Legal / Privacy Policy

Privacy Policy

How Breeze collects, uses, stores, discloses, and protects personal data across our platforms, and the rights you hold over it under the NDPA and GDPR.

Effective 2026

01

Introduction and Scope

This Privacy Policy (“Policy”) is crafted in compliance with the Nigeria Data Protection Act (NDPA) and, where applicable, the EU General Data Protection Regulation (GDPR) and other relevant data protection laws, explains how Breeze FZE (“Breeze”, “we”, “us”, or “our”) collects, uses, stores, discloses, and protects personal data across our websites, mobile applications, APIs, and related services (collectively, the “Platforms”).

Our Policy cuts across customers and end-users, business clients and merchants, vendors and partners, website visitors, job applicants and any individual whose personal data is processed by Breeze. It further outlines the data we collect, reasons for collection of data, use and protection of data and the rights of data subjects in compliance with the NDPA.

Kindly note that we endeavour to update this Policy periodically to reflect legal, regulatory, or operational changes, ensuring our privacy standards are constantly upheld, aligning with best practices and meeting our transparency goals.

02

Roles and Responsibilities

Breeze has appointed a Data Protection Officer (DPO) responsible for the following:

  • Ensuring compliance with applicable data protection laws
  • Maintaining our Privacy Policy
  • Handling data subject requests and complaints

All Breeze employees, contractors, and partners are required to comply with this Policy when handling personal data.

03

Our Policy Statement

Breeze is committed to safeguarding personal data and maintaining the highest standards of privacy, security, and transparency.

We determine how and why personal data is processed and ensure that such processing complies with applicable legal and regulatory obligations.

04

About Breeze

Breeze is a financial technology company that provides digital infrastructure for payments, financial services, and cross-border transactions. We have created an operating system called Bridge to digitise trade across Africa by increasing transparency and efficiency.

Our operating system includes the following:

  • Trade services
  • Merchant payment processing tools
  • APIs and developer infrastructure
  • Wallet and transaction management systems
  • Compliance and identity verification systems (KYC/AML)
  • Data analytics and fraud prevention tools

Depending on the service provided, Breeze may act as a Data Controller (e.g., onboarding merchants) or a Data Processor (e.g., processing payments on behalf of merchants).

05

Personal Data We Collect

We collect personal data depending on your interaction with our Platforms:

Information You Provide

  1. 01Name, email address, phone number
  2. 02Business and registration details
  3. 03Banking and payment information
  4. 04Identity verification data (e.g., NIN, BVN, passport)
  5. 05Any other information necessary or incidental to the service provided

Automatically Collected Data

  1. 01IP address
  2. 02Device and browser information
  3. 03Usage data and activity logs
  4. 04Location data

Third Party Data

  1. 01Financial institutions
  2. 02Identity verification services
  3. 03Public databases
  4. 04Regulatory bodies

Sensitive Personal Data

Where required, we may process:

  1. 01Biometric data (e.g. facial recognition, finger prints)
  2. 02Financial and transaction data

Such processing is carried out with explicit consent or other lawful basis.

06

Why We Process Data

Breeze processes personal data for the following purposes:

  • Service delivery and platform functionality
  • Identity verification (KYC/AML compliance)
  • Payment processing and transaction management
  • Fraud detection and risk management
  • Customer support and communication
  • Marketing and product updates (with consent)
  • Legal and regulatory compliance
  • Recruitment and employment

We are big on privacy and only collect data that is necessary.

09

Cookies and Tracking Technologies

We use cookies and similar technologies to improve user experience, analyse usage patterns, enhance platform functionality and support marketing and analytics.

You can manage cookie preferences via your browser settings.

10

Disclosing Personal Data

Personal data may be shared by us with service providers and vendors, financial institutions and payment partners, regulatory authorities, affiliates and subsidiaries. We however do not sell personal data.

All third parties are bound by contractual data protection obligations.

11

Cross-Border Data Transfers

Given the international nature of our services, personal data may be transferred across multiple jurisdictions. We ensure that during these processes such transfers are protected through Data Processing Agreements, Standard contractual clauses and Regulatory approvals where required.

12

Retention of Data

Breeze will retain personal data as long as necessary for service delivery and regulatory compliance. Retention considerations include purpose, type, lawful basis, and data subject category.

  • Personal data is retained for up to ten (10) years after exit of relationship by the data subject or as may be required by regulation.
  • Transaction data is retained for a minimum of five (5) years.
  • Data is securely archived, deleted or destroyed when no longer needed.
13

Data Security

Breeze implements industry standard safeguards in ensuring all data are protected, including: encryption, access controls, firewalls and secure infrastructure. We align with global best practices such as ISO standards, PCI-DSS where applicable.

14

Notification of Data Breach

In the event of a breach, affected users and regulators will be notified within legally required timelines.

15

Data Subject Rights

You have the right to:

  1. 01Access your data
  2. 02Correct inaccurate data
  3. 03Request deletion
  4. 04Restrict processing
  5. 05Object to processing
  6. 06Withdraw consent
  7. 07Request data portability
  8. 08Lodge complaints with regulators

Requests by Data Subjects will be processed within 30 days.

16

Third-Party

Our Platforms may contain links to third-party services. We are not responsible for their privacy practices, however our Data Subjects will be notified where necessary of any breach or information relating to third parties.

Breeze will not disclose personal data to third parties without consent unless legally required by government authorities, law courts or law enforcement requirements. Where processing involves fraud prevention, legal obligations or protection of rights, lawful grounds will be established.

Breeze has put in place, to the best of its ability and in line with standard global practices, appropriate physical, technical, and organizational measures (including encryption and anonymization) to ensure the optimum protection of personal data, which also extends to data transferred or shared with third parties.

17

Children’s Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect data from minors without parental consent.

18

Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated appropriately.

19

Contact Information

To file a complaint about how your data is handled, contact:

Supervisory Authority

dpo@ndpc.gov.ng

Data Protection Officer (DPO)

compliance@bridge.trade