How we handle your data.
We collect only what we need to run the Platform, process payouts, and keep your account secure. This page explains exactly what we collect, why, who we share it with, and the rights you have under the Nigeria Data Protection Regulation (NDPR).
NairaFunded ("we", "us", "our") is the data controller for the personal information described in this Privacy Policy. We are committed to handling your data fairly, lawfully, and transparently in line with the Nigeria Data Protection Regulation (NDPR) issued by the National Information Technology Development Agency (NITDA) and any other applicable data-protection law.
This Policy applies to all personal data we collect through the NairaFunded website, mobile applications, MT5 trading platform, and any other service we operate. It does not apply to third-party services we link to (such as payment processors or identity-verification partners) — those services have their own privacy policies.
1. Information We Collect
We collect the following categories of personal data. We only collect what we need for the purposes set out in Section 2; we do not collect sensitive personal data (such as biometrics, health, or political opinions) except where strictly required for KYC.
Account information: full name, email address, phone number, date of birth, nationality, country of residence, and account credentials (username, password).
KYC and identity information: government-issued photo ID number, BVN, address, photograph of the ID, and a selfie holding the ID. We may also collect the issuer, issue date, and expiry date of the ID.
Financial information: bank account details (account number, bank name, account holder name) used for payouts, and transaction history.
Trading data: every order placed, every modification, every position opened or closed, your equity curve, your drawdown metrics, and your platform session metadata (login time, IP address, device fingerprint).
Communications: any message you send us through the contact form, email, WhatsApp, or social media; the metadata of those messages (timestamp, channel); and any call recordings of support calls (with your consent at the start of the call).
Technical data: IP address, browser type and version, device type, operating system, referring URL, pages visited, and cookies (see Section 5).
2. How We Use Your Information
We use the personal data we collect for the following purposes. Each purpose is grounded in a legal basis under the NDPR — either your consent, the performance of a contract with you, a legal obligation we are subject to, or our legitimate interests in running a secure and compliant platform.
To operate the Platform and provide our services: creating and maintaining your account, processing your challenge purchase, evaluating your trading performance, operating the funded account, and processing payouts.
To verify your identity and comply with anti-money-laundering (AML) and counter-terrorism-financing (CTF) laws: performing KYC, screening against sanctions lists, and monitoring for suspicious transaction patterns.
To prevent fraud and protect the integrity of the Platform: detecting duplicate accounts, coordinated trading, prohibited strategies, account takeovers, and unauthorised access.
To communicate with you: sending service announcements, payout confirmations, policy updates, and (where you have opted in) marketing communications. You can opt out of marketing at any time by clicking "unsubscribe" in any marketing email or contacting support.
To improve the Platform: analysing usage patterns, identifying bugs, and developing new features. Where possible we use aggregated, de-identified data for these purposes.
To comply with legal obligations: responding to lawful requests from regulators, tax authorities, and law-enforcement agencies; maintaining records as required by Nigerian law; and enforcing our Terms.
3. Legal Basis for Processing
Under the NDPR, every piece of personal data we process must be grounded in one or more of the following legal bases. We document the legal basis for each processing activity in our internal records of processing.
Consent: where you have given us clear, affirmative consent to process your data for a specific purpose (for example, marketing emails or call recording). You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Contract: where processing is necessary to perform the contract you have entered into with us (for example, processing your payout requires processing your bank details).
Legal obligation: where processing is necessary to comply with a legal obligation to which we are subject (for example, KYC under AML regulations, record-keeping under tax law, or responding to a court order).
Legitimate interests: where processing is necessary for our legitimate interests in operating a secure and profitable business, provided those interests are not overridden by your fundamental rights and freedoms. We balance our interests against yours on a case-by-case basis and document the assessment.
6. Data Security
We take the security of your personal data seriously. We use a combination of technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction. These measures include:
Encryption in transit (TLS 1.3) and at rest (AES-256) for all personal data.
Role-based access controls so that only staff with a legitimate need can access personal data, and only the minimum data necessary.
Multi-factor authentication on all staff accounts with access to personal data.
Regular penetration testing by an independent third-party security firm.
24/7 monitoring of our infrastructure for suspicious activity.
