Effective Date: May 19, 2026
At Filora Finance, protecting your money goes hand-in-hand with securing your data. We adhere strictly to the principle of data minimization and comply fully with Nigeria's Data Protection Act (NDPA) 2023. Rest assured that your biometrics, balance sheets, and linked accounts are sealed with military-grade AES-256 encryption.
This Privacy Policy (the "Policy") defines the contractual and operational rules under which ACE FILORA LIMITED (operating as "Filora Finance", hereinafter referred to as "the Company"), a private limited liability company registered under the laws of the Federal Republic of Nigeria with the Corporate Affairs Commission (CAC), collects, stores, uses, processes, and protects the personal data of users who navigate the website https://filorafinance.org or utilize its personal finance money management dashboard (the "Platform").
The Company processes personal data in absolute conformity with the Nigeria Data Protection Act (NDPA) 2023, the General Application and Implementation Directive (GAID) 2025, and the Central Bank of Nigeria (CBN) Consumer Protection Regulations.
The Company operates as a "Data Controller" when determining the purposes and means of processing personal data, and as a "Data Processor" when acting on behalf of partnering licensed financial institutions.
For any inquiries regarding this Policy or data processing activities, the Company can be contacted via the designated Data Protection Officer (DPO) at the registered address: Plot 12, Financial District, Victoria Island, Lagos, Nigeria, or via email at dpo@filorafinance.org.
Filora Finance operates under strict oversight. The designated DPO audits data transmission channels weekly to verify complete compliance with the GAID 2025 frameworks.
In accordance with Section 25 of the NDPA 2023, the Company is legally prohibited from processing personal data unless a valid, lawful basis has been established. The Company relies on the following legal bases:
Processing is required to create and manage the User's account, provide personal finance money management tools, deliver expense tracking analytics, and facilitate transactions requested by the User.
The Data Subject has provided clear, affirmative, specific, and unambiguous consent for designated processing activities, including marketing communications, third-party analytics, and non-essential cookie tracking.
Processing is necessary to comply with statutory mandates, including anti-money laundering (AML/CFT) laws, Central Bank of Nigeria (CBN) directives, Know Your Customer (KYC) compliance, and tax reporting obligations.
Processing is necessary to protect the Company's legitimate business interests—such as fraud prevention, platform security, and system optimization—provided these do not override the User's fundamental rights and privacy expectations.
Processing is necessary to protect the life, health, or safety of the Data Subject or another individual.
The Company adheres to the principle of data minimization, limiting collection to the minimum personal data necessary to provide its money management services. The categories of personal data collected include:
Full legal name, date of birth, biological sex, nationality, national identification number (NIN), bank verification number (BVN), and a photographic selfie for identity verification.
Physical residential address, verified email address, and mobile phone number.
Bank account details, linked payment card details (processed securely via PCI-DSS compliant third-party gateways), income details, historical expense logs, savings goals, and platform payment history.
Internet Protocol (IP) address, operating system, browser type, device identifiers, and platform navigation data.
Biometric identifiers (such as fingerprint or facial templates) processed solely for secure, localized platform login authentication, subject to the explicit consent requirements of Article 18 of the GAID 2025.
Pursuant to Article 18(1) of the NDP Act-GAID 2025, the Company is legally prohibited from relying on alternate legal bases (such as legitimate interests or contractual necessity) and must obtain the User's separate, prior, and explicit consent before executing the following processing activities:
Processing personal data for any form of direct marketing, including email campaigns, SMS notifications, customized push alerts, or targeted advertisements.
Processing biometric information, financial profiling details, or other sensitive categories defined under the NDPA 2023.
Using previously collected personal data for a new, secondary purpose that is incompatible with the original purpose disclosed to the User.
Processing the personal data of any child under eighteen (18) years of age.
Exporting the personal data of a Nigerian resident to a foreign country that lacks an adequacy determination from the NDPC.
Using automated processing, data profiling, or credit evaluation models that produce legal, binding, or significantly adverse effects on the User.
Under no circumstances does Filora utilize dark patterns or passive opt-ins to satisfy Article 18. Each override activity requires explicit positive action from the user.
In compliance with Section 31 of the NDPA 2023 and the Child Rights Act 2003, the Platform is restricted to individuals who have attained eighteen (18) years of age. A child is defined under Nigerian law as any person below 18 years. The Company enforces the following controls:
The Company will not collect or process the personal data of a child under 18 without obtaining the prior, explicit, and written consent of a parent or legal guardian. This consent must be verified using appropriate technological means.
