Legal

Privacy Policy

O3 Capital Finance Company Limited Effective: 2025 NDPA & GDPR Compliant
1

Introduction

O3 Capital Finance Company Limited ("O3 Capital", "we", "us", or "our") is committed to protecting the privacy and personal data of its clients, users, employees, and other stakeholders.

This Privacy Policy explains how we collect, use, disclose, store, and protect your personal data when you use our website, mobile applications, and services.

This Policy is issued in compliance with the Nigeria Data Protection Act (NDPA) 2023 and the General Data Protection Regulation (GDPR).

2

Scope of This Policy

This Policy applies to:

  • All users of our website and mobile applications
  • Customers and prospective customers
  • Employees, contractors, and vendors
  • Any individual whose personal data is processed by O3 Capital
3

Definitions

  • Personal Data: Any information relating to an identified or identifiable individual (e.g., name, email, phone number, financial data)
  • Data Subject: The individual whose personal data is processed
  • Processing: Any operation performed on personal data (collection, storage, use, disclosure, etc.) by the Data Processor
  • Data Controller: O3 Capital, which determines how and why personal data is processed
  • Data Processor: Entity processing the personal data, following the Data Controller's instructions
4

Information We Collect

4.1 Information You Provide

  • Full name, date of birth, gender
  • Contact details (email, phone number, address)
  • Identification details (e.g., BVN, NIN, passport, driver's licence)
  • Financial information (bank details, transaction history)
  • Employment and income information

4.2 Automatically Collected Data

  • IP address, device ID, browser type
  • Usage data (pages visited, session duration)
  • Location data (where permitted)

4.3 Third-Party Data

  • Data from credit bureaus, regulators, or financial partners
  • KYC/AML verification data
5

Legal Basis for Processing

We process personal data based on:

  • Consent of the Data Subject
  • Contractual necessity (e.g., providing financial services)
  • Legal obligations (e.g., anti-money laundering compliance)
  • Legitimate interests, provided such interests do not override your rights

These bases are consistent with NDPA and GDPR lawful processing requirements.

6

Purpose of Data Processing

We process your personal data for the following purposes:

  • Account creation and management
  • Provision of financial and investment services
  • Identity verification (KYC/AML compliance)
  • Processing transactions
  • Customer support and communication
  • Risk management and fraud prevention
  • Regulatory reporting and compliance
  • Marketing and promotional communications (with consent)
  • Improving our products, services, and user experience
7

Data Sharing and Disclosure

We may share your personal data with:

  • Regulatory authorities (e.g., CBN, NDPC)
  • Financial institutions and payment processors
  • Credit bureaus and identity verification providers
  • Service providers and vendors
  • Legal advisors and auditors

We ensure that all third parties comply with applicable data protection laws. We will not sell your personal data.

8

Cross-Border Data Transfer

Where personal data is transferred outside Nigeria, we shall ensure:

  • Adequate data protection safeguards
  • Use of Standard Contractual Clauses (SCCs)
  • Transfers to jurisdictions with adequate protection levels
9

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this Policy and to comply with legal and regulatory requirements. After this period, data is securely deleted or anonymised.

10

Data Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • Encryption and secure storage
  • Access controls and authentication
  • Firewalls and intrusion detection systems
  • Staff training and confidentiality obligations
11

Your Rights

You have the following rights under NDPA and GDPR:

Right to Access

Access your personal data we hold

Right to Rectification

Correct inaccurate data

Right to Erasure

"Right to be forgotten"

Right to Restrict

Restrict how we process your data

Right to Portability

Receive your data in a portable format

Right to Object

Object to certain processing activities

Withdraw Consent

Withdraw consent at any time

Right to Complain

Lodge a complaint with a supervisory authority

12

Cookies and Tracking Technologies

We use cookies and similar technologies to enhance user experience, analyse website traffic, and personalise content. You can manage cookie preferences through your browser settings.

For full details, please see our Cookies Policy.

13

Children's Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors without parental or guardian consent.

14

Data Breach Notification

In the event of a data breach, we will:

  • Notify affected individuals where required
  • Report to relevant regulatory authorities
  • Take immediate remedial actions
15

Data Protection Officer (DPO)

We have appointed a Data Protection Officer responsible for ensuring compliance.

Data Protection Officer

Email: dpo@o3cards.com

Address: 7th Floor, Churchgate Tower 1, Churchgate Street, Victoria Island, Lagos, Nigeria

16

Third-Party Links

Our platforms may contain links to third-party websites. We are not responsible for their privacy practices and encourage you to review their policies independently.

17

Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be published on our website and app with the revised effective date.

18

Contact Us

If you have any questions or concerns about this Privacy Policy or your personal data, please contact:

O3 Capital Finance Company Limited

Email: care@o3cards.com  ·  dpo@o3cards.com

Phone: 02013301070

Address: 7th Floor, Churchgate Tower 1, Churchgate Street, Victoria Island, Lagos, Nigeria

19

Governing Law

This Privacy Policy shall be governed by the Nigeria Data Protection Act 2023 and the General Data Protection Regulation (GDPR).

20

Consent

By using our website, mobile application, or services, you consent to the collection and use of your personal data in accordance with this Privacy Policy.