Privacy Notice
How CrediSure Financial Technologies Ltd collects, uses, discloses, and safeguards your personal data under the Nigeria Data Protection Act (NDPA) 2023.
Effective date: January 1, 2026
CrediSure Financial Technologies Ltd (“the Company”) is committed to protecting your personal data in line with the Nigeria Data Protection Act (NDPA) 2023, applicable regulations, and our internal privacy and security policies. This Privacy Notice explains how we collect, use, disclose, transfer, and safeguard your personal data, as well as your rights under the law.
Nigeria Data Protection Commission
CrediSure Financial Technologies Limited has filed its NDP Act, 2023 Compliance Audit Returns for 2025. The Nigeria Data Protection Commission (NDPC) has acknowledged this statutory filing — confirming we handle personal data in line with Nigerian data-protection law.
1. Personal Data We Collect
- Identification data (name, date of birth, gender, nationality, ID numbers, photographs).
- Contact details (address, phone number, email).
- Employment-related data (position, work history, qualifications).
- Financial information (bank details, tax information).
- Digital/IT data (IP address, device details, access logs).
- Sensitive personal data (e.g., health, biometric, racial/ethnic data, political opinions, religious beliefs, or sexual orientation), only where necessary and permitted by law.
2. Purposes of Processing
- Compliance with the NDPA 2023 and other applicable laws/regulations.
- Management of employees, contractors, customers, and third-party relationships.
- Legal and regulatory compliance, risk management, and reporting obligations.
- Fulfilment of statutory obligations to government agencies.
- Protection of Company integrity, security, and reputation.
- Safeguarding vital interests of individuals or the public.
- Performance of contracts and provision of services.
- Other lawful business-related purposes consistent with this Notice.
3. Lawful Bases for Processing
- Consent of the data subject.
- Performance of a contract or pre-contractual steps.
- Compliance with legal obligations.
- Protection of vital interests of individuals.
- Legitimate interests pursued by the Company, provided these do not override data subject rights.
- Public interest or official authority (where applicable).
4. Sharing and Disclosure of Data
- Government Ministries, Departments, Agencies, and Regulatory Bodies – for compliance, reporting, or lawful requests.
- Authorized Data Processors and Service Providers – who act on our instructions and are bound by confidentiality and data protection obligations.
- Third-Party Partners – providing statutory, employment, or contractual benefits and services.
- Law Enforcement or Courts – where required by law.
- Emergency Services or Authorities – in cases of urgent protection of life, safety, or vital interests.
- Cross-Border Transfers – where necessary, subject to NDPC adequacy decisions, safeguards, or other lawful mechanisms.
5. Data Subject Rights
- Request access to your personal data.
- Request information about your personal data.
- Request rectification of inaccurate or incomplete data.
- Request deletion ("right to erasure") in certain circumstances.
- Restrict or object to processing.
- Request data portability.
- Withdraw consent at any time (where consent is the lawful basis).
- Lodge a complaint with the Nigeria Data Protection Commission (NDPC).
Requests can be submitted through the contact details provided below.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable laws and regulations. Thereafter, data will be securely deleted or anonymized.
7. Data Security & Safeguards
We take reasonable steps to ensure that personal data is accurate, complete, and up to date. Personal data is protected through appropriate technical, administrative and physical measures to prevent unauthorized access, loss, misuse or abuse, disclosure, alteration or destruction.
8. Accountability & Governance
- CrediSure Financial Technologies Ltd has appointed/designated a Data Protection Officer (DPO) to oversee compliance.
- All staff handling personal data receive regular training on privacy and security obligations.
- Processing activities are documented and subject to periodic data protection audits in line with NDPC requirements.
9. Contact Information
If you have any questions, concerns, or requests regarding your personal data, please contact our Data Protection Officer at privacy@credisure.ng.
Data Protection Officer
CrediSure Financial Technologies Ltd
If you have any questions, concerns, or requests regarding your personal data, please contact us at privacy@credisure.ng.

