Nigeria Privacy Notice
Read this Privacy Notice if you want to know how Unlimint Nigeria Limited gathers, processes and stores your personal data.
The purpose of this Notice is to tell you which personal data we process, how, why and for how long we process your personal data. It is important to Unlimint that you know your rights regarding your personal data and how to reach us.
To get a complete understanding of Unlimint and our service offering to you, please read this Notice with the relevant Terms and Conditions and Cookie Policy on our Website.
Who is Unlimint?
Unlimint and its group companies or businesses are part of a global payments and technology organisation.
Unlimint Nigeria Limited (“Unlimint” or “we”) operate as a Payment Solutions Service Provider. This means that Unlimint provides its merchants with payment services and the platforms and applications (“platforms”) through which card payments services and other alternative payment methods are offered (“payment services”) to merchants.
When you use our payment services as a merchant of Unlimint, the merchant is the data controller.
This may change depending on your chosen services and products or when they become available in Unlimint.
When you visit our Website, or you are staff of Unlimint, Unlimint is the controller of your personal data.
Warning: Our Website may contain links to or come from websites or applications with their privacy notices or policies, which Unlimint does not control. These websites will have different privacy notices or statements, and we do not control these websites. Unlimint does not accept any responsibility or liability for such websites.
In this Notice, “personal data” refers to information that identifies you or may identify you (e.g., depending on who you are, a merchant, payer, supplier or business partner) and how you interact with us, we may process different types of personal data. “Processing” of personal data refers to collecting, gathering, handling, storing, transmitting and combining personal data. A “data subject” is a person that can be identified or identifiable from the personal data processed by a controller or processor. A “merchant” is a company or online store that uses our services to enable payments so that you can pay for goods, services or both.
What this Notice tells you
This Notice contains a description of:
- When and why do we process personal data:
- Why do we process personal data,
- When do we process personal data;
- What types of personal data do we process;
- How we collect and use personal data;
- What are the lawful grounds that we rely on to process your personal data;
- What are our purposes for processing your personal data;
- Who do we share your personal data with:
- International Transfers,
- Marketing and Cookies;
- Your rights and how to raise a complaint;
- How long we keep your personal data;
- How we keep your personal data secure;
- How we tell you when we change this Notice.
Why and when do we process personal data?
Why do we process personal data?
Establish a contract with a merchant and provide our services to a merchant. In this scenario, Unlimint needs the following personal data:
- To meet our legal obligations. We are required to identify you, authenticate your identity and perform due diligence checks on you, and if you are a legal person, we also then have to verify your directors, signatories and ultimate beneficial owners. This is an obligation on Unlimint under payments, anti-money laundering, sanction and anti-bribery and anti-corruption laws, as well as multiple directives, regulations and guidance to combat fraud, money laundering and bribery and corruption. Examples of such laws include: Money Laundering (Prevention and Prohibition) Act, 2022; Terrorism (Prevention and Prohibition) Act, 2022.
- For contractual purposes. To establish and maintain a business relationship for the provision of our services, to execute (complete) payment transactions and the performance of contractual obligations between both Unlimint and its merchants.
- For our legitimate interests. We implement online and physical security measures to properly provide our payment services, ensuring personal data and the underlying physical and logical security best practices, access control management and underlying analytics to further protect against cybercrime and fraud.
When do we process personal data?
Personal data is requested before and during the contractual relationship.
For example, when we perform card or online payment processing, Unlimint, in the capacity of a processor, processes personal data received from merchants, which is relevant for processing payments for merchants and reporting transactions to the merchant.
This includes personal data such as transaction details and payment reference identifier and personal data in the context of transactions processing (such as payment instrument and transaction details, identification details, contact details, such as email, telephone, name on card, date of birth), to complete the transaction initiated by the cardholder or payer to the merchant.
Please check your merchants’ privacy notices or statements regarding important information about your personal data processing.
