Privacy Policy
Last updated: June 2025
NetPay is a financial technology company that provides cross-border payment and remittance services enabling individuals to send and receive money across international borders. This Privacy Policy explains how we collect, use, disclose, transfer, and protect personal data belonging to our customers in the course of providing our services.
This Policy is issued in compliance with the Nigeria Data Protection Act, 2023 (NDPA), the General Application and Implementation Directive, 2025 (GAID) issued by the Nigeria Data Protection Commission (NDPC), the Central Bank of Nigeria (CBN) regulatory framework applicable to licensed Payment Solution Service Providers, and other applicable data protection and financial services laws in the jurisdictions in which NetPay operates.
By creating a NetPay account, accessing our application, or using any NetPay service to initiate a domestic or cross-border transaction, you acknowledge that you have read and understood this Privacy Policy.
01Introduction
NetPay provides cross-border payment and remittance services. By using our services, you agree to the terms of this Privacy Policy. We are committed to protecting your personal data and processing it lawfully, fairly, and transparently.
02Information We Collect
Because NetPay facilitates cross-border money transfers, we are required by our regulators to collect more extensive identity, financial, and transaction information than a typical consumer app, in order to verify identity, screen for sanctions and financial crime risk, and comply with reporting obligations to the CBN and the Nigerian Financial Intelligence Unit (NFIU). This includes identity data (full legal name, date of birth, nationality, BVN, NIN, passport/ID number, photograph, signature); contact data (phone, email, address); financial data (bank account, wallet balances, source-of-funds information, transaction history); transaction data (sender/recipient details, amounts, currencies, exchange rates, beneficiary bank details); technical data (IP address, device identifiers, geolocation); usage data (app interactions, support records); and compliance data (sanctions/PEP screening results, risk ratings, beneficial ownership information).
We collect this information directly from you during onboarding and transaction initiation, automatically through your use of the application, and from third parties such as identity verification providers, correspondent banks, partner payment institutions, card networks, and public sanctions or watchlist databases.
03Legal Basis for Processing
NetPay processes personal data only where a lawful basis exists under the NDPA: consent (for specific purposes such as marketing), performance of a contract (to open your account and execute payment instructions), compliance with a legal obligation (KYC, CDD, sanctions screening, suspicious transaction reporting), or legitimate interests (fraud prevention, network security, service improvement, balanced against your rights).
04How We Use Your Information
- To verify your identity and conduct customer due diligence (CDD) and enhanced due diligence (EDD) where required.
- To open, maintain, and administer your NetPay wallet or account.
- To execute, process, confirm, and reconcile domestic and cross-border payment instructions.
- To screen transactions and counterparties against applicable sanctions lists and PEP databases.
- To detect, investigate, and prevent fraud, money laundering, terrorism financing, and proliferation financing.
- To comply with reporting obligations to the CBN, NFIU, NDPC, and other competent authorities, including STRs and CTRs.
- To respond to customer support requests and resolve disputes or chargebacks.
- To improve, secure, and personalise the NetPay application.
See Section 5 of our Terms of Service for how this compliance-driven data use affects your account and transactions.
05Cross-Border Transfer of Personal Data
Given the nature of our cross-border payment service, your personal data may be transferred to, stored in, or accessed from countries outside Nigeria, including the destination country of your transfer, correspondent banks, partner payment institutions, and cloud infrastructure providers. Where we transfer personal data outside Nigeria, we do so only where the recipient country has been assessed by the NDPC as adequate, appropriate safeguards are in place (such as standard contractual clauses or binding corporate rules), the transfer is necessary to perform your payment instruction, or you have given explicit informed consent to the specific transfer. We maintain a record of all cross-border data transfer mechanisms and conduct periodic transfer impact assessments for high-risk corridors.
06Sharing and Disclosure of Information
We disclose personal data only to the extent necessary, including to correspondent banks, partner payment institutions, and mobile money operators to complete your transfer; regulators and law enforcement (CBN, NDPC, NFIU, EFCC, and equivalent authorities abroad) where legally required; identity verification, sanctions screening, and fraud-prevention providers acting on our behalf; card networks and settlement banks; professional advisers, auditors, and our licensed Data Protection Compliance Organisation; and a successor entity in the event of a merger or acquisition, subject to equivalent data protection safeguards. We do not sell your personal data to third parties.
07Data Retention
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, and thereafter as required by law. Transaction records, KYC documentation, and CDD records are retained for a minimum of five (5) years from the date of the transaction or termination of the business relationship, in line with CBN AML/CFT/CPF Regulations and the Money Laundering (Prevention and Prohibition) Act, 2022. Where retention is no longer required, data is securely deleted or anonymised.
08Data Security
We implement technical and organisational measures proportionate to the sensitivity of the data we process, including encryption of data in transit and at rest, role-based access controls, multi-factor authentication, network monitoring, regular security testing, and staff training. Access to customer and transaction data is restricted to personnel who need it to perform their duties.
09Your Rights
Subject to applicable law, you have the right to be informed of how and why we process your data; to access a copy of the personal data we hold about you; to request rectification of inaccurate data; to request erasure, subject to statutory retention obligations; to request restriction of processing in defined circumstances; to receive your data in a portable format where feasible; to object to processing based on legitimate interest or direct marketing; to request human review of automated decisions that produce legal or similarly significant effects; and to lodge a complaint with the Nigeria Data Protection Commission (NDPC) or another competent supervisory authority. To exercise any of these rights, contact our Data Protection Officer at dpo@netpayinstant.com. We may need to verify your identity before actioning a request.
10Automated Decision-Making
NetPay uses automated systems to screen transactions for fraud, sanctions exposure, and money-laundering risk. Where an automated decision produces a legal or similarly significant effect on you — such as declining or delaying a transaction — you may request human review by contacting compliance@netpayinstant.com.
11Cookies and Similar Technologies
Our website and application use cookies and similar technologies to maintain your session, remember preferences, and analyse usage. You can manage cookie preferences through your device or browser settings. Disabling certain cookies may limit your ability to use some features of the application.
12Children's Privacy
NetPay's services are not directed at, and may not be used by, individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected data from a minor, we will take steps to delete it promptly.
13Data Breach Notification
In the event of a personal data breach likely to result in a high risk to your rights and freedoms, NetPay will notify the NDPC without undue delay, and in any event within the timeframe prescribed by the NDPA, and will notify affected individuals where required, together with guidance on protective steps to take.
14Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal and regulatory requirements. We will notify you of material changes through the application or by email, and will indicate the date of the latest revision at the top of this Policy.
15Governing Law and Complaints
This Policy is governed by the laws of the Federal Republic of Nigeria, including the NDPA. If you are not satisfied with our response to a privacy concern, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at www.ndpc.gov.ng, or with the relevant data protection authority in your country of residence.