Privacy Policy (Nigeria)

Privacy Policy (Nigeria)

All the ways we get to know you better

All the ways we get to know you better

Yellow Card (referred to as "Yellow Card," "we," "us," or "our") is committed to protecting the privacy and confidentiality of the personal data of our users, including individuals and businesses. This Privacy Policy outlines how we collect, use, store, share, and protect your information when you access or use the Yellow Card Site (www.yellowcard.io), the Treasury Portal, any Yellow Card API (directly or through third-party applications), or any other Yellow Card product or service (collectively, "Yellow Card Services") within Nigeria.

This Privacy Policy forms an integral part of the relevant Yellow Card Service Agreement that applies to you. Terms defined in the Agreement apply equally herein unless otherwise indicated.

1. Information about the Data Controller and our role

For users of Yellow Card Services operated in Nigeria, the data controller, meaning the entity deciding on the purposes and means of processing personal data, is Yellow Card Financial Nigeria Ltd. Our registered office is at No. 59 Oduduwa Crescent, Ikeja GRA, Lagos, Nigeria.

A "User" is any natural person using Yellow Card Services. For B2B clients, while the primary User is a natural person interacting with the Service, we also process data related to the legal entity they represent.

Our role in relation to your personal data depends on the product and relationship:

  • Data Controller: We act as controller when we set up and maintain your Account, perform our Agreement with you, or carry out KYC, KYB, and AML/CFT screening required by Nigerian law.

  • Data Processor: Where a Business Client uses the Yellow Card API to service its own end-users (our Compliance Reliance Model, under which the Business Client conducts KYC on its end-users), Yellow Card acts as a data processor and processes end-user personal data on the Business Client's documented instructions, governed by a Data Processing Agreement between Yellow Card and that Business Client. In that scenario, the Business Client, not Yellow Card, is the primary controller for its end-users' KYC data, and the Business Client's own privacy notice governs that relationship.

2. Data Protection Officer (DPO) / Contact for Data Protection Matters

We have appointed a contact person for data protection matters. You may contact our Data Protection Officer regarding the protection of your personal data by e-mail at: Dataprotection@yellowcard.io.

3. Information We Collect

3.1 Information You Provide

  • Identity and Professional Information: Full name, email, phone number, date of birth, physical address, and government-issued identification (including national identity document type, number, and issue date). For Treasury Portal users, we also collect professional titles and authorisation levels.

  • Business and KYB Information: For institutional accounts, legal name, trading name, registration number, formation or incorporation date, entity type, tax identification numbers, industry classification, certificates of incorporation, memoranda of incorporation, shareholder registers, proof of registered business address, AML or compliance questionnaire responses, applicable regulatory certifications or licences, beneficial ownership (UBO) information, and documentation for authorised representatives.

  • Ownership and Corporate Structure Information: For business clients, details of ultimate beneficial owners and controlling persons, including full name, date of birth, nationality, residential address, identity document details, ownership percentage, and role within the company, together with the corporate ownership chart and shareholder register.

  • Financial and Wallet Data: Bank account numbers, routing numbers, IBANs, the name and jurisdiction of your bank, and linked payment method details. This includes generated USD stablecoin wallet addresses and multi-currency fiat balances (for example, USD and NGN), which are internal ledger records rather than bank accounts, and the fiat currencies and stablecoins you intend to trade.

  • Transaction and Audit Data: Full details of payments, currency conversions, expected monthly trading volumes, and Request for Quote history. We maintain a filterable Audit Trail recording the “Requestor Name” for every action taken within the Treasury Portal.

  • Priority Markets and Jurisdictional Intent: The geographic markets and jurisdictions in which you intend to transact, including specific countries and counterparty regions, and confirmation of whether you conduct business with counterparties in sanctioned or high-risk jurisdictions.

  • Technical and API Usage Data: Precise geolocation (with permission) for address verification, IP addresses, device identifiers, API call logs, and browser metadata collected via cookies and tracking pixels.