Suppose we cannot process certain categories of personal data. In that case, this can result in Unlimint not being able to enter into a services contract with a merchant or execute a payment instruction without the requested personal data, or we may no longer be able to continue with an existing relationship and provision of our services with a merchant.
What types of personal data do we process?
Various types of personal data are processed in the context of the relationship between you and Unlimint, depending on the service and product you are using. These may include:
Your personal data | Name, previous names, data and place of birth, language, if you hold prominent public functions (Peps), residence permit. |
Your personal contact details | Work address, home address, email address, telephone number, and other contact details. |
Your identity information | Passport, National ID card, Nationality, Utility bill, tax residence and tax ID. |
Relevant financial information | Personal bank details, professional status, employment field, employer details (including, for example, information such as certificates of directors). |
Specific authentication personal data | A signature or your user login to access our service dashboards. |
Communications | Personal data that you may provide by filling in forms or by communicating with us (e.g. directed to us in letters, emails, via our electronic channels). |
Transactional and other/documents information | Personal Data arising for the execution of payment transactions (including data such as date, time, amount, currencies, beneficiary details, location information and merchant details), supplementary/supporting documentary evidence related to transactions, and further information arising from contractual obligations between Unlimint and Merchants. |
Location and technical information | Location data (for example, at the time of login or a transaction); IP addresses and device information, visitor’s information and similar information subject to our Cookie Policy. |
Publicly available Personal Data | Details about you from public records and available in publicly accessible databases. |
Investigations data/results of due diligence and enhanced due diligence | Personal data regarding criminal convictions and offences (special category of data), as part of its compliance measures with regulatory obligations, as well as other supporting documents and personal data related to the categories above. |
CCTV | Closed circuit television (CCTV) at our offices (which may collect videos of you). |
Consents | Personal Data that you agree to give us by your active consent when you use our services or visit our Website. |
How do we collect your personal data?
1. Personal Data you submit to us
This can happen in different ways:
- When you have agreed to give to the merchant your personal data who has a contract with us so we can provide our services to them. We take all reasonable steps to collect the personal data of payers only what is needed to process the transaction for the Merchant.
- When you actively opt-in to accept our Privacy Notice, receive communications from us, via email or forms available on our Website or any other means of communication. When you consent to us collecting such Personal Data, you have the right to opt out of such collection at any time. To do so, please go to our Website to choose what Personal Data we may collect from you.
2. Personal Data we collect when you use our services
This personal data may include the following:
- Payment and Transactions data.
- Profile and usage data (such as data when you connect to internet banking, or SMS services (if applicable), and may include Personal Data on how you use the services. We may collect data from devices you use to connect to the services, such as computers and mobile phones, such as your IP address and use cookies (go to our Cookie Notice).
- Third-party data. Personal data we lawfully obtain from other entities such as service providers, fraud prevention aggregation agencies, public authorities, persons that refer you to us, our Group companies, and companies processing payments.
- Public Data. Databases and publicly accessible sources or other sources accessible to relevant payment institutions, such as Unlimint, due to the nature of Unlimints’ services (e.g., this includes Registrars of Companies, Commercial Registries, AML and sanction screening databases).
What are the lawful grounds we rely on to process your personal data?
When we process your personal data, we rely on one of the processing legal bases below. We may process your personal data for different purposes, and in such cases, the same personal data will be processed under another legal basis.
1. Conclusion and performance of a contract
We process personal data to conclude a services contract with a merchant and to perform our obligations under a contract to provide our payment services with our merchants in compliance with applicable laws and regulations.
2. Legal obligation or public interest
Unlimint is subject to various legal obligations and legal and regulatory requirements to provide payment services. We are also required to implement regulations and directives of multiple authorities to ensure compliance. The purposes of processing include verification controls of identity, money laundering and fraud prevention, compliance with our record reporting obligations, tax obligations, risk control measures, and providing information to a competent authority, public body or law enforcement agency.
3. Legitimate interests
Where necessary, we may process personal data where there is a legitimate interest for us or a third party in pursuing commercial and business interests, except where your interests, fundamental rights and freedoms override such interests.
