Privacy Policy
How Prophius collects, uses, stores, and protects your personal data, and the rights you have over it.
1. Who we are
Prophius Limited ("Prophius", "we", "us") is a payments company registered in Nigeria with its registered office at 19B Bosun Adekoya Street, Oniru, Victoria Island, Lagos. We are licensed by the Central Bank of Nigeria and we operate under the Nigeria Data Protection Act 2023 (NDPA) and the regulations issued by the Nigeria Data Protection Commission (NDPC).
For most of the processing described in this notice, Prophius is the data controller. Where we process cardholder data on behalf of a merchant that accepts payments through us, we act on the merchant's instructions for that transaction and as a controller for our own regulatory obligations such as fraud prevention and record keeping.
Our Data Protection Officer can be reached at legal@prophius.com or by post at the address above.
2. Who this notice covers
This notice applies to personal data we process about:
- visitors to www.prophius.com and users of our merchant portal;
- people who apply for a Prophius merchant, aggregator or partner account, and the owners, directors, signatories and staff of those businesses;
- customers who pay a Prophius merchant by card, bank transfer, payment link, tap to phone or POS terminal;
- people who contact us, subscribe to updates or apply for a job with us.
3. The personal data we collect
Merchants, partners and their people
- Identity and contact details: name, date of birth, phone number, email address, business address, passport photograph.
- Verification data required by Nigerian law: Bank Verification Number (BVN), National Identification Number (NIN), Tax Identification Number, government-issued identity documents, proof of address, and Corporate Affairs Commission registration documents including details of directors and of shareholders holding five percent or more.
- Financial details: settlement bank name and account number in Naira and, where applicable, US dollars; expected transaction volumes; business category.
- Account and usage data: login credentials, portal activity, devices used with the PayContactless app or POS Pulse terminals, support requests and correspondence.
Customers paying a merchant
- Transaction data: amount, currency, date and time, merchant, payment method, authorisation result and reference numbers.
- Payment instrument data: the card number in truncated form, expiry date, card type and issuing bank, or the account details used for a bank transfer. Full card numbers and security codes are handled under the Payment Card Industry Data Security Standard (PCI DSS) and are never stored in readable form by Prophius.
- Contact details you give a merchant so that a receipt or payment link can be sent to you, such as a phone number or email address.
Website visitors
- Technical data: IP address, browser type, device type, pages visited and the site you arrived from, collected through cookies and similar technologies described in our Cookie Policy.
- Anything you send us through our forms, such as a newsletter signup or a sales enquiry.
Job applicants
- The details you submit through our careers page, which is operated for us by BambooHR, including your CV, contact details and work history.
4. Where the data comes from
Most personal data comes directly from you or from the business you represent. We also receive data from identity and verification services (for example the Nigeria Inter-Bank Settlement System for BVN checks, the National Identity Management Commission for NIN checks and the Corporate Affairs Commission for company records), from banks and card schemes in the course of processing payments, from fraud and sanctions screening providers, and from public sources such as company registers.
5. Why we use personal data and our legal basis
| Purpose | Legal basis under the NDPA |
|---|---|
| Assessing and onboarding merchant and partner applications, including identity verification and Know Your Customer checks | Compliance with a legal obligation (Central Bank of Nigeria anti money laundering and customer due diligence rules); performance of a contract |
| Processing, authorising and settling payments, and providing receipts | Performance of a contract |
| Detecting and preventing fraud, money laundering and misuse of our services, including automated transaction screening | Compliance with a legal obligation; our legitimate interest in protecting our customers and our platform |
| Handling disputes, chargebacks and refunds | Performance of a contract; compliance with card scheme rules |
| Providing support and responding to enquiries | Performance of a contract; legitimate interest |
| Keeping records required by financial and tax regulators | Compliance with a legal obligation |
| Sending product news and marketing | Consent, which you can withdraw at any time |
| Measuring how the website is used | Consent, given through the cookie banner |
| Recruiting and assessing job applicants | Steps taken at your request before entering a contract; legitimate interest |
| Establishing, exercising or defending legal claims | Legitimate interest; compliance with a legal obligation |
6. Automated decisions
Transactions are screened automatically for fraud and money laundering risk. A transaction may be declined or held for review as a result. Merchant applications are reviewed by a person before any decision to decline. If you believe an automated decision has affected you unfairly, you can ask us to review it by contacting legal@prophius.com.