  • Communication Information: Information you provide when you contact customer support, respond to surveys, or communicate with us through other channels.

Failure to provide required information may limit or prevent your access to Yellow Card Services.

3.2 Information Collected Automatically

We automatically collect data about your device and how you interact with our platform, including access times, pages viewed, browser type, operating system, device identifiers, and IP address. See Section 9 (Cookies and Tracking Technologies) for full detail.

3.3 Information We Collect From Other Sources

  • Identity Verification and Fraud Prevention Services: Non-public information from identity verification sources or public databases to verify identity, prevent fraud, and satisfy KYC or AML obligations. For institutional and business clients, this includes KYB verification data from corporate registries and licensed third-party KYB providers such as AiPrise, together with document integrity and forensic analysis outputs, risk scoring results, and automated decisioning outcomes used to detect tampering or fraud. A current list of our sub-processors is maintained and made available to Business Clients on request.

  • Third-Party Analytics and Advertising Partners: Advertising and analytics tools, including LinkedIn Insight Tag, X (Twitter) Pixel, Google Ads and Google Analytics 4, and Meta Pixel, used to measure advertising effectiveness and target relevant users.

4. Purposes and Legal Basis of Personal Data Processing

We process your personal data for the following purposes, relying on the lawful bases under the Nigeria Data Protection Act (NDPA), 2023:

Purpose

Legal Basis (NDPA)

Account setup and maintenance

Necessary for performance of a contract, or steps taken at your request before entering one (Section 25(1)(b)(i))

Provision of core services (Treasury Portal, currency conversion, wallet services)

Necessary for performance of a contract (Section 25(1)(b)(i))

Customer identification and AML/CFT compliance (including for B2B clients and their beneficial owners)

Necessary for compliance with a legal obligation (Section 25(1)(b)(ii))

Service analytics and IT security

Legitimate interests pursued by the Controller (Section 25(1)(b)(v))

Fraud prevention and detection of unauthorised activity

Legitimate interests pursued by the Controller (Section 25(1)(b)(v))

Marketing communications and promotional offers

Consent (Section 25(1)(a)), or legitimate interests where legally permitted (Section 25(1)(b)(v))

B2B lead profiling, scoring, and attribution

Legitimate interests pursued by the Controller (Section 25(1)(b)(v)); you may object at any time

Claims management (establishing, asserting, or defending claims)

Legitimate interests pursued by the Controller (Section 25(1)(b)(v))

Withdrawal of Consent: Where processing is based on your consent (Section 25(1)(a)), you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. You can withdraw consent by emailing the Controller or using the Universal Preference Centre described in Section 9.

5. Recipients of Personal Data

Regulatory Authorities: The Nigeria Financial Intelligence Unit (NFIU), the Central Bank of Nigeria, the Nigeria Data Protection Commission (NDPC), and other relevant bodies as required by Nigerian AML/CFT and data protection law.

  • Third-Party Service Providers: Providers of legal, accounting, IT, cloud storage, payment processing, marketing, and identity verification services, bound by appropriate data processing agreements as required by the NDPA.

  • KYB and Identity Verification Providers: Licensed third-party providers, including AiPrise, engaged to verify identity and business information and to perform sanctions screening. These providers may retain and use your information solely to perform verification and fraud prevention services for Yellow Card and to improve their own services.

  • AI Processing and CRM Service Providers: Third-party providers who assist with AI processing, model training, and CRM functionality in support of the purposes in Section 4. These providers are contractually bound to process data only on our instructions and to implement appropriate security measures.

  • Yellow Card Group Companies: Other companies within the Yellow Card group, to the extent necessary for centralised compliance and treasury operations. See Section 6 for the safeguards applied to these transfers.

  • Authorised Public Authorities and Law Enforcement: Where compelled by subpoena, court order, or applicable law, or necessary to prevent physical harm or financial loss.

