1. Overview
Redivian Limited ("Redivian", "we", "our", or "us") is a financial technology company incorporated under the laws of the Federal Republic of Nigeria. We operate a suite of financial products including Minttapp (a bills of exchange marketplace), DashDosh (a digital gifting platform), CreditLens (a credit intelligence service), Insights (a business due diligence platform), and the Redivian Platform API.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you access or use any of our products, platforms, or services (collectively, the "Services"). It also describes your rights regarding your personal data under applicable Nigerian law.
By registering for or using any Redivian Service, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein.
This policy applies to all users of Redivian's services, including individuals, business owners, and developers accessing the Redivian Platform API. If you use our services on behalf of a business entity, you represent that you have authority to bind that entity to this policy.
2. Legal Basis for Processing
We process personal data in accordance with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), and guidelines issued by the Nigeria Data Protection Commission (NDPC). Our legal bases for processing your personal data include:
- Contractual necessity: Processing required to provide the Services you have requested, including account creation, agreement management, wallet operations, and identity verification.
- Legal obligation: Processing required to comply with applicable laws and regulations, including Central Bank of Nigeria (CBN) Know Your Customer (KYC) and Anti-Money Laundering (AML) requirements, and the Financial Reporting Council of Nigeria (FRC) standards.
- Legitimate interests: Processing necessary for fraud prevention, security monitoring, product improvement, and business analytics — where these interests do not override your fundamental rights.
- Consent: Processing for optional features, marketing communications, and data sharing with third-party partners — where we have obtained your explicit, informed consent.
You may withdraw consent at any time where consent is the legal basis for processing, without affecting the lawfulness of processing prior to withdrawal.
3. Data We Collect
3.1 Identity and Contact Data
When you create a Redivian account, we collect your full legal name, email address, phone number, date of birth, residential address, and government-issued identification details (such as BVN, NIN, international passport number, or driver's licence number) as required by CBN KYC/KYB guidelines.
3.2 Financial Data
To provide our financial services, we collect bank account details, transaction history within the Redivian ecosystem, agreement terms and repayment records on Minttapp, wallet funding and withdrawal records, and data used to compute your CreditLens profile including non-banking financial behaviour.
3.3 Business Verification Data (KYB)
For business accounts, we collect company registration details (CAC registration number, Memorandum and Articles of Association), tax identification number (TIN), details of directors and beneficial owners, and proof of business address.
3.4 Technical and Usage Data
We automatically collect device identifiers, IP address, browser type, operating system, pages visited, features used, timestamps of actions, and error logs when you interact with our Services. This data is used to maintain service quality, detect fraud, and improve the user experience.
3.5 Communications Data
We retain records of communications between you and Redivian, including support tickets, email correspondence, and in-app messages, for service improvement and dispute resolution purposes.
3.6 Data We Do Not Collect
We do not collect your passwords in plain text. We do not collect biometric data beyond what is required for identity verification through our approved KYC providers. We do not sell your personal data to advertisers.
4. How We Use Your Data
We use your personal data for the following purposes:
- Account creation and management: To register your account, verify your identity, and manage your profile across all Redivian products.
- Service delivery: To process financial agreements on Minttapp, execute wallet transactions, compute credit scores on CreditLens, facilitate digital gifts on DashDosh, and provide due diligence data through Insights.
- Regulatory compliance: To satisfy CBN KYC and AML obligations, file regulatory reports, respond to lawful requests from Nigerian law enforcement and regulatory agencies, and maintain mandatory audit trails.
- Fraud prevention and security: To detect, investigate, and prevent fraudulent transactions, identity theft, and unauthorised access to accounts.
- Credit profiling: To build and maintain your CreditLens profile based on your dealing history within the Redivian ecosystem, with your consent and subject to your right to opt out.
- Communications: To send you transaction notifications, security alerts, product updates, and — where you have opted in — promotional communications.
- Product improvement: To analyse usage patterns, conduct research, test new features, and improve the reliability, security, and functionality of our Services.
- Dispute resolution: To investigate and resolve disputes between users arising from Minttapp agreements or other transactions within our ecosystem.
