Privacy Policy
Effective date: 1 June 2025 · Last updated: 15 September 2026
1. Scope
This Privacy Policy explains how KONECTGATE Integrated Solutions Limited ("KONECTGATE", "we", "us") collects, uses, discloses, and protects personal data when you use the KREO website, mobile applications, APIs, and merchant dashboard (the "Platform"). It applies to merchants, their authorised users, and visitors to our website.
2. Information We Collect
Account & KYC data: business name, registration details, BVN consent confirmation token (we never store the BVN itself, only the token issued by NIBSS iGree), and contact information.
Transaction data: eNaira receipts, settlement records, and NIP transfer references processed through the Platform.
Usage data: pages visited, features used, device and browser information, and log data collected via cookies (see our Cookie Policy).
Communications: messages you send us through the contact form, email, or support channels.
3. How We Use Your Information
We use personal data to: operate and maintain the Platform; verify merchant identity and conduct KYC/AML checks; process eNaira transactions and NIP settlements; provide customer support; detect and prevent fraud; comply with CBN, NIBSS, and NDPR regulatory obligations; and improve the Platform through privacy-first, aggregated analytics.
4. Legal Basis for Processing
We process personal data under the Nigeria Data Protection Regulation (NDPR) 2019 on the basis of: your consent (e.g. BVN verification via NIBSS iGree); performance of our contract with you as a registered Merchant; and compliance with legal obligations, including CBN AML/CFT Regulations and NIBSS regulatory reporting requirements.
5. Data Sharing & Disclosure
We share data only where necessary to operate the Platform: with NIBSS (iGree consent verification, NIP settlement, NQR registry), the CBN eNaira platform, our Sponsor FI for settlement processing, and regulators where legally required. We do not sell personal data, and we do not share data with third-party advertisers or ad networks.
6. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy, or as required by CBN and NIBSS regulatory reporting obligations. BVN consent tokens and transaction records are retained in line with CBN AML/CFT record-keeping requirements. You may request deletion of data we are not legally required to retain.
7. Data Security
We protect personal data with mTLS encryption in transit, encryption at rest, and CBN AML/CFT transaction screening. Access to merchant data is restricted to authorised personnel on a need-to-know basis. Despite these measures, no system is completely secure, and we cannot guarantee absolute security.
8. Your Rights
Under the NDPR, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of data we are not legally required to retain; withdraw consent where processing is based on consent; and lodge a complaint with the National Information Technology Development Agency (NITDA). To exercise these rights, contact us using the details in Section 11.
10. Children's Privacy
The Platform is intended for use by registered businesses and their authorised representatives. We do not knowingly collect personal data from individuals under the age of 18.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified at least 14 days in advance via the email address or phone number on file, and continued use of the Platform after that date constitutes acceptance of the updated Policy.
12. Contact Us
For questions about this Privacy Policy or to exercise your data rights, contact us at info@konectgate.com, or write to KONECTGATE Integrated Solutions Limited, Lagos, Nigeria.