  • Corporate Transactions: In the event of a merger, acquisition, or purchase of assets, the acquiring company will have access to your information and will be required to follow this Privacy Policy.

Within Yellow Card, access to your information is limited to employees who require it for compliance, customer support, or verification purposes.

6. Cross-Border Data Transfers

As Yellow Card operates across multiple jurisdictions and relies on group infrastructure and service providers located outside Nigeria, your personal data may be transferred outside Nigeria. In line with NDPA Part VIII:

  • We will only transfer personal data outside Nigeria where the recipient is subject to a law, binding corporate rules, contractual clauses, code of conduct, or certification mechanism affording an adequate level of protection (Section 41), or where one of the alternative bases in Section 43 applies, for example your informed consent, necessity for performance of a contract with you, or necessity for the establishment or defence of legal claims.

  • We record the basis relied on for each transfer and its adequacy, as required by Section 41(2).

  • Where personal data is transferred to Yellow Card group entities or sub-processors in other jurisdictions, we use contractual safeguards intended to ensure a level of protection consistent with Nigerian law.

7. Storage Period of Data

  • Account-Related Data: Stored for the period of Account maintenance, until deleted by you.

  • Service Provision Data: Stored for five years from the date of termination of the business relationship or the date of execution of an occasional transaction, in accordance with the CBN AML/CFT Regulation, other applicable Nigerian AML/CFT regulations, and NDPA retention principles.

  • Cookie Data: Stored for the lifecycle of the relevant cookie, or until deleted by you.

  • Marketing Data: Stored until you withdraw consent to receive marketing content.

  • Claims-Related Data: Stored until the relevant proceeding is finally concluded and any decision enforced.

Yellow Card will not retain your personal data longer than necessary for the purpose for which it was collected, or as required by law.

8. Data Security

We employ technical and organisational measures designed to protect your personal data, including:

  • Authentication and Access Control: Mandatory multi-factor authentication for the Treasury Portal, cryptographic key management and token-based authentication for API access, and access granted on a least-privilege, need-to-know basis.

  • Encryption: Personal data and transaction data are encrypted in transit (TLS 1.2 or higher) and at rest.

  • Testing and Review: Regular security assessments, vulnerability scans, and independent third-party penetration testing.

  • Change Management: All production changes, including to the API and Treasury Portal, go through a formal change management process including security review, testing, and approval.

These measures are designed to comply with the security, integrity, and confidentiality requirements of NDPA Section 39.

9. Cookies and Tracking Technologies

Like most websites and applications, we use cookies and similar technologies to operate and improve our Services.

  • Consent Tool: In Nigeria, non-essential tracking is blocked by default. We will ask you to affirmatively accept non-essential tracking before it starts. You can change or withdraw your consent at any time using the floating cookie icon (Universal Preference Centre) on our website.

  • Session Recording and Heatmaps: We use session replay tools, such as Microsoft Clarity, to record clicks, mouse movements, and scrolling activity to improve platform usability. These tools mask keystrokes and sensitive personal data before transmission to us.

  • B2B Lead Profiling and Scoring: For B2B clients, we connect your past website browsing history and referral source with your CRM profile once you complete a form, to help our sales team assess your interest.

  • First-Touch Attribution Cookie: A persistent cookie lasting 180 days captures the external referring URL that first brought you to Yellow Card, to attribute B2B acquisition costs.

  • Advertising and Analytics Pixels: We use LinkedIn Insight Tag, X (Twitter) Pixel, Google Ads and Google Analytics 4, and Meta Pixel to measure advertising effectiveness.

  • Offline Conversion Tracking: When a B2B lead progresses through our sales funnel, we send hashed identifiers (email address, phone number) and conversion event data server-to-server to advertising partners such as Meta and LinkedIn, to measure return on ad spend, suppress existing leads from new acquisition ads, and build lookalike audiences. Because this transfer is server-to-server, browser ad blockers cannot prevent it. You can opt out via the Universal Preference Centre or by contacting our Data Protection Officer.

