Updated on: 31st January 2024
PRIVACY POLICY
This Privacy Policy governs the manner in which Pecantrust Microfinance Bank Limited
("Pecan Bank," "we," "our," and "us”) collects, uses, stores and discloses information
collected from our users("you).
This policy describes what information we collect about
you, how we collect and use the information you share with us, and with whom we share
that information, you don’t have to share any information with us, but to use our services, well need some information from you. This policy contains information about when we
share your personal information with third parties (such as our credit bureaus and
service providers).
This Privacy Policy governs the manner in which Pecantrust Microfinance Bank Limited
("Pecan Bank," "we," "our," and "us”) collects, uses, stores and discloses information
collected from our users("you). This policy describes what information we collect about
you, how we collect and use the information you share with us, and with whom we share
that information, you don’t have to share any information with us, but to use our services, well need some information from you. This policy contains information about when we
share your personal information with third parties (such as our credit bureaus and
service providers).
e may update this Privacy Policy from time to time to reflect current privacy practices. When we make changes to this policy, we will notify you by revising the “effective date” at the top this policy, and in some cases, we may provide you with additional notice
(such as adding a statement to the homepages of our mobile application or website).
CONSENT
By accessing or using our services or otherwise providing your personal data, you
accept this Privacy Policy and consent to the processing and transfer of your personal
data when you sign up, and use our website, mobile application including but not limited
to related sites, applications, promotional activities and offline interactions or visits to our
office(s). The Personal Data we collect is governed by the Nigerian Data Protection Regulation
(NDPR)
WHAT INFORMATION WE COLLECT
You may be asked to provide your information including personal data anytime you
contact us or otherwise to provide better services including but not limited to adverts and
content, performance evaluations, improve communication, perform due diligence (legal
and business) and develop new services for all our users.
Categories of Personal Data
e collect the personal data you provide to us depending on the products and services. These applies to opening a Pecan Bank account or when you communicate with us
about your Pecan bank account. The type of personal data we may collect includes:
-
Account and Contact Information:
Name, email address, postal address, residential address, phone number, date of birth, means of identification
(identification document number, passport number and/or national identification
number (NIN) as required); billing information, next of kin information, financial nformation, any other information required to comply with regulatory
requirements.
-
Financial Information:
Bank Verification Number, personal bank account
number, credit card details financial history (including information to determine
your creditworthiness) and other information provided by financial institutions or
merchants when we act on their behalf.
-
Biometric Information:
such as images of you, fingerprints, face recognition and
speech recognition to identify you for any form of account or during interaction
with our customer service team
-
Transaction Information:
includes details about your transactions
-
Device Information:
Includes information on the devices with which you access
our products, website or application
-
Profile Information:
Includes your username, password, transaction history, your interests, feedback and survey information.
-
Usage Information:
Includes your use of our products, services, the record of
correspondences with us online and offline, page response times, download
errors, page interaction information and browser methods. We may use your
usage information to aggregate the percentage of users accessing our products
and/or specific website features
-
Marketing and Communications Information:
Includes information related to
your interaction with our social media accounts, content and marketing
campaigns (including details provided by you for a market survey) and our third
parties and your communication preferences
-
Views, opinions and preferences:
Includes information regarding your views, opinions and preferences (such as surveys, feedback regarding our products or
services or online-based behavior). We may also collect, use, store and share
aggregated data such as demographic or statistical data for
-
Third-party Information:
Includes information collected about you from other
companies (such as credit bureau agencies and collection agencies to report
account information as permitted by law, banking partners as required for
credit/debit card association rules, law enforcement, government officials or other
third parties pursuant to a subpoena, court order or other legal processes
applicable to us or one of our affiliates), the information provided to our affiliate's
and other trusted businesses or persons to process for us based on our
instructions and in compliance with our privacy policy and any other
confidentiality and security measures. This is not limited to service providers to
help deliver our products and services, conduct due diligence and improve our
internal business processes and offer additional support to customers and users' personal information
PERSONAL DATA WE COLLECT
We (or our service providers acting on our behalf) may collect information about your
use of our services. This information may include Personal Information as well as
statistical information that does not identify you(“Analytics”). Some Analytics may be
correlated with Personal Information. When Analytics are, directly or indirectly, associated or combined with Personal Information, such Analytics will be considered
Personal Information for Purposes of this Privacy Policy.
