Medium taxpayer e-invoicing went live on July 1, 2026. Enforcement begins January 2027. Every untransmitted invoice carries a ₦200,000 fine.

Legal

Privacy Policy

How HarmonizedX collects, uses, stores, and protects your personal data under the Nigeria Data Protection Act 2023.

Last Updated: 18th March 2026

Contents

1. Introduction and Scope

At HarmonizedX Limited (“the Company,” “we,” “us,” or “our”), we place the utmost importance on our relationship with our customers. Transparency regarding the collection, use, and protection of your Personal Data is fundamental to that relationship. This Privacy Policy (“Policy”) sets out how we collect, process, use, store, and disclose your Personal Data when you access our website, integrate with our platform, or use our Services (collectively, the “Services”).

We recommend that you read this Policy carefully to understand our practices concerning your Personal Data. By clicking any icon indicating agreement, accessing our Sites, creating an account, integrating with our platform, or using our Services, you consent to the terms of this Policy and to the collection, use, storage, and disclosure of your Personal Data as described herein. This Policy explains your rights, the legal basis for our processing activities, and how you may exercise those rights under Nigerian law, including the Nigeria Data Protection Act 2023.

The Company reserves the right to amend this Privacy Policy from time to time to comply with evolving regulatory requirements or business improvements. In the event of any amendments, the “Last Updated” date at the top of this Policy will be revised, and clients will be notified via the email address provided in connection with our Services prior to the amendments becoming effective. Continued use of the Services following such amendments will constitute acceptance of the revised Privacy Policy. Clients are encouraged to periodically review this Policy to stay informed of updates. Any enquiries or comments regarding this Privacy Policy should be addressed to harmonizedx@harmonizedx.com

2. Definitions

For the purposes of this Policy, the following terms shall have the meanings assigned under the Nigeria Data Protection Act 2023 (“NDPA”):

  1. Data Subject: an identifiable natural person who can be identified, directly or indirectly.

  2. Personal Data: any information relating to an identified or identifiable natural person.

  3. Processing: any operation performed on Personal Data, including collection, recording, storage, verification, or disclosure.

  4. Sensitive Personal Data – Personal data that relates to a person’s race, ethnic origin, political opinions, religious beliefs, health status, biometrics, genetic data, or other information considered sensitive under the NDPA.

  5. Processing – Any operation or set of operations performed on Personal Data, whether automated or manual, including collection, storage, use, disclosure, or deletion.

  6. Cross-Border Transfer – The transmission of Personal Data to a country outside Nigeria, including safeguards to ensure adequate protection as required under the NDPA.

  7. Consent – Any freely given, specific, informed, and unambiguous indication of a Data Subject’s wishes by which they signify agreement to the processing of their Personal Data.

  8. Automated Processing / Automated Decision-Making – Any decision made by technological means without human intervention, which has legal or similarly significant effects on a Data Subject.

  9. Data Breach – Any accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access to Personal Data.

  10. Account – Any user account, profile, or registration with the Company that allows access to the Services.

  11. User / Data Subject / Client – Any individual whose Personal Data is collected, processed, or stored by the Company in the course of providing Services.

  12. Services / Platform – The Company’s website, APIs, and any other digital or physical services offered for identity verification and related purposes.

3. Personal Data We Collect

In providing identity verification, E-invoicing Solutions and related Services, the Company collects several categories of Personal Data. This includes identification data such as your full name, date of birth, gender, and nationality; government-issued identifiers including National Identification Number (NIN), Tax Identification Number (TIN), Bank Verification Number (BVN), biometric data; contact information including email address, telephone number, and residential address; and technical information such as IP addresses, device identifiers, and cookies used to enhance security and user experience.

We may also collect information automatically about your usage of our platforms, including browser type, device specifications, location and time zone settings, and interactions with our Services. Business-related information submitted by corporate clients, such as registration documents, directors’ information, and addresses, may also be collected to facilitate compliance and proper service delivery.

