Privacy Policy
What personal data we collect, why we process it, who we share it with, how long we keep it and what you can ask us to do with it.
- Last updated
- 21 August 2026
- Applies to
- Niimbu System Limited
- Questions
- [email protected]
Two kinds of personal data pass through Niimbu, and they are treated differently. Data about you and your business is ours to be accountable for. Data about your customers, suppliers and staff is yours, and we process it on your instructions to deliver the service.
We do not sell personal data to anybody, and we do not use the contents of your business records to market to your customers.
1.What this policy covers
This policy explains what we do with personal data when you visit niimbu.com, when you open and run a Niimbu account, and when you contact us.
It covers two groups of people, and the difference matters. The first is you: the owners, directors and staff of a business that uses Niimbu. For that data we decide why and how it is processed, so we are the controller. The second is your own customers, suppliers and employees, whose details you put into Niimbu to run your business. For that data you are the controller and we are your processor. We handle it on your instructions and to deliver the service, not for purposes of our own.
2.Who is responsible
Niimbu System Limited, trading as Niimbu, registered in Nigeria and based in Abuja, is the controller for the data described in this policy.
For any question about privacy, or to make a request about your data, write to [email protected] with "Data protection" in the subject line and it will reach the right person.
3.What we collect
Information you give us
- Account details: name, email address, phone number, password and the business you act for
- Business details: registered name, registration number, address, sector and ownership structure
- Verification details: identity documents, BVN or NIN where required, and documents such as your CAC certificate
- Payout details: account numbers and recipient names you enter to send money
- Anything you send us in a support conversation, including attachments
Information created as you use the service
- Transaction records: amounts, counterparties, timing, status and the fees applied
- Records you build in the product: customers, products, stock movements, invoices, expenses, projects and staff
- Activity logs: which user did what and when, which is what makes an audit trail possible
- Technical data: IP address, device and browser type, and pages visited
Information from other sources
- Verification results from identity providers and from official registries
- Screening results against sanctions and politically exposed person lists
- Payment status and settlement information from licensed partners and payment networks
We do not ask for and do not want special category data such as health or religious information. Please do not upload it into free text fields.
4.Why we process it, and on what basis
We only process personal data where we have a lawful basis to do so. In practice there are four.
| Purpose | Basis |
|---|---|
| Creating and running your account, processing transactions, providing support | Performance of the contract between us |
| Verifying identity, screening against sanctions, monitoring for money laundering, keeping records | Compliance with a legal obligation on us and on our licensed partners |
| Preventing fraud, securing the platform, fixing faults, improving the product in aggregate | Our legitimate interest in running a safe and working service |
| Marketing emails to people who are not customers, and non essential cookies | Your consent, which you can withdraw at any time |
Where we rely on legitimate interest, we have considered whether that interest is outweighed by your rights, and you can object to the processing at any time.
5.Automated checks and decisions
Some checks run automatically, because a human cannot review every transaction as it happens. Identity verification, sanctions screening and fraud monitoring all involve automated processing, and they can result in a transaction being held or an account being limited.
Where an automated decision has a significant effect on you, you can ask for a person to look at it. Write to us, tell us what was blocked, and we will review it and explain what we are permitted to explain. Some anti money laundering decisions cannot be explained in detail by law, which is a limit on us rather than a preference.
7.Storage and international transfer
Some of the providers we rely on operate outside Nigeria, so personal data may be transferred and stored abroad. Where that happens we take the steps the Nigeria Data Protection Act requires, which means transferring only to a country with adequate protection, or under contractual terms that keep the same level of protection with the recipient.
If you need to know where a specific category of data is held for a vendor review, ask us and we will tell you.
8.How long we keep it
We keep personal data for as long as we need it for the purpose we collected it, and then for as long as the law requires. Financial services record keeping obligations are long, and they override a deletion request for the records they cover.
| Category | Kept for |
|---|---|
| Account and profile details | While the account is open, then in line with the record keeping period below |
| Transaction and financial records | At least the period required by Nigerian financial and tax law after the transaction or the end of the relationship |
| Verification documents and screening results | The period required by anti money laundering law after the relationship ends |
| Support conversations | Up to three years, so we can see the history of an issue |
| Technical and security logs | Up to twelve months, unless one is needed for an ongoing investigation |
| Marketing contacts | Until you unsubscribe, and then a suppression record so we do not contact you again |
When a period ends, we delete the data or anonymise it so it can no longer identify anyone.
9.Your rights
Under the Nigeria Data Protection Act you have the right to:
- Ask what personal data we hold about you and get a copy of it
- Have inaccurate data corrected
- Ask us to delete data, where we are not required to keep it
- Ask us to restrict processing while a dispute about accuracy is resolved
- Object to processing we carry out on the basis of legitimate interest
- Receive data you gave us in a portable format, or have it sent to another provider
- Withdraw consent at any time, where consent is the basis we relied on
- Complain to the Nigeria Data Protection Commission
To exercise any of these, write to [email protected]. We will confirm receipt, may need to verify your identity first, and will respond within the period the law sets. There is no charge unless a request is repetitive or excessive.
If your request concerns data that a business holds about you inside its own Niimbu account, that business is the controller and you should ask them. If they need our help to act, we will give it.
11.How we protect it
Data is encrypted in transit and at rest, access inside Niimbu is limited to the people whose job needs it, and administrative access is logged. Our Security page describes the controls in more detail.
No system is perfect. If a breach occurs that is likely to affect your rights, we will notify the Nigeria Data Protection Commission and the people affected within the time the law requires, and we will tell you what happened, what we did, and what you should do.
12.Children
Niimbu is a business product and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has reached us, tell us and we will remove it.
13.Changes and how to complain
We update this policy as the product and the law change, and the date at the top always shows the current version. For a change that materially affects how we handle your data, we will tell you by email or in the dashboard before it takes effect.
If you are unhappy with how we have handled your data, tell us first at [email protected] and we will try to put it right. You can also complain directly to the Nigeria Data Protection Commission, and nothing here removes that right.
Something here unclear?
Write to us and a person will answer. If you are completing a procurement or vendor review and need a specific clause confirmed in writing, say so and we will put it in a letter.
Email [email protected]