Accion Microfinance Bank

ACCION MFB PRIVACY POLICY


PERSONAL DATA

Personal data comprises all the details we hold or collect about you, directly or indirectly, your transactions, transactions you effect, financial information, interactions and dealings with us, including information received from third parties, the public domain, collected through use of our website and our electronic banking services. This Privacy Policy ("Policy") outlines Accion Microfinance Bank's ("Accion", "we", "us", "our") personal data processing activities as a data controller. This policy covers the use, storage and dissemination of personal data we obtain from you or about you when you interact with us in the provision of the banking services you request, during your use of the website, and when you complete surveys or register for our webinars. This policy also describes our processing of the personal data of individuals representing our business partners and suppliers.

Personal Data Collected & How It Is Used
Categories of Data Subjects Personal Data Processed Business/Commercial Purpose for Processing Lawful Basis for Processing
Customers Personal details such as your given name(s); preferred name(s); gender; date of birth / age; marital status; government issued number(s) such as tax identification number (TIN), bank verification number (BVN), national identity number (NIN), passport number(s) and driving license number(s); nationality; lifestyle and social circumstances; photographs, images of passport data pages, driving licenses, and signatures; authentication data (including but not limited to, passwords, mother's maiden name etc.) Fulfilling our regulatory compliance obligations, including 'Know Your Client' checks, confirming and verifying individuals' identity; and screening against relevant sanctions lists and other legal restrictions Necessary step prior to entering into a contract or for the performance of a contract
Family details such as names and contact details of family members and dependents. Contact details such as residential address; telephone number; email address; and social media profile details. Employment details such as business activities; names of current and former employers; work address; work telephone number; work email address Establishing your credit worthiness by conducting credit reference checks and other financial due diligence Necessary step prior to entering into a contract or for the performance of a contract
Financial details such as billing address; bank account numbers; total assets and overall financial position, Debit/credit card numbers; instruction records; transaction details; and counterparty details. Provision of products and services to individuals: administering relationships and related services; performance of tasks necessary for the provision of the requested services i.e., processing applications for products and services, processing transactions, disbursing loans, processing repayments; communicating with individuals concerning those services Necessary step prior to entering into a contract or for the performance of a contract
Electronic marketing communications with individuals via any means (including via email, telephone) Consent
Webinar Attendees Personal and contact details i.e., name, age range, gender, email address, location, occupation Communicating details of webinars with attendees Consent
Survey Respondents Personal details i.e., name, age range Participation in survey/research purposes Consent
Vendors Name of contact personnel, telephone number, email address To establish correspondence and to facilitate the provision of the goods and services for which the vendors are contracted. Necessary step prior to entering into a contract or for the performance of a contract
Website Visitors Name, Phone number, company, email, location To address requests contained within the forms. Consent
Unique ID, IP address, online activity To generate statistics on website usage Consent
CCTV Physical appearance of individuals captured on video footage This monitoring is conducted in the public interest toward ensuring a secure environment Public interest
Sharing of Personal Data

When we disclose personal information for a business purpose to external third parties, the same standards of security and confidentiality described in this policy will be upheld. These third parties act as data processors, acting solely on our instructions and on our behalf, and we establish contracts with them to ensure personal data is adequately protected. These contracts prohibit them from retaining, using, or disclosing any personal data for any purpose other than performing services under our direct instructions and in line with the purposes set out in this policy. The following describes some scenarios for which we may share personal data with a third party:



Cookies

Cookies are information often including unique identifiers that a website saves on your device or computer when you visit. Accion MFB uses cookies collected to remember you, your preferences to customize and improve your experience on our site.

  • Cookie types and Purpose

    Temporary/Session Cookies help websites recognize you and the information provided when you navigate through a website. This type expires when you end the session by either leaving the site or closing the browser. Permanent/Persistent Cookies unlike temporary cookies remain in use until its expiration date or you delete it.

  • Cookie Consent

    In accordance to NDPR and other applicable regulations, we provide a cookie consent alert which gives you the option to opt-in or out.

Data Retention

We will retain and use personal data for as long as is necessary, in any case until the purpose of data collection is achieved and subject to any requirements to retain information in order to comply with any applicable law, regulation, professional requirements or standards.

Data Security

We have implemented appropriate technical and organizational security measures (such as Secure Sockets Layer (SSL) on our website and access controls on our information systems) to protect the personal data in our care, both during transmission and once we receive it. This includes measures to protect personal data from accidental or unauthorized destruction, loss, or alteration, and from unauthorized disclosure or access.

Personal Data Breach Management

Accion takes reasonable and practicable security measures to ensure privacy. In the event of a data breach, we shall report such breach to the relevant authority and if necessary, affected individuals of personal data breach (where the personal data breach will likely result in high risks to the freedoms and rights of the individual) within 72 hours of becoming aware of the breach or being notified by any processor of a personal data breach. We will take steps to investigate and recover personal data and will ensure security controls are improved to prevent a re-occurrence of the data breach. Personal data breach refers to a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. This includes breaches that are the result of both accidental and deliberate causes.

Individual Privacy Rights

Depending on location and applicable data protection regulation, an individual may be able to exercise some of the following rights regarding their personal data. An individual may be able to:

  • request further details about how we process personal data
  • request for a copy of any personal data which we hold
  • withdraw consent to process personal data, where we rely on consent as a legal basis to justify personal data processing
  • restrict/object to the processing of personal data
  • request to update or delete personal data which we hold
  • request to transfer personal data to a third-party provider of services (data portability)

Please note that we may ask individuals to provide us with the information necessary to confirm their identity before responding. We will aim to acknowledge enquiries within 24 hours and respond within one month unless otherwise required by law. Where permitted to do so, complying with your request may be subject to a fee to meet our associated costs.
We will consider all individual requests. However, we may not fulfil requests under circumstances where exemptions exist, which include a need to keep processing information to comply with a legal obligation. If such an exception applies, we will notify individuals when responding to their request.

Right to Amend the Privacy Notice

Accion may periodically change its privacy policy to reflect updates to personal data processing activities conducted. Changes will become effective as of the published effective date. Hence, our privacy policies will be dated to reflect the most recent update.

Contact Us

Accion is dedicated to protecting your privacy. If you have any questions or comments regarding this policy or any complaints concerning our compliance to it, please contact our Data Protection Officer at dataprotection@accionmfb.com or the Contact Center by; Phone call: 07000ACCION (07000222466), WhatsApp: 07045222933 or Email: info@accionmfb.com We will use reasonable efforts to respond promptly to requests, questions, or concerns.

Head Office, 154 Ikorodu Road, Onipanu, Lagos, Nigeria
Licensed by The Central Bank of Nigeria
(234) 1 271-9326   info@accionmfb.com
© 2007 - Accion Microfinance Bank Limited. All Right Reserved