A documented incident response plan and a designated Data Protection Officer who oversees any data breach notification within the NDPR-mandated 72-hour window.
Despite our efforts, no system is 100% secure. If we become aware of a data breach affecting your personal information, we will notify you and the relevant supervisory authority in accordance with the NDPR.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which we collected it, including (but not limited to) the purposes of satisfying any legal, accounting, or reporting requirements.
Account and trading data: retained for the lifetime of your account plus 7 years after closure, in line with Nigerian tax law and AML record-keeping requirements.
KYC data: retained for 5 years after the end of the business relationship, in line with the Money Laundering (Prohibition) Act 2011 (as amended).
Marketing data: retained until you opt out, after which we delete it from our active systems within 30 days (and from backups within 90 days).
Support communications: retained for 3 years for quality and training purposes, after which they are anonymised.
On expiry of the retention period we either delete the data or anonymise it so it can no longer be associated with you. Anonymised data may be retained indefinitely for statistical and research purposes.
8. Your Rights
Under the NDPR you have the following rights in respect of your personal data. We will respond to all verified requests within 30 days. There is no charge for making a request, although we may charge a reasonable fee for requests that are manifestly unfounded or excessive.
- Right of access — request a copy of the personal data we hold about you
- Right of rectification — correct any inaccurate or incomplete personal data
- Right of erasure — request deletion of your personal data, subject to our legal retention obligations
- Right to restrict processing — limit how we use your data while a complaint is being investigated
- Right to data portability — receive your data in a structured, machine-readable format and transmit it to another controller
- Right to object — object to processing based on our legitimate interests, including direct marketing
- Right to withdraw consent — where we rely on consent, withdraw it at any time without affecting prior lawful processing
- Right to lodge a complaint — with the Nigeria Data Protection Commission (NDPC) if you believe we have breached your rights
9. International Data Transfers
We are based in Nigeria and your personal data is primarily stored and processed in Nigeria. Some of our service providers (cloud hosting, KYC vendors, payment processors) may be located in other countries. When we transfer your personal data outside Nigeria, we ensure the transfer is permitted under the NDPR by one of the following mechanisms:
The destination country has been adjudged by the NDPC to provide an adequate level of data protection.
We have put in place binding contractual clauses with the recipient that oblige them to handle your data to the same standard as the NDPR requires.
You have given explicit consent to the transfer after being informed of the possible risks.
The transfer is necessary for the performance of a contract with you or for the implementation of pre-contractual measures taken at your request (for example, processing a payout via an international banking partner).
A list of the countries we transfer data to and the safeguard used for each is available on request from our Data Protection Officer.
10. Children's Privacy
The Platform is not intended for use by anyone under the age of 18 (or the age of legal majority in their jurisdiction, whichever is higher). We do not knowingly collect personal data from anyone under that age.
If we become aware that we have collected personal data from a person under 18 without verifiable parental consent, we will delete that data as soon as possible. If you believe we have collected data from a person under 18, please contact our Data Protection Officer immediately.
11. Third-Party Links & Services
The Platform may contain links to third-party websites or services we do not control (for example, links to MT5 documentation or our liquidity provider's website). This Privacy Policy does not apply to those third-party services. We are not responsible for the privacy practices of any third party.
We encourage you to read the privacy policy of every third-party service that collects your personal data. Where a third-party service is essential to operating the Platform (for example, the MetaTrader 5 platform or our payment processor), we have a data-processing agreement with that service that obliges them to handle your data to the same standard as this Policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to your registered address and by a Platform banner at least 14 days before the changes take effect. Non-material changes (typographical corrections, clarification of existing provisions) may be made without prior notice.
The current version of this Policy is always available at /privacy. The "Last updated" date at the top of the page indicates when the most recent changes were made.
13. Contact & Data Protection Officer
If you have any questions about this Privacy Policy, wish to exercise any of your rights, or want to lodge a complaint, please contact our Data Protection Officer (DPO). The DPO is responsible for overseeing our compliance with the NDPR and is your point of contact for all data-protection matters.
Talk to our Data Protection Officer.
Whether you want a copy of the data we hold on you, want to correct something, or want to lodge a complaint — we answer every privacy request within 30 days.
