KARRABO
0%
Karrabo

Data Privacy Policy

Karrabo is committed to protecting your privacy and handling your personal data in line with the Nigeria Data Protection Act, 2023 (NDPA), relevant NDPC directives, and applicable financial regulations. This Policy explains how Karrabo Financial Solutions Ltd collects, uses, stores, shares, and protects personal data and confidential information in connection with its financial technology products and services.

Effective 19 June 2026Karrabo Financial Solutions Ltd
On this page
1

Scope

Karrabo is committed to protecting your privacy and handling your personal data in line with the Nigeria Data Protection Act, 2023 (NDPA), relevant NDPC directives, and applicable financial regulations.

About this Policy

This Data Protection and Privacy Policy (the “Policy”) explains how Karrabo Financial Solutions Ltd (“Karrabo”, “the Company”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal data and confidential information in connection with its financial technology products and services. Karrabo is duly incorporated under the laws of the Federal Republic of Nigeria and is authorised to operate its platform and enter into binding agreements relating to the services it provides. This Policy is intended to protect the legitimate interests of Karrabo and the individuals and organisations that interact with our platform.

Who this Policy Applies To

This Policy applies to individuals and corporate organisations that use any part of the Karrabo Payment Ecosystem, including service partners, clients, merchants, customers, prospective customers, agents, and other users of our mobile application, website, APIs, and related services (collectively, the “Services”).

Acceptance of this Policy

By accessing or using the Karrabo platform through registration, an agent location, the Karrabo website, mobile application, or any related interface, you confirm that you have read, understood, and agreed to this Policy. If you do not agree with it, you must stop using the platform and related services. We recommend that you keep a copy of this Policy for future reference.

2

Definitions

Personal Data
Any information relating to an identified or identifiable natural person.
Special / Sensitive Personal Data
Data with higher risks (e.g., biometrics, health data, identity numbers) processed only where necessary and with enhanced protections.
Processing
Any operation performed on personal data.
NDPR
Nigeria Data Protection Regulation.
Service Partner
Any organization or individual that provides services within the Karrabo payment ecosystem.
Clients
Organizations that use our platform to achieve their business objectives, such as merchant acquirers, microfinance banks, super-agents, and regulatory authorities including the CBN and NFIU.
Merchants
Business organizations acquired or co-acquired by Karrabo for payment collection and disbursement services.
Agents
Business organizations that provide agent banking services to the public under Karrabo’s super-agent umbrella.
3

Categories of Personal Data We Collect

We collect categories of personal information necessary to provide, secure and improve our Services and to comply with extant regulations, including but not limited to the CBN Anti-Money Laundering, Combating the Financing of Terrorism and Countering Proliferation Financing (AML/CFT/CPF) Policy.

Identity & KYC
Full name, date of birth, gender, nationality, photograph, signature, national ID (NIN), BVN, passport, driver’s license, taxpayer ID, occupation, employer details.
Contact
Phone numbers, email addresses, postal addresses.
Account & Transaction Data
Source and destination bank account numbers, account balances, transaction history, payment references, merchant details, card information (only tokenized/stored if required and in compliance with PCI-DSS where applicable).
Device & Technical
Device identifiers, OS, app version, IP address, mobile network, push token, crash logs.
Location
Approximate or precise location data relating to where a transaction takes place, where permitted by law.
Biometrics & Security Data
Fingerprints or facial templates used for authentication where you opt in.
Communications & Support
Messages, support logs, and call recordings where calls are recorded.
Credit & Risk
Credit reference data, fraud scores, and sanctions or politically exposed person screening results.
Profile, Usage & Marketing
Preferences, marketing consents, cookies, and analytics data.
4

How We Collect Personal Data

  • Directly from you at onboarding, account opening, support interactions, KYC uploads.
  • From devices when you use our platforms (with permissions).
  • From third parties: credit bureaus, identity verification providers (e.g., BVN/NIN checks), payment rails, partner banks, fraud databases, governmental authorities, public sources.
  • From analytics and advertising providers.
5

How We Use Personal Data

We process personal data for the following legitimate purposes:

Provision of financial services / contract performance
To open and maintain accounts, process payments, transfers, deposits, withdrawals, loans, overdrafts, rewards. (Contract)
Legal & regulatory compliance
To meet AML/CFT/CPF, tax, court orders, CBN and other regulatory obligations. (Legal obligation)
Fraud prevention, security & risk management
Transaction monitoring, suspicious activity reporting, sanctions screening. (Legitimate interest / legal obligation)
Identity verification & KYC
Verifying identity with BVN/NIN and other ID services. (Legal obligation / Contract)
Customer support & dispute resolution
Responding to enquiries, disputes and chargebacks. (Contract / legitimate interest)
Marketing & product improvement
With your consent for direct marketing; otherwise based on legitimate interest after balancing where permitted. (Consent / Legitimate interest)
Analytics & performance
Improve services, debugging, product analytics. (Legitimate interest)
Statutory reporting & audit
Respond to audits, tax, AML reporting. (Legal obligation)

We will inform you where specific processing requires consent, and we will obtain consent in clear, granular ways (e.g., for marketing, precise geolocation, biometric use). You may withdraw your consent at any time (withdrawal does not affect the lawfulness of prior processing).

