Skip to main content

UZOVIA Privacy Policy

Effective
1 May 2026
Last updated
24 June 2026
Version
1.4

Data Controller:
Swiftliner Technologies Limited (RC 9571507)
Lagos, Nigeria
privacy@uzovia.com

1. Introduction

UZOVIA ("we", "us", "our") is a digital transit payment platform operated by Swiftliner Technologies Limited (RC 9571507), incorporated under the laws of the Federal Republic of Nigeria. We are committed to protecting the personal data of our users.

This Privacy Policy is prepared in accordance with the Nigeria Data Protection Act 2023 (NDPA), applicable regulations, directives, and guidance issued by the Nigeria Data Protection Commission (NDPC), and other applicable laws.

This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your rights as a data subject.

By registering for or using the UZOVIA platform (mobile app, web portal, or API), you acknowledge that you have read and understood this policy.

2. Data We Collect

2.1 Identity data

  • Full legal name (first, last, middle)
  • Date of birth (from BVN verification)
  • Bank Verification Number (BVN) — collected during KYC Tier 1 verification; stored only as a SHA-256 hash. The raw BVN is transmitted to our identity verification provider for name-match against NIBSS records and is never retained at rest by UZOVIA. BVN verification is conducted solely for customer due diligence, fraud prevention, identity verification, anti-money laundering compliance, and regulatory obligations. BVN verification does not provide UZOVIA access to your bank accounts.
  • National Identification Number (NIN) — not collected at MVP launch. Reserved for a future KYC Tier 2 expansion (higher transaction limits). When introduced, it will also be stored only as a SHA-256 hash. Any future collection of NIN shall be subject to a Data Protection Impact Assessment (DPIA), regulatory review, and publication of an updated Privacy Policy before collection begins.
  • Profile photograph (stored on Cloudinary)
  • Email address and phone number

2.2 Transit account & journey data

  • Transit account balance and journey records
  • Account loading and withdrawal records
  • Payment codes and QR code usage
  • Trip records (route, fare amount, payment method, timestamp)
  • VAT amounts charged per transaction and the jurisdiction under which they were calculated
  • VAT remittance records (aggregated; no individual identifiers beyond what is already in the transaction ledger)

2.3 Device and technical data

  • Device type and operating system
  • IP address
  • Session tokens (hashed)
  • Geolocation data during active collection sessions (inspectors only; not stored permanently)
  • Driver online/offline availability status for institutional spaces (stored ephemerally in Redis while Online; used for fleet visibility and optional operational reporting — not continuous GPS tracking)

2.4 Compliance and identity verification data

  • BVN verification result and date
  • Enrollment bank (logged for NFIU audit purposes)
  • KYC tier status
  • Compliance flags (AML/fraud alert types and review status)
  • Suspicious transaction reports (where applicable)

2.5 Communication data

  • Support ticket messages
  • Broadcast notifications received
  • Email and in-app notification records

3. How We Use Your Data

PurposeLegal basis (NDPA s.25)
Account registration and identity verificationContract performance
Processing transit account transactions and paymentsContract performance
AML/CFT screening and fraud monitoringLegal obligation (CBN/NFIU)
BVN verification (Prembly API)Legal obligation (CBN KYC)
VAT calculation and remittance to tax authoritiesLegal obligation (Value Added Tax Act, Cap V1 LFN 2004 as amended; equivalent legislation in applicable jurisdictions)
Sending operational notificationsContract performance
Responding to support requestsContract performance
Platform analytics (aggregated)Legitimate interests
Compliance reporting to regulatorsLegal obligation
Security monitoring and fraud preventionLegitimate interests

We do not use your personal data for automated profiling that produces legal or similarly significant effects without human oversight.

4. Data Retention

CategoryRetention period
Account and identity data7 years after account closure (CBN KYC)
Transaction ledger records7 years (CBN/NFIU)
BVN hash and verification records7 years after account closure
Support ticket records2 years after closure
Compliance flags and AML records7 years (NFIU AMLCFT 2022)
VAT transaction records and remittance logs7 years (FIRS requirement; equivalent periods in applicable jurisdictions)
Device/session data90 days
Geolocation data (inspector GPS)Not stored (ephemeral, 10-min Redis TTL)
Driver online/offline presenceEphemeral Redis (typically ≤12h while Online); not written to permanent ledger

Data may be retained for longer periods where required for legal proceedings, regulatory investigations, dispute resolution, enforcement of legal rights, or compliance with applicable law.