4. Use of Personal Data

The Company processes your Personal Data for purposes that include, but are not limited to, operating and managing your access to our Services; ensuring compliance with regulatory obligations, including KYC and AML requirements; detecting, preventing, and investigating fraud or security breaches; responding to inquiries and resolving disputes; providing customer support; improving our Services; and communicating promotional offers or updates where you have consented.

We will only use your Personal Data for the purposes for which it was collected, or for purposes compatible with those originally stated. Where the Company intends to use your Personal Data for a new purpose, you will be notified, and consent will be sought where required. You may withdraw consent at any time; however, withdrawal will not affect the lawfulness of processing carried out prior to withdrawal, nor processing necessary to comply with statutory, regulatory, or contractual obligations. Certain Services or features may be restricted if consent for processing is withdrawn.

5. How We Collect Your Personal Information

The Company collects Personal Data through various methods in the course of providing our identity verification Services:

  1. Direct Interactions: We collect information that you provide to us directly when you register for our Services, create an account, use our platform, complete forms, provide documents for verification, or communicate with us via email, phone, or other channels. This may include your name, contact information, government-issued identifiers, biometric data, and other information necessary to provide and manage our Services.

  2. Automated Technological Interactions: Certain Personal Data is collected automatically as you interact with our websites, applications, or platforms. This may include technical information about your device, browser, IP address, location, and usage patterns. Such information is collected through cookies, server logs, web beacons, and other similar technologies to enhance user experience, improve our Services, and maintain security and fraud prevention.

  3. Third Parties and Publicly Available Sources: We may also receive Personal Data about you from third parties or publicly available sources. This may include information from financial institutions, government agencies, regulatory bodies, or other partners to facilitate identity verification, comply with regulatory obligations, or enhance the accuracy of our Services.

All Personal Data collected is processed in accordance with the Nigeria Data Protection Act 2023 and this Privacy Policy.

6. Lawful Basis for Processing

The Company processes Personal Data only on lawful grounds as set out under the Nigeria Data Protection Act 2023. Processing is carried out where one or more of the following lawful bases apply:

  1. Consent: Where you have given clear and explicit consent for the Company to process your Personal Data. You may withdraw your consent at any time by notifying the Company, subject to the limitation that such withdrawal does not affect the lawfulness of processing carried out prior to withdrawal, or processing required to meet statutory, regulatory, or contractual obligations.

  2. Contractual Necessity: Where processing is necessary for the performance of a contract to which you are a party, including the provision of Services or products you have requested from us.

  3. Legal Obligation: Where processing is necessary for the Company to comply with a legal or regulatory obligation, including but not limited to Anti-Money Laundering (AML), Know Your Customer (KYC), financial reporting obligations and other statutory or regulatory mandates applicable to identity verification and related services.

  4. Legitimate Interests: Where processing is necessary for the legitimate interests pursued by the Company or a third party, provided that such interests are not overridden by your rights and freedoms. This may include purposes such as fraud detection, security monitoring, service improvement, and the protection of the Company’s or its users’ rights, property, or safety. You have the right to object to processing on this basis where it is not essential to the performance of the Services or for legal compliance.

In certain circumstances, the Company may request additional information from you to verify your identity before granting access to your Personal Data or to facilitate the exercise of your legal rights. This is a security measure to ensure that Personal Data is not disclosed to any person without lawful entitlement.

8. Automated Decision-Making and Profiling

The Company employs automated systems to perform identity verification and “liveness” detection. Data Protection Impact Assessments are conducted regularly to minimise risks of errors or bias. You have the right to request human review of any automated decision that adversely affects you, including failed verifications, in accordance with the NDPA.

9. Cookies and Tracking Technologies

The Company uses cookies and other tracking technologies on its website and platforms to enhance user experience, monitor site usage, and improve the delivery of our Services. Cookies are small text files placed on your device by your web browser when you visit our website. These files help the Company recognise your device on subsequent visits and enable smoother navigation and personalised features.

You may configure your web browser to refuse cookies or to notify you when cookies are being placed. Please note, however, that restricting or disabling cookies may affect the functionality of certain parts of our website or Services, and may result in a reduced user experience. The Company does not store sensitive login credentials in persistent cookies, ensuring that your account remains secure even if others access your device.