6

Who We Share Data With

We may share personal data with:

Group companies & affiliates
For processing and services.
Service providers / processors
Including payment processors, cloud providers, identity verification services, fraud monitoring providers, KYC/OCR vendors, analytics providers, and SMS/email gateways. We require them to protect personal data and process it only on our instructions.
Banks, card issuers, switch/processors
Card networks and other CBN-regulated financial institutions, to process transactions.
Regulators, law enforcement & courts
Tax authorities and insurance companies, where required by law, court order or regulation (e.g., CBN, NIBSS, NDPC, NFIU, EFCC).
Credit bureaus and risk agencies
For credit decisions.
Merchants / counterparties
Where necessary for transaction fulfilment.

We do not sell personal data. Any cross-border transfers will be governed by appropriate safeguards (NDPA-compliant transfer mechanisms and contractual protection).

7

International Transfers

If your personal data is transferred outside Nigeria (for example to cloud providers or analytics partners), we will ensure adequate safeguards such as standard contractual clauses, binding corporate rules, or other NDPC-approved measures. We will inform you of cross-border transfer locations where required.

8

Security Measures

We implement administrative, technical and physical measures to protect data, including encryption in transit and at rest where practicable, role-based access controls, multi-factor authentication for staff, secure development lifecycle and periodic security testing (penetration tests, code reviews), logging and monitoring, vendor security assessments, and incident response plans. No system is impenetrable; we therefore combine technical safeguards with ongoing policy and training.

9

Data Retention

We retain personal data only for as long as necessary for the purposes described and to comply with legal/regulatory obligations. Suggested baseline retention periods:

Transaction records
Minimum 5 years from transaction date (to satisfy AML/CFT/CPF & regulatory retention).
KYC / identity records
Retained at least 5 years after account closure or relationship ends (unless longer retention is required by law).
Support logs, communications
Typically 2–7 years depending on dispute requirements.
Marketing & analytics data
Until withdrawal of consent or as necessary for product improvement/legitimate interests (subject to periodic review).
Backups / logs
As required for operational integrity and legal holds.

When retention is no longer required, we will securely delete or anonymize personal data. Where laws require longer retention (court orders, regulatory investigations), we will retain data for the required period.

10

Data Subject Rights

Under the NDPA you have rights including (but not limited to):

  • Right of access: request a copy of personal data we hold about you.
  • Right to rectification: correct inaccurate or incomplete data.
  • Right to erasure (right to be forgotten): request deletion where processing basis allows.
  • Right to restriction of processing: ask us to suspend processing while a dispute is resolved.
  • Right to object: object to processing including profiling and direct marketing.
  • Right to data portability: request your data in a structured, machine-readable format when processing is based on consent or contract.
  • Right to withdraw consent.

To exercise these rights, follow the in-app flow: Account → Privacy → Request data. We will respond within statutory timelines; where NDPA/NDPC defines specific timelines, we will adhere to them. You can also lodge complaints with the Nigeria Data Protection Commission (NDPC).

11

Breach Notification

We maintain an Incident Response Plan. If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the NDPC within 72 hours of becoming aware (subject to NDPC guidance) and communicate to affected data subjects where required by law, describing the nature of the breach, likely consequences and measures taken.

12

Automated Decision-Making & Profiling

Where automated processing (including profiling) is used to make decisions that produce legal or similarly significant effects (e.g., credit decisions, automated fraud declines), we will inform you and provide meaningful information about the logic, significance and envisaged consequences, and allow you to challenge or request human review where required by law.

13

Children

Our Services are not directed at people under 18. We do not knowingly collect personal data of children. If we learn that we have collected personal data of a minor in a way that violates law, we will take steps to delete it.

14

Cookies & Similar Technologies

We use cookies and similar technologies for authentication, security, app performance and analytics. You can manage cookie preferences in-app or via your device settings. For marketing cookies, we will seek consent where required.

16

Changes to This Privacy Policy

We may update this policy to reflect changes in law, products, or processing practices. We will post an updated version in the app and specify the effective date. Where changes are material, we will notify users and obtain consent if required.

17

Additional Financial-Sector Notices

Regulatory reporting & law enforcement requests
We may retain and share data with competent authorities in line with AML/CFT/CPF laws, court orders, tax obligations and regulatory reporting (e.g., CBN, NFIU, EFCC).
PCI-DSS & card data
If we process card data, we will follow PCI-DSS standards and avoid storing sensitive authentication data.
18

Complaints & Supervisory Authority

If you are unsatisfied with our handling of your personal data, please contact our DPO first at karlegcomp@karrabo.com. You may also lodge a complaint with the Nigeria Data Protection Commission (NDPC): ndpc.gov.ng

Questions about this policy?

Reach out and we’ll help you understand how it applies to you.

Contact us