Skip to content
Legal

Privacy Policy

Last Updated: August 3, 2026

Overview & Scope

OneView Technologies Ltd. (“OneView”, “we”, “us”, or “our”) respects the privacy of our enterprise customers, their personnel, and the individuals whose information may be processed through the OneView platform. This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with our website, contracting activities, support services, and enterprise software.

This Policy should be read with the applicable customer agreement and data processing agreement. A financial institution using OneView may provide its own privacy notice to customers and personnel. That notice governs the institution’s independent processing activities and may provide additional information and rights.

Our Role in Processing Personal Data

Customer Data
For identity, transaction, telemetry, screening, case, and regulatory-reporting data submitted by an enterprise customer, the customer generally determines why and how the data is processed and acts as data controller. OneView generally acts as data processor and follows the customer’s documented instructions.
OneView Business Data
OneView acts as an independent controller for personal data we determine how to use, such as website enquiries, contracting contacts, billing contacts, product communications, security records, and support administration.
Role-Specific Terms
The applicable data processing agreement, order form, or law may allocate roles differently for a particular activity. Where those documents conflict with this general explanation, the role-specific document controls.

Individuals Covered

Depending on how OneView is deployed and used, this Policy may concern:

  • Customers, prospective customers, authorized users, administrators, service-account owners, and support contacts.
  • Bank customers, account holders, beneficial owners, directors, signatories, counterparties, merchants, employees, agents, and other persons represented in customer-submitted records.
  • Website visitors, event participants, vendors, professional advisers, and persons who communicate with OneView.

Categories of Data We Process

Identity & KYC Data
Names, customer identifiers, dates of birth, addresses, nationality, identity-document details, photographs, document images, BVN or NIN data, verification results, liveness or biometric-derived results where enabled, risk tiers, PEP status, sanctions results, and related review context.
Transaction & Financial Data
Account numbers, masked or tokenized payment identifiers, transaction references, amounts, currency, direction, payment methods, timestamps, status, counterparties, beneficiary or biller details, and double-entry general ledger legs.
Device, Network & Channel Data
IP addresses, device identifiers or hashes, geolocation coordinates where supplied, VPN or proxy indicators, user agents, application versions, session context, and originating channels such as mobile, web, USSD, card, branch, or API.
Compliance & Investigation Data
Rule matches, risk scores, alerts, review decisions, case notes, report fields, generated CTR, STR, FTR, or GOAML-compatible outputs, audit history, and user actions.
Account & Administration Data
Business contact details, organization names, user roles, permissions, authentication events, service-account identifiers, license records, support requests, and billing or contracting information.
Provider Credentials
Encrypted or otherwise protected API credentials and configuration details supplied by a customer for approved third-party integrations. Secret values should not be exposed in user-facing logs or ordinary support communications.

Sources of Personal Data

We may receive personal data from:

  • Enterprise customers and their authorized users, core banking systems, channels, databases, files, APIs, and service accounts.
  • Customer-selected identity, KYC, AML, sanctions, PEP, fraud, communications, or infrastructure providers.
  • Individuals who contact us, submit a website form, request a demonstration, participate in contracting, or seek support.
  • System-generated logs, security monitoring, licensing activity, and product interaction records, subject to the configured deployment boundary.
  • Public, governmental, regulatory, or commercially licensed sources where lawfully used for screening or compliance purposes.

Purposes of Processing

Depending on the licensed modules and customer instructions, personal data may be processed to:

  • Provide, authenticate, secure, administer, support, and maintain the Service.
  • Ingest and monitor transactions, evaluate configurable rules, identify anomalies, and support fraud or account-takeover prevention.
  • Orchestrate customer-selected identity verification, document, PEP, sanctions, and other compliance checks.
  • Generate, validate, review, and export compliance and regulatory reports, including CTR, STR, FTR, and GOAML-compatible files.
  • Create audit records, investigate errors or misuse, enforce access controls, and preserve operational accountability.
  • Manage enterprise relationships, licenses, invoices, demonstrations, support requests, notices, and product communications.
  • Comply with law, lawful regulatory requests, court orders, and obligations to establish, exercise, or defend legal claims.

