Back to Penicent

Legal · Mobile App

Privacy Policy

Last updated 2025-01-01 · Penicent Limited · Plot 8 Providence Street, Lekki, Lagos, Nigeria

No Data SalesNo AdsAES-256 EncryptionNDPA & GDPR

Important Notice — Regulated Financial Services

Penicent is a regulated financial technology company. Unlike standard apps, we are legally required by anti-money laundering (AML) and know-your-customer (KYC) regulations to collect, verify, and retain identity and transaction data. Some data cannot be deleted upon request because deletion would violate our legal obligations. We are transparent about all such cases in Section 5 (Data Retention) and Section 6 (Your Rights).

Introduction

Penicent ("we", "our", or "us") operates the Penicent mobile application ("App"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our platform.

By downloading, installing, or using Penicent, you agree to the data practices described in this policy. If you do not agree, please do not use the App.

This policy applies to all Penicent services — including our mobile app, USSD banking, cross-border payment services, virtual card programme, and the Penicent Rewards Programme — as well as our website at penicent.io.

1. Information We Collect

We may collect the following categories of data:

Personal information you provide

We collect information you directly give us when creating or using your account:

  • · Full name
  • · Email address
  • · Phone number
  • · Login credentials
  • · Uploaded documents and photos (for identity verification)
  • · Profile information
  • · Contact information

Automatically collected information

When you use the App, we automatically collect certain technical data:

  • · Device information (model, operating system, unique identifiers)
  • · IP address
  • · App usage data and session information
  • · Crash logs and error reports
  • · Analytics data
  • · Cookies and similar tracking technologies

Optional permissions

The App may request the following device permissions, only when needed for specific features:

  • · Camera — for profile photos and document upload during KYC
  • · Media & Storage — for saving files and uploading documents
  • · Microphone — if you use our AI-powered voice finance features
  • · Location — if specific features require location confirmation

2. How We Use Your Information

We use the data we collect for the following purposes only:

  • To create and manage your user account
  • To process requests and provide full app functionality
  • To improve app performance and user experience
  • To send important notifications (security alerts, transaction confirmations)
  • To provide customer support
  • To monitor app analytics and prevent fraud
  • To administer the Penicent Rewards Programme based on your activity
  • To comply with legal and regulatory obligations, including KYC/AML requirements
  • To verify your identity and screen against applicable sanctions lists

We do not use your data to build advertising profiles or sell targeted advertising. Penicent does not serve ads.

3. Legal Bases for Processing

If you reside in the EU/EEA, we process your personal data on the following legal bases under GDPR:

Consent

Where you have given us explicit permission — for example, opting into marketing communications or enabling voice history.

Contract performance

To deliver the services you have signed up for, including account management, payment processing, and card issuance.

Legitimate interest

To improve our platform, prevent fraud, and ensure the security of all users on the network.

Legal obligation

To comply with applicable financial regulations, including anti-money laundering (AML) laws, know-your-customer (KYC) requirements, and mandatory reporting to regulators.

Protection of vital interests

In circumstances where processing is necessary to protect the vital interests of any person.

For users in Nigeria, we additionally process data in compliance with the Nigeria Data Protection Act (NDPA). For users in Nigeria, the Nigeria Data Protection Act. For users in Nigeria, POPIA.

4. Sharing of Information

We do not sell personal data. Full stop. We may share your information only in the following limited circumstances:

Service providers

We work with trusted third-party service providers who help us operate the platform — including hosting infrastructure, analytics, authentication, and customer support tooling. Each provider is bound by a Data Processing Agreement and may only use your data to provide their service to us.

Licensed banking partners

As a fintech company, we partner with licensed banking institutions to provide regulated financial services. Your identity and transaction data is shared with banking partners as required to open accounts, process payments, and maintain regulatory compliance.

Third-party integrations

The App integrates with the following services, each governed by their own privacy policy:

  • · Google Play Services
  • · Apple App Services
  • · Firebase Authentication & Analytics
  • · Payment processors

Legal authorities

We may disclose data to law enforcement, financial regulators, or government agencies when required by law. Where legally permitted, we will notify you before complying.

Business transfers

In the event of a merger, acquisition, or asset sale, user data may transfer. You will be notified at least 30 days in advance and given the option to delete your account.

Cloud storage providers

Data may be stored on cloud infrastructure located outside your country (see Section 10: International Transfers).

5. Data Retention

We retain your personal data only as long as necessary for the purpose it was collected, or as required by law.

General principles

We retain data for:

  • · Providing our services to you
  • · Meeting legal and regulatory compliance obligations
  • · Resolving disputes and enforcing agreements

Specific retention periods

  • · Active account data: Retained for the duration of your account, plus 30 days after closure
  • · KYC/Identity documents: Minimum 5 years post-closure to comply with AML regulations
  • · Transaction records: 7 years to meet financial record-keeping requirements
  • · Usage telemetry: Raw data 12 months; anonymised aggregates may be retained longer
  • · Support communications: 3 years from last interaction
  • · Voice commands: Processed and discarded in real time (unless you opt into Voice History)
  • · Rewards data: 24 months of transaction activity metrics
  • · Marketing opt-outs: Retained indefinitely to prevent inadvertent re-subscription

When your data is no longer required, it is securely deleted or anonymised.

