Skip to content Skip to footer

Azari Pay Technologies Ltd Data Processing Agreement (DPA)

Effective Date: 27/7/2026

Last Updated: 27/7/2026

  1. Purpose

This Data Processing Agreement (“DPA“) forms part of the agreement between AzariPay Technologies Ltd(“AzariPay“, “Controller“, “Processor“, “we“, “our“, or “us“, as applicable) and the customer, merchant, business client, enterprise customer, service provider, technology partner, or other contracting party (“Customer“, “Business Partner“, “Controller“, or “Processor“, as applicable).

This DPA governs the Processing of Personal Data in connection with the products and services provided by AzariPay and supplements the applicable commercial agreement, Terms and Conditions, Privacy Policy, Merchant Agreement, API Agreement, or other contract between the parties.

  1. Definitions

For the purposes of this DPA:

  • Applicable Data Protection Laws means all laws and regulations governing the Processing of Personal Data applicable to the parties, including those of jurisdictions in which the Services are offered.
  • Controller means the party that determines the purposes and means of Processing Personal Data.
  • Processor means the party that Processes Personal Data on behalf of a Controller.
  • Personal Data means any information relating to an identified or identifiable natural person.
  • Processing includes collecting, recording, storing, organising, using, transmitting, disclosing, analysing, deleting, or otherwise handling Personal Data.
  • Data Subject, Personal Data Breach, Sub-Processor, and other capitalised terms shall have the meanings assigned under Applicable Data Protection Laws.
  1. Scope

This DPA applies whenever either party Processes Personal Data in connection with:

  • Digital Wallet Services;
  • Business Accounts;
  • Merchant Services;
  • Payment Processing;
  • Cross-Border Payments;
  • Card Services;
  • Global Accounts;
  • API Services;
  • Identity Verification;
  • Customer Support;
  • Fraud Prevention;
  • Compliance Services; and
  • Any other AzariPay products or services.
  1. Roles of the Parties

Depending on the Service provided:

  • AzariPay may act as a Controller;
  • AzariPay may act as a Processor;
  • Both parties may act as independent Controllers; or
  • The parties may have another lawful relationship recognised under Applicable Data Protection Laws.

Each party shall comply with the obligations applicable to its role.

  1. Subject Matter and Duration

This DPA applies for as long as Personal Data is Processed under the applicable commercial agreement and continues until all Personal Data has been securely returned, deleted, anonymised, or otherwise disposed of in accordance with Applicable Data Protection Laws.

  1. Categories of Personal Data

Depending on the Services used, Personal Data may include:

  • Name;
  • Date of birth;
  • Nationality;
  • Residential address;
  • Email address;
  • Telephone number;
  • Government-issued identification details;
  • Biometric verification information where permitted by law;
  • Financial information;
  • Bank account details;
  • Wallet information;
  • Transaction history;
  • Merchant information;
  • Business registration details;
  • Device identifiers;
  • IP addresses;
  • Geolocation data where authorised;
  • Customer communications; and
  • Any other information necessary for providing the Services.
  1. Categories of Data Subjects

Data Subjects may include:

  • Individual Customers;
  • Business Customers;
  • Merchants;
  • Directors;
  • Beneficial Owners;
  • Employees;
  • Authorised Users;
  • Vendors;
  • Agents;
  • Contractors;
  • Applicants;
  • Website Visitors; and
  • Other individuals whose Personal Data is Processed in connection with the Services.
  1. Processing Instructions

Where AzariPay acts as a Processor, it shall Process Personal Data only:

  • On documented instructions from the Controller;
  • As required to provide the agreed Services; or
  • As otherwise required by applicable law.

If AzariPay believes an instruction violates Applicable Data Protection Laws, it may notify the Controller and suspend implementation until the matter is resolved.

  1. Confidentiality

Each party shall ensure that personnel authorised to Process Personal Data:

  • Are subject to confidentiality obligations;
  • Receive appropriate privacy and security training; and
  • Access Personal Data only where necessary for their duties.

These obligations survive termination of this DPA.

  1. Security Measures

Each party shall implement appropriate technical and organisational measures to protect Personal Data, including, where appropriate:

  • Encryption;
  • Access controls;
  • Multi-factor authentication;
  • Secure development practices;
  • Network security;
  • Logging and monitoring;
  • Vulnerability management;
  • Business continuity measures;
  • Disaster recovery arrangements; and
  • Regular security assessments.

