Legal

Privacy Policy

What personal data we collect, why we process it, who we share it with, how long we keep it and what you can ask us to do with it.

Last updated
21 August 2026
Applies to
Niimbu System Limited

Two kinds of personal data pass through Niimbu, and they are treated differently. Data about you and your business is ours to be accountable for. Data about your customers, suppliers and staff is yours, and we process it on your instructions to deliver the service.

We do not sell personal data to anybody, and we do not use the contents of your business records to market to your customers.

1.What this policy covers

This policy explains what we do with personal data when you visit niimbu.com, when you open and run a Niimbu account, and when you contact us.

It covers two groups of people, and the difference matters. The first is you: the owners, directors and staff of a business that uses Niimbu. For that data we decide why and how it is processed, so we are the controller. The second is your own customers, suppliers and employees, whose details you put into Niimbu to run your business. For that data you are the controller and we are your processor. We handle it on your instructions and to deliver the service, not for purposes of our own.

2.Who is responsible

Niimbu System Limited, trading as Niimbu, registered in Nigeria and based in Abuja, is the controller for the data described in this policy.

For any question about privacy, or to make a request about your data, write to [email protected] with "Data protection" in the subject line and it will reach the right person.

3.What we collect

Information you give us

  • Account details: name, email address, phone number, password and the business you act for
  • Business details: registered name, registration number, address, sector and ownership structure
  • Verification details: identity documents, BVN or NIN where required, and documents such as your CAC certificate
  • Payout details: account numbers and recipient names you enter to send money
  • Anything you send us in a support conversation, including attachments

Information created as you use the service

  • Transaction records: amounts, counterparties, timing, status and the fees applied
  • Records you build in the product: customers, products, stock movements, invoices, expenses, projects and staff
  • Activity logs: which user did what and when, which is what makes an audit trail possible
  • Technical data: IP address, device and browser type, and pages visited

Information from other sources

  • Verification results from identity providers and from official registries
  • Screening results against sanctions and politically exposed person lists
  • Payment status and settlement information from licensed partners and payment networks

We do not ask for and do not want special category data such as health or religious information. Please do not upload it into free text fields.

4.Why we process it, and on what basis

We only process personal data where we have a lawful basis to do so. In practice there are four.

Creating and running your account, processing transactions, providing supportPerformance of the contract between us
Verifying identity, screening against sanctions, monitoring for money laundering, keeping recordsCompliance with a legal obligation on us and on our licensed partners
Preventing fraud, securing the platform, fixing faults, improving the product in aggregateOur legitimate interest in running a safe and working service
Marketing emails to people who are not customers, and non essential cookiesYour consent, which you can withdraw at any time

Where we rely on legitimate interest, we have considered whether that interest is outweighed by your rights, and you can object to the processing at any time.

5.Automated checks and decisions

Some checks run automatically, because a human cannot review every transaction as it happens. Identity verification, sanctions screening and fraud monitoring all involve automated processing, and they can result in a transaction being held or an account being limited.

Where an automated decision has a significant effect on you, you can ask for a person to look at it. Write to us, tell us what was blocked, and we will review it and explain what we are permitted to explain. Some anti money laundering decisions cannot be explained in detail by law, which is a limit on us rather than a preference.

6.Who we share it with

We do not sell personal data. We share it only where it is needed to run the service or where the law requires it.

  • Licensed financial institutions and payment networks, to hold funds and move money
  • Identity verification and screening providers, to confirm who you are and meet our obligations
  • Cloud hosting, storage and logging providers that run our infrastructure
  • Communication providers that deliver our emails, and notifications you have asked for
  • Professional advisers such as auditors and lawyers, under a duty of confidence
  • Regulators, law enforcement and courts, where we are legally required to disclose
  • A buyer or successor, if the business is ever sold or reorganised, subject to this policy continuing to apply

Every processor we use is under a written contract that limits them to our instructions and requires them to protect the data. Where you connect a third party tool of your own to Niimbu, data flows to that tool because you asked it to, and their policy governs what they then do with it.

7.Storage and international transfer

Some of the providers we rely on operate outside Nigeria, so personal data may be transferred and stored abroad. Where that happens we take the steps the Nigeria Data Protection Act requires, which means transferring only to a country with adequate protection, or under contractual terms that keep the same level of protection with the recipient.

If you need to know where a specific category of data is held for a vendor review, ask us and we will tell you.

8.How long we keep it

We keep personal data for as long as we need it for the purpose we collected it, and then for as long as the law requires. Financial services record keeping obligations are long, and they override a deletion request for the records they cover.

Account and profile detailsWhile the account is open, then in line with the record keeping period below
Transaction and financial recordsAt least the period required by Nigerian financial and tax law after the transaction or the end of the relationship
Verification documents and screening resultsThe period required by anti money laundering law after the relationship ends
Support conversationsUp to three years, so we can see the history of an issue
Technical and security logsUp to twelve months, unless one is needed for an ongoing investigation
Marketing contactsUntil you unsubscribe, and then a suppression record so we do not contact you again

When a period ends, we delete the data or anonymise it so it can no longer identify anyone.

9.Your rights

Under the Nigeria Data Protection Act you have the right to:

  • Ask what personal data we hold about you and get a copy of it
  • Have inaccurate data corrected
  • Ask us to delete data, where we are not required to keep it
  • Ask us to restrict processing while a dispute about accuracy is resolved
  • Object to processing we carry out on the basis of legitimate interest
  • Receive data you gave us in a portable format, or have it sent to another provider
  • Withdraw consent at any time, where consent is the basis we relied on
  • Complain to the Nigeria Data Protection Commission

To exercise any of these, write to [email protected]. We will confirm receipt, may need to verify your identity first, and will respond within the period the law sets. There is no charge unless a request is repetitive or excessive.

If your request concerns data that a business holds about you inside its own Niimbu account, that business is the controller and you should ask them. If they need our help to act, we will give it.

10.Cookies and analytics

We use cookies that are strictly necessary to make the site and the dashboard work: keeping you signed in, remembering preferences, and protecting against cross site request forgery. These cannot be turned off without breaking the service.

We also use a small amount of analytics to understand which pages are useful and where people get stuck. Where a cookie is not strictly necessary, we ask before setting it, and you can change your mind later. Your browser settings also let you block or clear cookies, though doing so may sign you out.

11.How we protect it

Data is encrypted in transit and at rest, access inside Niimbu is limited to the people whose job needs it, and administrative access is logged. Our Security page describes the controls in more detail.

No system is perfect. If a breach occurs that is likely to affect your rights, we will notify the Nigeria Data Protection Commission and the people affected within the time the law requires, and we will tell you what happened, what we did, and what you should do.

12.Children

Niimbu is a business product and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has reached us, tell us and we will remove it.

13.Changes and how to complain

We update this policy as the product and the law change, and the date at the top always shows the current version. For a change that materially affects how we handle your data, we will tell you by email or in the dashboard before it takes effect.

If you are unhappy with how we have handled your data, tell us first at [email protected] and we will try to put it right. You can also complain directly to the Nigeria Data Protection Commission, and nothing here removes that right.

Something here unclear?

Write to us and a person will answer. If you are completing a procurement or vendor review and need a specific clause confirmed in writing, say so and we will put it in a letter.

Email [email protected]