7. Who we share personal data with
- Banks, settlement partners and the Nigeria Inter-Bank Settlement System, to move money and settle transactions.
- Card schemes such as Visa, Mastercard and Verve, and the banks that issue cards, to authorise and clear card payments.
- Identity verification, fraud prevention and sanctions screening providers.
- The Central Bank of Nigeria, the Nigeria Data Protection Commission, the Nigerian Financial Intelligence Unit, tax authorities, courts and law enforcement, where the law requires it.
- Service providers who work for us under contract, including cloud hosting, consent management (Ketch), website analytics (Google), recruitment software (BambooHR) and email delivery. They may only use the data to provide their service to us.
- Aggregators or channel partners who introduced your business to Prophius, limited to what they need to manage that relationship.
- Professional advisers such as auditors, lawyers and insurers.
- A buyer or successor in the event of a merger, acquisition or reorganisation, subject to the same protections.
We do not sell personal data.
8. Transfers outside Nigeria
Some of our service providers store or process data outside Nigeria, including in the United States and the European Union. Where we transfer personal data abroad we rely on the safeguards permitted by the NDPA, such as transferring to a country the NDPC recognises as providing adequate protection, or putting contractual protections in place with the recipient. You can ask us for details of the safeguards that apply to a particular transfer.
9. How long we keep personal data
- Merchant identity, verification and transaction records: for at least five years after the business relationship ends, as required by Nigerian anti money laundering rules, and longer where a dispute or investigation is open.
- Cardholder transaction data: for the period needed to settle, reconcile and handle disputes under card scheme rules, and for the statutory record keeping period.
- Marketing preferences: until you withdraw consent or we stop the relevant activity.
- Website analytics: for the periods set out in the Cookie Policy.
- Job applications: for three years after the role closes, unless you ask us to delete them sooner or you join Prophius.
10. How we protect personal data
Prophius maintains PCI DSS certification for its payment systems. Personal data is encrypted in transit and at rest, access is restricted to staff who need it for their role and is logged, and our systems are monitored and tested regularly. Full card numbers are tokenised and card security codes are never stored. No system is completely secure, so we also maintain incident response procedures and will notify the NDPC and affected people of a breach where the law requires.
11. Your rights
Under the NDPA you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate or incomplete data corrected;
- have your data deleted, where we no longer have a legal reason to keep it;
- restrict or object to certain processing, including direct marketing;
- receive data you provided to us in a portable format;
- withdraw consent at any time, without affecting processing that took place before withdrawal;
- not be subject to a decision based solely on automated processing that significantly affects you, subject to the exceptions in the NDPA;
- complain to the Nigeria Data Protection Commission.
To exercise any of these rights, email legal@prophius.com. We will respond within the time the NDPA allows and may ask you to verify your identity first. Some records, such as transaction and verification records, must be kept by law even if you ask for deletion; we will tell you when that applies.
12. Cookies
Our use of cookies and similar technologies, and how to change your choices, is explained in our Cookie Policy.
13. Children
Our services are for businesses and for adults paying those businesses. We do not knowingly collect personal data from anyone under 18, except transaction data where a minor pays a merchant, which we process only to complete that payment.
14. Changes to this notice
We will update this notice when our practices or the law change. The version and effective date appear at the top. Significant changes will be announced on the website or by email to merchants.
15. Contact
Prophius Limited, 19B Bosun Adekoya Street, Oniru, Victoria Island, Lagos, Nigeria. Email legal@prophius.com.
Nigeria Data Protection Commission: ndpc.gov.ng.
