Data Deletion Policy
PERCENTPAY
USER DATA DELETION POLICY
Version 1.0 • Effective 20 May 2026
This Data Deletion Policy (this “Policy”) explains how Percent Technologies Limited (“PercentPay”, “we”, “us”, or “our”) handles requests from Users to delete their Personal Information, and the legal and regulatory limits on what we can lawfully delete. It is issued under the Nigeria Data Protection Act 2023 (the “NDPA”), and in accordance with the Central Bank of Nigeria (“CBN”) AML/CFT/CPF Regulations 2022, the Money Laundering (Prevention and Prohibition) Act 2022, the CBN Consumer Protection Regulations 2019, the NDPC General Application and Implementation Directive 2025 (“GAID”), and other applicable Nigerian laws.
This Policy supplements our Privacy Policy and our Terms and Conditions. Where there is any conflict between this Policy and our Privacy Policy in respect of data deletion, this Policy prevails.
1. Purpose and Scope
The purpose of this Policy is to:
- explain your right under the NDPA to request deletion of your Personal Information held by PercentPay;
- explain when we will, may, or must refuse a deletion request because of overriding legal or regulatory obligations;
- set out the process, timelines, and verification steps for requesting deletion; and
- describe what happens to your data after a deletion request is processed.
This Policy applies to all Personal Information processed by PercentPay through the PercentPay Mobile Application at https://percentpayapp.com and through any related Services, whether you are an active User, a former User, an external party who deposited funds into a Public Space via a Virtual Account Number (“VAN”), or any other identifiable individual whose Personal Information we hold.
2. Definitions
Terms defined in our Terms and Conditions have the same meaning when used in this Policy. In addition, the following terms apply:
- “Account Closure” means the deactivation of your PercentPay Account so that you can no longer log in, transact, or operate Spaces. Account Closure is not, by itself, deletion of your Personal Information.
- “Anonymisation” means the irreversible alteration of Personal Information so that it can no longer be associated with you or any identifiable person. Anonymised data is no longer Personal Information for the purposes of the NDPA.
- “Data Deletion” means the permanent and irreversible removal, destruction, or anonymisation of your Personal Information from our active systems and, in accordance with our backup-retention schedule, from our backup systems.
- “Deletion Request” means a request made by you (or, where applicable, by a person authorised to act on your behalf) for the deletion of your Personal Information.
- “Mandatory Retention” means the legal or regulatory obligation to retain certain categories of Personal Information for a specified minimum period, irrespective of a Deletion Request.
- “Pseudonymisation” means the processing of Personal Information in such a way that it can no longer be attributed to a specific data subject without the use of additional information held separately and subject to technical and organisational measures.
- “Retention Period” means the period for which a specific category of Personal Information is retained, as set out in this Policy or as required by law.
3. Legal Framework
This Policy reflects and applies the following legal and regulatory instruments:
- Nigeria Data Protection Act 2023 (NDPA): section 34 confers the right to erasure of Personal Information in certain circumstances, subject to lawful grounds for retention.
- NDPC General Application and Implementation Directive 2025 (GAID): Article 49(3) sets a default storage lapse of six (6) calendar months after the purpose of processing has been accomplished, subject to any time-bound obligation imposed by other laws.
- Money Laundering (Prevention and Prohibition) Act 2022 (MLPPA): requires retention of customer due diligence (“CDD”) records, transaction records, and reports for a minimum of five (5) years from the end of the business relationship or the date of the transaction.
- Terrorism (Prevention and Prohibition) Act 2022 (TPPA): imposes parallel record-keeping obligations for transactions and accounts.
- CBN AML/CFT/CPF Regulations 2022: require Financial Institutions and their agents to maintain transaction and KYC records in a form that is easily retrievable, for at least five (5) years, subject to the supervisory powers of the CBN and the Nigerian Financial Intelligence Unit (NFIU).
- CBN Consumer Protection Regulations 2019 and the CBN Consumer Protection Framework 2016: require maintenance of customer complaint records and supporting evidence for at least five (5) years.
