Back home

Legal

Privacy Policy

Zolan Global Technologies Limited

Effective 1 July 2026 · Updated 19 June 2026 · Version 1.1

This Privacy Policy explains how Zolan Global Technologies Limited collects, uses, stores, shares, and protects your personal data when you use the Zolan Platform. Please read it carefully. By using our Services, you confirm that you have read and understood this Policy. It should be read together with our Terms of Use.

1. Who We Are and How to Contact Us

Zolan Global Technologies Limited (“Zolan”, “we”, “us”, or “our”) is a company incorporated under the Companies and Allied Matters Act (CAMA) 2020 in the Federal Republic of Nigeria. We operate a cross-border payments and financial services platform for Micro, Small, and Medium Enterprises (MSMEs) across Africa, accessible at usezolan.com.

Our role. Zolan is a data controller for personal data processed in connection with your use of the Platform. Certain regulated payment and virtual asset services are delivered together with our Licensed Partners. For those activities Zolan and the relevant Licensed Partner may act as joint controllers, or Zolan may act as a processor on the Partner’s instructions, depending on the activity. Where a Licensed Partner is the controller, its privacy notice also applies to that processing.

2. Scope and Legal Framework

This Policy applies to all personal data Zolan processes in connection with: your use of the Platform, website, and any associated apps or APIs; our cross-border payment, remittance, currency conversion, stablecoin wallet, and CNY supplier payment services; your registration, onboarding, and Know-Your-Business (KYB) / Know-Your-Customer (KYC) checks; blockchain and virtual asset transaction monitoring and wallet screening; and our communications with you. It does not cover third-party websites or services linked from the Platform, which have their own policies.

Zolan processes personal data in compliance with the NDPA 2023 and the GAID 2025, which together form Nigeria’s operative data protection framework and are administered by the NDPC. Mandatory obligations under the Anti-Money Laundering and Counter-Terrorist Financing Laws also shape our processing.

3. Our Data Protection Principles

Our processing follows the NDPA principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. We collect only the minimum data needed for the purposes in this Policy, retain it only as long as necessary (Section 8), and maintain records of our processing activities.

Impact assessments. For higher-risk processing — large-scale financial data, systematic profiling, blockchain transaction analysis, and cross-border transfers — we conduct Data Protection Impact Assessments before processing begins, in line with the NDPA and GAID. Where a residual high risk cannot be mitigated, we consult the NDPC before proceeding.

4. What Personal Data We Collect

The data we collect depends on your relationship with us and the services you use:

  • Identity and registration: legal name(s) of owners and authorised representatives; government-issued ID; date of birth and nationality; selfie/verification images; business registration name and number (CAC or equivalent); Tax Identification Number where required; and business address.
  • Biometric data: facial geometry extracted from selfie images for liveness detection and matching against your ID document, plus the match result. This is processed by our identity-verification provider acting as our processor, and is not retained beyond verification except where the law requires.
  • Contact and communication: email, phone, correspondence address, communication preferences, and records of your contact with us (support tickets, emails, chat logs).
  • Financial and transaction: bank and payment instrument details, wallet information, transaction history and counterparties, source-of-funds and purpose declarations, FX records, balances and limits, and dispute/refund records.
  • Business verification (KYB): incorporation and constitutional documents, board resolutions, financial statements (for enhanced due diligence), licences, and ownership/control charts.
  • Technical and usage: IP address and device identifiers, browser and OS, login and session data, on-platform activity, error logs, and cookies (Section 11).
  • Compliance and risk: sanctions, PEP, and adverse-media screening results; risk classification and enhanced due diligence records; and regulatory records generated under our AML/CFT obligations.
  • Blockchain and virtual asset: wallet addresses and on-chain data (sender address, transaction hash, network, amount, timestamp); wallet risk scores from blockchain analytics providers; hop-analysis of sending-wallet history (typically 2–3 transactions back) to assess origin of funds; Travel Rule originator/beneficiary information; and stablecoin-to-fiat conversion records.
  • Trade and supplier (CNY corridor): Chinese supplier details and business registration (营业执照), supplier bank details, trade documentation (pro forma invoices, purchase orders, Bills of Lading, customs declarations), goods category, import history, and pricing data used for invoice-reasonableness checks.
  • Data from third parties: verification and screening results from Licensed Partners and identity providers; government and regulatory databases (e.g. CAC, FIRS, NIN, NIBSS BVN); sanctions and watchlists (NFIU, CBN, OFAC, UN, EU, UK HMT); blockchain analytics intelligence; and correspondent/recipient banks.

