1. Who we are
Fintegrity Technologies Limited (“Fintegrity”, “we”, “us”) is a Nigerian company (RC No. 9642721) with its registered address at 13B, Luis Ubebe, Coker Estate, Shasha, Akowonjo, Lagos State, Nigeria. We provide a business-to-business compliance-orchestration platform offering compliance decisioning, KYC orchestration, screening orchestration, transaction monitoring, case management and audit/evidence services to financial institutions and other regulated businesses (our “Clients”).
This Privacy Policy explains how we handle personal data under the Nigeria Data Protection Act 2023 (“NDPA”) and the General Application and Implementation Directive 2025 (“GAID”) issued by the Nigeria Data Protection Commission (“NDPC”). It applies to our website, our marketing, our corporate operations and, to the extent described in Section 2, our platform.
We have designated a Data Protection Officer (“DPO”), who can be contacted at privacy@getfintegrity.com or by post at the registered address above, marked for the attention of the Data Protection Officer. Fintegrity is registered with the NDPC as a data controller/processor of major importance. NDPC registration number: registration in progress.
2. Our two roles: controller and processor
Understanding our role determines who is responsible to you and where to direct your requests:
2.1 Where we act as a processor.When a Client uses our platform to verify identities, screen names, monitor transactions or manage compliance cases, the personal data involved (“Platform Data”) belongs to the Client's relationship with its own customers. The Client is the data controller: it decides why and how that data is processed, and its own privacy notice governs. Fintegrity acts strictly as a data processor on the Client's documented instructions, under a data processing agreement. If you are a customer of one of our Clients and contact us about your data, we will refer your request to the relevant Client within five (5) business days, tell you we have done so, and assist the Client in responding. We do not use Platform Data for our own purposes, except in aggregated, de-identified form that cannot reasonably identify anyone, and as required by law.
2.2 Where we act as a controller. We are the data controller for personal data we collect for our own purposes: visitors to our website; recipients of our marketing; business contacts at Clients, prospects, partners and vendors; job applicants; and our personnel. The remainder of this Policy (Sections 3 to 12) applies to these categories.
3. Personal data we collect as controller
Depending on your interaction with us, we collect: identity and contact data (name, employer, role, email, phone); business correspondence and meeting records; contract and billing details for Client and vendor contacts; website and technical data (IP address, device and browser information, pages visited, cookie identifiers — see our Cookie Policy); marketing preferences and consent records; recruitment data (CVs, qualifications, references, interview notes); and personnel records for our staff. We collect this data directly from you, from your organisation, from publicly available professional sources, and through our website.
We do not seek to collect sensitive personal data (as defined in the NDPA — such as health, biometric or genetic data, religious or political beliefs, or ethnic origin) in these contexts. Financial data is not a statutory category of sensitive data, but where we handle it we apply equivalent safeguards.
4. Purposes and lawful bases
We process personal data as controller for the following purposes, on the following NDPA lawful bases:
| Purpose | Data categories | Lawful basis (NDPA) |
|---|---|---|
| Providing, administering and billing our services to Client organisations | Business contact, contract and billing data | Contract; legitimate interests |
| Responding to enquiries and managing business relationships | Identity, contact, correspondence | Legitimate interests |
| Operating, securing and improving our website and platform (including fraud and abuse prevention) | Technical and usage data | Legitimate interests; legal obligation (security duties under the NDPA) |
| Direct marketing and event communications | Contact and preference data | Consent; legitimate interests for existing business contacts, with opt-out in every message |
| Product analytics and improvement | Aggregated, de-identified usage data | Legitimate interests (details of our assessment available on request) |
| Compliance with law, regulatory engagement, and establishing or defending legal claims | As relevant | Legal obligation; legitimate interests |
| Recruitment | Recruitment data | Consent; steps prior to a contract; legitimate interests |
| Employment administration | Personnel data | Contract; legal obligation |
5. Automated decision-making and profiling
Our platform performs automated screening, matching and risk-scoring. In these operations we act as a processor executing decisioning logic configured and instructed by the Client, which remains responsible as controller for the lawful basis, for the consequences of decisions, and for providing routes to obtain human review. Where a screening or monitoring outcome affects you, you may seek human intervention, express your point of view and contest the decision through the relevant Client; if you contact us, we will route your request to that Client as described in Section 2.1. Acting as a controller (website, marketing, recruitment, HR), we do not make decisions based solely on automated processing that produce legal or similarly significant effects for you.