- Companies and Allied Matters Act 2020 (CAMA): imposes record-keeping obligations of at least six (6) years for company books and records that may contain Personal Information.
- Federal Inland Revenue Service (Establishment) Act and other tax legislation: imposes a six (6) year minimum retention of tax-relevant records.
- CBN Risk-Based Cybersecurity Framework for Payment Service Providers 2024 and CBN Cybersecurity Framework for Other Financial Institutions 2022: impose retention obligations for security and incident records.
- NDPR 2019 and NDPR Implementation Framework: provide minimum retention guidance, including three (3) years after the last active use of a digital platform and six (6) years after the last transaction in a contractual agreement.
Where the periods above conflict, the longest applicable period (the “Mandatory Retention Floor”) prevails. We delete or anonymise Personal Information promptly once all applicable Mandatory Retention Floors have lapsed.
4. Account Closure Is Not Data Deletion
It is important to understand the difference between Account Closure and Data Deletion:
- Account Closure is the deactivation of your PercentPay Account. After Account Closure, you can no longer log in, transact, or operate Spaces. However, your Personal Information remains in our records, subject to the Retention Periods set out in this Policy.
- Data Deletion is the permanent removal or anonymisation of your Personal Information. Data Deletion can only take effect, in full, after all applicable Mandatory Retention Floors have lapsed.
Where you ask us to delete your data while one or more Mandatory Retention Floors are still in force, we will:
- close your Account immediately (subject to Section 12);
- remove or restrict your data from active use as soon as practicable;
- continue to hold the data covered by Mandatory Retention in restricted, access-controlled storage solely for the purposes for which it must be retained; and
- delete or anonymise it as soon as the relevant Mandatory Retention Floor lapses.
5. Your Right to Request Deletion
Under section 34 of the NDPA, you have the right to request the deletion of your Personal Information where any of the following applies:
- the Personal Information is no longer necessary for the purposes for which it was collected or otherwise processed;
- you withdraw consent on which the processing was based, and there is no other lawful basis for processing;
- you object to the processing and there are no overriding legitimate grounds for the processing;
- the Personal Information has been unlawfully processed;
- the Personal Information must be erased to comply with a legal obligation; or
- the Personal Information was collected in relation to the offer of information society services to a child.
This right is not absolute. We may refuse, restrict, or defer a Deletion Request in the circumstances set out in Section 7 (Mandatory Retention) and Section 8 (Special Circumstances).
6. Data Categories and Retention Schedule
The table below sets out the principal categories of Personal Information we hold, the Retention Period that applies to each category, and the legal source of that period. Where multiple periods could apply, the longest period prevails.
Data Category | Retention Period | Legal / Operational Basis |
Identity / KYC Information (name, DOB, BVN, NIN, ID images) | 5 years from end of business relationship | MLPPA 2022 s.7; CBN AML/CFT/CPF Regulations 2022 |
Transaction and payment records (Internal Flows, External Inflows, Card transactions, Escrow, Spaces transactions) | 5 years from transaction date | MLPPA 2022 s.7; CBN AML/CFT/CPF Regulations 2022; TPPA 2022 |
Wallet, Space, and VAN account records | 5 years from closure of the wallet or Space | CBN AML/CFT/CPF Regulations 2022 |
Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) records, PEP screening, beneficial ownership data | 5 years from end of business relationship | MLPPA 2022; CBN AML/CFT/CPF Regulations 2022 |
Suspicious Transaction Reports (STRs) and Currency Transaction Reports (CTRs) filed with NFIU | Retained as required by the NFIU, typically not less than 5 years | MLPPA 2022; NFIU Act 2018 |
Voting and Space governance records (votes cast, admin decisions, member changes) | 5 years from closure of the Space | CBN AML/CFT/CPF Regulations 2022; contractual evidence |
Risk-acknowledgement records (e.g., the in-App Space deposit acknowledgement) | 7 years from the date of acknowledgement | Contractual evidence and litigation defence; aligned with longest applicable limitation period |
Customer complaints, dispute resolution and escalation records | 5 years from resolution of the complaint | CBN Consumer Protection Regulations 2019; CBN Consumer Protection Framework 2016 |
