Data Subject Rights Notice
The Nigeria Data Protection Act (NDPA) 2023 gives you important rights over your personal data. This notice explains those rights and how to exercise them.
Table of Contents
1. Your Rights Under the NDPA
The Nigeria Data Protection Act (NDPA) 2023 establishes your rights as a data subject in relation to the personal information held about you. As a user of NillarPay, operated by Nillar Technology Limited, you have the rights described in this notice.
These rights are not absolute — in some cases, they may be limited by our legal obligations (e.g., AML record-keeping requirements), the rights of third parties, or where processing is necessary for the performance of a contract with you.
We will always inform you if we are unable to fulfil a rights request and explain the reason why.
2. Right to Access
What This Right Means
You have the right to request a copy of the personal data we hold about you and to receive information about how we process it. This is known as a "Subject Access Request" (SAR).
What You Will Receive
- Confirmation that we process your personal data (or that we do not).
- A copy of the personal data we hold about you.
- Information about the purposes for which we process your data.
- Information about who we share your data with.
- The retention period for your data.
- Your other rights in relation to your data.
Limitations
We may redact information that relates to other individuals or information that is subject to legal professional privilege. Where we are required to maintain your data by law (e.g., AML records), we cannot delete it even following a SAR.
3. Right to Rectification
What This Right Means
You have the right to ask us to correct personal data about you that is inaccurate or incomplete. For example, if your name, address, or date of birth is recorded incorrectly.
How to Exercise This Right
- For basic profile information (name, email, address): You can update most details directly in the NillarPay app under Settings → Profile.
- For KYC-verified data: Changes to BVN-linked information require verification. Contact us at privacy@nillar.com with supporting documentation.
- For transaction data: We can add clarifying notes but cannot alter transaction records for regulatory compliance reasons.
4. Right to Deletion (Right to Be Forgotten)
What This Right Means
You have the right to ask us to delete your personal data in certain circumstances, including where:
- The data is no longer necessary for the purposes for which it was collected.
- You withdraw consent and there is no other legal basis for processing.
- You object to processing and there are no overriding legitimate grounds.
- The data has been unlawfully processed.
Limitations on Deletion
Where we cannot delete your data due to a legal obligation, we will explain this to you and, where possible, restrict processing of your data to the extent required by law only.
5. Right to Object
What This Right Means
You have the right to object to processing of your personal data in certain circumstances:
5.1 Objecting to Processing Based on Legitimate Interests
Where we process your data based on our legitimate interests (e.g., fraud prevention, platform security improvements), you can object. We must stop the processing unless we can demonstrate compelling legitimate grounds that override your interests.
5.2 Objecting to Direct Marketing
You have an absolute right to object to your data being used for direct marketing at any time. You can exercise this right by:
- Clicking 'Unsubscribe' in any marketing email we send.
- Adjusting notification preferences in the NillarPay app under Settings → Notifications.
- Contacting us at privacy@nillar.com.
5.3 Limitations
You cannot object to processing that is required by law (e.g., AML monitoring, regulatory reporting) or necessary for the performance of your contract with us (e.g., processing your transactions).
6. Right to Restrict Processing
What This Right Means
You have the right to request that we limit the processing of your personal data in certain circumstances, such as when:
- You contest the accuracy of the data — we restrict processing while we verify it.
- Processing is unlawful, but you prefer restriction over deletion.
- We no longer need the data, but you need it for a legal claim.
- You have objected to processing, and we are considering your objection.
When processing is restricted, we can continue to store your data but can only process it with your consent, for legal claims, to protect others' rights, or for important public interest reasons.
7. Right to Data Portability
What This Right Means
Where we process your data by automated means, based on your consent or a contract with you, you have the right to receive a copy of your personal data in a structured, commonly used, machine-readable format.
What We Can Provide
- Your account profile data in JSON or CSV format.
- Your transaction history in CSV or PDF format.
- Your KYC submission data (name, date of birth, address) in structured format.
How to Request
Email your portability request to privacy@nillar.com specifying the data you require and your preferred format. We will respond within 30 days.
8. Right to Withdraw Consent
Where we process your personal data based on your consent (for example, for marketing communications or optional analytics), you have the right to withdraw that consent at any time.
- Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
- Where consent withdrawal affects our ability to provide you with the Services, we will inform you in advance.
- To withdraw consent, contact us at privacy@nillar.com or use the opt-out options in the NillarPay app.
9. Right to Lodge a Complaint with the NDPC
If you are not satisfied with how we have handled your personal data or a data subject rights request, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC), the national data protection supervisory authority.
Nigeria Data Protection Commission (NDPC)
Web: ndpc.gov.ng
Email: info@ndpc.gov.ng
You should normally raise your concern with us first before approaching the NDPC.
10. How to Exercise Your Rights
To exercise any of your data subject rights, please submit a request through one of the following channels:
Data Protection Officer — Nillar Technology Limited
Email: privacy@nillar.com
Address: Kano, Nigeria, Lagos, Nigeria
Information Required with Your Request
- Your full name as registered on NillarPay.
- Your registered phone number or email address.
- The specific right you wish to exercise.
- A clear description of your request.
- Any supporting documents if applicable (e.g., for rectification requests).
We may need to verify your identity before processing your request to ensure the security of your personal data.
11. Response Timelines
| Right | Response Time |
|---|---|
| Right to Access (SAR) | 30 days from receipt of valid request |
| Right to Rectification | Within 10 working days |
| Right to Deletion | Within 30 days (or explanation if not possible) |
| Right to Object | Within 30 days |
| Right to Restrict | Within 10 working days |
| Right to Portability | Within 30 days |
| Right to Withdraw Consent | Within 5 working days |
Where a request is complex or involves a large volume of data, we may extend the response period by up to an additional 30 days. We will notify you within the first 30 days if an extension is required and the reason for it.