Privacy Policy
How ONEBANQ collects, uses, and protects your personal data. The short green lines are plain-language summaries; the full text below them is what applies.
NDPR Audit FiledNigeria Data Protection Commission · 2025
arrow_outward
Your Rights at a Glance
You can exercise all of these from the Privacy and Data Rights hub inside the app, or by writing to our Data Protection Officer.
1. Who We Are
smsIn short: ONEBANQ Technologies Limited is responsible for your data and is registered with the NDPC.
ONEBANQ Technologies Limited (“ONEBANQ”, “we”, “us”) is the data controller of personal data processed through the ONEBANQ mobile application, website (theonebanq.com), and zero-interest credit card services. We are registered (or have applied for registration) as a data controller with the Nigeria Data Protection Commission (NDPC) and comply with the Nigeria Data Protection Act, 2023 (NDPA) and the NDPC General Application and Implementation Directive (GAID), 2025.
Our Data Protection Officer (DPO) can be reached at support@theonebanq.com (attn: Data Protection Officer) or by post at No 6, Mokola-UCH Road, Ibadan, Oyo State, 200221.
2. Personal Data We Collect
smsIn short: identity, contact, financial, and credit data. Never your contacts, photos, or call logs.
| Category | Examples | Source |
|---|---|---|
| Identity data | Full name, date of birth, gender, BVN, NIN, ID documents, selfie/liveness images | You |
| Contact data | Phone number, email address, residential address | You |
| Financial data | Bank account details, transaction history, income indicators | You; Mono (with your consent) |
| Credit data | Credit bureau reports, repayment history, credit score | First Central Credit Bureau; our records |
| Transaction data | Card spend, airtime, data, and electricity purchases, repayments | Your use of the Services |
| Device and technical data | Device ID, IP address, app version, log and crash data | Your device |
| Communications data | Support conversations, complaints, survey responses | You |
We do not collect or access your phone contacts, photo gallery, or call logs, and we do not use such data for credit scoring or recovery.
3. Why We Process Your Data and Lawful Bases
smsIn short: every use of your data has a legal basis, and consent can be withdrawn at any time.
| Purpose | Lawful basis (NDPA s.25) |
|---|---|
| Identity verification and onboarding (KYC) | Legal obligation; contract |
| Credit assessment and setting your credit limit | Contract; legitimate interest |
| Issuing and operating your card; processing transactions and repayments | Contract |
| Bank data access through open banking (Mono) | Consent |
| Credit bureau checks and default reporting | Legal obligation; legitimate interest |
| Fraud prevention, security, anti-money laundering | Legal obligation |
| Customer support and complaint handling | Contract; legal obligation |
| Service notifications and statements | Contract |
| Marketing communications | Consent (opt-out at any time) |
| Product analytics and service improvement | Legitimate interest (aggregated or pseudonymised where possible) |
Where we rely on consent, it is requested clearly and specifically, and you may withdraw it at any time without affecting processing carried out before withdrawal.
4. Who We Share Data With
smsIn short: only the partners needed to run the service. We never sell your data.
We share personal data only where necessary and under written agreements that meet NDPA standards:
- Verve (card scheme) and card issuing/processing partners, to issue and operate your card.
- Mono, to retrieve your bank transaction data with your consent.
- First Central Credit Bureau and other licensed credit bureaux, for credit checks and statutory credit reporting.
- Quickteller and payment partners, to process airtime, data, and electricity purchases.
- Identity verification providers (BVN/NIN validation), cloud hosting providers, and communications providers.
- Regulators, law enforcement, and courts where required by law (including the FCCPC, NDPC, and CBN).
We never sell your personal data, and we do not share it with third parties for their own marketing.
5. International Transfers
smsIn short: your data stays in Nigeria, except under NDPC-approved safeguards.
Your data is stored primarily in Nigeria. Where a service provider processes data outside Nigeria (for example, cloud hosting), we transfer only to countries with adequate protection as recognised by the NDPC, or under contractual safeguards and conditions permitted by Part VIII of the NDPA.
6. How Long We Keep Data
smsIn short: only as long as the law and the service require, then securely deleted.
| Data | Retention period |
|---|---|
| KYC and identity records | At least 5 years after the relationship ends (statutory AML requirement) |
| Transaction and repayment records | At least 5 years after the relevant transaction |
| Credit decision records | 5 years from decision |
| Support and complaint records | 3 years from closure |
| Marketing preferences | Until consent is withdrawn |
When retention periods expire, data is securely deleted or irreversibly anonymised.
7. Your Rights
smsIn short: access, correct, delete, restrict, export, withdraw consent, and ask a human to review automated decisions.
Under the NDPA you have the right to:
- Access the personal data we hold about you and obtain a copy.
- Correct inaccurate or incomplete data.
- Request deletion of data we no longer have a lawful basis to keep.
- Restrict or object to processing, including for direct marketing.
- Withdraw consent at any time where processing is based on consent.
- Data portability: receive your data in a structured, commonly used format.
- Not to be subject to a decision based solely on automated processing with significant effects. If your card application is declined by our automated credit assessment, you may request human review.
To exercise any right, contact the DPO at support@theonebanq.com (attn: Data Protection Officer). We respond within the timelines set by the NDPA and GAID, and never charge a fee for a first request. You may lodge a complaint with the NDPC (ndpc.gov.ng) if you are dissatisfied with our response.
8. How We Protect Your Data
smsIn short: encryption, tokenised card data, strict access controls, and annual audits.
- Encryption of data in transit (TLS) and at rest.
- Tokenisation of card data; we do not store full card numbers in plain text.
- Role-based access controls, audit logging, and least-privilege access.
- Annual data protection compliance audits filed with the NDPC through a licensed Data Protection Compliance Organisation (DPCO).
- Staff confidentiality obligations and regular data protection training.
If a personal data breach occurs that is likely to risk your rights, we will notify the NDPC within 72 hours and inform you without undue delay, as required by the NDPA.
9. Cookies and App Analytics
smsIn short: necessary cookies only, analytics with consent, no third-party advertising.
Our website uses strictly necessary cookies and, with your consent, analytics cookies. The app uses analytics SDKs to measure performance and crashes. You can manage cookie preferences through the website banner and limit app analytics in your device settings. We do not use cookies for third-party advertising.
10. Children
smsIn short: ONEBANQ is for adults aged 18 and over.
The Services are for persons aged 18 and over. We do not knowingly process children’s data. If you believe a minor has provided data to us, contact the DPO and we will delete it.
11. Changes to This Policy
smsIn short: material changes come with at least 30 days’ notice.
We will notify you of material changes through the app and your registered email at least 30 days before they take effect. The current version is always available at theonebanq.com/privacy.
12. Contact
smsIn short: write to our DPO, or to the NDPC.
Data Protection Officer, ONEBANQ Technologies Limited, No 6, Mokola-UCH Road, Ibadan, Oyo State, 200221. Email: support@theonebanq.com (attn: Data Protection Officer). Supervisory authority: Nigeria Data Protection Commission (ndpc.gov.ng).