Skip to main content

Privacy Policy

Last updated: April 2026 — NDPR/NDPA compliant

1. Data Controller

Floatra Technology Solutions Limited (“Floatra”, “we”, “us”, or “our”), a company registered in Nigeria, is the data controller responsible for the collection and processing of your personal data as described in this Privacy Policy.

Contact: privacy@floatra.com

2. Data Protection Officer

We have appointed a Data Protection Officer (DPO) in compliance with the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Regulation (NDPR) 2019. You may contact our DPO with any questions about how we handle your personal data:

DPO Contact: dpo@floatra.com

3. Categories of Data We Collect

Depending on your role and interaction with our platform, we may collect the following categories of personal data:

a) Personal Identification Data

  • — Full name
  • — Phone number
  • — Email address

b) Identity Verification Data

  • — Bank Verification Number (BVN) — stored as an encrypted hash, never in plaintext
  • — National Identification Number (NIN) — stored as an encrypted hash, never in plaintext
  • — Government-issued ID documents (passport, driver's license, voter's card) submitted for manual identity review

c) Biometric Data

  • — Facial image (selfie) captured for biometric identity matching via Smile Identity
  • — Biometric confidence scores derived from identity matching

d) Financial Data

  • — Order history and transaction records
  • — Loan performance data (disbursement, repayment, default records)
  • — Repayment records and payment references

e) Device and Technical Data

  • — IP address
  • — User agent (browser and device information)
  • — Device fingerprints used for fraud detection

f) Credit Data

  • — Credit bureau reports obtained from CRC Credit Bureau Limited
  • — Credit scores and credit history information

4. Purpose of Processing

We process your personal data for the following purposes:

  • — Personal identification data: Account creation, authentication, communication regarding your account and transactions
  • — Identity verification data (BVN/NIN): KYC (Know Your Customer) compliance as required by the Central Bank of Nigeria (CBN), identity verification before credit issuance
  • — Biometric data: Identity matching and fraud prevention through biometric comparison of selfie with government-issued identity records
  • — Financial data: Credit eligibility assessment, loan origination, repayment tracking, and portfolio monitoring
  • — Device and technical data: Fraud detection, platform security, abuse prevention, and audit logging
  • — Credit data: Credit risk assessment, credit scoring, loan performance reporting to credit bureaus

5. Legal Basis for Processing

We rely on the following legal bases for processing your personal data under the NDPA and NDPR:

  • — Consent: Biometric data collection (facial image capture and matching), credit bureau inquiry and reporting. You provide explicit, informed consent before these processes, and may withdraw consent at any time.
  • — Contractual necessity: Processing required to perform the credit facilitation service you have requested, including loan origination, disbursement routing, and repayment processing.
  • — Legitimate interest: Fraud prevention, platform security, device fingerprinting for abuse detection, and risk monitoring. We have assessed that these interests do not override your fundamental rights.
  • — Legal obligation: KYC/AML compliance under CBN regulations, tax and audit record retention, and reporting obligations under Nigerian law.

6. Third Parties We Share Data With

We share your personal data with the following categories of third parties, strictly on a need-to-know basis and in accordance with applicable data protection requirements:

  • Smile Identity Limited
    Identity verification and biometric matching. Receives BVN/NIN and facial images for identity confirmation.
  • CRC Credit Bureau Limited
    Credit history inquiry and loan performance reporting. Receives and provides credit data with your explicit consent.
  • Nigeria Inter-Bank Settlement System (NIBSS)
    BVN verification as required by CBN KYC regulations.
  • National Identity Management Commission (NIMC)
    NIN verification for identity confirmation.
  • Paystack Payments Limited
    Payment processing for loan disbursements and repayment collection.
  • Termii
    Delivery of SMS and WhatsApp notifications related to your account, verification status, and loan lifecycle.
  • Licensed Lending Partners
    Loan origination and servicing. Your loan is issued by a licensed lending partner, not by Floatra. Partners receive data necessary for credit decisions and loan management.

We do not sell your personal data to any third party. Data is shared only as described above and subject to appropriate contractual safeguards.

7. Cross-Border Data Transfers

Our cloud infrastructure may process or store your personal data on servers located outside Nigeria. Where this occurs, we implement the following safeguards to protect your data:

  • — Encryption of personal data in transit and at rest (AES-256-GCM for sensitive fields)
  • — Data Processing Agreements (DPAs) with all cloud and third-party service providers
  • — Contractual obligations requiring providers to maintain security standards equivalent to or exceeding Nigerian data protection requirements
  • — Compliance with the NDPA cross-border transfer provisions and any adequacy determinations by the Nigeria Data Protection Commission (NDPC)

8. Data Retention Periods

We retain personal data only as long as necessary for the purposes described in this policy or as required by law:

  • — KYC/AML records (BVN, NIN, identity verification results): 5 years after the end of the business relationship, as required by CBN regulations
  • — Transaction data (orders, loans, repayments, disbursements): 7 years, as required for tax and audit purposes
  • — Biometric verification results: 5 years. Stored as encrypted hashes and confidence scores. Raw facial images are retained under strict access controls and encryption
  • — Audit logs: 7 years, for regulatory compliance and security investigation purposes
  • — General account data: 3 years after your last activity on the platform

After the applicable retention period, personal data is securely deleted or anonymized in accordance with our data retention policy.

9. Your Rights as a Data Subject

Under the Nigeria Data Protection Act (NDPA) 2023 and the NDPR, you have the following rights:

  • — Right of access: You may request a copy of the personal data we hold about you.
  • — Right to rectification: You may request correction of inaccurate or incomplete personal data.
  • — Right to erasure: You may request deletion of your personal data, subject to legal retention obligations (see Section 8).
  • — Right to data portability: You may request your personal data in a structured, commonly used, machine-readable format.
  • — Right to withdraw consent: Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • — Right to lodge a complaint: You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your data protection rights have been violated.

10. How to Exercise Your Rights

You can exercise your data subject rights in the following ways:

  • — Email: privacy@floatra.com — submit a request and we will respond within 30 days
  • — Merchant Portal: Use the consent management feature in your merchant profile to view and withdraw consents

We may ask you to verify your identity before processing your request to prevent unauthorized access to your data.

11. Automated Decision-Making

Our credit scoring system uses automated rules to assess credit eligibility. Decisions are based on factors including account age, order history, repayment performance, credit tier, and credit bureau data.

If your credit application is declined through automated processing, you have the right to request a human review of the decision. Contact us at privacy@floatra.com to request a review.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms:

  • — The Nigeria Data Protection Commission (NDPC) will be notified within 72 hours of becoming aware of the breach
  • — Affected individuals will be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms
  • — Notifications will include the nature of the breach, likely consequences, measures taken to address it, and recommendations for affected individuals

13. Cookies

Floatra uses essential cookies only for session management and platform functionality. We do not use tracking cookies, advertising cookies, or any third-party analytics cookies.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to you via email or SMS notification. Continued use of the platform after notification constitutes acceptance of the updated policy.

We encourage you to review this policy periodically. The “Last updated” date at the top of this page indicates when the policy was last revised.

15. Contact Us

For privacy-related inquiries or to exercise your data rights:

16. Complaint to Regulator

If you are not satisfied with how we handle your personal data or your data subject request, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC):