PayFet Privacy Policy

Last updated: 21 July 2026  Effective date: 21 July 2026


1. About this policy

PayFet (“PayFet”, “we”, “us”, “our”) is committed to protecting your privacy. This policy explains what personal information we collect when you use the PayFet app, website, cards, and related services (together, the “Services”), why we collect it, who we share it with, and the rights you have over it.

PayFet is operated by Payfet Banking, with its registered office at Plot 1234, Victoria Island, Lagos, Nigeria. We are a licensed financial institution regulated by the Central Bank of Nigeria, and are registered as a data controller with the Nigeria Data Protection Commission (NDPC).

By using the Services, you agree to this policy. If you do not agree, please do not use the Services.


2. Who is responsible for your data

For the purposes of the Nigeria Data Protection Act 2023 (NDPA), PayFet is the data controller for the personal information described here.

Data Protection Officer Email: dpo@PayFet.net Address: Plot 1234, Victoria Island, Lagos, Nigeria


3. Information we collect

3.1 Information you give us

Category Examples
Identity Full name, date of birth, gender, nationality, signature, photograph or selfie
Identification BVN, NIN, passport, driver’s licence, voter’s card, TIN, CAC documents for business accounts
Contact Phone number, email address, residential and postal address
Financial Bank account details, card details, income and employment information, source of funds
Account Username or PayFet tag, PIN, password, security questions, preferences
Communications Messages to support, call recordings, chat transcripts, survey and feedback responses

3.2 Information we collect automatically

  • Transaction data — amounts, dates, recipients, merchants, currency, balances, and transaction descriptions
  • Device and technical data — device model, operating system, unique device identifiers, IP address, mobile network, app version, language settings
  • Usage data — screens visited, features used, session times, referral source, in-app actions
  • Location data — approximate location from your IP address and, where you grant permission, precise device location used for fraud detection and ATM or agent location
  • Biometric data — fingerprint or facial recognition used to unlock the app. Where this is handled by your device, we receive only a confirmation that authentication succeeded, not the biometric template itself
  • Cookies and similar technologies on our website and in the app (see Section 10)

3.3 Information from third parties

  • Identity and verification providers — NIBSS (for BVN verification), NIMC (for NIN verification), and KYC/AML screening providers
  • Credit bureaux — licensed Nigerian credit bureaux, where you apply for credit or where we report your repayment behaviour
  • Fraud prevention and sanctions databases — including politically exposed person (PEP) and international sanctions lists
  • Payment partners — banks, card schemes, switches, and payment processors involved in your transactions
  • Public sources — corporate registries, court records, and publicly available information
  • Referrals — limited information from a person who refers you to PayFet

We may collect information about other people from you — for example, a beneficiary’s account details or a next of kin. By providing it, you confirm you are entitled to share it with us.


4. Why we use your information and our legal basis

Under the NDPA we must have a lawful basis for each use.

Purpose Lawful basis
Creating and operating your account Performance of a contract
Verifying your identity (KYC), and screening for money laundering, terrorist financing, fraud, and sanctions Legal obligation
Processing your transactions and issuing cards Performance of a contract
Assessing eligibility for credit and reporting to credit bureaux Contract and legal obligation
Detecting, investigating, and preventing fraud and financial crime Legal obligation and legitimate interests
Providing customer support and handling complaints Contract and legal obligation
Sending service messages (transaction alerts, security notices, service changes) Contract and legal obligation
Sending marketing and product offers Consent
Improving and developing the Services, analytics and research Legitimate interests
Responding to regulators, law enforcement, and court orders Legal obligation
Protecting our legal rights and enforcing our terms Legitimate interests

Where we rely on legitimate interests, we assess that our interest is not overridden by your rights, and you may object at any time (see Section 8).


5. Automated decisions and profiling

We use automated systems to:

  • Screen transactions in real time for signs of fraud, which may result in a transaction being declined or your account being temporarily restricted
  • Verify your identity during onboarding
  • Assess credit applications and set limits, where applicable

These decisions can affect you significantly. You have the right to ask for a human to review any automated decision, to express your point of view, and to challenge the outcome. Contact us at support@PayFet.net or dpo@PayFet.net.


