Last updated: 20 July 2026

Privacy Policy

Paidrex Technologies Limited respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, store, disclose and protect personal data when you:

  • Visit https://paidrextech.com/;

  • Submit a contact or project-enquiry form;

  • Communicate with us by email, telephone or social media;

  • Request information about our services;

  • Engage us for a technology project;

  • Request financial or technical support;

  • Apply to use a Paidrex product;

  • Use Paidrex Mobile or another service where this Policy is referenced; or

  • Otherwise interact with Paidrex Technologies Limited.

This Policy should be read together with our Terms and Conditions and any product-specific privacy notice presented within a Paidrex application or service.

1. Who We Are

Paidrex Technologies Limited is a technology and fintech company based in Lagos, Nigeria.

For the personal data covered by this Privacy Policy, Paidrex Technologies Limited generally acts as the data controller, meaning that we determine why and how the data is processed.

For some enterprise technology projects, we may process personal data solely on the instructions of a business customer. In those circumstances, the business customer may be the data controller and Paidrex Technologies Limited may act as a data processor.

2. Applicable Data-Protection Law

We process personal data in accordance with applicable Nigerian data-protection and privacy laws, including the Nigeria Data Protection Act 2023 and applicable directives, regulations and guidance issued by the Nigeria Data Protection Commission.

Where we offer services to individuals in another jurisdiction, additional local privacy requirements may apply.

3. Personal Data We Collect

The information we collect depends on how you interact with us.

3.1 Information you provide through the website

When you complete our contact form or communicate with us, we may collect:

  • Full name;

  • Email address;

  • Telephone number;

  • Company or organisation name;

  • Service of interest;

  • Enquiry subject;

  • Message or project requirements;

  • Documents or files you choose to provide;

  • Preferred communication method; and

  • Other information included in your correspondence.

3.2 Business and project information

When you request or purchase technology services, we may collect:

  • Business name and registration details;

  • Business address;

  • Names and contact details of representatives;

  • Project requirements and technical specifications;

  • Contracts, proposals and statements of work;

  • Billing and invoicing information;

  • Payment status and transaction references;

  • User-account information;

  • System-access details provided for project delivery;

  • Support requests and communication records;

  • Technical documentation;

  • Software, databases or content supplied for a project; and

  • Information needed to manage the customer relationship.

Customers should avoid sharing production passwords or unrestricted credentials through ordinary email or website forms. Secure access methods should be used for sensitive technical information.

3.3 Identity and compliance information

For financial services, wallet services, transaction services or regulated functionality, we may collect information required for identity verification, fraud prevention and regulatory compliance, including:

  • Full legal name;

  • Date of birth;

  • Residential address;

  • Telephone number and email address;

  • Nationality;

  • Government-issued identity-document details;

  • Bank Verification Number, National Identification Number or equivalent identifiers where legally required;

  • Photograph or facial-verification data;

  • Proof of address;

  • Occupation and employment information;

  • Business-registration information;

  • Tax or company identification numbers;

  • Beneficial ownership information;

  • Source-of-funds information;

  • Transaction purpose;

  • Sanctions and politically exposed person screening results; and

  • Other Know Your Customer or anti-money-laundering information.

Sensitive identity or biometric information will only be collected where necessary and permitted by law. A product-specific privacy notice may provide further information before such data is collected.

3.4 Account and Paidrex Mobile information

Where you create or use a Paidrex account, we may collect:

  • Username or customer identifier;

  • Account credentials in protected form;

  • Telephone number and email address;

  • Device registration information;

  • Security questions or authentication settings;

  • Wallet or account balance information;

  • Beneficiary details;

  • Transaction history;

  • Bill-payment, airtime and data-purchase records;

  • Customer-support records;

  • Login and account-activity history;

  • Fraud-risk indicators; and

  • Account preferences.

Passwords, PINs and similar credentials should be stored using appropriate security controls. We will not ask you to disclose your complete password, PIN or one-time password through an unsolicited communication.

3.5 Transaction information

When you use a payment or financial service, we may collect:

  • Transaction amount;

  • Date and time;

  • Currency;

  • Sender and recipient information;

  • Bank or wallet account identifiers;

  • Beneficiary details;

  • Payment purpose or narration;

  • Transaction status;

  • Fees and charges;

  • Reversal, refund or dispute information;

  • Device and location indicators associated with the transaction;

  • Payment-channel information; and

  • Fraud, compliance or risk-review information.