Legal Bases & Customer Instructions

Where OneView acts as controller, processing may rely on performance of a contract, steps requested before entering a contract, compliance with a legal obligation, legitimate interests that are not overridden by individual rights, consent where required, or another lawful basis recognized by applicable law.

Where OneView acts as processor, the enterprise customer is responsible for identifying and documenting the lawful basis for Customer Data, providing required notices, respecting purpose limitation, and issuing lawful instructions. OneView processes that data only as permitted by the Agreement, the customer’s documented instructions, and applicable law.

Automated Rules & Human Review

OneView can evaluate customer-configured transaction rules, calculate or display risk indicators, trigger configured interventions, and prepare reports. The enterprise customer determines the rules, thresholds, response actions, and legal or operational effect of those outputs.

Customers are responsible for providing any notice, human review, appeal, exception handling, enhanced due diligence, or other safeguard required before making a decision that has a legal or similarly significant effect on an individual. OneView does not independently decide whether a person should be denied a financial service or reported to an authority.

Deployment Architecture & Data Sovereignty

On-Premises or Private Cloud
Where OneView is deployed inside a customer-managed environment, full customer PII, transaction payloads, results, and historical logs are stored within that environment. The customer controls the database, backups, network boundary, retention configuration, and local access.
Provider Egress
When an authorized workflow calls a customer-selected provider, only the fields required for that selected service are transmitted to the allowlisted provider endpoint. Provider-bound requests are not routed through the OneView corporate control plane unless an applicable agreement expressly states otherwise.
Control-Plane Data
Licensing and update services may receive limited installation, entitlement, version, environment, and health metadata approved for that purpose. They are not intended to receive customer KYC records or transaction payloads.
Company-Hosted Services
If a hosted service is expressly included in an order form, its hosting location, encryption controls, subprocessors, retention, and security commitments will be described in the applicable agreement, data processing agreement, or security schedule. OneView does not claim a certification unless that certification is expressly identified in a signed agreement or current assurance document.

Sharing & Disclosure

OneView does not sell, rent, or monetize Customer Data. Personal data may be disclosed only as appropriate to:

  • Customer-selected identity, screening, payment, communications, or other providers when an authorized workflow requests their service, including through BYOK credentials.
  • Approved subprocessors and service providers that support hosting, security, communications, support, billing, or business operations and are bound by appropriate contractual obligations.
  • Professional advisers, auditors, insurers, financing sources, and transaction counterparties subject to confidentiality and need-to-know restrictions.
  • Regulators, courts, law-enforcement bodies, or other authorities where disclosure is required or permitted by law, or is reasonably necessary to protect rights, safety, systems, or legal claims.
  • A successor or prospective successor in a merger, financing, reorganization, acquisition, or sale, subject to appropriate confidentiality and data-protection safeguards.

International Data Transfers

A customer may configure providers or infrastructure located outside the country where data originates. The customer is responsible for assessing and authorizing those provider destinations when OneView acts on the customer’s instructions.

Where OneView transfers personal data as controller or processor across borders, we use a lawful transfer mechanism and appropriate safeguards required by the Nigeria Data Protection Act 2023, the NDP Act General Application and Implementation Directive 2025, the GDPR where applicable, or other relevant law. Transfer details may be addressed in the applicable data processing agreement.

Retention, Return & Deletion

Customer-Managed Data
For on-premises and customer-managed private cloud deployments, the customer determines and operates retention, archival, backup, legal-hold, export, and deletion controls for Customer Data, subject to applicable law and the Agreement.
Company-Held Data
OneView retains business, account, support, security, and any expressly hosted data only for as long as needed for the stated purpose, the Agreement, legal obligations, dispute resolution, fraud prevention, and legitimate recordkeeping.
End of Service
Return, export, deletion, and backup-expiry procedures for Company-hosted Customer Data are governed by the order form and data processing agreement. Deletion may be delayed where retention is legally required or data is preserved under a valid legal hold.