6. Who we share your information with

We never sell your personal information. We share it with:

  • Financial infrastructure — NIBSS, card schemes (Verve, Mastercard, Visa), switches, settlement banks, and partner banks holding customer funds
  • Regulators and authorities — the Central Bank of Nigeria, the NDPC, the Nigerian Financial Intelligence Unit (NFIU), the EFCC, tax authorities, courts, and law enforcement, where we are required or permitted to disclose
  • Credit bureaux — licensed Nigerian bureaux, in line with CBN requirements
  • Service providers acting on our instructions — cloud hosting, KYC and identity verification, card production and processing, SMS and email delivery, customer support tools, analytics, and security services
  • Professional advisers — auditors, lawyers, insurers, and consultants
  • Corporate transactions — a buyer or successor entity if PayFet is sold, merged, or restructured
  • Other people, at your direction — for example, the recipient of a transfer will see your name

We require all service providers to protect your data, use it only for the purposes we specify, and comply with the NDPA.


7. International transfers

Some of our service providers are located outside Nigeria — including in [the European Union, the United Kingdom, the United States, and South Africa].

Where we transfer your data abroad, we do so only if the destination country provides adequate protection as recognised by the NDPC, or where we have put appropriate safeguards in place such as standard contractual clauses, binding corporate rules, or your explicit consent. You can request details of these safeguards from our DPO.


8. Your rights

Under the NDPA you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — have inaccurate or incomplete data corrected
  • Erasure — ask us to delete your data, subject to the retention limits in Section 9
  • Restriction — ask us to pause processing while a dispute is resolved
  • Object — object to processing based on legitimate interests, and to direct marketing at any time
  • Portability — receive your data in a structured, commonly used, machine-readable format
  • Withdraw consent — where we rely on consent, withdraw it at any time without affecting past processing
  • Human review — of automated decisions (Section 5)
  • Complain — to us, or directly to the Nigeria Data Protection Commission

To exercise any right, contact dpo@PayFet.net or use the privacy controls in the app. We will respond within [30] days. We may ask you to verify your identity first. These rights are free to exercise, though we may charge a reasonable fee for manifestly excessive or repetitive requests.

Important: we cannot delete records we are legally required to keep, and we cannot continue providing regulated financial services to you if you withdraw consent to identity verification.


9. How long we keep your information

We keep your data only as long as necessary.

  • Active accounts — for as long as your account is open
  • After account closure — identity records, transaction history, and related communications are retained for at least [X] years from the end of our relationship, as required by anti-money-laundering law and CBN regulations
  • Call recordings and support chats — 2 years
  • Marketing preferences — until you withdraw consent, plus a record of the withdrawal
  • CCTV and physical access records at our offices — 23 days

When a retention period ends, we securely delete or irreversibly anonymise the data.


10. Cookies and tracking

We use cookies and similar technologies on our website and SDKs in our app to keep you signed in, remember preferences, measure performance, detect fraud, and — with your consent — measure marketing effectiveness.

Strictly necessary cookies cannot be turned off. You can manage all others through our cookie banner or your browser settings. See our [Cookie Policy] for the full list.


11. How we protect your information

We use encryption in transit and at rest, multi-factor authentication, PIN and biometric protection, network segregation, access controls on a need-to-know basis, continuous monitoring, and regular independent security testing. Our card systems are maintained to PCI DSS standards.

No system is completely secure. You are responsible for keeping your PIN, password, and OTPs confidential — PayFet staff will never ask you for your PIN, password, OTP, or full card details. If you suspect your account has been compromised, contact us immediately at support@PayFet.net or +234 800 123 4567.

If a breach occurs that is likely to result in a risk to your rights, we will notify the NDPC within 72 hours and inform you without undue delay where the risk is high.


12. Children

The Services are not intended for anyone under [18], and we do not knowingly collect data from children. [If you offer a teen product, describe it here and the parental consent process.] If we learn we have collected a child’s data without proper consent, we will delete it.


13. Changes to this policy

We may update this policy from time to time. If changes are material, we will notify you in the app, by email, or by SMS at least [14] days before they take effect. The “last updated” date at the top always shows the current version. Continuing to use the Services after changes take effect means you accept the updated policy.


14. Contact us

Questions, requests, or complaints: Email: support@PayFet.net Data Protection Officer: dpo@PayFet.net Phone: +234 800 123 4567 Address: Plot 1234, Victoria Island, Lagos, Nigeria

If you are unhappy with our response, you may complain to:

Nigeria Data Protection Commission (NDPC) Website: ndpc.gov.ng

You may also refer complaints about our financial services to the Central Bank of Nigeria Consumer Protection Department.