Device Information:
This includes device specific information (such as hardware model, operating system version, unique device identifiers, and mobile network information,
including your phone number). We may associate your device identifiers or mobile
phone number with your pecan bank account.
Log Information:
We may record or log information from your devices, their software
and your activity accessing or using our services. This information may include:
- The Device Internet Protocol(“IP”) address
Identification numbers associated with your devices
-
Device event information such as crashes, system activity and hardware settings
-
System configuration Information
-
Date and Time stamps of transactions
-
Other interactions with our service
Location Information:
information regarding your current location disclosed by GPS
technology and other sensor data from your device, offline address, IP address,
information about things near your device such as Wi-Fi access points, cell towers, browser plug-in types ad versions, system activity, crash reports, date, time and referrer
Uniform Resource Locators (URL) clickstream including date and time of your request
with your prior consent. Any information collected via your use of google maps will be
transmitted directly to google and not collected by us. Please refer to Google’s privacy
policy for details about their collection, use and sharing of this information.
USE OF COOKIES AND OTHER
We use cookies to personalize and improve our services for you and to collect
aggregate information about the usage of our services. A cookie is a text file or other
local storage identifier provided by your browser or associated applications. We use
cookies for record-keeping purposes to enhance quality of your use of our services. We
may also collect information using web beacons (also known as “tracking pixels”). These
are electronic images that may be used in our services or emails and help deliver
cookies, count visits, understand usage and campaign effectiveness and determine
whether an email has been opened and acted upon.
HOW WE USE YOUR PERSONAL INFORMATION
We may use your information including personal data as follows:
- Provide, maintain and
- Carry out our obligations arising from any contracts entered between you and us
and provide you with the information, product and services that you request from
us;
- Notify you about changes to our service;
- Personalize and improve services, provide content, advertisements or features
that match you’re your interests
- Send you technical notices, updates, security alerts, support and administrative
messages
- Monitor and analyze trends, usage and activities in connection with our services.
- Analyze internal operations, troubleshooting, data analysis, testing, research, statistical and survey purposes;
- Make suggestions and recommendations to you about our services that may
interest you
- Carry out any other purpose for which the information was collected
We will use the information provided by you to provide you or permit selected third
parties to provide you, with information about goods or services we feel may interest you.
If you are an existing customer, we will only contact you via electronic means (e-mail or
SMS) with information about goods and services similar to those, which were the subject
of a previous sale or negotiations of a sale to you. If you are a new customer, and where
we permit selected third parties to use your data, we (or they) will contact you by
electronic means only if you have consented to this. If you do not want us to use your
data in this way, or to pass your details on to third parties for marketing purposes, you
may unsubscribe from promotional emails via a link provided in each email.
HOW WE SHARE INFORMATION
You agree that we have the right to share your information and any other information you
share with us:
- If you request or authorize
- If the information provided is to help complete a transaction for you
- For every business operation.
- With any of our affiliated companies or service providers.
- With non-financial companies such as email service providers that perform
branding and marketing services, and fraud prevention service providers that use
the information to
- With a non-affiliated third party to access and transmit your personal and
financial information according to the terms of their privacy policy.
- With selected third parties including business partners and sub-contractors for
the performance of any contractual relationship established with them or you.
- In response to a request for information, if required or we believe disclosure is in
accordance with applicable laws, rules, regulations, governmental and quasi- governmental requests, court orders or subpoenas or legal processes.
- To protect our rights, property or safety of our users or others.
- For publication of our events and competitions on digital and print media.
- With law enforcement officials or third parties such as auditors, if we believe it's
appropriate to investigate fraud
LEGAL BASIS FOR THE PROCESSING OF PERSONAL INFORMATION
We may process your Personal Data in the regular management of our business and
where we have a legal basis to do so. We consider the legal basis for using your
Personal Data as set out in the Nigeria Data Protection Regulation (NDPR). These
include:
- To process personal information/data upon your consent.