10. Data Sharing and Third-Party Disclosure

Your Personal Data may be shared with third parties under strict conditions, including:

  1. Regulatory or enforcement agencies for legal compliance.

  2. Agents, contractors, and service providers assisting in the delivery of Services, all bound by confidentiality and processing restrictions.

  3. Financial institutions for payment processing purposes.

  4. Legal counsel to establish, exercise, or defend legal rights.

  5. Courts or judicial authorities as required by law.

We may also share your Personal Data in cases of fraud detection or security threats. Consent will be sought before sharing your data for other purposes not previously disclosed.

11. Data Retention

The Company retains Personal Data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law, including obligations under the Nigeria Data Protection Act 2023 and other relevant regulatory frameworks. Invoice, tax, and other statutory records are retained for a minimum period of six (6) years in accordance with Nigerian financial and corporate regulations.

User accounts, technical information, and identity verification records are retained for as long as reasonably necessary to provide the Services, to ensure the accuracy and integrity of identity verification, and to meet any contractual or legal obligations, including the resolution of disputes or enforcement of legal claims. Where appropriate, Personal Data may be anonymised or pseudonymised for research, statistical, or internal audit purposes, in which case it may be retained indefinitely.

Upon expiry of applicable retention periods, Personal Data will be securely destroyed using methods designed to render the data irrecoverable, in accordance with best practices and technical standards. Contact and marketing information will be retained until you opt out of receiving communications, after which such information will be added to suppression lists to prevent further unsolicited contact.

12. Data Security

The Company implements technical and organisational measures to protect Personal Data against unauthorised access, loss, alteration, or disclosure. These include firewalls, TLS/AES-256 encryption, role-based access, multi-factor authentication, and periodic security audits. Access is restricted to authorised personnel and service providers, all bound by confidentiality obligations. While we implement commercially reasonable and technically appropriate safeguards, no system can be guaranteed to be completely secure. By using our Services, you acknowledge and accept that there is always a residual risk of unauthorised access, loss, alteration, or disclosure of your Personal Data.

Data breaches or security incidents are treated with the utmost urgency. In the event of a confirmed breach, the Company will notify the Nigeria Data Protection Commission and affected users within seventy-two (72) hours, in accordance with applicable law. Users are responsible for maintaining the confidentiality of their login credentials and for logging out after use.

13. Customer Contact

For quality assurance, security, and training purposes, all telephone calls to and from the Company’s Customer Contact Centre may be recorded. These recordings help us address and resolve any queries or issues relating to the Services, ensure the accuracy of information exchanged, and improve our overall service delivery.

By contacting our Customer Contact Centre, you consent to the recording of your calls for these purposes. The Company will handle and store any recorded information in accordance with this Privacy Policy and applicable laws, including the Nigeria Data Protection Act 2023, ensuring that access is restricted to authorised personnel and that recordings are securely maintained.

14. Opting Out of Marketing Communications

The Company may, from time to time, use your Personal Data to provide information on new products, services, promotional offers, or other marketing-related communications, where permitted by law. You have the right to opt out of receiving such communications at any time.

All promotional emails or messages sent to you will include a clear and accessible option to unsubscribe or withdraw consent. By using the unsubscribe option, you will no longer receive marketing or promotional communications from the Company at the email address or contact details provided. Requests to opt out will be processed promptly, and your decision will not affect the provision of other Services you have requested or any processing of your Personal Data required by law, regulation, or for the proper performance of our contractual obligations. You may also contact the Company directly at harmonizedx@harmonizedx.com to withdraw consent for marketing communications. The Company will ensure that all reasonable steps are taken to respect your preferences while remaining compliant with legal, regulatory, and operational requirements.

15. Your Rights as a Data Subject

Under the Nigeria Data Protection Act 2023, you have certain rights in relation to your Personal Data, which the Company respects and adheres to. These rights may be exercised at any time; however, they are not absolute and may only apply in specific circumstances provided by law.

  1. You have the right to request access to your Personal Data (commonly referred to as a “data subject access request”). This enables you to obtain a copy of the Personal Data the Company holds about you and to verify that it is being processed lawfully.

