UZOVIA Privacy Policy
Data Controller:
Swiftliner Technologies Limited (RC 9571507)
Lagos, Nigeria
privacy@uzovia.com
1. Introduction
UZOVIA ("we", "us", "our") is a digital transit payment platform operated by Swiftliner Technologies Limited (RC 9571507), incorporated under the laws of the Federal Republic of Nigeria. We are committed to protecting the personal data of our users.
This Privacy Policy is prepared in accordance with the Nigeria Data Protection Act 2023 (NDPA), applicable regulations, directives, and guidance issued by the Nigeria Data Protection Commission (NDPC), and other applicable laws.
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your rights as a data subject.
By registering for or using the UZOVIA platform (mobile app, web portal, or API), you acknowledge that you have read and understood this policy.
2. Data We Collect
2.1 Identity data
- Full legal name (first, last, middle)
- Date of birth (from BVN verification)
- Bank Verification Number (BVN) — collected during KYC Tier 1 verification; stored only as a SHA-256 hash. The raw BVN is transmitted to our identity verification provider for name-match against NIBSS records and is never retained at rest by UZOVIA. BVN verification is conducted solely for customer due diligence, fraud prevention, identity verification, anti-money laundering compliance, and regulatory obligations. BVN verification does not provide UZOVIA access to your bank accounts.
- National Identification Number (NIN) — not collected at MVP launch. Reserved for a future KYC Tier 2 expansion (higher transaction limits). When introduced, it will also be stored only as a SHA-256 hash. Any future collection of NIN shall be subject to a Data Protection Impact Assessment (DPIA), regulatory review, and publication of an updated Privacy Policy before collection begins.
- Profile photograph (stored on Cloudinary)
- Email address and phone number
2.2 Transit account & journey data
- Transit account balance and journey records
- Account loading and withdrawal records
- Payment codes and QR code usage
- Trip records (route, fare amount, payment method, timestamp)
- VAT amounts charged per transaction and the jurisdiction under which they were calculated
- VAT remittance records (aggregated; no individual identifiers beyond what is already in the transaction ledger)
2.3 Device and technical data
- Device type and operating system
- IP address
- Session tokens (hashed)
- Geolocation data during active collection sessions (inspectors only; not stored permanently)
- Driver online/offline availability status for institutional spaces (stored ephemerally in Redis while Online; used for fleet visibility and optional operational reporting — not continuous GPS tracking)
2.4 Compliance and identity verification data
- BVN verification result and date
- Enrollment bank (logged for NFIU audit purposes)
- KYC tier status
- Compliance flags (AML/fraud alert types and review status)
- Suspicious transaction reports (where applicable)
2.5 Communication data
- Support ticket messages
- Broadcast notifications received
- Email and in-app notification records
3. How We Use Your Data
| Purpose | Legal basis (NDPA s.25) |
|---|---|
| Account registration and identity verification | Contract performance |
| Processing transit account transactions and payments | Contract performance |
| AML/CFT screening and fraud monitoring | Legal obligation (CBN/NFIU) |
| BVN verification (Prembly API) | Legal obligation (CBN KYC) |
| VAT calculation and remittance to tax authorities | Legal obligation (Value Added Tax Act, Cap V1 LFN 2004 as amended; equivalent legislation in applicable jurisdictions) |
| Sending operational notifications | Contract performance |
| Responding to support requests | Contract performance |
| Platform analytics (aggregated) | Legitimate interests |
| Compliance reporting to regulators | Legal obligation |
| Security monitoring and fraud prevention | Legitimate interests |
We do not use your personal data for automated profiling that produces legal or similarly significant effects without human oversight.
4. Data Retention
| Category | Retention period |
|---|---|
| Account and identity data | 7 years after account closure (CBN KYC) |
| Transaction ledger records | 7 years (CBN/NFIU) |
| BVN hash and verification records | 7 years after account closure |
| Support ticket records | 2 years after closure |
| Compliance flags and AML records | 7 years (NFIU AMLCFT 2022) |
| VAT transaction records and remittance logs | 7 years (FIRS requirement; equivalent periods in applicable jurisdictions) |
| Device/session data | 90 days |
| Geolocation data (inspector GPS) | Not stored (ephemeral, 10-min Redis TTL) |
| Driver online/offline presence | Ephemeral Redis (typically ≤12h while Online); not written to permanent ledger |
Data may be retained for longer periods where required for legal proceedings, regulatory investigations, dispute resolution, enforcement of legal rights, or compliance with applicable law.
