1. Purpose of This Data Policy
This Data Policy supplements our Privacy Policy and explains in greater detail how Orjar Technology Ventures ("Orjar") collects, processes, stores, shares, and protects data in connection with Orjar Finance.
It is designed to meet transparency obligations under the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), CBN guidelines on customer data protection, and industry best practices for Nigerian fintech platforms.
This policy applies to all users in Nigeria and to personal data processed through Plan Mode, Live Mode, support channels, and marketing communications.
2. Data Protection Principles
Orjar processes personal data in accordance with the following principles:
- Lawfulness, fairness, and transparency — we process data on valid legal bases and explain our practices clearly.
- Purpose limitation — data is collected for specified, explicit, and legitimate purposes.
- Data minimisation — we collect only data reasonably necessary for each feature.
- Accuracy — we take steps to keep data correct and allow you to update it.
- Storage limitation — data is retained only as long as necessary.
- Integrity and confidentiality — appropriate security safeguards are applied.
- Accountability — we maintain records of processing and respond to regulatory enquiries.
3. Categories of Data We Process
The table below summarises major data categories, examples, and primary purposes:
- Identity data — name, DOB, gender, address, BVN, NIN, ID documents — KYC, AML, account opening.
- Contact data — email, phone — authentication, notifications, support.
- Financial planning data — budgets, expenses, jars, investments — Plan Mode features.
- Transaction data — transfers, deposits, references, balances — Live Mode operations.
- Technical data — IP, device, logs — security, fraud prevention, diagnostics.
- Preference data — notification settings, appearance, Ade data access toggle — personalisation.
- Biometric processing data — liveness session results — identity verification via Youverify.
4. Plan Mode Data Handling
Plan Mode data is stored in our secure database and linked to your user account. This data is not transmitted to the Banking Partner unless you activate Live Mode or explicitly connect planning data to wallet features.
Plan Mode figures are user-entered and may not reflect actual bank balances. We do not guarantee accuracy of planning data you provide.
You may export or delete planning data subject to retention limits described below.
5. Live Mode and Banking Data
When you activate Live Mode, identity and transaction data is shared with Anchor Microfinance Bank to open and operate your deposit account, process NIP transfers, receive inflows to your virtual account, and comply with CBN reporting.
Wallet balances displayed in Orjar are sourced from the Banking Partner and cached for performance. Authoritative balances are those maintained by the Banking Partner.
Webhook and API data from Anchor is processed to reconcile transactions, classify inflows and outflows, and display activity in your ledger.
6. KYC and Verification Data Flow
Before collecting KYC data, we present a consent screen explaining categories of data and partners involved.
BVN verification may be performed through Youverify or similar licensed providers. Results are transmitted to Anchor for customer creation and tier assignment.
Government ID images and proof-of-address documents for Tier 2 and Tier 3 upgrades are stored securely and accessible only to authorised personnel and verification partners.
Encrypted BVN and NIN fields, where stored, use AES-256-GCM or equivalent encryption with keys managed under strict access controls.
7. Data Processors and Sub-Processors
We engage third-party processors who process personal data on our instructions. Key categories include authentication and database hosting, application hosting, transactional email, identity verification, and banking infrastructure.
Processors are bound by written agreements requiring confidentiality, security measures, and processing only on documented instructions. A current list of material processors is available on request at privacy@orjar.app.
- Authentication and database hosting (e.g. Supabase).
- Application hosting and CDN (e.g. Netlify).
- Transactional email (e.g. Resend).
- Identity verification (Youverify).
- Banking infrastructure (Anchor Microfinance Bank).
8. Consent Management
Explicit consent is obtained before KYC data collection and for optional marketing communications.
You may withdraw marketing consent via notification settings or by emailing privacy@orjar.app.
Withdrawal of KYC consent may require account closure or downgrade to Plan Mode where identity data can no longer be lawfully retained or is required for open banking relationships.
9. Retention Schedule
- Active account profile and Plan Mode data — retained while account is active.
- Closed account data — deleted or anonymised within ninety (90) days where no legal hold applies.
- KYC and AML records — minimum five (5) years from last transaction or account closure, or longer if required by CBN/NFIU.
- Transaction records (Live Mode) — minimum five (5) years per AML regulations.
- Support tickets — up to twenty-four (24) months unless related to disputes or regulatory matters.
- Server logs and security logs — typically ninety (90) to three hundred sixty-five (365) days.
10. Technical and Organisational Security
- TLS encryption for data in transit.
- Encryption at rest for sensitive database fields.
- Role-based access control for staff and administrators.
- Multi-factor authentication options for users.
- Transaction PIN for sensitive wallet operations.
- Webhook signature verification for banking events.
- Regular dependency updates and environment segregation (development vs production).
- Incident response procedures aligned with NDPA breach notification requirements.
11. Internal Access and Admin Controls
Access to production user data is restricted to authorised personnel on a need-to-know basis. Administrative actions (such as KYC review notes) are logged in audit trails.
We do not permit staff to browse user financial data without a legitimate support, compliance, or engineering reason.
12. Cross-Border Processing
Some infrastructure providers may store or process data outside Nigeria (for example, in the European Union or United States). Where this occurs, we implement NDPA-compliant transfer mechanisms and assess vendor security practices.
You may request information about the countries in which your data may be processed by contacting privacy@orjar.app.
13. Marketing and Analytics
We may send product updates, feature announcements, and educational content if you opt in. You can unsubscribe at any time.
We do not sell personal data to advertisers. Any analytics we use are aimed at improving the Service, not profiling you for third-party ad networks.
14. Exercising Your Data Rights
Submit data subject requests to privacy@orjar.app with the subject line "Data Subject Request" and include your registered email and a description of your request.
We may request additional verification (such as a code sent to your registered email) before fulfilling access or deletion requests.
We will respond within thirty (30) days, extendable once where permitted by the NDPA, and explain any refusal with legal grounds.
15. Children's Data
We do not knowingly process personal data of persons under eighteen (18). Accounts found to belong to minors will be closed and data deleted subject to legal exceptions.
16. Regulatory Cooperation
We cooperate with the Nigeria Data Protection Commission (NDPC), Central Bank of Nigeria (CBN), Nigeria Deposit Insurance Corporation (NDIC), and law enforcement agencies when legally required.
We may disclose personal data without your consent where mandated by court order, statutory authority, or to protect vital interests.
17. Updates to This Data Policy
We review this Data Policy periodically and update it when our processing activities or legal obligations change. Material updates will be notified through the app or email.
18. Contact
Data protection enquiries: privacy@orjar.app
Related documents: Privacy Policy (/privacy), Terms of Service (/terms)
Orjar Technology Ventures — Orjar Finance