1. Overview & Scope
Paylign Technologies Limited ("Paylign", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy describes how we collect, store, process, transfer, and disclose your personal data when you use the Paylign mobile applications, websites, APIs, and multi-currency payment services.
By using Paylign, you consent to the data practices described in this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.
2. Personal Data We Collect
We collect information you directly provide, data generated through your transactions, and technical device signals:
A. Personal Identification & KYC Data
- Full legal name, date of birth, nationality, gender, and residential address.
- Contact details: verified email address and primary telephone number.
- Government identification credentials: International Passport, National Identity Number (NIN), Voter's Card, or Driver's License.
- Bank Verification Number (BVN) and facial biometric liveness scans for anti-fraud identity authentication.
B. Financial & Transactional Data
- Multi-currency digital wallet balances and payment transaction history.
- Cryptocurrency public wallet deposit and withdrawal addresses.
- Transaction records: timestamps, amounts, conversion rates, and counterparty transfer details.
3. How We Use Your Data & Legal Basis
We process your personal information under the following lawful bases:
- Performance of Contract: To operate your multi-currency wallets, process crypto off-ramp and on-ramp orders, and execute cross-border payouts to recipients.
- Legal & Regulatory Compliance: To satisfy mandatory Anti-Money Laundering (AML), Counter-Terrorist Financing (CFT), and Know Your Customer (KYC) requirements imposed by central banks and financial intelligence units.
- Legitimate Interests: To protect our platform from cyberattacks, account takeovers, and fraudulent payment activities.
- Consent: To send you push notifications, marketing updates, or to process optional biometric login tokens on your local device.
4. Data Sharing & Third-Party Processors
We only share your information with trusted third parties under strict confidentiality and data protection agreements:
- Licensed Banking & Payment Partners: Regulated financial institutions, money service businesses, and payment switch operators that process local bank transfers and cross-border remittances.
- Identity Verification Providers: Authorized KYC and biometric verification providers (e.g. Dojah, Sumsub, IdentityPass) to validate government credentials against official databases.
- Customer Support Infrastructure: Secure enterprise support platforms to deliver responsive 24/7 in-app customer assistance.
- Regulatory & Law Enforcement Authorities: When legally compelled by a valid subpoena, court order, or statutory regulatory reporting obligation.
5. Data Security & Storage Standards
Paylign employs comprehensive administrative, technical, and physical security measures to safeguard your personal data:
- All data in transit is encrypted using modern TLS 1.3 cryptographic protocols with 256-bit encryption.
- Sensitive databases and financial ledger records are encrypted at rest using AES-256 standards with hardware security modules (HSM).
- Access to user data within Paylign is restricted to authorized personnel under strict role-based access control (RBAC) and audited logging.
6. Data Retention & Statutory Financial Storage
We retain your personal information for as long as your account remains active and as required by applicable laws. In compliance with global financial regulatory mandates (such as AML/CFT statutory preservation laws), transaction histories, identity records, and audit logs are retained for a statutory period of five (5) to seven (7) years following account closure.
When data is no longer required for regulatory compliance or legitimate operational purposes, it is securely destroyed or irreversibly anonymized.
7. Your Privacy Rights
Depending on your jurisdiction, you have the following rights regarding your personal information:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete identity details.
- Right to Erasure (Account Deletion): Request the permanent deletion of your account and erasure of non-statutory personal data. You can exercise this via our Request Delete Portal.
- Right to Restrict Processing: Object to or restrict the processing of your data in specific scenarios.
- Right to Data Portability: Request that your transaction statements and account records be provided in a structured, machine-readable format.
8. Cookies & Tracking Technologies
Our website and mobile applications use necessary cookies and local storage tokens to maintain your session authentication, remember user preferences, and safeguard against cross-site request forgery (CSRF). We do not utilize third-party cross-site advertising tracking cookies.
Contact Our Data Protection Officer (DPO)
If you have questions, complaints, or wish to exercise your data privacy rights, please contact our Data Protection Officer at:
Email: legal@paylign.com
General Support: Contact Support Desk