1. Who We Are
Investa ("we", "our", "us") is a Nigerian fixed-deposit investment platform that connects retail investors with partner banks. We are the Data Controller of the personal data described in this policy.
Contact: privacy@investaa.online
2. Legal Framework
This policy is issued in compliance with:
- Nigeria Data Protection Act 2023 (NDPA)
- Nigeria Data Protection Regulation 2019 (NDPR)
- Central Bank of Nigeria (CBN) KYC/AML Guidelines
- Money Laundering (Prevention and Prohibition) Act 2022
3. Data We Collect
Account Data
First name, last name, email address, phone number, hashed password, email verification status, account creation date.
Purpose: Creating and managing your account. Basis: Contract (NDPA s.25(1)(b)).
Identity Data (KYC)
National Identification Number (NIN) — stored AES-256 encrypted and as a one-way SHA-256 hash for deduplication only. Photo or scan of your NIN card or slip — stored in private server storage, accessible only to authorised staff.
Purpose: Regulatory identity verification (KYC) required by CBN AML guidelines. Basis: Legal obligation (NDPA s.25(1)(c)) and your explicit consent (NDPA s.25(1)(a)).
Financial & Investment Data
Investment amounts, product selections, maturity dates, payment reference numbers, virtual account details, transaction history, payout records.
Purpose: Executing and managing your investments. Basis: Contract.
Technical Data
IP address (for security audit logs), browser/device type (from user-agent header), session identifiers. We do not use tracking cookies or third-party analytics.
Purpose: Security, fraud prevention, audit trail. Basis: Legitimate interest (NDPA s.25(1)(e)).
Consent Records
Timestamps of when you accepted these Terms and Privacy Policy, and when you provided explicit KYC consent, together with the policy version number.
Purpose: Demonstrating lawful processing under NDPA s.25(1)(a). Basis: Legal obligation.
4. How We Use Your Data
- Creating and securing your account
- Processing and managing your investments
- Complying with KYC/AML regulatory requirements
- Sending transactional emails (payment confirmations, maturity notices, certificates)
- Detecting and preventing fraud and unauthorised access
- Maintaining an audit trail of significant account and financial actions
We do not sell your data, use it for marketing without separate consent, or profile you for advertising.
5. Third-Party Sharing
Paystack (Stripe Technology Ltd) — Payment processing, virtual account creation, and fund transfers. Your name and phone number are shared to create your Paystack customer profile. Paystack is bound by its own Privacy Policy and PCI DSS standards.
Partner Banks — Your investment details are shared with the specific partner bank managing your fixed deposit, for account booking and settlement purposes only.
Identity Providers (Smile Identity / NIMC) — When the production NIN verification service is enabled, your NIN will be transmitted over TLS to the provider for identity matching. The response is encrypted before storage.
Regulatory Authorities — We will disclose data to the CBN, NDPC, EFCC, or law enforcement when required by law.
6. Data Retention
| Data Category |
Retention Period |
| Account data | 5 years after account closure |
| KYC / NIN data & document | 6 years after the last transaction (AML Act requirement) |
| Investment & financial records | 6 years after maturity (CAMA 2020 s.381) |
| Audit logs | 3 years |
| Technical / security logs | 90 days |
7. Security Measures
- NIN stored as AES-256 ciphertext (Laravel Crypt) — decryptable only with the server-side key
- KYC documents stored in non-public server storage, access-logged on every download
- Passwords hashed with bcrypt (cost factor 12)
- All traffic over HTTPS/TLS 1.2+
- Admin accounts require two-factor authentication (TOTP)
- Every admin action on your data is logged with timestamp and IP address
8. Your Rights Under the NDPA 2023
Under the Nigeria Data Protection Act 2023 (Sections 34–42), you have the following rights:
Right to Information: Know what personal data we hold about you and how it is processed.
Right of Access: Request a copy of the personal data we hold about you.
Right to Rectification: Correct inaccurate personal data. Update your profile in account settings or contact us.
Right to Erasure: Request deletion of your personal data. Note: KYC and financial records must be retained for the periods above under AML regulations.
Right to Restrict Processing: Ask us to limit processing while a complaint is being resolved.
Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format.
Right to Object: Object to processing based on legitimate interests.
Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time — this does not affect lawfulness of prior processing.
To exercise any right, email privacy@investaa.online. We will respond within 30 days.
10. Changes to This Policy
We may update this policy as our services or the law changes. Material changes will be notified by email at least 14 days in advance. Continued use of Investa after the effective date constitutes acceptance. The version number and effective date at the top of this page will always reflect the current policy.
© 2026 Investa. All rights reserved.
·
Terms of Service