- To perform a contract with you or take steps at your request before entering into
a contract.
- To protect your interest, the interest of other data subject or to perform a task
carried out in public interest or the legitimate interest of others
- To maintain, monitor, improve and develop our business policies, systems and
controls.
- To design, develop and test products, services and solutions.
- To customize products, services and solutions, messaging and advertising
- To process and settle transactions and payments
- To meet record-keeping obligations
- To enable you to use value-added solutions and participate in reward programs
- To comply with integrity and business conduct checks required for compliance
purposes including due diligence and onboarding processes, monitoring and
assurance reviews and conduct sanctions screening against any sanctions list.
- To comply with our legal and regulatory obligations
- To detect, prevent and report theft, money laundering, terrorist financing, corruption or other potentially illegal activity or activity that could lead to loss.
- To conduct research and analysis (that may include assessing product suitability, credit quality, insurance risks, market risks and affordability, developing credit
models and tools and obtaining related information).
PRIVACY BY DESIGN
When designing and implementing a new business or technological process involving the
collection, use or disclosure of personal data, we will carefully consider the need for
structured privacy planning for this process. For example, the Bank will assess the
necessity of gathering solely the pertinent information essential for the initial business
process.
SECURITY OF DATA
We have implemented thorough measures to safeguard your personal information from
accidental loss, unauthorized access, or misuse by third parties. These measures include
the implementation of appropriate technical and organizational procedures, as well as
security protocols. Our processes are designed specifically to protect your data from
unauthorized access, unlawful processing, accidental loss, damage, or destruction. This
includes restricting access to your personal data to only those employees, agents, and
third parties who have a legitimate business need to access it.
As part of our standard procedures, Pecan Bank adheres to global Information Security
Management Systems (ISMS) protocols and integrates both digital and physical security
measures to mitigate or eliminate the risk of data privacy breaches. Nevertheless, we
strongly advise against sharing confidential information, including passwords, with anyone.
Furthermore, it is important to note that despite our efforts to maintain a secure online
environment, we cannot ensure 100% safety on the internet. As a precaution, we kindly
urge you to protect your Pecan Bank account login username and password, refrain from
sharing it with others and access our services within a secure setting. In the event that
instructions are received using your Pecan Bank account login information, we will
interpret this as authorization for those instructions. By using our services, you agree to
promptly notify us of any unauthorized use of your account or security breaches.
DISCLOSURE OF PERSONAL DATA
We may disclose any information we collect about current and former customers to
affiliates as follows:
- If you request or authorize it
- If the information is provided to help complete a transaction for you
- If the disclosure is required by authorized employees of Pecan Bank for the
purpose of issues associated with the use of our services
If the information is required to:
- Publicize our events and products on digital and print media
- Examine data to enhance the optimization of our corporate and product website.
- Comply with applicable laws, rules, regulations, governmental and quasi- governmental requests, court orders
- Enforce our terms of use and other agreements
- For everyday business purposes
- Protect our rights, property, or safety, or the rights of our users or others
- Share with delivery companies for dispatch of ATM cards upon your request
- Share with third-party payment processing services when you pay through our
website or mobile
We refrain from sharing your personal information with any third parties for marketing
purposes.
WHERE WE STORE YOUR DATA
We transfer and store your personal information in our offices and authorized computer
systems within Nigeria. By submitting your data, you consent to this transfer, storage, and/or processing. We have implemented appropriate measures to ensure the secure
treatment of your data in accordance with this Privacy Policy.
All the personal information you provide is stored on our secure servers. For added
security, all transactions are encrypted using Secure Sockets Layer (SSL) technology.
