Legal

Privacy Policy

Last updated: July 24, 2026

1. Introduction

AchiPay is a fintech platform that enables users to send and receive money through WhatsApp and other digital channels. This Privacy Policy explains how we collect, use, store, share, and protect your personal information. We comply with the UK GDPR and Data Protection Act 2018, the Nigeria Data Protection Act (NDPA) 2023, and applicable data protection laws in other jurisdictions where we operate. JAFA Tech Limited (registered at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom) is the data controller responsible for deciding how and why your personal data is processed. By using AchiPay, you acknowledge you have read and agree to this Policy; if you do not agree, you must not use the Service.

2. Personal Data We Collect

We collect account information (full legal name, date of birth, email, phone number, login credentials, encrypted transaction PIN), KYC information (government ID, selfie, residential address, proof of address, tax ID where required, occupation and source of funds), transaction information (amounts, dates, recipient details, references, currency conversion data), communications you send us, and payment information (bank details, card details processed by our payment partners). We also automatically collect device and usage data (IP address, device/OS, browser, WhatsApp version, session logs, clickstream), transaction metadata, and approximate location/country. We receive information from third parties including WhatsApp, identity verification providers, payment and banking partners, and compliance databases (sanctions and PEP screening). We do not intentionally collect special-category data such as racial or ethnic origin, political opinions, religious beliefs, or health data, though identity documents may incidentally reveal some of this, which we process only for verification and compliance purposes.

3. How We Use Your Data

Our lawful bases include contractual necessity (providing the Service and processing transactions), legal obligation (AML, counter-terrorism financing, and sanctions compliance), legitimate interests (improving the Service, preventing fraud, ensuring security), and consent (for marketing). We use your data to operate your account and transactions, verify your identity and screen for sanctions/PEP status, detect and prevent fraud and money laundering, improve and develop our Service, monitor security, send service and (with consent) marketing communications, and comply with legal and regulatory obligations, including responding to lawful authority requests and enforcing our Terms.

4. Retention Periods

We keep account information for the duration of your account plus 6 years, transaction records for 6 years, identity verification documents for 6 years from account closure, support communications for 3 years, marketing data until you withdraw consent, and technical logs for 12 months — all as required by UK and Nigerian financial regulations. After these periods expire, we securely delete or anonymise your data.

5. Data Sharing and Cross-Border Transfers

We share data with payment partners and banking institutions, identity verification providers and sanctions screening databases, cloud hosting and technology partners, regulators including the FCA, CBN, NDPC, and NFIU, professional advisors such as legal counsel and auditors, and (only with consent) marketing partners. Third-party processors are bound by Data Processing Agreements requiring appropriate security and breach notification. Your data may be transferred outside the UK and Nigeria — including to the US and EU — under appropriate safeguards such as UK International Data Transfer Agreements, the UK Addendum to the EU SCCs, or adequacy decisions, and under NDPA-compliant safeguards for Nigeria. We may disclose data without consent to comply with a legal obligation, protect vital interests, prevent or detect financial crime, enforce our Terms, protect the Service's security, or in connection with a merger or sale of assets.

6. Your Data Protection Rights

Under UK GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, objection (including to direct marketing), and rights related to automated decision-making. Under the NDPA you have similar rights of access, correction, erasure, objection, portability, and withdrawal of consent. To exercise any right, email info@achipay.com with enough information to identify you and specify the right you wish to exercise; we respond within 30 days under UK GDPR or as required by the NDPC. If unsatisfied, you may complain to the Information Commissioner's Office (ico.org.uk) in the UK or the Nigeria Data Protection Commission (ndpc.gov.ng) in Nigeria. We use automated decision-making for fraud detection, identity verification, and sanctions/PEP screening, and you may request human intervention by contacting us.

7. Data Security

We use encryption in transit (TLS/SSL) and at rest, strict role-based access controls, multi-factor authentication, real-time monitoring, firewalls and intrusion detection, and ISO-certified secure data centres, alongside regular security audits. Organisationally, we maintain a designated Data Protection Officer, staff training, written data-handling policies, least-privilege access, and a documented incident response process. In the event of a breach, we will notify the ICO or NDPC within 72 hours where required, and notify affected individuals where there is a high risk to their rights and freedoms. You should also keep your PIN and password secure, avoid sharing credentials, log out on shared devices, and report suspicious activity promptly.

8. Cookies and Tracking

Our website uses essential cookies necessary for the site to function, preference cookies to remember your settings, and (only with consent) analytics and marketing cookies. You can manage or withdraw consent for non-essential cookies via your browser settings, though essential cookies cannot be disabled. We may use third-party analytics services such as Google Analytics, which set their own cookies under their own privacy policies.

9. Children's Privacy

AchiPay is not intended for individuals under 18, and we do not knowingly collect data from minors. If we discover we have collected data from someone under 18, we will delete it promptly. If you believe we have collected data from a minor, contact info@achipay.com.

10. Third-Party Services

AchiPay uses the WhatsApp Business API, so your use of WhatsApp is also subject to WhatsApp's own Terms of Service and Privacy Policy. We also use third-party payment processors with their own privacy practices, and our website may link to external sites for which we are not responsible.

11. Data Protection Officer and Complaints

We have appointed a Data Protection Officer, contactable at info@achipay.com. For a data protection complaint, email info@achipay.com — we acknowledge within 5 business days and respond within 30 days. If unsatisfied, escalate to the ICO (UK, ico.org.uk, 0303 123 1113) or the NDPC (Nigeria, ndpc.gov.ng).

12. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at info@achipay.com, via achipay.com, or by post at JAFA Tech Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

A product of JAFA Tech Limited · achipay.com · info@achipay.com