Dexa Logo

Privacy Policy

Effective Date: 12/12/2025

This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our tax automation and filing assistance platform (the "service"). We are committed to processing personal data in accordance with the Nigeria Data Protection Act (NDPA) 2023 and all subsidiary data protection regulations.

By accessing or using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.

1. Data Controller Information

  • The data controller responsible for processing your personal data is:
  • b) Company Logo
  • c) Address: [insert address]
  • d) Email: [insert contact address]
  • e) We may appoint a Data Protection Officer (DPO) as required by NDPA. Contact details will be published if applicable.

2. Categories of Personal Data We Collect

We may collect and process the following information:

Identity & Contact Information

  • Full Name
  • Phone Number
  • Email Address
  • TIN | Chat Identification Number
  • Medical & Identification Number (MIN) (If required for tax purposes)

Financial & Transaction Data (with consent)

  • Account transaction history
  • Bank account metadata (via licensed Open Banking provider)
  • Payment confirmation

Tax ID

  • Tax filing history
  • Generated tax computation reports
  • Payment receipts and remittances

Technical Data

  • Device Information
  • IP address
  • Conduct and usage analytics

Authentication Data

  • API authentication tokens
  • Session logs

Note: We do not store your bank login credentials. All financial access is via secure bank API tokens from licensed Open Banking providers.

3. Lawful Basis for Processing

We process your data under the following NDPA lawful bases:

  • Purpose
  • NDPA Basis
  • Access to transaction history
  • Consent
  • Tax computations & filing
  • Contract + Consent
  • Communication & support
  • Legitimate Interest
  • Regulatory reporting
  • Legal obligation
  • Fraud & security
  • Legitimate interest

Note: We will obtain explicit consent before accessing financial data or acting on tax-related tasks on your behalf.

4. Purpose of Data Processing

  • a) Provide automated tax calculation services
  • b) Assist in tax planning and filing preparation
  • c) Connect with your financial institution via licensed open banking APIs
  • d) Generate and complete tax returns
  • e) Provide support and manage tax receipts
  • f) Improve the Service and ensure security
  • g) We do not use your data for marketing without explicit consent.

5. Data Sharing & Third Parties

We may share data only with:

  • a) Licensed Open Banking providers
  • b) Payment processors
  • c) Tax authorities (FIRS, LIRS, JTB) when filing on your instruction
  • d) Cloud hosting and security providers
  • e) Regulatory authorities where required

We do not sell personal data.

All third parties must comply with the NDPA and maintain strict confidentiality.

6. International Data Transfers

  • a) Where data is to be processed outside Nigeria, we:
  • b) Ensure NDPA-compliant safeguards are implemented
  • c) Use countries with adequate protection or apply appropriate contractual clauses

7. Data Retention

  • a) We retain data only as long as necessary, including:
  • b) Up to 7 years for tax regulatory audit obligations
  • c) Shorter periods for compliance session logs unless retained for security
  • d) You may request deletion where legally permitted.

8. Your Rights under NDPA

You have the right to:

  • a) Access your data
  • b) Request correction or deletion
  • c) Withdraw consent
  • d) Object to processing
  • e) Request data portability
  • f) Lodge complaints with the Nigeria Data Protection Commission (NDPC)

Note: To exercise your rights, contact us at [support email].

9. Security Measures

We employ:

  • a) Encryption
  • b) Tokenised financial access (no credential storage)
  • c) Multi-Factor authentication (MFA)
  • d) Access control
  • e) Routine data protection assessments

10. Children's Data

  • a) This Service is not intended for individuals under 18.
  • b) We do not knowingly process minors' data.

11. Cookies & Tracking

We use cookies for:

  • a) Authentication
  • b) Session management
  • c) Service improvement

You may manage cookie settings via your browser.

12. Updates to This Policy

  • a) We may update this policy periodically.
  • b) The updated version will include an updated 'Effective Date'.

13. Contact Information

For privacy inquiries or complaints:

  • a) Email: [insert]
  • b) Address: [insert]

By using this Service, you acknowledge that you have read and understood this Privacy Policy.