01What the NDPR is
The Nigeria Data Protection Regulation, now reinforced by the Data Protection Act 2023, sets the rules for handling the personal data of people in Nigeria, and it is overseen by the Nigeria Data Protection Commission (NDPC).
It gives you clear rights over your data and places clear duties on organisations like us. We treat those duties as a floor, not a ceiling.
02Our lawful basis
We only process your personal data when we have a lawful reason. For Qoyla, that is almost always one of these:
- Performance of a contract, the core service you signed up for, such as calculating Safe-to-Spend.
- Consent, for anything optional, freely given and just as easily withdrawn.
- Legal obligation, where financial or AML rules require us to keep certain records.
- Legitimate interest, narrowly, for security and fraud prevention, balanced against your rights.
03Principles we follow
The NDPR's core principles map directly onto how we work.
| Lawful & fair | Every use of data has a clear, lawful purpose we can explain. |
|---|---|
| Purpose limitation | We use data for the reason we collected it, not for unrelated ends. |
| Data minimisation | We collect only what we genuinely need to be useful. |
| Accuracy | You can correct your data at any time, and we keep it current. |
| Storage limitation | We keep data only as long as needed, then delete or de-identify it. |
| Security | Encryption, access control and monitoring protect it throughout. |
04Your rights under the NDPR
As a data subject, you have the right to be informed, to access your data, to correct it, to have it deleted, to restrict or object to processing, and to data portability. You also have the right not to be subject to solely automated decisions with significant effect, which is exactly why Qoyla always asks you to approve.
Exercise any of these through Your data rights. Requests are free and answered within 30 days.
05Our DPO & audits
We have appointed a Data Protection Officer responsible for our compliance, and we maintain records of processing activities. In line with NDPR expectations, we engage a licensed Data Protection Compliance Organisation to support our annual data-protection audit and filing with the NDPC.
06Cross-border transfers
Where data leaves Nigeria, we rely on a lawful transfer mechanism and on data residency for Nigerian customer data where required. Our subprocessors that handle Nigerian data are bound by terms consistent with the NDPR, see the Subprocessors list.
07Breach handling
If a breach is likely to affect your rights, we notify the NDPC and affected users promptly, in line with regulatory timelines, with what happened and what we are doing about it. Our process is described in the DPA.
08Contact & complaints
Reach our Data Protection Officer at any time. If you are not satisfied with our response, you have the right to lodge a complaint with the NDPC.
dpo@qoyla.ai
Data Protection Officer, Qoyla, Inc. · You may also contact the Nigeria Data Protection Commission directly.