Cybersecurity and fraud-investigation records, system access logs, audit trails | Minimum 5 years; longer where required for an active investigation | CBN Risk-Based Cybersecurity Framework for PSPs 2024; CBN Cybersecurity Framework for OFIs 2022; NDPA |
Tax-relevant records | 6 years from end of the relevant tax year | FIRS (Establishment) Act and other tax legislation |
Company records and corporate books containing Personal Information | 6 years | CAMA 2020 |
Marketing and communications preferences and consent records | Until consent is withdrawn or the User becomes inactive for 12 consecutive months, whichever is earlier | NDPA s.25 (consent); NDPR Implementation Framework s.8.2 |
Cookies, device identifiers, analytics data | Up to 24 months from collection or shorter as set in the cookie itself | GAID 2025; NDPR Implementation Framework |
Account login credentials (hashed), session tokens | Up to 90 days after Account Closure | NDPA; security best practice |
Records of Deletion Requests and responses | 5 years from the date of the request | NDPA accountability requirement; CBN supervisory standards |
Where Personal Information falls into more than one category, the longest applicable Retention Period applies. Where a Retention Period has lapsed but the data has been combined with other data subject to a longer period, only the portion subject to the longer period is retained.
7. When We Cannot Delete: Mandatory Retention Exceptions
We will not delete your Personal Information, even on receipt of a valid Deletion Request, where retention is required because:
- it is necessary for compliance with a legal or regulatory obligation, including those listed in Section 3;
- it is required for the establishment, exercise, or defence of legal claims, including in connection with an actual or threatened dispute, regulatory enquiry, or litigation;
- it is required for the prevention, detection, investigation, or reporting of fraud, money laundering, terrorism financing, sanctions evasion, or other criminal activity;
- it is the subject of a hold, freeze, or production order issued by a court, regulator, law enforcement agency, or the NFIU;
- it forms part of a Suspicious Transaction Report (STR), Currency Transaction Report (CTR), or related working file filed with or under examination by the NFIU;
- it is necessary to fulfil the contract between you and PercentPay, including an open or pending transaction, dispute, escrow, Space governance matter, or unresolved chargeback; or
- it is required for archiving in the public interest, scientific or historical research, or statistical purposes, where deletion would render impossible or seriously impair the objectives of that processing.
Where we hold data on the basis of Mandatory Retention, we will:
- restrict access to that data to the minimum necessary personnel;
- use it only for the purposes for which retention is mandated;
- not use it for marketing, profiling, or product development; and
- delete or anonymise it as soon as the basis for retention falls away.
8. Special Circumstances
8.1 Spaces and Multi-Party Data
Where you are a Space Admin or Space Member and your Personal Information is intertwined with the records of a Space that is still active or has not yet completed its lifecycle:
- we will not delete Personal Information that is necessary to operate the Space for the remaining Members, to provide an audit trail of contributions and disbursements, or to satisfy our regulatory record-keeping;
- where you are a Space Admin and the Space has active funds or unresolved transactions, your Deletion Request will not be processed until the Space has been closed in accordance with our Terms and Conditions, or until the funds have been resolved with the Partner Bank and other Members;
- we will, where practicable, pseudonymise your identifying details from the in-App view of other Members (e.g., display name and profile picture), while retaining the underlying records for our regulatory obligations.
8.2 External Depositors into Public Spaces (Non-Users)
Where you are not a registered PercentPay User but you have deposited funds into a Public Space via a Virtual Account Number issued by our Partner Bank, the Personal Information we hold about you is limited (typically your name, the sending bank account number, the BVN-linked identifier provided by NIBSS, the amount, and the date and time of the deposit).
You may request deletion of that Personal Information by contacting our Data Protection Officer at dp*@***********pp.com. However, because that information is part of a transaction record under the MLPPA 2022 and the CBN AML/CFT/CPF Regulations 2022, we will not be able to delete it until the five (5) year Mandatory Retention Floor has lapsed. In the interim, we will restrict access to that information.
