Legal · Mobile App
Last updated 2025-01-01 · Penicent Limited · Plot 8 Providence Street, Lekki, Lagos, Nigeria
Important Notice — Regulated Financial Services
Penicent is a regulated financial technology company. Unlike standard apps, we are legally required by anti-money laundering (AML) and know-your-customer (KYC) regulations to collect, verify, and retain identity and transaction data. Some data cannot be deleted upon request because deletion would violate our legal obligations. We are transparent about all such cases in Section 5 (Data Retention) and Section 6 (Your Rights).
Introduction
Penicent ("we", "our", or "us") operates the Penicent mobile application ("App"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our platform.
By downloading, installing, or using Penicent, you agree to the data practices described in this policy. If you do not agree, please do not use the App.
This policy applies to all Penicent services — including our mobile app, USSD banking, cross-border payment services, virtual card programme, and the Penicent Rewards Programme — as well as our website at penicent.io.
On this page
We may collect the following categories of data:
Personal information you provide
We collect information you directly give us when creating or using your account:
Automatically collected information
When you use the App, we automatically collect certain technical data:
Optional permissions
The App may request the following device permissions, only when needed for specific features:
We use the data we collect for the following purposes only:
We do not use your data to build advertising profiles or sell targeted advertising. Penicent does not serve ads.
If you reside in the EU/EEA, we process your personal data on the following legal bases under GDPR:
Consent
Where you have given us explicit permission — for example, opting into marketing communications or enabling voice history.
Contract performance
To deliver the services you have signed up for, including account management, payment processing, and card issuance.
Legitimate interest
To improve our platform, prevent fraud, and ensure the security of all users on the network.
Legal obligation
To comply with applicable financial regulations, including anti-money laundering (AML) laws, know-your-customer (KYC) requirements, and mandatory reporting to regulators.
Protection of vital interests
In circumstances where processing is necessary to protect the vital interests of any person.
For users in Nigeria, we additionally process data in compliance with the Nigeria Data Protection Act (NDPA). For users in Nigeria, the Nigeria Data Protection Act. For users in Nigeria, POPIA.
We do not sell personal data. Full stop. We may share your information only in the following limited circumstances:
Service providers
We work with trusted third-party service providers who help us operate the platform — including hosting infrastructure, analytics, authentication, and customer support tooling. Each provider is bound by a Data Processing Agreement and may only use your data to provide their service to us.
Licensed banking partners
As a fintech company, we partner with licensed banking institutions to provide regulated financial services. Your identity and transaction data is shared with banking partners as required to open accounts, process payments, and maintain regulatory compliance.
Third-party integrations
The App integrates with the following services, each governed by their own privacy policy:
Legal authorities
We may disclose data to law enforcement, financial regulators, or government agencies when required by law. Where legally permitted, we will notify you before complying.
Business transfers
In the event of a merger, acquisition, or asset sale, user data may transfer. You will be notified at least 30 days in advance and given the option to delete your account.
Cloud storage providers
Data may be stored on cloud infrastructure located outside your country (see Section 10: International Transfers).
We retain your personal data only as long as necessary for the purpose it was collected, or as required by law.
General principles
We retain data for:
Specific retention periods
When your data is no longer required, it is securely deleted or anonymised.
Depending on your region, you may have the following rights regarding your personal data. Penicent honours all of these globally.
Right to access
Request a complete export of all personal data we hold about you.
Right to rectification
Request correction of inaccurate or incomplete information. Most data can be updated directly in-app.
Right to erasure ("right to be forgotten")
Request deletion of your account and personal data. Some data cannot be deleted where we have a legal obligation to retain it (e.g., KYC records and transaction history required for AML compliance — see Section 5).
Right to data portability
Receive your data in a structured, machine-readable format to transfer to another service.
Right to withdraw consent
Where processing is based on consent, withdraw it at any time without affecting prior processing.
Right to opt-out of data sale or sharing
We do not sell your data. You may still contact us to restrict any non-essential sharing.
Right to restrict processing
Request a pause on processing while a dispute is being resolved.
Right to non-discrimination
We will not discriminate against you for exercising any of your privacy rights.
How to exercise your rights
Email support@penicent.com from your registered email address. We will verify your identity and respond within 30 days. There is no fee for any rights request.
Note for African jurisdictions
We comply with the Nigeria Data Protection Act (NDPA), Nigeria Data Protection Act, Nigeria POPIA, and applicable national data protection laws across all our operating territories.
Penicent does not knowingly collect, solicit, or retain personal data from children under the age of 13.
Our services are intended for individuals aged 18 and above. We do not market to, or knowingly onboard, minors.
If you believe that a child under 13 has provided personal information through our App, please contact us immediately at support@penicent.com. We will take prompt steps to delete the information and close any associated account.
This policy is compliant with the Children's Online Privacy Protection Act (COPPA) and CalOPPA.
Cookies & tracking technologies
We use cookies, device identifiers, and similar technologies for the following purposes:
Do Not Track (CalOPPA)
Penicent does not currently respond to browser "Do Not Track" signals, as there is no universally accepted standard for how to respond to such signals.
However, you can manage data collection and tracking preferences through your in-app privacy settings at any time.
Third-party analytics
We use Firebase Analytics (Google) to collect anonymised, aggregated usage data. This data cannot be used to identify you personally. You may opt out of Firebase Analytics data collection through your device's ad settings.
We do not use third-party advertising cookies or cross-site tracking technologies.
We implement industry-standard security measures to protect your information:
Encryption
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Encryption keys are managed in a Hardware Security Module (HSM) with automatic annual rotation.
Secure infrastructure
Our servers run on SOC 2 Type II certified cloud infrastructure. Physical access to data centres requires multi-factor authentication.
Access controls
Internal access to production systems follows strict least-privilege principles. All access is role-based, logged, and subject to quarterly reviews.
Vulnerability assessments
We conduct regular vulnerability assessments and penetration tests. Critical vulnerabilities are patched within 24 hours of discovery.
Fund segregation
Your deposits are held in segregated accounts at our licensed banking partners — never commingled with Penicent's operational funds.
Incident response
In the event of a data breach affecting personal data, we will notify affected users and relevant regulators within 72 hours, as required by applicable law.
While we take every reasonable measure, no system is 100% secure. We encourage you to use a strong, unique password and enable two-factor authentication on your account.
Your data may be transferred to, stored on, and processed on servers located outside your country of residence — including countries that may have different data protection standards than your own. We ensure all international transfers comply with applicable law, including:
If you have questions about where your data is stored or the safeguards in place, contact privacy@penicent.io.
We may update this Privacy Policy from time to time as our services evolve or regulatory requirements change. When we make material changes, we will:
Your continued use of the App after the updated policy takes effect constitutes your acceptance of the revised terms. We encourage you to review this policy periodically to stay informed about how we protect your information.
If you have any questions, requests, or complaints about this Privacy Policy or how we handle your data, please contact us:
support@penicent.com
Address
Penicent Limited
Plot 8 Providence Street, Lekki, Lagos, Nigeria
Data protection inquiries
For specific privacy rights requests (access, deletion, correction, portability), email support@penicent.com from your registered account email. We respond within 30 days. There is no fee.
Regulatory complaints
If you believe we have violated your privacy rights and we have not resolved your concern, you have the right to lodge a complaint with your relevant data protection authority — for example, the Nigeria Data Protection Commission (NDPC), the Nigeria Office of the Data Protection Commissioner (ODPC), or the Information Regulator (Nigeria).
Questions about your privacy?
Our support team is here to help with any privacy-related questions.
support@penicent.com