponding laws, regulations and frameworks:

  • access your personal data (access rights): You have the right to ask us if we process personal information that relates to you and you may ask us to provide you with details of the personal information we process about you (as required under applicable laws);
  • correct or rectify your personal data: You can ask us to have inaccurate personal information we process about you fixed or changed;
  • erase your personal data: You can ask us to delete or erase personal information under certain circumstances if the personal information is no longer needed for the purposes for which we collected them (subject to local data retention legal obligations);
  • withdraw your consent: You may withdraw a consent to processing that you have given us and prevent further processing if there is no other legal ground (including legitimate interests) for processing your personal information;
  • restrict: the processing of your personal information: You can require certain personal information to be marked as restricted for processing in certain circumstances, such as an objection to our processing of your personal information based on our legitimate interests;
  • request data portability: You can ask us to transmit your personal information that you have provided to us to a third party in a machine-readable form;
  • object to automated decision making, including profiling, if these decisions produce a legal effect on you.

Exercising your rights

Please contact our Data Protection Officer directly at contact details to exercise your rights or if you have questions about the use of your personal data.

You may be subject to identification procedures and measures in order to ensure that no personal data is disclosed to unauthorized persons. We may also request additional clarifications to process your request as rapidly and efficiently as possible.

All requests must be made in English in a comprehensive manner and contain a clear description of the object of the request. We will not be able to process requests which are incomprehensive or in languages other than English.

We will not normally charge a fee to access your personal data (or exercise other rights). We may charge a fee where your request is clearly unfounded, excessive or repetitive. Alternatively, we may reject such a request as manifestly or excessively burdensome, unfounded and not submitted in good faith.

Depending on the complexity of your request and volume of data associated with it, we will aim to satisfy all legitimate requests within one month of receipt or to inform you of refusal, or of an extension period of up to three months to satisfy your request. We will notify you appropriately if your request requires more than one month to fulfil.

Right to file a complaint

If you have any complaints about the use of your data, exercise of your rights, please notify and/or file a complaint with our data protection function directly at the contact details indicated below or fill out and submit the relevant form available on the Company’s website: www.unlimint.com. We will immediately investigate and inform you in regard to your complaint.

Complaints must be made in English in a comprehensive manner and contain sufficient details and a clear description of the complaint. We will not be able to process requests which are incomprehensive or in languages other than English.

If you believe that we have not been able to resolve your complaint, you may also submit a complaint to the competent data protection authority. For Unlimint Nigeria, you may submit a complaint here.

Retention period

Our obligations primarily determine our retention period under applicable legislation to retain data for a specific time. Destruction will only be possible after the lapse of this period.

We are obliged to keep Transaction data (including personal data) during the business relationship and for a minimum period of 5 years after business relationship termination, or after Customer application rejection/withdrawal, per AML legislation and other requirements applicable to our business.

The retention period may be extended in case of other lawful reasons justifying longer retention (such as for complaints handling, legal proceedings, investigations, regulatory, tax, money laundering and crime and fraud prevention purposes).

Data Protection Officer Contact details

Unlimint has appointed a Group Data Protection Officer and also has appointed a Nigeria Data Protection Officer. Can be contacted as follows:

Data Protection Officer
Unlimint Nigeria Limited
6th Floor, Landmark Towers,
5B Water Corporation Road,
Victoria Island,
Lagos
Nigeria

Email: [email protected] to contact the data protection function, including the Data Protection Officer on record or Unlimint’s Group Data Protection Officer.

Your Responsibilities

You are responsible for ensuring that the information provided to Unlimint by you/about you or on your behalf is accurate and up to date. You must inform us if anything changes as soon as possible.

If you provide information about another person, you must direct them to this Privacy Notice and ensure they agree to Unlimint using their information as described.

Unlimint’s services are not intended or designed to attract minors. If we learn that we collected the personal data of a minor without first receiving verifiable parental consent, we will delete the information as soon as possible.

Changes to our Privacy Notice

We may revise or update our Privacy Notice from time to time. In such a case, we make the most recent version of the Privacy Notice available to you, informing you accordingly by displaying the updated version and relevant date of update.

You are advised to visit our Website frequently to consult our Privacy Notice in its most recent version.

Version 1.0_DP_Unlimint Nigeria Limited_January 2023

Unlimint Nigeria Privacy Notice.pdf

We’ve got all your details, thanks!