6. Who we share personal data with
We share personal data, on a need-to-know basis and under appropriate safeguards, with: (a) our service providers and sub-processors — cloud hosting and infrastructure providers, communications, analytics, customer-support and productivity tools (a current list of the sub-processors used for Platform Data is available on request and provided to Clients under our data processing agreements); (b) professional advisers (legal, accounting, audit, insurance); (c) the NDPC, other regulators, law enforcement and courts, where required by law or lawful request; and (d) a prospective or actual acquirer or investor in connection with a corporate transaction, under confidentiality obligations. We do not sell personal data, and we do not permit advertising networks to build profiles from Platform Data.
7. International transfers
Some of our service providers store or process data outside Nigeria. Where personal data is transferred outside Nigeria, we do so only in compliance with sections 41 to 43 of the NDPA and the GAID: to jurisdictions covered by an adequacy decision of the NDPC, or under appropriate safeguards such as approved contractual instruments, or on another lawful basis recognised by the NDPA. Details of current storage locations and safeguards are available from the DPO on request.
8. Security
We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, role-based access controls with multi-factor authentication for administrative access, logical segregation of Client environments, logging and monitoring, secure development practices, vulnerability management and penetration testing, staff confidentiality undertakings and training, and documented incident-response procedures.
If a personal-data breach occurs: where we are the controller, we will notify the NDPC within seventy-two (72) hours of becoming aware where required, and affected individuals without undue delay where the breach is likely to result in a high risk to them; where we are a processor, we will notify the affected Client without undue delay (and within the timeframe in our data processing agreement) so the Client can meet its own obligations.
9. How long we keep personal data
We retain personal data only as long as necessary for the purposes described, and then delete, anonymise or securely destroy it, in accordance with our Data Retention Policy (available on request or on our website). Platform Data is retained and deleted according to each Client's instructions under the applicable data processing agreement.
10. Your rights
Under the NDPA you have the right to: access your personal data and information about our processing; correct inaccurate or incomplete data; request deletion; restrict or object to processing (including an absolute right to object to direct marketing); data portability (for data you provided that we process by automated means on the basis of consent or contract); withdraw consent at any time, without affecting prior processing; not be subject to solely automated decisions with legal or similarly significant effects, and to obtain human review as described in Section 5; and lodge a complaint with the NDPC.
To exercise any right, contact the DPO at privacy@getfintegrity.com or use our Data Subject Access Request (DSAR) Form. We will acknowledge your request within five (5) business days with a reference number, verify your identity, and respond without undue delay and in any event within thirty (30) days; for complex or multiple requests we may extend by up to a further thirty (30) days, and we will tell you within the first period, with reasons. Requests are free of charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse, giving reasons and informing you of your right to complain to the NDPC. If your request concerns Platform Data, Section 2.1 applies and we will refer it to the relevant Client within five (5) business days.
If you are dissatisfied with our response, you may ask the DPO to review the decision, and you may complain at any time to the Nigeria Data Protection Commission (ndpc.gov.ng).
11. Children
Our website and services are directed at businesses and are not intended for children under 18. We do not knowingly collect children's data as a controller; if we learn that we have, we will delete it. Where Platform Data instructed by a Client relates to a child or other vulnerable person, the Client is responsible as controller for the required lawful basis and consents, and we apply the safeguards required of processors under the NDPA and GAID.
12. Changes and contact
We review this Policy at least annually and will post any updated version on our website with a new effective date; material changes will be notified prominently. Questions, requests and complaints may be directed to the DPO at privacy@getfintegrity.com or to the registered address above.