Compliant

NDPR compliance

Qoyla is built in Nigeria, for Nigeria among other markets, so the Nigeria Data Protection Regulation, and the Data Protection Act that builds on it, are not an afterthought. Here is how we meet them, in practice.

Updated 1 May 2026 NDPR 2019 · NDPA 2023 Regulator: NDPC

01What the NDPR is

The Nigeria Data Protection Regulation, now reinforced by the Data Protection Act 2023, sets the rules for handling the personal data of people in Nigeria, and it is overseen by the Nigeria Data Protection Commission (NDPC).

It gives you clear rights over your data and places clear duties on organisations like us. We treat those duties as a floor, not a ceiling.

02Our lawful basis

We only process your personal data when we have a lawful reason. For Qoyla, that is almost always one of these:

  • Performance of a contract, the core service you signed up for, such as calculating Safe-to-Spend.
  • Consent, for anything optional, freely given and just as easily withdrawn.
  • Legal obligation, where financial or AML rules require us to keep certain records.
  • Legitimate interest, narrowly, for security and fraud prevention, balanced against your rights.

03Principles we follow

The NDPR's core principles map directly onto how we work.

Lawful & fairEvery use of data has a clear, lawful purpose we can explain.
Purpose limitationWe use data for the reason we collected it, not for unrelated ends.
Data minimisationWe collect only what we genuinely need to be useful.
AccuracyYou can correct your data at any time, and we keep it current.
Storage limitationWe keep data only as long as needed, then delete or de-identify it.
SecurityEncryption, access control and monitoring protect it throughout.

04Your rights under the NDPR

As a data subject, you have the right to be informed, to access your data, to correct it, to have it deleted, to restrict or object to processing, and to data portability. You also have the right not to be subject to solely automated decisions with significant effect, which is exactly why Qoyla always asks you to approve.

Exercise any of these through Your data rights. Requests are free and answered within 30 days.

05Our DPO & audits

We have appointed a Data Protection Officer responsible for our compliance, and we maintain records of processing activities. In line with NDPR expectations, we engage a licensed Data Protection Compliance Organisation to support our annual data-protection audit and filing with the NDPC.

06Cross-border transfers

Where data leaves Nigeria, we rely on a lawful transfer mechanism and on data residency for Nigerian customer data where required. Our subprocessors that handle Nigerian data are bound by terms consistent with the NDPR, see the Subprocessors list.

07Breach handling

If a breach is likely to affect your rights, we notify the NDPC and affected users promptly, in line with regulatory timelines, with what happened and what we are doing about it. Our process is described in the DPA.

08Contact & complaints

Reach our Data Protection Officer at any time. If you are not satisfied with our response, you have the right to lodge a complaint with the NDPC.

dpo@qoyla.ai
Data Protection Officer, Qoyla, Inc. · You may also contact the Nigeria Data Protection Commission directly.