5. Data Sharing and Disclosure
We do not sell your personal data. We share your data only in the circumstances described below:
5.1 Service Providers
We share data with carefully selected third-party service providers who process data on our behalf under strict data processing agreements. These include identity verification providers (such as QoreID and SmileID), payment processors (Paystack, Flutterwave, and Fincra), cloud infrastructure providers, and customer support platforms. All providers are contractually obligated to process data only for specified purposes and in accordance with applicable data protection law.
5.2 Regulatory and Legal Disclosure
We disclose personal data to the Central Bank of Nigeria, the Nigerian Financial Intelligence Unit (NFIU), the Economic and Financial Crimes Commission (EFCC), the Independent Corrupt Practices Commission (ICPC), and any other competent authority where required to do so by law, court order, or regulatory directive.
5.3 Consent-Based Sharing
Through CreditLens and Insights, you may choose to share your financial profile with third-party institutions or business partners. Such sharing occurs only with your explicit, informed consent and you may revoke consent at any time through your account settings.
5.4 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of Redivian's business, your personal data may be transferred as part of the transaction. We will notify you before your data becomes subject to a different privacy policy.
6. Data Retention
We retain your personal data for as long as necessary to provide our Services and fulfil the purposes described in this policy, subject to the following minimum retention periods required by Nigerian law:
- KYC and identity verification records: Minimum 5 years after account closure, in accordance with CBN AML/CFT regulations.
- Transaction records and financial agreement data: Minimum 6 years, in accordance with the Money Laundering (Prevention and Prohibition) Act 2022.
- Communications and support records: 3 years from the date of communication.
- Technical and usage logs: 12 months from collection, unless required for ongoing investigations.
After the applicable retention period, we securely delete or anonymise your personal data. Where anonymisation is used, the resulting data may be retained indefinitely for statistical and analytical purposes as it can no longer be linked to you.
7. Your Rights
Under the Nigeria Data Protection Act 2023, you have the following rights with respect to your personal data:
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may request correction of inaccurate or incomplete personal data.
- Right to erasure: You may request deletion of your personal data, subject to our legal retention obligations and the rights of counterparties in active Minttapp agreements.
- Right to data portability: You may request your personal data in a structured, machine-readable format for transfer to another provider.
- Right to object: You may object to processing based on legitimate interests, including direct marketing.
- Right to restrict processing: You may request that we limit the processing of your data in certain circumstances.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, contact us at privacy@redivian.com. We will respond within 30 days. If you are dissatisfied with our response, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpb.gov.ng.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include:
- Encryption of data in transit using TLS 1.2 and above
- Encryption of sensitive data at rest using AES-256
- Role-based access controls limiting employee access to personal data on a need-to-know basis
- Multi-factor authentication for all internal systems
- Regular security assessments and penetration testing
- Service-to-service authentication using RSA keypairs and short-lived JWT tokens
- Audit logging of all access to sensitive personal data
While we take security seriously, no method of transmission over the internet or electronic storage is completely secure. We encourage you to protect your account credentials, enable two-factor authentication, and notify us immediately at security@redivian.com if you suspect unauthorised access to your account.
10. Children's Privacy
Redivian's Services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a person under 18, please contact us immediately at privacy@redivian.com and we will take prompt steps to delete the data.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, regulatory requirements, or data processing practices. When we make material changes, we will notify you by email, in-app notification, or by posting a prominent notice on our website at least 14 days before the changes take effect. Continued use of our Services after the effective date constitutes acceptance of the updated policy.
The most current version of this policy will always be available at redivian.com/privacy.
Redivian Products
This policy applies to all products and services offered by Redivian Limited, including:
- Minttapp — Bills of exchange marketplace for structured lending and debt trading
- DashDosh — Digital gifting platform for individuals and businesses
- CreditLens — Non-banking credit scoring and financial reputation platform
- Insights — Business due diligence and financial intelligence
- Redivian Platform — Developer API for financial infrastructure
For full details on each product, visit redivian.com.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:
- Email: privacy@redivian.com
- Post: Data Protection Officer, Redivian Limited, Lagos, Nigeria
For complaints that we have not resolved to your satisfaction, you may contact the Nigeria Data Protection Commission (NDPC) through their official channels at ndpb.gov.ng.
Questions about this document?
Reach our compliance and legal team:
Redivian Limited · Lagos, Nigeria