Privacy Policy

We care about your privacy

Your privacy is important to us at Belema Fintech. We respect your privacy regarding any information we may collect from you across our website.

Last updated: 2 December 2025

Data Privacy Policy

1. Introduction

Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Processing: Any operation performed on personal data such as collection, storage, use, disclosure, or deletion.
  • Controller: The entity that determines the purposes and means of processing personal data.
  • Processor: A third party that processes personal data on behalf of the controller.

This Privacy & Data Protection Policy is designed to comply with:

  • Nigeria Data Protection Act (NDPA 2023)
  • Nigeria Data Protection Regulation (NDPR : NDPA) and related laws and regulation on data privacy and data protection.

We adopt principles of lawfulness, fairness, transparency, accountability, and respect for data subject rights under these laws. All processing activities will be documented and monitored to ensure compliance.

Belema Financial Technology (referred to as "we", "us", "our") provides this Privacy & Cookie Policy to explain how we collect, process, disclose, protect, and discard personal information. By using the Services, you accept the practices described in this policy.

2. Scope & applicability

This policy applies to:

  • Users of our digital products (customers, merchants, administrators, testers) in the environment.
  • Data collected via digital products, APIs, and third-party services integrated with the Services.

Where local laws apply (NDPR in Nigeria and DPDPA in India), we process personal data in line with that law as applicable. If you are in a jurisdiction with specific rights (for example the EU), those rights are described below and will be respected where applicable.

3. What information we collect

a) Information you provide directly

  • Account registration details (name, phone number, email, username).
  • Verification data (ID documents, KYC where required).
  • Transaction details (sender, recipient, amounts, descriptions).
  • Payment instrument info (tokenized payment IDs; we do not store raw card PANs — payment processors may handle raw details).
  • Support requests and communications.

b) Information collected automatically

  • Usage and analytics data (pages visited, features used, timestamps).
  • Device and connection information (device type, OS version, browser, IP address, device identifiers).
  • Essential cookies.
  • Logs and telemetry (error logs, performance metrics).

c) Information from third parties

  • Fraud detection services, identity verification providers, payment processors, and analytics providers may share data with us as needed to provide Services.

Processing of personal data will rely on one or more of the following legal grounds:

  • Consent of the data subject
  • Performance of a contract
  • Compliance with legal obligations
  • Legitimate interests pursued by the controller
  • Protection of vital interests
  • Public interest or official authorities

We use personal data to:

  • Provide and operate the banking Services (account creation, payments, transfers).
  • Process transactions and maintain transaction history.
  • Authenticate users and prevent fraud.
  • Comply with legal and regulatory obligations (KYC, anti-money laundering).
  • Improve product functionality, analytics, and debugging.
  • Communicate with you (notifications, updates, support).
  • Security monitoring and incident response.

Legal basis (where applicable):

  • Performance of contract.
  • Legal compliance.
  • Legitimate interests (fraud prevention, service improvement).
  • Consent for marketing & non-essential cookies.

Data classification

This table describes how we classify data:

S/NData elementClassification
1PublicInformation approved for public disclosure. Exposure poses no risk to the company, customers, or partners. Eg. sales & marketing materials, social media posts, press releases etc.
2InternalOperational or system data used within Belema Fintech. Exposure may cause limited internal disruption but no regulatory impact. Eg. monthly reports, employee handbooks, company performance reports, internal mails.
3ConfidentialPersonal, business, or transactional data whose exposure could lead to privacy violations, reputational damage, or financial loss. Eg. data containing PII, card details, BVN, NIN, bank account details, trade secrets, authentication data.
4RestrictedHighly sensitive or regulated data. Unauthorized disclosure could result in serious legal, financial, or compliance consequences. Eg. trade secrets, proprietary processes, card PIN, and all legal documents.

5. Roles and Responsibility

We believe that data protection is a team effort led by the following teams:

  • Data Protection Officer (DPO): Oversee the implementation and enforcement of this policy and monitor compliance with the Nigeria Data Protection Regulation (NDPR).
  • Information Security Team: Support the technical implementation of data protection measures.
  • All Employees: Handle data in accordance with this policy and report incidents or concerns promptly.

6. Your Rights

Belema Fintech and all related products adopt all rights provided through the NDPA in Nigeria and the DPDPA. Hence your rights include access, rectification, objection, portability, deletion, informed, restrict, complain, erasure, lodging complaint, automation, and consent removal.

To exercise rights, contact dataprivacy@belemafintech.com. We will respond within the timeframe required by applicable law.

7. Sharing and Disclosures

We may share personal data upon obtaining consent from the data subject with:

  • Service providers (payment processors, hosting, analytics, identity verification).
  • Law enforcement, regulators, or courts if required by law or to protect safety and rights.
  • Affiliates and subsidiaries where necessary for service operations.

All third parties must maintain appropriate security measures and are prohibited from using data for other purposes.

8. Cookies & similar technologies (summary)

We use cookies, local storage, and similar technologies to operate the site, remember your preferences, secure the platform, and collect analytics. You can accept or decline non-essential cookies using the cookie banner and settings. Essential cookies required for site operation are always active.

9. Cookies managed by third parties / analytics

If we use third-party analytics or crash reporting (e.g., Google Analytics, Sentry) they may place their own cookies. We provide granular consent controls for those cookies. You can also opt out via browser settings or opt-out links where available.

10. Data retention

We retain personal data only as long as necessary for the purposes described and to comply with legal/regulatory obligations. Typical retention:

  • Transaction records: 6 years after last transaction — fulfilling NDPR and CBN requirements.

Personal data may be retained up to 3 years after the last active use of your digital platform by the data subject.

11. Security

We implement industry standard technical and organizational measures to protect personal data (encryption in transit, access controls, secure development practices). However, no system is perfectly secure; report suspected incidents to securityoperations@belemafintech.com.

12. Data Destruction

After data must have used its entire lifecycle or upon request from the data owner, we implement industry standard practices to destroy and dispose of it in accordance with the approved disposal policy.

13. Children

Our Services are not directed to children under 13 (or local age of consent). We do not knowingly collect personal info of children. If detected, we will delete it and notify the requester.

14. International transfers

If personal data is transferred outside your country (e.g., to cloud providers or processors), we ensure appropriate safeguards (standard contractual clauses, data processing agreements) are in place.

15. Changes to this policy

We may update this Policy from time to time. We'll post changes on this page with a new effective date. For material changes, we will provide notice.

16. Contact & complaints

For privacy questions or complaints contact dataprivacy@belemafintech.com. If unsatisfied you may contact your local data protection authority.