8.3 Active Disputes, Investigations, or Legal Proceedings
Where your Personal Information is the subject of an active dispute, investigation, or actual or threatened legal proceeding (including a chargeback, an Escrow dispute, an internal fraud investigation, or an enquiry by the CBN, NFIU, NDPC, FCCPC, or a court), we will place the relevant records under a litigation hold and will not delete them until the matter is resolved and the applicable Retention Period has lapsed.
8.4 Deceased Users
On receipt of credible evidence of the death of a User (such as a certified copy of the death certificate or letters of administration), we will:
- immediately close the deceased User’s Account;
- liaise with the Partner Bank to deal with any wallet balance and active Spaces in accordance with the law of succession of Nigeria;
- delete Personal Information that is no longer required, in line with section 8.2 of the NDPR Implementation Framework; and
- retain only the Personal Information that we are obliged to retain (including AML records, transaction records, and tax records) for the duration of the applicable Mandatory Retention Floor.
8.5 Children’s Data
Where Personal Information has been collected from a person we later confirm to be under the age of eighteen (18), we will treat any deletion request as urgent. We will:
- immediately suspend further processing of that Personal Information;
- delete the Personal Information unless we are subject to a Mandatory Retention obligation;
- preserve only the minimum information necessary to evidence the closure of the Account and the date of deletion.
8.6 Third-Party Requesters
A Deletion Request may be submitted on your behalf by a person duly authorised in writing (such as a lawyer, executor, attorney-in-fact under a registered power of attorney, or legal guardian of a minor). We will require evidence of identity of the requester, evidence of identity of the data subject (or proof of death where applicable), and evidence of authority. We will not act on a third-party request that we are not reasonably satisfied is genuine and authorised.
8.7 Partial Deletion
You may request the deletion of specific categories of your Personal Information (for example, marketing preferences, profile picture, optional profile fields) without closing your Account. Where the requested category is not subject to Mandatory Retention and is not necessary for the operation of your Account, we will action the partial deletion.
9. How to Submit a Deletion Request
You can submit a Deletion Request by:
- Email: sending an email to our Data Protection Officer at dp*@***********pp.com with the subject line “Data Deletion Request”;
- In-App: using the “Delete my account / data” option in your PercentPay Account settings (where available);
- Post: writing to: Data Protection Officer, Percent Technologies Limited, at our registered office address.
To help us process your request quickly, please include:
- your full registered name and PercentPay Tagname;
- the email address and mobile phone number associated with your Account;
- a clear statement of what you want deleted (your entire Account, or specific categories of data);
- any context that explains why you are requesting deletion (this is not required, but it helps us assess any objections under the NDPA);
- proof of identity, as set out in Section 10.
There is no fee for a Deletion Request, unless the request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or refuse to act on the request, in line with the NDPA.
10. Identity Verification
To protect against unauthorised deletion (including by a fraudster who has compromised your email or device), we will verify your identity before acting on a Deletion Request. The verification we apply is proportionate to the sensitivity of the data and the risk of harm.
Verification may include (without limitation):
- confirming your control of the registered email address and mobile phone number on the Account;
- asking security questions or transaction-history questions that only the genuine Account holder is reasonably likely to be able to answer;
- requesting a clear copy of a valid government-issued identification document together with a brief recorded statement confirming the request; and
- for high-value or complex requests, a video verification call.
Where we cannot reasonably verify your identity, we may refuse to action the Deletion Request. We will tell you the reason for the refusal and explain how you can resubmit the request with the necessary verification.
11. Our Response Timelines
We will:
- Acknowledge your Deletion Request within seventy-two (72) hours of receipt;
- Verify your identity within ten (10) business days of receipt of all required verification information;
- Provide a substantive response within thirty (30) calendar days of receipt of your verified request, in line with the NDPA;
- Where the request is complex (for example, where it involves multiple jurisdictions, third parties, or large volumes of data), extend the response period by up to a further sixty (60) calendar days, with notice to you of the reason for the extension.