5. Who We Share Your Data With
5.1 Service providers (data processors)
We engage the following processors under data processing agreements:
| Provider | Purpose |
|---|---|
| Prembly | BVN identity verification (NIN reserved for future Tier 2) |
| Paystack (Stripe Inc.) | Payment processing, card funding |
| Cloudinary | Profile photo storage |
| DigitalOcean | Cloud hosting (backend API and database) |
| Vercel | Web dashboard hosting |
| Resend | Transactional email delivery |
| Firebase (Google) | Push notifications |
5.2 Regulatory authorities
We may disclose personal data without your prior consent where required by law to: the Central Bank of Nigeria (CBN), the Nigerian Financial Intelligence Unit (NFIU), the Federal Inland Revenue Service (FIRS), the Nigeria Data Protection Commission (NDPC), the Economic and Financial Crimes Commission (EFCC), or under lawful law enforcement requests.
Where UZOVIA receives a subpoena, court order, or lawful law enforcement request for user data, we will assess its validity, comply where legally required, and notify affected users where permitted by law.
5.3 Institutional partners (spaces)
Space administrators (e.g., university transport offices) can view member names and roles within their space, plus fare payment records and session history relevant to their operations. Space administrators may only access records reasonably necessary for fare verification, operational administration, reconciliation, security, and auditing purposes within their designated space. They cannot access account balances, BVN data, or personal financial information outside their space.
5.4 No sale of personal data
We do not sell, rent, or lease personal data to third parties for marketing or commercial purposes.
6. Cross-Border Data Transfers
Some of our service providers are based outside Nigeria (e.g., Stripe/Paystack in Ireland, Cloudinary in USA). Where we transfer personal data outside Nigeria, we ensure appropriate safeguards are in place in accordance with NDPA s.44, including Standard Contractual Clauses (SCCs) with processors and adequacy assessments where applicable.
7. Data Security
- Encryption in transit: TLS 1.2+ for all API communications
- Encryption at rest: Database-level encryption for sensitive fields
- BVN hashing: Raw BVN is never stored — only SHA-256 hashes. The same standard will apply to NIN if introduced in a future Tier 2 expansion.
- Access controls: Role-based access control (RBAC) with least-privilege principle
- Audit logging: All data access events are logged with timestamps and user IDs
- Pessimistic locking: Money-moving operations use database-level row locks
- JWT security: Short-lived access tokens (15 min), refresh token rotation, cookie-free transport
7.1 Data Breach Notification
Where a personal data breach is likely to result in a risk to the rights and freedoms of data subjects, UZOVIA shall notify the Nigeria Data Protection Commission (NDPC) and affected individuals in accordance with NDPA s.40 and applicable law.
7.2 Data Protection Impact Assessments
UZOVIA may conduct Data Protection Impact Assessments (DPIAs) where processing activities are likely to result in a high risk to the rights and freedoms of individuals, including transit account operations, payment processing, KYC verification, and fraud monitoring.
8. Your Rights as a Data Subject
Under the NDPA 2023 you have the following rights:
| Right | How to exercise |
|---|---|
| Access | Request a copy via the app or privacy@uzovia.com |
| Rectification | Update your profile in the app; legal name changes after KYC require admin review |
| Erasure | Request account deletion via the app or our web form. Note: financial records must be retained for 7 years. |
| Restriction | Email privacy@uzovia.com to restrict processing in specific circumstances |
| Data portability | Request an export of your transaction history in machine-readable format |
| Object | Object to processing based on legitimate interests |
| Withdraw consent | Where processing is consent-based, withdraw at any time without affecting prior processing |
To exercise any of these rights, email privacy@uzovia.com with your full name, registered email address, and a description of your request. We will respond within 30 days.
If you believe we have mishandled your personal data, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
9. Cookies and Tracking
The UZOVIA mobile app does not use cookies. The UZOVIA web admin dashboard uses:
- Essential cookies: Session management (refresh token for web users)
- No tracking or advertising cookies
We do not use third-party analytics that profile individual users.
10. Children's Data
UZOVIA's transit account funding, withdrawals, and KYC identity verification require users to be at least 18 years of age, in compliance with CBN BVN requirements. Users under 18 may access limited functionality — specifically, fare payments within institutional spaces — subject to institutional enrolment. We do not knowingly collect personal data from minors for independent transit account operations. If we become aware that we have inadvertently collected data from a minor in breach of this policy, we will delete it promptly.
11. Changes to This Policy
We may update this policy periodically. When we make material changes, we will update the "Last updated" date above, notify registered users via in-app notification and email, and publish the updated policy at uzovia.com/privacy. Your continued use of the platform after notification constitutes acceptance of the updated policy.
12. Contact Us
Privacy and Data Subject Requests:
Email: privacy@uzovia.com
Data Protection Officer (DPO):
Swiftliner Technologies Limited (RC 9571507)
Email: dpo@uzovia.com
General Support:
Email: support@uzovia.com
For urgent data breach notifications or regulatory inquiries, email privacy@uzovia.com with the subject line [URGENT] Data Protection Matter.
This policy is published in compliance with the Nigeria Data Protection Act 2023 (NDPA), applicable regulations and directives issued by the Nigeria Data Protection Commission (NDPC), and the CBN Know-Your-Customer (KYC) Requirements.
