Legal / Privacy Policy
Privacy Policy
How Breeze collects, uses, stores, discloses, and protects personal data across our platforms, and the rights you hold over it under the NDPA and GDPR.
Effective 2026
Introduction and Scope
This Privacy Policy (“Policy”) is crafted in compliance with the Nigeria Data Protection Act (NDPA) and, where applicable, the EU General Data Protection Regulation (GDPR) and other relevant data protection laws, explains how Breeze FZE (“Breeze”, “we”, “us”, or “our”) collects, uses, stores, discloses, and protects personal data across our websites, mobile applications, APIs, and related services (collectively, the “Platforms”).
Our Policy cuts across customers and end-users, business clients and merchants, vendors and partners, website visitors, job applicants and any individual whose personal data is processed by Breeze. It further outlines the data we collect, reasons for collection of data, use and protection of data and the rights of data subjects in compliance with the NDPA.
Kindly note that we endeavour to update this Policy periodically to reflect legal, regulatory, or operational changes, ensuring our privacy standards are constantly upheld, aligning with best practices and meeting our transparency goals.
Roles and Responsibilities
Breeze has appointed a Data Protection Officer (DPO) responsible for the following:
- Ensuring compliance with applicable data protection laws
- Maintaining our Privacy Policy
- Handling data subject requests and complaints
All Breeze employees, contractors, and partners are required to comply with this Policy when handling personal data.
Our Policy Statement
Breeze is committed to safeguarding personal data and maintaining the highest standards of privacy, security, and transparency.
We determine how and why personal data is processed and ensure that such processing complies with applicable legal and regulatory obligations.
About Breeze
Breeze is a financial technology company that provides digital infrastructure for payments, financial services, and cross-border transactions. We have created an operating system called Bridge to digitise trade across Africa by increasing transparency and efficiency.
Our operating system includes the following:
- Trade services
- Merchant payment processing tools
- APIs and developer infrastructure
- Wallet and transaction management systems
- Compliance and identity verification systems (KYC/AML)
- Data analytics and fraud prevention tools
Depending on the service provided, Breeze may act as a Data Controller (e.g., onboarding merchants) or a Data Processor (e.g., processing payments on behalf of merchants).
Personal Data We Collect
We collect personal data depending on your interaction with our Platforms:
Information You Provide
- 01Name, email address, phone number
- 02Business and registration details
- 03Banking and payment information
- 04Identity verification data (e.g., NIN, BVN, passport)
- 05Any other information necessary or incidental to the service provided
Automatically Collected Data
- 01IP address
- 02Device and browser information
- 03Usage data and activity logs
- 04Location data
Third Party Data
- 01Financial institutions
- 02Identity verification services
- 03Public databases
- 04Regulatory bodies
Sensitive Personal Data
Where required, we may process:
- 01Biometric data (e.g. facial recognition, finger prints)
- 02Financial and transaction data
Such processing is carried out with explicit consent or other lawful basis.
Why We Process Data
Breeze processes personal data for the following purposes:
- Service delivery and platform functionality
- Identity verification (KYC/AML compliance)
- Payment processing and transaction management
- Fraud detection and risk management
- Customer support and communication
- Marketing and product updates (with consent)
- Legal and regulatory compliance
- Recruitment and employment
We are big on privacy and only collect data that is necessary.
Legal Grounds for Processing Data
Personal data is processed by us under the following lawful bases:
- Consent
- Performance of a contract
- Compliance with legal obligations
- Legitimate interests
- Protection of vital interests
- Public interest obligations
Consent
By using our Platforms, you consent to this Privacy Policy. You may withdraw your consent at any time, subject to legal or contractual restrictions. Withdrawal may affect your ability to use certain services provided by us.
Disclosing Personal Data
Personal data may be shared by us with service providers and vendors, financial institutions and payment partners, regulatory authorities, affiliates and subsidiaries. We however do not sell personal data.
All third parties are bound by contractual data protection obligations.
Cross-Border Data Transfers
Given the international nature of our services, personal data may be transferred across multiple jurisdictions. We ensure that during these processes such transfers are protected through Data Processing Agreements, Standard contractual clauses and Regulatory approvals where required.
Retention of Data
Breeze will retain personal data as long as necessary for service delivery and regulatory compliance. Retention considerations include purpose, type, lawful basis, and data subject category.
- Personal data is retained for up to ten (10) years after exit of relationship by the data subject or as may be required by regulation.
- Transaction data is retained for a minimum of five (5) years.
- Data is securely archived, deleted or destroyed when no longer needed.
Data Security
Breeze implements industry standard safeguards in ensuring all data are protected, including: encryption, access controls, firewalls and secure infrastructure. We align with global best practices such as ISO standards, PCI-DSS where applicable.
Notification of Data Breach
In the event of a breach, affected users and regulators will be notified within legally required timelines.
Data Subject Rights
You have the right to:
- 01Access your data
- 02Correct inaccurate data
- 03Request deletion
- 04Restrict processing
- 05Object to processing
- 06Withdraw consent
- 07Request data portability
- 08Lodge complaints with regulators
Requests by Data Subjects will be processed within 30 days.
Third-Party
Our Platforms may contain links to third-party services. We are not responsible for their privacy practices, however our Data Subjects will be notified where necessary of any breach or information relating to third parties.
Breeze will not disclose personal data to third parties without consent unless legally required by government authorities, law courts or law enforcement requirements. Where processing involves fraud prevention, legal obligations or protection of rights, lawful grounds will be established.
Breeze has put in place, to the best of its ability and in line with standard global practices, appropriate physical, technical, and organizational measures (including encryption and anonymization) to ensure the optimum protection of personal data, which also extends to data transferred or shared with third parties.
Children’s Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect data from minors without parental consent.
Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated appropriately.
Contact Information
To file a complaint about how your data is handled, contact:
Supervisory Authority
dpo@ndpc.gov.ngData Protection Officer (DPO)
compliance@bridge.trade