Where we are unable to delete some or all of your Personal Information because of Mandatory Retention or other restriction set out in this Policy, we will explain to you the reason, the category of data we are required to retain, the legal basis for retention, and the date on which retention is expected to lapse.
12. What We Delete, Restrict, or Anonymise
Following a successful Deletion Request, and subject to Mandatory Retention, we will:
- Delete your Personal Information from our active production systems, including the PercentPay Mobile Application, our customer support tools, our marketing systems, and our analytics tools (other than aggregated, anonymised analytics that cannot be linked back to you);
- Remove or pseudonymise your in-App display details (name, photo, Tagname) so that other Users cannot identify you from your historical activity;
- Restrict access to any Personal Information that is subject to Mandatory Retention, so that only authorised compliance and audit personnel can access it, and only for the purposes for which retention is mandated;
- Instruct our Partner Bank and other third-party service providers to delete or, where applicable, restrict the Personal Information they hold on our behalf, in accordance with our contracts with them and their own legal obligations;
- Delete your Personal Information from our backup systems in accordance with our backup-retention schedule, which currently provides for the deletion of backup copies within ninety (90) days of the corresponding deletion in production.
Anonymised data, by its nature, is no longer Personal Information. We may retain anonymised statistical or analytical information indefinitely.
13. Third Parties and Our Partner Bank (9PSB)
Some of the Personal Information we collect about you is also held by our Partner Bank (9 Payment Service Bank Limited or “9PSB”) and by other third parties who provide services to us (such as hosting providers, KYC providers, analytics providers, and communication providers).
On receipt of a valid Deletion Request, we will:
- promptly notify each relevant third-party processor of the request and instruct them to act in accordance with this Policy and with their own contractual and legal obligations;
- where the third party is itself a Data Controller (for example, 9PSB in respect of wallet, escrow, and VAN data), inform you of that fact and provide you with the third party’s contact details so that you can submit a separate request to them where you wish;
- not require, and not be able to require, 9PSB or any other regulated counterparty to delete data that they are independently required to retain under their own regulatory obligations.
14. Cross-Border Storage and Deletion
Some of our infrastructure (including hosting and backup) may be located outside Nigeria. When we delete your Personal Information, we instruct each relevant infrastructure provider to delete the data from all production and backup environments under their control, in accordance with our contractual arrangements and the requirements of sections 41 to 43 of the NDPA on cross-border data transfers.
Where a cross-border recipient is itself subject to an overriding legal obligation that prevents deletion, we will document the obligation, restrict the use of the data to the purposes for which retention is required, and resume deletion as soon as the obligation lapses.
15. If You Are Not Satisfied
If you are not satisfied with our handling of your Deletion Request, you may:
- escalate the matter to a Senior Officer of PercentPay by writing to in**@***********pp.com;
- refer the matter to our complaints process under Section 30 of our Terms and Conditions;
- lodge a complaint with the Nigeria Data Protection Commission (NDPC) at in**@******ov.ng or via https://ndpc.gov.ng;
- where the matter relates to the underlying wallet, escrow, or VAN, contact the Partner Bank (9PSB) directly and, where appropriate, escalate to the CBN Consumer Protection Department.
We will not retaliate against you in any way for making a Deletion Request, for escalating a concern, or for lodging a complaint with the NDPC or any other competent authority.
16. Method of Deletion
We use deletion methods that are appropriate to the sensitivity of the data and consistent with industry standards, including (as applicable):
- cryptographic erasure (destruction of encryption keys) for encrypted records;
- logical deletion from production databases, with periodic verification;
- overwriting, secure wiping, or physical destruction of decommissioned media;
- pseudonymisation or hashing of identifiers where complete deletion is not yet possible due to Mandatory Retention;
- anonymisation of statistical and analytical records.
17. Records of Deletion
We maintain a record of each Deletion Request and our response to it. The record will typically include the date of the request, the identity of the requester (verified), the categories of data subject to the request, the action taken, the legal basis for any refusal or restriction, the date of deletion or anonymisation, and confirmation that backup copies have been deleted in line with our backup-retention schedule.
We retain this record for five (5) years from the date of the request, in line with the accountability requirements of the NDPA and the supervisory standards of the CBN.
