Karrabo is committed to protecting your privacy and handling your personal data in line with the Nigeria Data Protection Act, 2023 (NDPA), relevant NDPC directives, and applicable financial regulations. This Policy explains how Karrabo Financial Solutions Ltd collects, uses, stores, shares, and protects personal data and confidential information in connection with its financial technology products and services.
Karrabo is committed to protecting your privacy and handling your personal data in line with the Nigeria Data Protection Act, 2023 (NDPA), relevant NDPC directives, and applicable financial regulations.
This Data Protection and Privacy Policy (the “Policy”) explains how Karrabo Financial Solutions Ltd (“Karrabo”, “the Company”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal data and confidential information in connection with its financial technology products and services. Karrabo is duly incorporated under the laws of the Federal Republic of Nigeria and is authorised to operate its platform and enter into binding agreements relating to the services it provides. This Policy is intended to protect the legitimate interests of Karrabo and the individuals and organisations that interact with our platform.
This Policy applies to individuals and corporate organisations that use any part of the Karrabo Payment Ecosystem, including service partners, clients, merchants, customers, prospective customers, agents, and other users of our mobile application, website, APIs, and related services (collectively, the “Services”).
By accessing or using the Karrabo platform through registration, an agent location, the Karrabo website, mobile application, or any related interface, you confirm that you have read, understood, and agreed to this Policy. If you do not agree with it, you must stop using the platform and related services. We recommend that you keep a copy of this Policy for future reference.
We collect categories of personal information necessary to provide, secure and improve our Services and to comply with extant regulations, including but not limited to the CBN Anti-Money Laundering, Combating the Financing of Terrorism and Countering Proliferation Financing (AML/CFT/CPF) Policy.
We process personal data for the following legitimate purposes:
We will inform you where specific processing requires consent, and we will obtain consent in clear, granular ways (e.g., for marketing, precise geolocation, biometric use). You may withdraw your consent at any time (withdrawal does not affect the lawfulness of prior processing).
If your personal data is transferred outside Nigeria (for example to cloud providers or analytics partners), we will ensure adequate safeguards such as standard contractual clauses, binding corporate rules, or other NDPC-approved measures. We will inform you of cross-border transfer locations where required.
We implement administrative, technical and physical measures to protect data, including encryption in transit and at rest where practicable, role-based access controls, multi-factor authentication for staff, secure development lifecycle and periodic security testing (penetration tests, code reviews), logging and monitoring, vendor security assessments, and incident response plans. No system is impenetrable; we therefore combine technical safeguards with ongoing policy and training.
We retain personal data only for as long as necessary for the purposes described and to comply with legal/regulatory obligations. Suggested baseline retention periods:
When retention is no longer required, we will securely delete or anonymize personal data. Where laws require longer retention (court orders, regulatory investigations), we will retain data for the required period.
Under the NDPA you have rights including (but not limited to):
To exercise these rights, follow the in-app flow: Account → Privacy → Request data. We will respond within statutory timelines; where NDPA/NDPC defines specific timelines, we will adhere to them. You can also lodge complaints with the Nigeria Data Protection Commission (NDPC).
We maintain an Incident Response Plan. If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the NDPC within 72 hours of becoming aware (subject to NDPC guidance) and communicate to affected data subjects where required by law, describing the nature of the breach, likely consequences and measures taken.
Where automated processing (including profiling) is used to make decisions that produce legal or similarly significant effects (e.g., credit decisions, automated fraud declines), we will inform you and provide meaningful information about the logic, significance and envisaged consequences, and allow you to challenge or request human review where required by law.
Our Services are not directed at people under 18. We do not knowingly collect personal data of children. If we learn that we have collected personal data of a minor in a way that violates law, we will take steps to delete it.
The Karrabo Payment Ecosystem may link to third-party websites or services. We are not responsible for the privacy practices of third parties — please review their policies.
We may update this policy to reflect changes in law, products, or processing practices. We will post an updated version in the app and specify the effective date. Where changes are material, we will notify users and obtain consent if required.
Reach out and we’ll help you understand how it applies to you.
Contact us