PRIVACY POLICY

OUR PRIVACY POLICY

1. Introduction

Dabtikir Microfinance Bank is committed to protecting the privacy and security of our users’
data. This Data Safety Policy explains how our mobile application collects, uses, stores, and
shares user data, in accordance with Google Play’s Data Safety Section requirements, Nigeria
Data Protection Regulation (NDPR), and applicable international standards (GDPR).
By using the Dabtikir Microfinance Bank App, users agree to the data practices described below.

2. Data Collection
The App collects the following categories of data to provide core banking services and ensure a
secure user experience:

3. Data Usage 

Collected data is used solely for legitimate purposes, including: 

  • Enabling financial transactions and user authentication 
  • Compliance with regulatory and anti-fraud requirements 
  • Customer service and communication 
  • Improving app functionality and user experience
  • Marketing (only with explicit user consent) 

4. Data Sharing and Disclosure 

We only share data with trusted third parties under strict confidentiality and data protection agreements: All partners comply with NDPR, GDPR, and Google Play’s Data Safety standards.

5. Data Security
We employ bank-grade security measures to protect user data:
Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
Authentication: Biometric and two-factor authentication for user access.
Access Control: Role-based access for authorized personnel only.
Monitoring: Real-time fraud detection and intrusion prevention systems.
Regular Security Audits: Periodic penetration testing and security reviews.

6. Data Retention and Deletion
Data is retained only as long as necessary for service provision, regulatory compliance,
or dispute resolution.
Users may request data deletion through the in-app privacy center or via our support
email.
Upon deletion, user data is permanently removed from our active servers within 30 days
unless legally required to retain it.

7. User Rights
Users have the following rights under NDPR and GDPR principles:
 Access: Request a copy of their data.
 Correction: Update or correct inaccurate information.
 Deletion: Request data deletion.
 Withdrawal of Consent: Opt-out of marketing or optional data sharing.
 Portability: Request export of data in a structured format.