18. Changes to This Policy
We may update this Policy from time to time, in particular where the law, our regulators’ expectations, our products, or our internal practices change. Where the update is material, we will notify you in-App or by email at least seven (7) days before the update takes effect, and we will update the version number and effective date at the top of this Policy.
19. How to Contact Us
For any matter relating to this Policy, including to submit a Deletion Request, you can contact our Data Protection Officer at:
Data Protection Officer
Percent Technologies Limited
Email: dp*@***********pp.com
General Enquiries: in**@***********pp.com
Website: https://percentpayapp.com
Annex A — Internal Workflow for Handling Deletion Requests
This Annex is intended for internal operational use by the PercentPay Data Protection, Compliance, Customer Operations, and Engineering teams. It is not part of the public-facing policy but is published here so that it is auditable and aligned with the policy itself.
A.1 Intake
- All Deletion Requests are routed to the DPO inbox (dp*@***********pp.com) and logged in the Deletion Request Register within 24 hours.
- Each request is assigned a unique Request ID, timestamped, and tagged with: (a) channel of receipt, (b) requester role (User, third party, executor, regulator), (c) scope (full Account or partial), (d) urgency flag (minor, deceased, regulator-driven).
- An acknowledgement is sent to the requester within 72 hours, citing the Request ID and confirming the verification steps required.
A.2 Identity Verification
- Apply the verification matrix in Section 10: minimum step for low-sensitivity requests, escalating to government-ID + recorded statement for full-Account requests.
- Where verification cannot be completed within 10 business days, escalate to the DPO who will decide whether to close the request or extend.
A.3 Mandatory Retention Assessment
- The Compliance team runs the Mandatory Retention checklist against the requester’s record: open transactions, pending disputes, NFIU filings, ongoing investigations, regulatory holds, tax-relevant data, contractual obligations.
- The output is a Retention Determination that lists, for each data category, (a) whether the category can be deleted now, (b) whether it must be retained, (c) the legal basis for retention, and (d) the projected deletion date.
- The Retention Determination is reviewed and signed off by the DPO before any deletion is executed.
A.4 Execution
- Engineering executes the deletion against the production environment using the approved deletion runbook. The runbook covers: (a) the PercentPay primary database, (b) the customer support CRM, (c) the marketing platform, (d) the analytics warehouse (with anonymisation), (e) authentication and session stores, (f) push notification stores, (g) document/object storage (KYC images and receipts).
- Production deletion is recorded with timestamps and a hash of the deleted record set, so that the deletion can be evidenced without retaining the underlying Personal Information.
- Backup copies are deleted in line with the standard backup-retention schedule (90 days), with verification by the Engineering Lead.
- A formal cascade instruction is sent to each external processor (including 9PSB, hosting providers, KYC providers, communication providers). Each is required to confirm execution and to provide their own confirmation timestamp within 30 days.
A.5 Communication with the Requester
- Within 30 calendar days, send the requester a substantive response that itemises (a) what has been deleted, (b) what has been restricted, (c) what has been retained and on what legal basis, (d) the projected date of full deletion, and (e) their right to escalate.
- Where an extension is needed, write to the requester before day 30 with the reason and the revised timeline (capped at +60 days).
A.6 Closure and Audit
- Close the Request in the Register with the Retention Determination, the deletion runbook output, the third-party confirmation evidence, and the response sent to the requester.
- Retain the closed Request record for 5 years for audit purposes (CBN supervisory standards and NDPA accountability).
- Surface metrics monthly to the DPO and the Head of Compliance: volume, source channel, verification time, response time, refusal reasons, escalations to NDPC.
A.7 Periodic Sweep for Lapsed Mandatory Retention
- Engineering runs an automated monthly sweep that identifies records whose Mandatory Retention Floor has lapsed and triggers the appropriate deletion or anonymisation workflow.
- The DPO reviews the sweep output before deletion is finalised, to catch any records that should be held longer (e.g., because a related investigation or litigation hold has been opened).
— END OF DATA DELETION POLICY —