4. Your consent
Your personal data will be processed in this way if you agree to this. Where the legal basis is the consent you provided, you may withdraw your consent at any time. The revocation of your consent will not affect the legality of the data processed before the revocation.
Purposes for which we use your personal data
We process your personal data for the following purposes:
1. Authenticate, Verify and Authorise you
- To verify your identity (e.g., for authentication, purposes and fraud prevention purposes);
- To provide our payment services requested (e.g., conduct merchant acceptance procedures to enter into a contract);
- To execute transactions;
- To execute merchant payment requests, act upon instructions;
- To perform our contractual obligations.
2. Ensure we comply with the law and applicable regulations, directives
- To perform anti-money laundering checks and evaluations;
- For crime prevention purposes and, when required, to co-operation with authorities;
- Statistics and analytics for internal purposes and improvement of services and website;
- Enforce or defend the rights of Unlimint or Unlimint group/affiliates;
- Ensure physical and technical security and business continuity;
- For internal operational support and administrative purposes (e.g. product development, audit, risk management);
- General administrative functions (e.g. maintenance of our internal records necessary for keeping up-to-date information in our systems, general record-keeping).
3. To communicate, establish and maintain our services relationship with you
- To provide ongoing support and handle inquiries, complaints and similar issues;
- To provide information about our products, services or both when you request it;
- To ensure that our internal procedures and protective measures against fraud, risk and financial crime are followed and that you are kept informed of this;
- To obtain reports of an online problem (e.g. with our website or payment services);
- To notify you of any quality management change, important product or service improvement, update or upgrade.
4. To market our product and services
- To provide information about our products, services or both;
- To improve and customise the content of our advertisements, promotions, and advertising that you may be interested in.
The provision of marketing activities is subject to the applicable laws of the country in which the marketing and communication activity occurs. This means that you can in Nigeria actively opt-in to receive such marketing communications. You are entitled to opt-out from receiving such marketing by clicking on the opt-out or unsubscribe link(s) provided in Unlimint marketing communications.
How we keep your personal data secure?
Unlimint has established and regularly reviews its security internal policies and procedures for secure processing of personal data in order to protect personal data from unauthorised access, loss, misuse, alteration or destruction.
We ensure to the best of our abilities that access to personal data is limited to persons on a need-to-know basis, and that persons who have access are required to maintain its confidentiality. We utilise a series of technology and security solutions to protect personal data (such as storage of information you provide us on secure servers, perimeter security mechanisms, such as encryption etc.).
Transmission of information via the internet is not completely secure. We cannot guarantee the security of data transmitted to us via email, to our website or online resources; such transmissions are at your own risk.
Unlimint follows the payments industry standards regarding the protection of payment card information. Unlimint’s payment card infrastructure is regularly audited to maintain the highest level of security certification with the Payments Card Information Security Standard Council (PCI) in respect of protecting card data.
Your Rights
Depending on the applicable law, you may have rights as afforded under applicable data protection law — these rights are afforded to natural persons who are data subjects of personal data which we hold as a controller.
We ensure that you may exercise your rights under applicable privacy and data protection laws, which means that Unlimint endeavours to provide reasonable assistance in respect to requests from individuals regarding processing of personal data, rights to access, deletion, amendment etc. Please note that your rights are not absolute and may be limited due to a legal basis replied upon by us to process your data.
As the majority of processing we perform is a consequence of legal obligations, some of the rights may be limited by our legal and regulatory requirements or legitimate interests.