We do not necessarily receive or store complete payment-card details where payment processing is handled by an authorised third-party processor.

3.6 Technical and device information

When you visit the website or use a Paidrex digital service, we may automatically collect:

  • Internet Protocol address;

  • Browser type and version;

  • Device type;

  • Operating system;

  • Language and time-zone settings;

  • Referring website;

  • Pages viewed;

  • Date and time of access;

  • Clickstream and navigation information;

  • Session identifiers;

  • Crash and diagnostic data;

  • Application version;

  • Device identifiers;

  • Network information; and

  • Security and fraud-detection logs.

3.7 Location information

We may infer an approximate location from an IP address.

Where a mobile application requires more precise location information for security, fraud prevention, regulatory compliance or a location-based feature, we will request the appropriate device permission where required.

3.8 Communications

We may record or retain communications between you and Paidrex, including:

  • Emails;

  • Contact-form submissions;

  • Customer-support messages;

  • Telephone-call notes;

  • Social-media messages;

  • Complaint correspondence; and

  • Service notifications.

Calls may be recorded for quality, security, training or dispute-resolution purposes where permitted by law and after appropriate notice.

3.9 Information from third parties

We may receive information from:

  • Banks and financial institutions;

  • Payment processors;

  • Identity-verification providers;

  • Credit-reference or fraud-prevention providers where legally permitted;

  • Mobile-network operators;

  • Utility and bill-payment providers;

  • Business customers;

  • Public company registries;

  • Sanctions and compliance databases;

  • Social-media services;

  • Analytics and security providers;

  • Professional advisers; and

  • Government, judicial or regulatory authorities.

4. How We Use Personal Data

We may process personal data to:

4.1 Respond to enquiries

We use contact information and enquiry details to:

  • Respond to questions;

  • Understand project requirements;

  • Recommend suitable services;

  • Prepare quotations and proposals;

  • Arrange meetings;

  • Provide technical support; and

  • Maintain records of communications.

4.2 Provide technology services

We use customer and project information to:

  • Deliver software, web, mobile, cloud and enterprise IT services;

  • Configure and integrate systems;

  • Manage projects and milestones;

  • Test and deploy solutions;

  • Provide maintenance and support;

  • Manage customer relationships;

  • Issue invoices and receive payments; and

  • Enforce contractual rights.

4.3 Operate financial products and transactions

Where applicable, we use personal data to:

  • Create and manage customer accounts;

  • Process wallet funding and transfers;

  • Facilitate bill payments;

  • Process airtime and data purchases;

  • Maintain beneficiary information;

  • Display transaction histories;

  • Calculate fees;

  • Process reversals and refunds;

  • Investigate failed or disputed transactions; and

  • Communicate transaction status.

4.4 Verify identity and comply with legal obligations

We may use personal data to:

  • Verify identity;

  • Perform Know Your Customer checks;

  • Conduct anti-money-laundering checks;

  • Screen against sanctions or watchlists;

  • Verify beneficial ownership;

  • Monitor transactions;

  • Detect suspicious activity;

  • Respond to lawful regulatory requests;

  • Maintain legally required records; and

  • Submit reports required by law or an authorised regulator.

4.5 Protect security and prevent fraud

We process technical, account and transaction information to:

  • Authenticate users;

  • Prevent unauthorised access;

  • Identify unusual account activity;

  • Detect fraud and cybersecurity threats;

  • Protect our website, customers and systems;

  • Investigate security incidents;

  • Enforce transaction limits;

  • Maintain audit logs; and

  • Improve security controls.

4.6 Improve our website and services

We may analyse usage and diagnostic information to:

  • Understand how visitors use the website;

  • Improve design and navigation;

  • Identify technical problems;

  • Test new features;

  • Monitor performance;

  • Improve accessibility and user experience;

  • Develop new products; and

  • Measure service effectiveness.

Where reasonably possible, aggregated or de-identified information will be used for analytics and product development.

