DRAFT — this document is pending legal review and is not yet binding.
Last updated: 29 July 2026
This policy explains how Acreden collects and uses personal data, in line with the Nigeria Data Protection Act 2023 (NDPA). Acreden (operated by [company legal name — PENDING registration details]) is the data controller.
We share data only with the service providers needed to run Acreden (identity/KYC, payments and escrow, hosting, email), with professional advisers, and with authorities where the law requires. We never sell personal data. Counterparties in a chat see your role, not your contact details, until a transaction stage requires disclosure.
Transaction and verification records are kept for as long as the law and fraud prevention require — property transactions have long legal tails. [PENDING LEGAL REVIEW — specific retention periods.]
Under the NDPA you may request access to, correction of, or deletion of your personal data, object to certain processing, and complain to the Nigeria Data Protection Commission. Write to privacy@acreden.com — we respond within the statutory period. Deletion requests cannot erase records we must keep by law (e.g. completed transaction and anti-fraud records).
Documents are stored in access-controlled storage with every access logged; payments run through licensed partners; admin actions are audited. No system is perfectly secure — report concerns to security@acreden.com.