1. Purpose of This Data Policy
This Data Policy supplements our Privacy Policy and explains in greater detail how Orjar Technology Ventures ("Orjar") collects, processes, stores, shares, and protects data in connection with Orjar Finance.
It is designed to meet transparency obligations under the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), CBN guidelines on customer data protection, and industry best practices for Nigerian fintech platforms.
This policy applies to all users in Nigeria and to personal data processed through Budget demo, Live Mode, support channels, and marketing communications.
2. Data Protection Principles
Orjar processes personal data in accordance with the following principles:
- Lawfulness, fairness, and transparency — we process data on valid legal bases and explain our practices clearly.
- Purpose limitation — data is collected for specified, explicit, and legitimate purposes.
- Data minimisation — we collect only data reasonably necessary for each feature.
- Accuracy — we take steps to keep data correct and allow you to update it.
- Storage limitation — data is retained only as long as necessary.
- Integrity and confidentiality — appropriate security safeguards are applied.
- Accountability — we maintain records of processing and respond to regulatory enquiries.
3. Categories of Data We Process
The table below summarises major data categories, examples, and primary purposes:
- Identity data — name, DOB, gender, address, BVN, NIN, ID documents — KYC, AML, account opening.
- Contact data — email, phone — authentication, notifications, support.
- Financial planning data — budgets, expenses, jars, investments — Budget demo features.
- Transaction data — transfers, deposits, references, balances — Live Mode operations.
- Technical data — IP, device, logs — security, fraud prevention, diagnostics.
- Preference data — notification settings, appearance, Orjar AI data access toggle — personalisation.
- Biometric processing data — liveness session results — identity verification via licensed partners (Dojah / Youverify).
4. Budget demo Data Handling
Budget demo data is stored in our secure database and linked to your user account. This data is not transmitted to the Banking Partner unless you activate Live Mode or explicitly connect planning data to wallet features.
Budget demo figures are user-entered and may not reflect actual bank balances. We do not guarantee accuracy of planning data you provide.
You may export or delete planning data subject to retention limits described below.
5. Live Mode and Banking Data
When you activate Live Mode, identity and transaction data is shared with Anchor Microfinance Bank to open and operate your deposit account, process NIP transfers, receive inflows to your virtual account, and comply with CBN reporting.
Wallet balances displayed in Orjar are sourced from the Banking Partner and cached for performance. Authoritative balances are those maintained by the Banking Partner.
Webhook and API data from Anchor is processed to reconcile transactions, classify inflows and outflows, and display activity in your ledger.
6. KYC and Verification Data Flow
Before collecting KYC data, we present a consent screen explaining categories of data and partners involved.
BVN verification may be performed through Dojah, Youverify, or similar licensed providers as configured. Results are transmitted to Anchor for customer creation and tier assignment. Orjar does not store BVN in our database.
Government ID images and proof-of-address documents for Tier 2 and Tier 3 upgrades are stored securely and accessible only to authorised personnel and verification partners.
Where other identity fields are retained, we apply encryption and access controls appropriate to the sensitivity of the data.
7. Data Processors and Sub-Processors
We engage third-party processors who process personal data on our instructions. Key categories include authentication and database hosting, application hosting, transactional email, identity verification, and banking infrastructure.
Material processors are covered by written SLAs or data processing terms. A current list is available on request at privacy@orjar.app and maintained in our internal vendor register.
- Authentication and database hosting (e.g. Supabase).
- Application hosting and CDN (e.g. Netlify).
- Transactional email (e.g. Resend).
- Transactional SMS for Live Mode money alerts (e.g. Termii).
- Identity verification (Dojah — SLA; Youverify where configured).
- Banking infrastructure (Anchor Microfinance Bank — SLA).
8. Consent Management
Explicit consent is obtained before KYC data collection and for optional marketing communications.
Transaction SMS and email alerts for account security may be turned off in notification settings; money alerts are not delayed by quiet hours.
You may withdraw marketing consent via notification settings or by emailing privacy@orjar.app.
Withdrawal of KYC consent may require account closure or downgrade to Budget demo where identity data can no longer be lawfully retained or is required for open banking relationships.
9. Retention Schedule
- Active account profile and Budget demo data — retained while account is active.
- Closed account data — deleted or anonymised within ninety (90) days where no legal hold applies.
- KYC and AML records — minimum five (5) years from last transaction or account closure, or longer if required by CBN/NFIU.
- Transaction records (Live Mode) — minimum five (5) years per AML regulations.
- Support tickets — up to twenty-four (24) months unless related to disputes or regulatory matters.
- Server logs and security logs — typically ninety (90) to three hundred sixty-five (365) days.
- Admin audit logs (including profile view events) — retained for security and accountability, typically twelve (12) to thirty-six (36) months.
10. Technical and Organisational Security
- TLS encryption for data in transit.
- Encryption at rest for sensitive database fields where applicable.
- Role-based access control for staff and administrators.
- Multi-factor authentication options for users.
- Transaction PIN for sensitive wallet operations.
- Webhook signature verification for banking events.
- Regular dependency updates and environment segregation (development vs production).
- Incident response procedures aligned with NDPA breach notification requirements.
11. Internal Access and Admin Controls
Access to production user data is restricted to authorised personnel on a need-to-know basis. Administrative actions (such as KYC review notes) and admin views of user profiles are logged in audit trails.
We do not permit staff to browse user financial data without a legitimate support, compliance, or engineering reason.
12. Cross-Border Processing
Some infrastructure providers may store or process data outside Nigeria (for example, in the European Union or United States). Where this occurs, we implement NDPA-compliant transfer mechanisms and assess vendor security practices.
You may request information about the countries in which your data may be processed by contacting privacy@orjar.app.
13. Marketing and Analytics
We may send product updates, feature announcements, and educational content if you opt in. You can unsubscribe at any time.
We do not sell personal data to advertisers. Any analytics we use are aimed at improving the Service, not profiling you for third-party ad networks.
14. Exercising Your Data Rights
Submit data subject requests to privacy@orjar.app with the subject line "Data Subject Request" and include your registered email and a description of your request.
We may request additional verification (such as a code sent to your registered email) before fulfilling access or deletion requests.
We will respond within thirty (30) days, extendable once where permitted by the NDPA, and explain any refusal with legal grounds.
15. Children's Data
We do not knowingly process personal data of persons under eighteen (18). Accounts found to belong to minors will be closed and data deleted subject to legal exceptions.
16. Regulatory Cooperation
We cooperate with the Nigeria Data Protection Commission (NDPC), Central Bank of Nigeria (CBN), Nigeria Deposit Insurance Corporation (NDIC), and law enforcement agencies when legally required.
We may disclose personal data without your consent where mandated by court order, statutory authority, or to protect vital interests.
17. Updates to This Data Policy
We review this Data Policy periodically and update it when our processing activities or legal obligations change. Material updates will be notified through the app or email.
18. Contact
Data Protection Officer: Asere Damilola — privacy@orjar.app
Related documents: Privacy Policy (/privacy), Terms of Service (/terms)
Orjar Technology Ventures — Orjar Finance