Security Measures

OneView applies technical and organizational measures appropriate to the nature of the Service and the processing under our control. Depending on the deployment, these measures may include access controls, least-privilege permissions, authentication, encryption in transit, protected secret storage, audit logging, secure development practices, vulnerability management, backup procedures, and incident response.

No system can be guaranteed completely secure. Customers remain responsible for securing their own infrastructure, endpoints, identity systems, databases, backups, networks, and credentials, and for applying supported updates in accordance with the Agreement.

Personal Data Breaches & Security Incidents

OneView maintains procedures to identify, investigate, contain, remediate, and document security incidents affecting systems under our control. Where OneView acts as processor and becomes aware of a personal data breach affecting Customer Data, we will notify the affected customer without undue delay and provide information reasonably available to support the customer’s assessment and legal duties.

The enterprise customer is responsible for regulatory and data-subject notifications unless the applicable agreement or law assigns that responsibility to OneView. Customers must promptly notify OneView of suspected compromise involving OneView credentials, integrations, or software.

Data Subject Rights

Subject to applicable law, individuals may have rights to receive information about processing, request access, obtain a copy, correct inaccurate data, request deletion, restrict or object to processing, request portability, withdraw consent, challenge certain automated decisions, and lodge a complaint with a competent supervisory authority.

These rights are not absolute. A request may be limited where identity cannot be verified, another person’s rights would be affected, retention is legally required, an exemption applies, or the request should be handled by the enterprise customer that controls the data.

How to Exercise Privacy Rights

If your information was submitted to OneView by a bank, employer, or other enterprise customer, contact that organization first. As controller, it is generally responsible for responding to your request. When instructed and legally permitted, OneView will provide reasonable assistance to the customer.

For personal data OneView controls directly, send a request to privacy@oneview.ng. We may request information necessary to verify identity and authority. Authorized representatives may be required to provide proof of authorization. We will respond within the period required by applicable law.

Where a request involves data processed by a third-party KYC or verification provider connected via a Bring Your Own Keys (BYOK) workflow, the individual must direct such requests to the respective enterprise customer or third-party vendor controlling those API credentials.

Website Data, Communications & Cookies

Our public website may process basic device, browser, request, security, and interaction data needed to deliver pages, prevent abuse, diagnose faults, and understand service performance. If optional analytics, marketing technologies, or non-essential cookies are introduced, we will provide any notice and choice required by applicable law.

You may opt out of non-essential product or marketing emails using the instructions in the message or by contacting us. Service, security, legal, billing, and account notices may still be sent where necessary for an enterprise relationship.

Children

OneView is an enterprise compliance platform and is not directed to children. We do not knowingly collect personal data directly from children through the public website. Customer Data may include information relating to a minor where an enterprise customer has a lawful basis and uses the Service for an authorized purpose. The customer remains responsible for notices, permissions, safeguards, and age-related legal requirements for that processing.

Regulatory Compliance & Complaints

OneView is designed to support customers’ obligations under the Nigeria Data Protection Act 2023, the NDP Act General Application and Implementation Directive 2025, sector-specific requirements, and the GDPR where applicable. Compliance depends on the customer’s configuration, instructions, deployment controls, notices, lawful basis, retention, and operational use.

You may raise a privacy concern with us using the contacts below. You may also have the right to complain to the Nigeria Data Protection Commission or another supervisory authority with jurisdiction over the processing.

Changes to This Policy

We may update this Privacy Policy to reflect changes in law, guidance, technology, deployment models, or our processing practices. The revised version will be posted with a new “Last Updated” date. Where required, we will provide additional notice of a material change through an appropriate channel.

Contact Information

For privacy questions, data-protection requests, or enterprise privacy documentation, contact:

Data Protection Officer
dpo@oneview.ng
General Enquiries
info@oneview.ng