  2. You have the right to request correction of your Personal Data. This allows you to have any incomplete, inaccurate, or outdated information held by the Company corrected.

  3. You may request the erasure of your Personal Data where there is no lawful reason for its continued processing, or where you have validly objected to its processing. Please note, however, that the Company may not be able to comply with such a request where retention is necessary to comply with statutory obligations, contractual requirements, or for the establishment, exercise, or defence of legal claims.

  4. You have the right to request that your Personal Data be transferred to you or to a third party in a structured, machine-readable format, where technically feasible.

  5. You may object to the processing of your Personal Data where the Company relies on its legitimate interests or those of a third party, and there is something specific to your situation that warrants such objection. You also have the right to object to the processing of your Personal Data for direct marketing purposes at any time.

  6. You have the right to request the restriction of processing of your Personal Data. This allows you to ask the Company to suspend processing, for example, where you wish to verify the accuracy of your data or challenge the grounds on which it is being processed.

In order to exercise any of these rights, the Company may require you to provide sufficient information to verify your identity. This is a necessary security measure to prevent Personal Data from being disclosed to any person who does not have the right to receive it. The Company may also contact you to clarify or complete your request.

All requests to exercise your rights should be submitted to the Company’s Data Protection Officer at harmonizedx@harmonizedx.com, and the Company will respond in accordance with the timelines set out under the Nigeria Data Protection Act 2023.

17. Breach of Privacy Policy

The Company takes the protection of your Personal Data seriously and has established robust procedures to address any suspected or actual breaches of this Privacy Policy. In the event of a personal data breach, the Company will take all reasonable steps to investigate, contain, and remediate the breach, as well as to mitigate any potential adverse effects on affected individuals.

Where required by law, including the Nigeria Data Protection Act 2023, the Company will notify affected users and relevant regulatory authorities of the breach without undue delay. Such notification will include details of the nature of the breach, the potential risks, and the corrective measures and security enhancements implemented to prevent a recurrence.

The Company remains committed to continuously improving its security measures and procedures to safeguard your Personal Data and to maintain compliance with all applicable data protection laws.

18. GDPR Alignment

While the Company primarily operates under the Nigeria Data Protection Act 2023, we recognise the importance of aligning with international data protection standards, particularly where our Services may involve data subjects outside Nigeria. In this regard, the Company adopts practices consistent with the General Data Protection Regulation (GDPR), including maintaining records of processing activities, conducting Data Protection Impact Assessments (DPIAs) where necessary, and employing Standard Contractual Clauses for cross-border data transfers to jurisdictions that do not provide an adequate level of data protection.

These measures are intended to ensure that the Company maintains high standards of data protection and privacy, in line with international best practices, while complementing its obligations under Nigerian law.

20. Children’s Data

The Company’s Services are intended for business and adult use only. Our products and identity verification services are not directed at children or persons under the age of eighteen (18) years. In the event that we are required to process the Personal Data of any individual under the age of eighteen (18), we will obtain verified consent from a parent or legal guardian prior to such processing, in full compliance with the Nigeria Data Protection Act 2023.

We take all reasonable steps to ensure that children’s Personal Data is processed lawfully and securely, and that no child uses our Services without appropriate parental or guardian oversight.

21. Anonymised and Aggregated Data

The Company may use Personal Data to produce anonymised or aggregated information for purposes such as research, statistical analysis, service improvement, risk management, and internal reporting. Anonymised data refers to Personal Data that has been processed so that it can no longer be used to identify any individual, either directly or indirectly. Aggregated data refers to information combined from multiple users in a way that individual identities are not discernible.

Such anonymised or aggregated data may be used internally or shared with third parties for legitimate business, research, or regulatory purposes, provided that individual users cannot be identified from such information. This ensures that your privacy is protected while allowing the Company to derive insights, improve services, and comply with applicable laws and regulations, including the Nigeria Data Protection Act 2023.

The Company remains committed to ensuring that no Personal Data is disclosed in a manner that could compromise your privacy or security.

Contact us about this policy

REGISTERED ADDRESS

Block B8, Ministry of Finance Quarters, House AR.I Uzoma Street, Wuye District, Abuja FCT