Security measures shall be proportionate to the risks presented by the Processing.

  1. Sub-Processors

AzariPay may engage Sub-Processors to provide services such as:

  • Cloud hosting;
  • Payment processing;
  • Identity verification;
  • Customer support;
  • Fraud prevention;
  • Analytics;
  • Communications;
  • Technology infrastructure; and
  • Other operational services.

AzariPay shall ensure that Sub-Processors are bound by appropriate contractual obligations regarding the protection of Personal Data.

  1. International Data Transfers

Personal Data may be Processed in countries outside the jurisdiction where it was collected where necessary for providing the Services.

Where required by Applicable Data Protection Laws, appropriate safeguards shall be implemented before transferring Personal Data internationally.

  1. Assistance with Data Subject Rights

Where applicable, the Processor shall reasonably assist the Controller in responding to lawful requests relating to:

  • Access;
  • Correction;
  • Erasure;
  • Restriction;
  • Objection;
  • Data portability;
  • Withdrawal of consent; and
  • Other rights available under Applicable Data Protection Laws.
  1. Personal Data Breaches

Each party shall maintain procedures for identifying, investigating, containing, and responding to Personal Data Breaches.

Where required by law or contract, the Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed on the Controller’s behalf and provide available information reasonably necessary for the Controller to comply with its legal obligations.

  1. Audits and Compliance

Where required by Applicable Data Protection Laws or the applicable commercial agreement, and subject to appropriate confidentiality safeguards, a Controller may request reasonable information demonstrating the Processor’s compliance with this DPA.

Any audit rights shall be exercised:

  • On reasonable notice;
  • During normal business hours;
  • In a manner that does not unreasonably interfere with business operations; and
  • Subject to security and confidentiality requirements.
  1. Retention and Deletion

Upon termination of the applicable agreement, or when Personal Data is no longer required, the Processor shall, subject to Applicable Data Protection Laws:

  • Return Personal Data;
  • Delete Personal Data; or
  • Anonymise Personal Data,

unless retention is required by law, regulation, court order, or legitimate compliance obligations.

  1. Regulatory Cooperation

Each party shall cooperate with lawful requests from competent supervisory authorities and regulatory bodies where required by Applicable Data Protection Laws.

Nothing in this DPA requires either party to disclose information where disclosure would be unlawful or subject to legal privilege.

  1. Liability

Each party remains responsible for its own compliance with Applicable Data Protection Laws and shall be liable for breaches of this DPA to the extent provided under the applicable commercial agreement and governing law.

Nothing in this DPA excludes liability that cannot lawfully be limited or excluded.

  1. Changes to this DPA

AzariPay may amend this DPA where necessary to reflect:

  • Changes in law;
  • Regulatory guidance;
  • Industry standards;
  • Technology developments;
  • Security improvements; or
  • Operational requirements.

Material changes will be communicated where required by applicable law or contract.

  1. Governing Law

This DPA shall be governed by the governing law specified in the applicable commercial agreement, unless mandatory local law requires otherwise.

  1. Contact Information

Questions relating to this DPA or Personal Data Processing may be directed to:

AzariPay Technologies Ltd

Website: www.azaripay.co

Privacy Email: privacy@azaripay.co

Compliance Email: compliance@azaripay.co

General Enquiries: info@azaripay.co

Customer Support: support@azaripay.co

Registered Office: [Abuja, Nigeria]

  1. Order of Precedence

If there is any conflict between this DPA and the applicable commercial agreement regarding the Processing of Personal Data, this DPA shall prevail solely to the extent of that conflict. All other provisions of the commercial agreement shall remain in full force and effect.

  1. Acceptance

By entering into the applicable commercial agreement, using the Services, or otherwise engaging AzariPay to Process Personal Data, the parties acknowledge that they have read, understood, and agree to be bound by this Data Processing Agreement.

24. Account Deletion

The account deletion will happen from the app, More screen —> Profile —> Delete account.

When user clicks on delete account button, a modal appears that tells them:

  1. That this deletion is final, it cannot be undone
  2. Their information being deleted – their profile, wallet info, saved beneficiaries etc
  3. ⁠⁠If we are going to retain any information required by law like their kyc.