4.7 Communicate with you

We may send:

  • Responses to enquiries;

  • Project updates;

  • Account and security notifications;

  • Transaction notifications;

  • Service announcements;

  • Maintenance notices;

  • Compliance requests;

  • Changes to legal terms; and

  • Customer-support communications.

These operational communications are not marketing messages and may be necessary for the service.

4.8 Marketing

Where permitted by law, we may use your contact details to send information about Paidrex products, services, events or updates.

You may unsubscribe from marketing messages at any time by:

Opting out of marketing will not prevent us from sending essential account, transaction, security or service communications.

4.9 Establish, exercise or defend legal claims

We may process and retain information where reasonably necessary to:

  • Enforce contracts;

  • Recover debts;

  • Resolve disputes;

  • Respond to complaints;

  • Protect our legal rights;

  • Defend legal proceedings; or

  • Comply with court orders.

5. Lawful Bases for Processing

Depending on the circumstances, we rely on one or more of the following lawful bases:

5.1 Consent

We may rely on your consent for activities such as:

  • Optional marketing;

  • Non-essential cookies;

  • Certain device permissions;

  • Optional biometric processing; or

  • Other processing for which consent is appropriate.

You may withdraw consent at any time. Withdrawal will not affect processing carried out lawfully before the withdrawal.

5.2 Contract

We process personal data where necessary to:

  • Take steps at your request before entering into a contract;

  • Provide a requested service;

  • Manage an account;

  • Process a transaction; or

  • Perform a contract with you.

5.3 Legal obligation

We process information where necessary to comply with laws and regulatory requirements relating to:

  • Identity verification;

  • Financial recordkeeping;

  • Anti-money laundering;

  • Fraud prevention;

  • Tax;

  • Consumer protection;

  • Data protection;

  • Cybersecurity; or

  • Lawful requests from public authorities.

5.4 Legitimate interests

We may process personal data where necessary for legitimate business interests, provided those interests are not overridden by your rights.

These interests may include:

  • Responding to business enquiries;

  • Securing our website and systems;

  • Preventing fraud;

  • Improving our services;

  • Managing customer relationships;

  • Maintaining business records;

  • Establishing legal claims; and

  • Conducting proportionate business-to-business marketing.

5.5 Public interest and other recognised lawful bases

Where applicable, we may process information where necessary for a task carried out in the public interest, to protect vital interests or under another lawful basis recognised by applicable law.

6. Cookies and Similar Technologies

Our website may use cookies, pixels, local storage, tags and similar technologies.

Cookies are small files stored on your device. They may be used to:

  • Enable core website functions;

  • Maintain security;

  • Remember preferences;

  • Analyse website traffic;

  • Measure performance;

  • Prevent fraud; and

  • Support embedded or third-party content.

Types of cookies

Strictly necessary cookies:
Required for security, navigation, form submission and essential website functionality.

Preference cookies:
Remember choices such as language or display settings.

Analytics cookies:
Help us understand website usage and improve performance.

Marketing cookies:
May be used to measure campaigns or deliver more relevant advertising, where applicable.

Where required, we will request consent before placing non-essential cookies.

You may control cookies through your browser settings. Blocking certain cookies may affect website functionality.

7. How We Share Personal Data

We do not sell personal data.

We may share information with the following categories of recipients where necessary and lawful.

7.1 Service providers

These may include providers of:

  • Website hosting;

  • Cloud infrastructure;

  • Email and communication services;

  • Customer-support systems;

  • Analytics;

  • Cybersecurity;

  • Software development;

  • Data storage and backup;

  • Identity verification;

  • Fraud detection;

  • Payment processing; and

  • Professional services.

Service providers may process data only for authorised purposes and are expected to protect it appropriately.

7.2 Banks and financial-service partners

For financial transactions or related services, information may be shared with:

  • Banks;

  • Licensed financial institutions;

  • Payment processors;

  • Card networks;

  • Settlement providers;

  • Wallet providers;

  • Mobile-money operators;

  • Currency-exchange partners;

  • Remittance providers; and

  • Bill-payment or telecommunications providers.

7.3 Business customers

Where Paidrex processes data on behalf of an enterprise customer, information may be made available to that customer in accordance with its instructions and the applicable agreement.

7.4 Professional advisers

We may share information with lawyers, accountants, auditors, insurers, consultants and other professional advisers where reasonably necessary.