YOUR RIGHTS
The Nigeria Data Protection Regulation (NDPR) gives you certain rights in respect of the
information we hold about you. Below is a highlight of some of those rights. This is not a
complete, exhaustive processed statement of your rights in respect of your Personal Data:
- You have the right to consent to this Privacy Policy and to withdraw your consent
at any time. If you choose to withdraw your consent, we will stop processing your
data unless there is a legal ground for us to continue doing so. In the event that
we intend to continue processing your data under such circumstances, we will
notify
- You have the right to transfer personal data received from us to another, also the
use of your Personal Data, who it is shared with and how long it is retained by us. You will be reasonably charged for additional copies of such personal data in the
case of unfounded and excessive requests
- You have the right to access the personal data retained by us
- In some circumstances, you have the right to request the deletion of your
information with us if it is retained beyond a certain period or if there is no legal
basis for its processing. Additionally, in certain circumstances, you may request
restrictions on the processing of
- You have the right to file a complaint regarding the handling of your Personal
Data with the Nigerian Information Technology Development Agency (NITDA).
- If you wish to exercise your rights, you may contact the office of our data
protection officer at infosec@mypecanbank.com
- You have the right to ask us not to process your Personal Data for marketing
purposes. We will usually inform you (before collecting your data) if we intend to
use your data for such purpose or if we intend to disclose your Personal Data to
any third party for such purposes.
CHILDREN'S PRIVACY
Our services are not intended for children under the age of 18 without the approval of a
guardian. All personal information for such customers is provided by the guardian. It is
essential for a parent or guardian to thoroughly review this policy to understand how we
collect, use, and disclose all personal information provided.
Except as it pertains to the services or products of the bank, we do not knowingly collect
personal information from children under the age of 18, except under the conditions stated
above. If we become aware that we have collected Personal Data from anyone without
verification of parental consent, we take appropriate steps to remove that information from
our servers. Please contact us as provided in the “Contact Us” section below for further
assistance.
RETENTION OF INFORMATION
Your Personal data will only be retained to achieve the purposes for as long as it is active
or is required to provide you with our services or comply with our legal and statutory
obligations.
BREACH OF DATA PRIVACY
While Pecan Bank takes reasonable precautions to minimize the occurrence and impact of
personal data breaches, it's important to acknowledge that the risk cannot be completely
eliminated. Therefore, if there is reasonable suspicion or awareness of a personal data
breach or compromise of personal data integrity or confidentiality, Pecan Bank will
promptly, within 72 hours of such knowledge, report the details of the breach to NITDA.
In cases where it is determined that such a breach poses a risk to your rights and freedom, Pecan Bank will, within 7 days of such knowledge, take steps to inform you of the breach
incident. This communication will include details of the breach, the potential risks to your
rights and freedom resulting from the breach, and any recommended course of action to
remedy the situation.
DELETION OF PERSONAL DATA
We store data until it is no longer necessary to provide our services and Pecan bank
products, or until your account is deleted, whichever occurs first. This differs per case, depending on the nature of the data, why it is collected and processed and relevant legal
or operational retention needs. When you delete your account, we delete all financial
transactional history, communications and you will not be able to retrieve this information
later. Note that this policy does not apply to account deactivation.
TRAINING
Pecan Bank ensures comprehensive training on data privacy and protection for all
employees involved in collecting, accessing, and processing personal data. This training is
aimed at equipping them with the necessary skills, knowledge, and competence to
effectively handle the compliance framework outlined in this privacy policy and the Nigeria
Data Protection Regulation (NDPR). Additionally, Pecan Bank develops an annual
capacity-building plan to enhance its employees' understanding of data privacy and
protection, aligning with the requirements of the Nigeria Data Protection Act.
CHANGES TO OUR PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect current privacy practices. When we make changes to this policy, we will revise the “effective date” of this policy and
notify you by posting a notice on our website. You are advised to review this privacy policy periodically for any changes.
CONTACT US
If you have questions, complaints or suggestions relating to the processing of your
personal information by Pecantrust Microfinance Bank or require clarification regarding
this privacy policy, you can us using any of the contact below:
Email: info@mypecanbank.com or our visit our office at
No. 32, Grace Anjous Drive, Lekki
Phase 1, Lagos State.