5. Who We Share Your Data With

5.1 Service providers (data processors)

We engage the following processors under data processing agreements:

ProviderPurpose
PremblyBVN identity verification (NIN reserved for future Tier 2)
Paystack (Stripe Inc.)Payment processing, card funding
CloudinaryProfile photo storage
DigitalOceanCloud hosting (backend API and database)
VercelWeb dashboard hosting
ResendTransactional email delivery
Firebase (Google)Push notifications

5.2 Regulatory authorities

We may disclose personal data without your prior consent where required by law to: the Central Bank of Nigeria (CBN), the Nigerian Financial Intelligence Unit (NFIU), the Federal Inland Revenue Service (FIRS), the Nigeria Data Protection Commission (NDPC), the Economic and Financial Crimes Commission (EFCC), or under lawful law enforcement requests.

Where UZOVIA receives a subpoena, court order, or lawful law enforcement request for user data, we will assess its validity, comply where legally required, and notify affected users where permitted by law.

5.3 Institutional partners (spaces)

Space administrators (e.g., university transport offices) can view member names and roles within their space, plus fare payment records and session history relevant to their operations. Space administrators may only access records reasonably necessary for fare verification, operational administration, reconciliation, security, and auditing purposes within their designated space. They cannot access account balances, BVN data, or personal financial information outside their space.

5.4 No sale of personal data

We do not sell, rent, or lease personal data to third parties for marketing or commercial purposes.

6. Cross-Border Data Transfers

Some of our service providers are based outside Nigeria (e.g., Stripe/Paystack in Ireland, Cloudinary in USA). Where we transfer personal data outside Nigeria, we ensure appropriate safeguards are in place in accordance with NDPA s.44, including Standard Contractual Clauses (SCCs) with processors and adequacy assessments where applicable.

7. Data Security

  • Encryption in transit: TLS 1.2+ for all API communications
  • Encryption at rest: Database-level encryption for sensitive fields
  • BVN hashing: Raw BVN is never stored — only SHA-256 hashes. The same standard will apply to NIN if introduced in a future Tier 2 expansion.
  • Access controls: Role-based access control (RBAC) with least-privilege principle
  • Audit logging: All data access events are logged with timestamps and user IDs
  • Pessimistic locking: Money-moving operations use database-level row locks
  • JWT security: Short-lived access tokens (15 min), refresh token rotation, cookie-free transport

7.1 Data Breach Notification

Where a personal data breach is likely to result in a risk to the rights and freedoms of data subjects, UZOVIA shall notify the Nigeria Data Protection Commission (NDPC) and affected individuals in accordance with NDPA s.40 and applicable law.

7.2 Data Protection Impact Assessments

UZOVIA may conduct Data Protection Impact Assessments (DPIAs) where processing activities are likely to result in a high risk to the rights and freedoms of individuals, including transit account operations, payment processing, KYC verification, and fraud monitoring.

8. Your Rights as a Data Subject

Under the NDPA 2023 you have the following rights:

RightHow to exercise
AccessRequest a copy via the app or privacy@uzovia.com
RectificationUpdate your profile in the app; legal name changes after KYC require admin review
ErasureRequest account deletion via the app or our web form. Note: financial records must be retained for 7 years.
RestrictionEmail privacy@uzovia.com to restrict processing in specific circumstances
Data portabilityRequest an export of your transaction history in machine-readable format
ObjectObject to processing based on legitimate interests
Withdraw consentWhere processing is consent-based, withdraw at any time without affecting prior processing

To exercise any of these rights, email privacy@uzovia.com with your full name, registered email address, and a description of your request. We will respond within 30 days.

If you believe we have mishandled your personal data, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.

9. Cookies and Tracking

The UZOVIA mobile app does not use cookies. The UZOVIA web admin dashboard uses:

  • Essential cookies: Session management (refresh token for web users)
  • No tracking or advertising cookies

We do not use third-party analytics that profile individual users.

10. Children's Data

UZOVIA's transit account funding, withdrawals, and KYC identity verification require users to be at least 18 years of age, in compliance with CBN BVN requirements. Users under 18 may access limited functionality — specifically, fare payments within institutional spaces — subject to institutional enrolment. We do not knowingly collect personal data from minors for independent transit account operations. If we become aware that we have inadvertently collected data from a minor in breach of this policy, we will delete it promptly.

11. Changes to This Policy

We may update this policy periodically. When we make material changes, we will update the "Last updated" date above, notify registered users via in-app notification and email, and publish the updated policy at uzovia.com/privacy. Your continued use of the platform after notification constitutes acceptance of the updated policy.

12. Contact Us

Privacy and Data Subject Requests:
Email: privacy@uzovia.com

Data Protection Officer (DPO):
Swiftliner Technologies Limited (RC 9571507)
Email: dpo@uzovia.com

General Support:
Email: support@uzovia.com

For urgent data breach notifications or regulatory inquiries, email privacy@uzovia.com with the subject line [URGENT] Data Protection Matter.

This policy is published in compliance with the Nigeria Data Protection Act 2023 (NDPA), applicable regulations and directives issued by the Nigeria Data Protection Commission (NDPC), and the CBN Know-Your-Customer (KYC) Requirements.