7.5 Regulators and public authorities

We may disclose information to:

  • Courts;

  • Law-enforcement agencies;

  • Tax authorities;

  • Financial regulators;

  • Data-protection authorities;

  • Government agencies; or

  • Other authorised public bodies.

Disclosure may occur where required by law or reasonably necessary to investigate fraud, comply with a lawful request or protect legal rights.

7.6 Corporate transactions

Information may be disclosed in connection with a proposed or completed:

  • Merger;

  • Acquisition;

  • Investment;

  • Financing;

  • Reorganisation;

  • Sale of assets; or

  • Transfer of a business or product.

Recipients will be expected to handle personal data in accordance with applicable law.

8. International and Cross-Border Transfers

Some service providers, cloud platforms, development tools or financial partners may process information outside Nigeria.

Where personal data is transferred internationally, we will take steps required by applicable law to ensure an appropriate level of protection.

These measures may include:

  • Assessing the destination’s data-protection framework;

  • Using contractual safeguards;

  • Requiring confidentiality and security commitments;

  • Obtaining consent where appropriate;

  • Limiting transferred information; and

  • Relying on another legally recognised transfer mechanism.

9. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, regulatory, accounting, security and dispute-resolution requirements.

Retention periods may vary according to the type of information.

For example:

  • General enquiries may be retained for the period needed to respond and manage follow-up communications;

  • Contract and project records may be retained for the duration of the engagement and an appropriate period afterward;

  • Financial and transaction records may be retained for the period required by financial, tax and anti-money-laundering laws;

  • Identity-verification records may be retained as required by applicable regulation;

  • Security logs may be retained for fraud prevention, investigation and system protection;

  • Marketing information may be retained until you unsubscribe or the information is no longer needed; and

  • Complaint and legal records may be retained until the matter and applicable limitation periods have concluded.

When information is no longer required, it will be deleted, anonymised or securely archived, subject to applicable legal obligations.

10. Data Security

We use reasonable technical and organisational measures designed to protect personal data against:

  • Unauthorised access;

  • Accidental loss;

  • Destruction;

  • Alteration;

  • Misuse;

  • Unlawful disclosure; and

  • Other forms of unlawful processing.

Measures may include:

  • Encryption in transit and, where appropriate, at rest;

  • Access controls;

  • Authentication requirements;

  • Network and application security;

  • Logging and monitoring;

  • Secure development practices;

  • Vulnerability management;

  • Backup and recovery procedures;

  • Staff confidentiality obligations;

  • Vendor-security assessments; and

  • Incident-response procedures.

Access to personal data is limited to persons who require it for authorised business purposes.

Despite these measures, no internet-based service or storage system is completely secure. You should also protect your devices, passwords, PINs and authentication credentials.

11. Personal-Data Breaches

Where a security incident affects personal data, we will assess the nature, scope and potential consequences of the incident.

Where required by applicable law, we will:

  • Notify the Nigeria Data Protection Commission or another relevant authority;

  • Notify affected individuals;

  • Take steps to contain and investigate the incident; and

  • Implement measures to reduce the risk of recurrence.

12. Your Data-Protection Rights

Subject to applicable law and certain exemptions, you may have the right to:

12.1 Be informed

You have the right to receive clear information about how your personal data is processed.

12.2 Access your personal data

You may request confirmation of whether we process your data and request a copy of relevant information.

12.3 Correct inaccurate information

You may ask us to correct inaccurate or incomplete personal data.

12.4 Request deletion

You may request deletion of personal data where there is no lawful reason for us to continue processing it.

Deletion may not be available where information must be retained for legal, regulatory, security, transaction or contractual purposes.

12.5 Restrict processing

You may request that processing be restricted in circumstances recognised by law.

12.6 Object to processing

You may object to processing based on legitimate interests, depending on the circumstances.

You may object to direct marketing at any time.

12.7 Withdraw consent

Where processing is based on consent, you may withdraw that consent at any time.

12.8 Data portability

Where applicable, you may request personal data in a structured, commonly used and machine-readable format or ask that it be transferred to another controller where technically feasible.

12.9 Rights concerning automated decisions

You may have rights relating to decisions based solely on automated processing that produce legal or similarly significant effects.