  • Note on Personal Data: Cookies are personal data only when linked to other identifying information you have provided. Restricting cookies may affect the functionality of our Services.

10. Your Rights as a Data Subject

Under the NDPA, you have the following rights:

  • Right to Withdraw Consent (Section 35): Withdraw consent at any time where processing is based on it. Withdrawal takes effect from the moment we receive your request and does not affect the lawfulness of prior processing.

  • Right to Access (Section 34(1)(a)): Confirmation of whether we process your data, and if so, the purposes, categories of data, recipients, retention period or criteria for determining it, your rights, the right to complain to the NDPC, the source of the data, and details of any automated decision-making.

  • Right to a Copy of Your Data (Section 34(1)(b)): A copy of your personal data in a commonly used electronic format.

  • Right to Rectification (Section 34(1)(c)): Correction, or deletion where correction is not feasible, of personal data that is inaccurate, out of date, incomplete, or misleading.

  • Right to Erasure (Section 34(1)(d) and 34(2)): Erasure of your personal data without undue delay, where the data is no longer necessary for the purpose for which it was collected, or we have no other lawful basis to retain it. We may continue processing where necessary to establish, exercise, or defend a legal claim, or to comply with a legal obligation.

  • Right to Restriction of Processing (Section 34(1)(e)): Restriction of processing pending resolution of a request you have raised, pending an objection you have made, or where the data is retained solely for the establishment, exercise, or defence of legal claims.

  • Right to Object (Section 36): Object at any time to processing based on our legitimate interests. Where you object to processing for direct marketing, including related profiling, we will stop that processing. Where you object on other grounds, we will stop processing unless we can demonstrate an overriding public interest or other legitimate ground.

  • Right Not to Be Subject to Solely Automated Decision-Making (Section 37): You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. This does not apply where the decision is necessary for a contract with you, authorised by law, or based on your consent, and in each case we will offer human intervention, the ability to express your view, and the ability to contest the decision.

  • Right to Data Portability (Section 38): The NDPA allows the NDPC to make regulations establishing a right of data portability; this right is not yet in force by operation of the Act itself. Where technically feasible and pending any such regulation, we will endeavour to provide your data in a structured, commonly used, machine-readable format on request.

  • Right to Lodge a Complaint: You may lodge a complaint with the Nigeria Data Protection Commission if you consider your data protection rights have been violated.

Response Times: We aim to respond to requests exercising these rights within one month of receipt, or such shorter period as required by applicable law. Where a request is complex, we may extend this period, and we will tell you about any extension within the initial one-month period.

To exercise any of these rights, contact our Data Protection Officer at Dataprotection@yellowcard.io.

11. Voluntariness of Providing Personal Data

Providing your personal data is voluntary. However, it is necessary for us to contact you, to conclude and perform our contract with you, and to provide Yellow Card Services. If you do not provide the required data, we may be unable to serve you

12. Automated Decision-Making and Profiling

We may use your data on preferences, behaviour, and marketing engagement to support automated decisions, for example in relation to KYC risk scoring, fraud detection, or transaction limits. Where automated decision-making significantly affects you, you have the rights described in Section 10, including the right to human intervention and the right to object.

13. Privacy of Children Under 18

You must be at least eighteen years old to use Yellow Card Services. By using our Services, you confirm you are at least eighteen. Yellow Card does not knowingly or intentionally collect personal data from anyone under 18. Where NDPA Section 31 requires parental or guardian consent for a data subject who is a child, we will apply the safeguards required by that section.

14. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes through a notice on the Website. The "Updated" date at the top of this Policy will be revised accordingly.

14. Contact Us

Contact the Controller by email at Dataprotection@yellowcard.io or through our Support Page with any questions or concerns regarding this Privacy Policy.