Data Protection & Privacy Policies
Effective Date: July 2026
Regulatory Framework: Nigeria Data Protection Act (NDPA) 2023
Document Version: 1.0
NDPA compliance pack for regulatory submissions. See also Privacy Policy, Information Security Policy, and Governance Hub.
FidemIt processes personal data in accordance with the Nigeria Data Protection Act (NDPA) 2023.
Principles: lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity/confidentiality, and accountability.
Legal bases: contract performance, legal obligation (AML/KYC), legitimate interest, and consent (marketing).
Contact: privacy@fidemit.com
| Data | Retention |
|---|---|
| KYC / identity | 5 years after account closure |
| Transaction records | 5 years after completion |
| Activity logs | 2–5 years |
| Grievance records | 3 years after resolution |
Users may request deletion via account deletion, subject to legal retention holds.
Data subject rights are published here and in our Privacy Policy.
| Right | How to Exercise |
|---|---|
| Access | privacy@fidemit.com or account settings |
| Rectification | Update profile or contact support |
| Erasure | Delete account or privacy@fidemit.com |
| Restriction / objection | privacy@fidemit.com |
| Portability | privacy@fidemit.com |
| Complaint to regulator | NDPC (Nigeria Data Protection Commission) |
Response within 30 days of a verified request.
FidemIt maintains an active grievance redress process:
| Channel | Contact |
|---|---|
| Privacy grievances | privacy@fidemit.com |
| General support | support@fidemit.com |
| Compliance | compliance@fidemit.com |
| In-app | Contact page |
Acknowledgement within 5 business days. Resolution within 30 days.
We use cookies for authentication, functional preferences, and (where consented) analytics. See full cookie types in the repository policy document.
Strictly necessary: session/auth tokens, reCAPTCHA.
Functional: dashboard preferences, cached wallet display.
Manage cookies via the site consent card, footer Cookie settings, or browser settings.
| Name | [YOUR FULL LEGAL NAME] |
| Title | Founder & Sole Director (acting DPO) |
| privacy@fidemit.com |
Responsible for NDPA compliance, DPIAs, data subject requests, and NDPC liaison.
Security incidents: security@fidemit.com. Privacy breaches: privacy@fidemit.com.
Lifecycle: detect → triage → contain → eradicate → recover → post-incident review.
VAPT findings tracked with owner, severity, and remediation timeline. Latest OWASP VAPT: May 2026 (retest passed).
- OWASP VAPT — at least annually
- Access reviews — quarterly
- Server security monitoring — daily/weekly
- Policy compliance review — annually
Critical processors: Paystack/VFD (payments), Cloudinary (media), cloud hosting, Firebase (notifications).
Due diligence, data processing agreements, annual review, and access revocation on offboarding.
DPIAs required before new high-risk processing (new data categories, large-scale sensitive data, new processors, automated decisions).
Completed assessments: KYC verification, wallet/payments, public profile endpoints (May 2026).
Beyond baseline security awareness:
- Engineering — OWASP secure coding, secrets management (annual)
- Admin/support — KYC data handling, privacy rights (annual)
- Compliance/DPO — NDPA, breach notification, DPIA (annual)
Training records retained for 3 years.
Contact
- DPO / Privacy: privacy@fidemit.com
- Security: security@fidemit.com
- Support: support@fidemit.com