Privacy Policy

UHURU MICROFINANCE BANK LTD

DATA PRIVACY POLICY

Effective Date: October, 14 2025

Last Updated: October, 14 2025

Uhuru Microfinance Bank Ltd (“Uhuru MFB”, “we”, “our”, or “us”) is committed to safeguarding the privacy and security of all personal information entrusted to us by our customers. This Data Privacy Policy outlines the principles and practices guiding how we collect, process, store, and share personal data in compliance with the Nigeria Data Protection Act (NDPA) 2023 and other relevant regulations issued by the Nigeria Data Protection Commission (NDPC).

By engaging our banking products and services—whether through our branches, website, mobile application, or any other digital platform—you acknowledge and agree to the terms set out in this Policy.

Purpose of the Policy

The purpose of this Policy is to ensure transparency and accountability in Uhuru Microfinance Bank’s handling of customers’ personal information. It explains the type of data we collect, the reasons for its collection, how it is processed, and the measures we have adopted to protect it. The Policy also defines the rights of our customers concerning their personal data and our obligations as a data controller and processor.

Data We Collect

Uhuru Microfinance Bank collects and processes personal data that enables us to identify our customers and provide efficient banking services. This may include personal identification details such as full name, date of birth, gender, occupation, address, BVN, NIN, and valid means of identification such as an international passport, driver’s license, or voter’s card. We may also collect contact information including phone numbers and email addresses.

In the course of providing our financial services, we process financial and transactional information such as bank account details, card details, wallet balances, loan records, repayment history, and payment preferences. Technical and digital information such as device identifiers, IP addresses, operating systems, and browsing activity may also be collected through our online banking channels and mobile applications.

Where required, we may process biometric data such as facial images or fingerprints for verification and security purposes. Additional supporting information such as employment details, next-of-kin, proof of address, and income documentation may also be collected as part of our customer onboarding or service delivery process.

Purpose of Data Collection

Personal data is collected and processed for specific, legitimate purposes. These purposes include verifying customer identity in line with Know Your Customer (KYC) requirements; managing and administering customer accounts; facilitating transactions, payments, and loan services; and ensuring compliance with legal, regulatory, and anti-money laundering obligations.

We also process personal data to communicate important account-related information to customers, to improve our products and digital platforms, to enhance customer experience, and to prevent fraud or unauthorized access. In certain cases, data may be used for research and statistical analysis, provided such data is anonymized and cannot identify any individual customer.

Legal Basis for Processing

Uhuru Microfinance Bank processes personal data only on lawful grounds. These include the consent of the data subject, the necessity of processing for the performance of a contract, compliance with legal or regulatory obligations, and the pursuit of legitimate business interests such as risk management and fraud prevention.

Where processing is based on consent, customers have the right to withdraw such consent at any time without affecting the legality of prior processing activities.

Data Sharing and Disclosure

Uhuru Microfinance Bank may share personal data with third parties strictly for legitimate purposes and in accordance with applicable data protection laws. Such third parties include regulatory bodies such as the Central Bank of Nigeria (CBN), the Nigeria Deposit Insurance Corporation (NDIC), the Nigeria Data Protection Commission (NDPC), law enforcement agencies, and other relevant authorities.

We may also share limited data with payment processors, integration partners, switching companies, licensed aggregators, and credit bureaus in order to facilitate transactions and risk assessment. In certain circumstances, professional advisers such as auditors, legal consultants, and IT vendors may have access to personal information under strict confidentiality and data protection agreements.

Uhuru Microfinance Bank does not sell, lease, or trade customers’ personal data to any third party.

Data Retention

All personal data collected by Uhuru Microfinance Bank is retained for as long as necessary to fulfil the purposes for which it was obtained. Data may also be retained to comply with applicable legal and regulatory obligations, resolve disputes, and enforce agreements. Once the retention period expires, data is securely deleted, anonymized, or archived in line with the Bank’s data retention policy and NDPA requirements.

Data Security and Protection

Uhuru Microfinance Bank implements robust technical and organizational measures to protect customers’ personal data from unauthorized access, alteration, loss, or misuse. These measures include data encryption, secured servers, multi-factor authentication, role-based access controls, firewalls, and continuous monitoring of our systems.

Employees and service providers who handle personal data are bound by confidentiality obligations and undergo regular training to ensure compliance with data protection best practices.

International Data Transfers

Where personal data must be transferred outside Nigeria, Uhuru Microfinance Bank ensures that such transfers comply with the Nigeria Data Protection Act 2023. Data is transferred only to countries with adequate data protection standards or under legally binding agreements that guarantee the protection of the transferred data.

Customer Rights

Under the Nigeria Data Protection Act 2023, customers have specific rights concerning their personal data. These include the right to access and obtain a copy of their personal data, the right to request correction of inaccurate information, the right to withdraw consent, and the right to request the deletion of personal data under certain conditions.

Customers may also object to the processing of their data for specific purposes, restrict processing in certain cases, or request the transfer of their data to another service provider (data portability). In addition, customers have the right to lodge a complaint with the Nigeria Data Protection Commission if they believe their data has been mishandled.

All requests relating to data protection should be addressed to the Bank’s Data Protection Officer.

Updates to this Policy

This Data Privacy Policy may be reviewed and updated periodically to reflect changes in legal, regulatory, or operational requirements. Any updates will be communicated through the Bank’s official channels, including its website, mobile application, and branch notice boards. Customers are encouraged to review the Policy regularly to remain informed about how their data is being processed.

Contact Information

For inquiries, feedback, or complaints regarding this Policy or the handling of personal data, customers may contact the Bank through the following channels:

Email:[email protected]

Phone: +234 702 500 3600

Website:www.uhurumfb.com

Address: 121 Aba-Owerri Road, Abia State.