6. Your Rights

Depending on your region, you may have the following rights regarding your personal data. Penicent honours all of these globally.

Right to access

Request a complete export of all personal data we hold about you.

Right to rectification

Request correction of inaccurate or incomplete information. Most data can be updated directly in-app.

Right to erasure ("right to be forgotten")

Request deletion of your account and personal data. Some data cannot be deleted where we have a legal obligation to retain it (e.g., KYC records and transaction history required for AML compliance — see Section 5).

Right to data portability

Receive your data in a structured, machine-readable format to transfer to another service.

Right to withdraw consent

Where processing is based on consent, withdraw it at any time without affecting prior processing.

Right to opt-out of data sale or sharing

We do not sell your data. You may still contact us to restrict any non-essential sharing.

Right to restrict processing

Request a pause on processing while a dispute is being resolved.

Right to non-discrimination

We will not discriminate against you for exercising any of your privacy rights.

How to exercise your rights

Email support@penicent.com from your registered email address. We will verify your identity and respond within 30 days. There is no fee for any rights request.

Note for African jurisdictions

We comply with the Nigeria Data Protection Act (NDPA), Nigeria Data Protection Act, Nigeria POPIA, and applicable national data protection laws across all our operating territories.

7. Children's Privacy

Penicent does not knowingly collect, solicit, or retain personal data from children under the age of 13.

Our services are intended for individuals aged 18 and above. We do not market to, or knowingly onboard, minors.

If you believe that a child under 13 has provided personal information through our App, please contact us immediately at support@penicent.com. We will take prompt steps to delete the information and close any associated account.

This policy is compliant with the Children's Online Privacy Protection Act (COPPA) and CalOPPA.

8. Cookies, Tracking & Do Not Track

Cookies & tracking technologies

We use cookies, device identifiers, and similar technologies for the following purposes:

  • · Authentication — keeping you securely logged in
  • · Analytics — understanding how the App is used in aggregate
  • · App performance — identifying and resolving technical issues
  • · Security — detecting suspicious activity and preventing fraud

Do Not Track (CalOPPA)

Penicent does not currently respond to browser "Do Not Track" signals, as there is no universally accepted standard for how to respond to such signals.

However, you can manage data collection and tracking preferences through your in-app privacy settings at any time.

Third-party analytics

We use Firebase Analytics (Google) to collect anonymised, aggregated usage data. This data cannot be used to identify you personally. You may opt out of Firebase Analytics data collection through your device's ad settings.

We do not use third-party advertising cookies or cross-site tracking technologies.

9. Security

We implement industry-standard security measures to protect your information:

Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Encryption keys are managed in a Hardware Security Module (HSM) with automatic annual rotation.

Secure infrastructure

Our servers run on SOC 2 Type II certified cloud infrastructure. Physical access to data centres requires multi-factor authentication.

Access controls

Internal access to production systems follows strict least-privilege principles. All access is role-based, logged, and subject to quarterly reviews.

Vulnerability assessments

We conduct regular vulnerability assessments and penetration tests. Critical vulnerabilities are patched within 24 hours of discovery.

Fund segregation

Your deposits are held in segregated accounts at our licensed banking partners — never commingled with Penicent's operational funds.

Incident response

In the event of a data breach affecting personal data, we will notify affected users and relevant regulators within 72 hours, as required by applicable law.

While we take every reasonable measure, no system is 100% secure. We encourage you to use a strong, unique password and enable two-factor authentication on your account.

10. International Transfers

Your data may be transferred to, stored on, and processed on servers located outside your country of residence — including countries that may have different data protection standards than your own. We ensure all international transfers comply with applicable law, including:

  • GDPR Standard Contractual Clauses (SCCs) for transfers from the EU/EEA
  • Adequacy decisions where applicable
  • Binding contractual protections with all receiving parties
  • For users in Nigeria: transfers are conducted in compliance with the NDPA cross-border transfer provisions.
  • For users in Nigeria: transfers comply with POPIA Section 72 requirements.

If you have questions about where your data is stored or the safeguards in place, contact privacy@penicent.io.

11. Changes to This Policy

We may update this Privacy Policy from time to time as our services evolve or regulatory requirements change. When we make material changes, we will:

  • Post the updated policy within the App
  • Update the "Last Updated" date at the top of this page
  • Send an in-app notification or email for significant changes

Your continued use of the App after the updated policy takes effect constitutes your acceptance of the revised terms. We encourage you to review this policy periodically to stay informed about how we protect your information.

12. Contact Us

If you have any questions, requests, or complaints about this Privacy Policy or how we handle your data, please contact us:

Email

support@penicent.com

Address

Penicent Limited

Plot 8 Providence Street, Lekki, Lagos, Nigeria

Data protection inquiries

For specific privacy rights requests (access, deletion, correction, portability), email support@penicent.com from your registered account email. We respond within 30 days. There is no fee.

Regulatory complaints

If you believe we have violated your privacy rights and we have not resolved your concern, you have the right to lodge a complaint with your relevant data protection authority — for example, the Nigeria Data Protection Commission (NDPC), the Nigeria Office of the Data Protection Commissioner (ODPC), or the Information Regulator (Nigeria).

Questions about your privacy?

Our support team is here to help with any privacy-related questions.

support@penicent.com