Data Protection
The principles that guide how Finzla handles personal information.
Regulatory basis: Nigeria Data Protection Act 2023; NDP Act – GAID 2025; CBN payment data localisation requirements (Circular PSS/DIR/PUB/CIR/001/004, June 2026)
Finzla is a financial-wellbeing platform, and much of what we handle — identity documents, bank transactions, spending patterns — is sensitive by nature. We apply careful, proportionate safeguards to all of it, and we design new features with data protection considered from the outset, not added afterward.
1. Introduction
This page sets out the principles Finzla follows when handling personal information, in line with the Nigeria Data Protection Act 2023 (NDP Act) and its General Application and Implementation Directive 2025 (GAID 2025). For the full details of what we collect, why, and your rights, see our Privacy Policy; this page is a shorter summary of the standards behind it.
2. Our data protection principles
In line with the NDP Act, Finzla applies the following principles to personal information:
- Lawfulness, fairness and transparency – we process personal information on an identified lawful basis, and explain clearly what we do with it.
- Purpose limitation – we collect information for specific, clearly stated purposes, and don't use it for something incompatible with those purposes without telling you.
- Data minimisation – we collect only what's needed for the purpose at hand.
- Accuracy – we take reasonable steps to keep information accurate and current, and to correct it when asked.
- Storage limitation – we keep information only as long as necessary, set out in our internal Data Retention Schedule, which accounts for legal and regulatory requirements such as AML/KYC record-keeping.
- Integrity and confidentiality – we protect information with appropriate technical and organisational security measures.
- Accountability – we're able to demonstrate how we meet these principles, and a designated privacy lead oversees our compliance.
3. Special-category and sensitive information
Some of what Finzla handles — identity verification data, biometric facial-verification results, and financial transaction data — warrants extra care under Nigerian data protection law. We apply enhanced safeguards to this information, including restricted access, and we don't hold it for longer than the applicable legal basis allows.
4. Security measures
We use technical and organisational safeguards appropriate to the sensitivity of the information involved, which may include access controls built on least privilege, encryption in transit and, where appropriate, at rest, monitoring for suspicious activity, and documented internal data-handling procedures. No system is completely risk-free, and we continually review these measures as the platform grows.
5. Data residency and cross-border data handling
Information that identifies you in connection with identity verification, bank connections and transactions is hosted using cloud infrastructure located in Nigeria, including applicable backup and disaster-recovery copies, and is not transferred outside Nigeria as part of our core hosting and processing of that information. This reflects Finzla's data-protection approach and applicable Nigerian data-localisation requirements.
Other limited personal information may be processed or hosted outside Nigeria where this is necessary to provide particular services. For example, we may use cloud-based communication services hosted in South Africa to send account and service-related emails. Only the minimum information necessary for those communications is transferred, and sensitive identity-verification, bank-account and detailed transaction information is not included in such communications unless separately assessed and lawfully permitted. These transfers are subject to an applicable cross-border transfer mechanism under the Nigeria Data Protection Act and GAID 2025, together with appropriate contractual, technical and organisational safeguards.
Where information is used to improve our AI/ML models, only anonymised, non-identifiable data may be processed outside Nigeria for that purpose, and only where this is technically achievable; where it is not, that data remains in Nigeria.
Some independent third-party service providers, such as identity-verification specialists, may process limited information outside Nigeria as part of providing their services. Where this occurs, we assess the transfer and apply the appropriate cross-border transfer mechanism and contractual, technical and organisational safeguards required under applicable data-protection law.
6. Employer-sponsored access
Where you access Finzla through an employer-sponsored programme, your individual financial information — balances, transactions, spending habits — is never shared with your employer. Employers may only see that you've joined and anonymised, aggregate activity across the whole programme.
7. Your rights and how to raise a concern
You can contact us to ask questions about your data, request access or correction, or raise a privacy concern; see our Privacy Policy for the full list of rights available to you and how to exercise them. If you're not satisfied with our response, you also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
8. Contact
For data protection enquiries, contact privacy@finzla.com.
Need help? Contact Finzla through the support details on our website.