During the onboarding process, the User must input a valid date of birth and upload a government-approved identity document (NIN, voter's card, driver's license, or international passport). The Platform uses automated verification APIs to cross-reference this information and prevent registration by underage users.
In accordance with Section 31(4) of the NDPA, parental consent is not required where processing is necessary to protect the vital interests of the child, or is carried out for verified educational, medical, or social care purposes by a professional bound by an equivalent statutory duty of confidentiality.
Pursuant to Article 40 of the NDP Act-GAID 2025, the Platform operates a formal Standardized Notice and Grievance (SNAG) protocol. Any Data Subject who reasonably believes that their privacy rights have been infringed may file a formal SNAG according to the following rules:
The Data Subject must download and complete the standardized SNAG Form (Form 2, Schedule 2 of the GAID) available on the Platform and submit it via email to dpo@filorafinance.org.
The Company will issue a formal, timestamped electronic acknowledgement to the Data Subject within forty-eight (48) hours of receipt.
The Company will conduct an internal audit of the complaint and issue a substantive written response to the Data Subject within thirty (30) days. This response will either: Accept the grievance, detailing the specific technical and organizational remediation measures implemented to resolve the violation; or Refute the grievance, providing detailed legal and technical evidence to prove compliance with the NDPA 2023.
If the SNAG remains unresolved after 30 days, or if the Data Subject is unsatisfied with the response, the Data Subject has the right to file a formal complaint with the Nigeria Data Protection Commission (NDPC) or initiate civil litigation in a Nigerian court.
The standardized SNAG Form is downloadable from our resources panel. Acknowledgment is sent electronically and starts the statutory 30-day response window.
In compliance with the "Obstructive Notice Requirement" of Article 7(l) of the NDP Act-GAID 2025, the Platform does not use hidden, passive, or pre-ticked cookie consent banners. The Platform applies the following rules:
Upon first accessing https://filorafinance.org, a high-contrast modal notice will launch. This banner will significantly obstruct the middle, the left, or the right side of the screen. It will not be placed at the bottom where it might be ignored.
The notice serves two buttons of equal size, color, and prominence: "Accept All" and "Decline All". No pre-checked boxes or manipulative design patterns (dark patterns) are permitted.
If the User scrolls past, clicks outside, or navigates the Platform without clicking "Accept All," the platform treats this action as a rejection. All non-essential analytical, tracking, and advertising cookies will remain deactivated.
In accordance with the NDPA 2023, the Data Subject possesses the following statutory rights, which the Company will facilitate free of charge within thirty (30) days of a verified request:
The right to obtain confirmation as to whether their personal data is being processed, and to receive a copy of that data in a structured format. The right to compel the Company to update, correct, or complete inaccurate or incomplete personal data.
The right to demand the deletion of their personal data where the data is no longer necessary for the original purpose, or where consent has been withdrawn. The right to limit data processing under specific circumstances, such as during investigations into the accuracy of the data.
The right to receive their personal data in a structured, machine-readable format and have it transferred directly to another data controller. The right to object at any time to data processing based on legitimate interests or direct marketing.
Where processing is based on consent, the Data Subject has the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent prior to its withdrawal.
The Company implements robust protection rules for data transmission, storage, and cross-border operations in strict accordance with the NDPA 2023 guidelines.
The Company implements strong technical security measures, including AES 256-bit encryption for data at rest, TLS 1.3 encryption for data in transit, multi-factor authentication (MFA) for administrative access, and monthly vulnerability assessments.
The Company will not transfer personal data outside Nigeria unless the destination country has been declared to have adequate data protections by the NDPC. In the absence of an adequacy decision, transfers are restricted unless secured by NDPC-approved Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or the User's explicit, informed consent.
In the event of a personal data breach that is likely to result in a high risk to the rights and freedoms of individuals, the Company will notify the NDPC within seventy-two (72) hours of discovery. The Company will also notify the affected Data Subjects immediately, providing clear recommendations to mitigate potential harm. The Company maintains a detailed internal registry of all data breaches, documenting the facts, effects, and remedial measures taken.
Personal data is retained only for as long as necessary to fulfill the purposes outlined in this Policy, or as required by applicable laws (including CBN financial record-keeping mandates). When personal data is no longer required, the Company will securely delete, destroy, or permanently anonymize it.
Our Data Protection Officer (DPO) is ready to help. Get clarification on the SNAG protocol, consent overrides, or initiate a statutory Subject Access Request (SAR).