Depending on the applicable laws, you may have certain rights under data protection law. For example, in Nigeria under the NDPR and its corresponding laws, regulations and frameworks:
- access your personal data (access rights): You have the right to ask us if we process personal information that relates to you and you may ask us to provide you with details of the personal information we process about you (as required under applicable laws);
- correct or rectify your personal data: You can ask us to have inaccurate personal information we process about you fixed or changed;
- erase your personal data: You can ask us to delete or erase personal information under certain circumstances if the personal information is no longer needed for the purposes for which we collected them (subject to local data retention legal obligations);
- withdraw your consent: You may withdraw a consent to processing that you have given us and prevent further processing if there is no other legal ground (including legitimate interests) for processing your personal information;
- restrict: the processing of your personal information: You can require certain personal information to be marked as restricted for processing in certain circumstances, such as an objection to our processing of your personal information based on our legitimate interests;
- request data portability: You can ask us to transmit your personal information that you have provided to us to a third party in a machine-readable form;
- object to automated decision making, including profiling, if these decisions produce a legal effect on you.
Exercising your rights
Please contact our Data Protection Officer directly at contact details to exercise your rights or if you have questions about the use of your personal data.
You may be subject to identification procedures and measures in order to ensure that no personal data is disclosed to unauthorized persons. We may also request additional clarifications to process your request as rapidly and efficiently as possible.
All requests must be made in English in a comprehensive manner and contain a clear description of the object of the request. We will not be able to process requests which are incomprehensive or in languages other than English.
We will not normally charge a fee to access your personal data (or exercise other rights). We may charge a fee where your request is clearly unfounded, excessive or repetitive. Alternatively, we may reject such a request as manifestly or excessively burdensome, unfounded and not submitted in good faith.
Depending on the complexity of your request and volume of data associated with it, we will aim to satisfy all legitimate requests within one month of receipt or to inform you of refusal, or of an extension period of up to three months to satisfy your request. We will notify you appropriately if your request requires more than one month to fulfil.
Right to file a complaint
If you have any complaints about the use of your data, exercise of your rights, please notify and/or file a complaint with our data protection function directly at the contact details indicated below or fill out and submit the relevant form available on the Company’s website: www.unlimint.com. We will immediately investigate and inform you in regard to your complaint.
Complaints must be made in English in a comprehensive manner and contain sufficient details and a clear description of the complaint. We will not be able to process requests which are incomprehensive or in languages other than English.
If you believe that we have not been able to resolve your complaint, you may also submit a complaint to the competent data protection authority. For Unlimint Nigeria, you may submit a complaint here.
Retention period
Our obligations primarily determine our retention period under applicable legislation to retain data for a specific time. Destruction will only be possible after the lapse of this period.
We are obliged to keep Transaction data (including personal data) during the business relationship and for a minimum period of 5 years after business relationship termination, or after Customer application rejection/withdrawal, per AML legislation and other requirements applicable to our business.
The retention period may be extended in case of other lawful reasons justifying longer retention (such as for complaints handling, legal proceedings, investigations, regulatory, tax, money laundering and crime and fraud prevention purposes).
Data Protection Officer Contact details
Unlimint has appointed a Group Data Protection Officer and also has appointed a Nigeria Data Protection Officer. Can be contacted as follows:
Data Protection Officer Unlimint Nigeria Limited |
6th Floor, Landmark Towers, 5B Water Corporation Road, Victoria Island, Lagos Nigeria |
Email: [email protected] to contact the data protection function, including the Data Protection Officer on record or Unlimint’s Group Data Protection Officer.
Your Responsibilities
You are responsible for ensuring that the information provided to Unlimint by you/about you or on your behalf is accurate and up to date. You must inform us if anything changes as soon as possible.
If you provide information about another person, you must direct them to this Privacy Notice and ensure they agree to Unlimint using their information as described.
Unlimint’s services are not intended or designed to attract minors. If we learn that we collected the personal data of a minor without first receiving verifiable parental consent, we will delete the information as soon as possible.
Changes to our Privacy Notice
We may revise or update our Privacy Notice from time to time. In such a case, we make the most recent version of the Privacy Notice available to you, informing you accordingly by displaying the updated version and relevant date of update.
You are advised to visit our Website frequently to consult our Privacy Notice in its most recent version.
Version 1.0_DP_Unlimint Nigeria Limited_January 2023