Paidrex may use automated tools to identify potential fraud or unusual transactions. Where a significant decision is made through automated processing, appropriate safeguards and review procedures will be provided where required by law.

12.10 Complain to a supervisory authority

You may lodge a complaint with the Nigeria Data Protection Commission where you believe that your personal data has been processed unlawfully.

We encourage you to contact us first so that we can attempt to resolve the issue.

13. Exercising Your Rights

To exercise a privacy right, contact:

Email: info@paidrextech.com

Your request should clearly describe:

  • Your name;

  • Your relationship with Paidrex;

  • The right you wish to exercise;

  • The information or account concerned; and

  • Any relevant reference number.

We may request reasonable information to verify your identity before responding. This helps prevent personal data from being disclosed to an unauthorised person.

We will respond within the period required by applicable law. Complex or repeated requests may require additional time where permitted.

We will generally not charge a fee for a legitimate request. A reasonable fee may apply where a request is manifestly unfounded, excessive or repetitive, where permitted by law.

14. Children’s Privacy

Our corporate website and general services are not directed to children under 18.

A person under 18 should not independently create a financial account, submit identity documentation or enter into a paid service contract unless the service expressly permits it and valid consent or authorisation has been obtained.

Where we knowingly process a child’s personal data, we will take steps required by applicable law, including obtaining appropriate consent and applying enhanced safeguards.

Parents or guardians who believe that a child has provided information without proper authorisation should contact us.

15. Biometrics and Sensitive Personal Data

Certain regulated products may use facial verification, identity-document images or other sensitive personal data to confirm identity and prevent fraud.

Where such information is collected:

  • The purpose will be communicated;

  • An appropriate lawful basis will be identified;

  • Access will be restricted;

  • Enhanced security safeguards will be applied;

  • Retention will be limited; and

  • Third-party verification providers will be subject to contractual and legal requirements.

Product-specific details should be presented before biometric or other sensitive personal data is collected.

16. Third-Party Websites and Services

Our website may contain links to external websites, social-media platforms, app stores, banks, payment providers or other services.

We are not responsible for the privacy practices of independent third parties. You should review their privacy notices before submitting personal information.

Where a third party processes data on our behalf, we will take reasonable steps to ensure appropriate contractual and security safeguards.

17. Social Media

When you interact with Paidrex through Facebook, X, Instagram, LinkedIn or another social platform, the platform may independently collect and process information under its own privacy policy.

Information posted publicly on social media may be visible to other users. Do not post passwords, PINs, identity documents, bank details or other sensitive information in public comments.

18. Marketing Preferences

You may ask us to stop sending promotional communications at any time.

You can do this by:

  • Clicking an unsubscribe link where provided;

  • Adjusting available account preferences; or

  • Emailing info@paidrextech.com.

We may retain limited information on a suppression list to ensure that your opt-out preference is respected.

19. Fraud and Phishing Awareness

Fraudsters may attempt to impersonate Paidrex Technologies Limited.

You should verify that communications originate from an authorised Paidrex channel before:

  • Sending money;

  • Providing identity documents;

  • Sharing account information;

  • Clicking a payment link; or

  • Installing software.

Paidrex personnel should never request your complete password, PIN or one-time password through an unsolicited call, email or social-media message.

Suspected fraud or phishing should be reported promptly to info@paidrextech.com.

20. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in:

  • Our products or services;

  • Data-processing practices;

  • Technology;

  • Business operations;

  • Security requirements; or

  • Applicable law.

The updated Policy will be published on this page with a revised “Last updated” date.

Where required, we will provide additional notice of significant changes through the website, application, email or another appropriate channel.

21. Contact Us

Questions, requests or complaints regarding this Privacy Policy may be directed to:

Paidrex Technologies Limited
Lagos, Nigeria
Email: info@paidrextech.com
Website: https://paidrextech.com/

Please include “Privacy Request” or “Data Protection Enquiry” in the subject of your message where appropriate.

22. Complaints to the Nigeria Data Protection Commission

You have the right to contact the Nigeria Data Protection Commission if you believe that your privacy rights have been violated.

Before making a regulatory complaint, you may contact Paidrex Technologies Limited so that we have an opportunity to investigate and resolve your concern.