5. How We Use Your Data and Our Legal Bases

We process your data only where we have a valid legal basis under the NDPA. Our key processing activities are:

  • Registration and onboarding
  • KYC/KYB verification (incl. biometrics)
  • Processing payments and remittances
  • Sanctions, PEP, adverse-media screening
  • FX and conversion
  • Travel Rule data exchange
  • CNY supplier payments and TBML controls
  • Fraud detection and prevention
  • AML transaction monitoring
  • Customer support and disputes
  • Regulatory reporting
  • Platform security and integrity
  • Service notifications
  • Marketing communications
  • Service improvement

6. How We Share Your Data

We do not sell your personal data. We share it only as needed, and only with parties bound to protect it:

  • Licensed Partners (licensed payment providers, financial institutions, and VASPs) to deliver regulated services, bound by contract to use it only for the agreed purposes.
  • Regulators and law enforcement, where required by law. These disclosures are mandatory and may be made without prior notice where the law requires.
  • Identity, KYB, and compliance providers (verification, biometric matching, sanctions screening, fraud prevention), acting as our processors under data processing agreements.
  • Blockchain analytics providers, for wallet screening, on-chain monitoring, and risk scoring (wallet addresses, transaction hashes, network identifiers, amounts).
  • Travel Rule solutions and counterpart VASPs, to exchange originator/beneficiary information where FATF Recommendation 16 applies (including South Africa and Kenya).
  • Technology and infrastructure providers (cloud hosting, databases, cybersecurity) under contractual protections.
  • Correspondent and recipient banks, including Chinese financial institutions for CNY supplier payments, to execute transactions and meet international AML/CFT standards.
  • Professional advisers (legal, audit) under confidentiality, and an acquirer in a merger, sale, or restructuring (subject to equivalent protections; we will notify you where required).

Knowing who holds your assets. Where stablecoin balances are custodied by a Licensed VASP Partner, we will identify that custodian to you at onboarding and in our subprocessor list, so you know which regulated entity holds your assets.

7. Your Rights

Under the NDPA you have the following rights over your personal data. Business entities may exercise them in respect of personal data relating to their officers, signatories, or beneficial owners.

  • Access — confirmation of whether we process your data and a copy of it.
  • Rectification — correction of inaccurate or incomplete data (much can be updated in-app).
  • Erasure — deletion where data is no longer needed or consent is withdrawn, subject to legal retention (we cannot delete records we must keep under the ML(PP)A 2022, minimum five years).
  • Restriction — to pause processing, e.g. while accuracy or an objection is being assessed.
  • Portability — to the extent provided by the NDPA, your data in a structured, common format where processing is by consent or contract and automated; this does not extend to data we must retain for compliance.
  • Objection — to legitimate-interests processing (including profiling for fraud prevention), and an absolute right to object to direct marketing.
  • Human review of automated decisions — see Section 9.
  • Withdraw consent — at any time, without affecting prior lawful processing.

Exercising your rights. Email compliance@usezolan.com with your name, account details, and the right you wish to exercise. We will acknowledge within 5 business days and respond within 30 days; for direct-marketing objections we will stop without undue delay. Complex or numerous requests may take a further 30 days, of which we will notify you. We may verify your identity first.

8. How Long We Keep Your Data

We retain data only as long as necessary for the purpose collected, to meet legal obligations, and to resolve disputes. If you close your Account, we will keep your data only as required to meet regulatory, anti-money laundering, and fraud prevention obligations. All data retention complies with the timelines and legal requirements of applicable law. After the applicable period, data is securely deleted or anonymised.

9. Security and Breach Notification

We apply appropriate technical and organisational measures, including: encryption of data in transit and at rest; multi-factor authentication; least-privilege access controls; regular security testing; and monitoring to detect and respond to incidents. Organisationally, we run staff data-protection training, hold data processing agreements with all processors, conduct internal audits, and maintain a documented breach-response procedure overseen by our DPO.

Breach notification. Where a breach is likely to risk your rights and freedoms, we notify the relevant authority without undue delay — the NDPC within 72 hours (NDPA/GAID); the Information Regulator (South Africa, POPIA) and the Data Protection Commissioner (Kenya, within 72 hours) where applicable; and other authorities within their required timeframes. Where the risk to you is high, we will also notify you directly. No system is completely secure; if you suspect your account is compromised, contact us immediately at compliance@usezolan.com.

10. Cookies

We use cookies and similar technologies on our website and Platform. Optional cookies (analytics and marketing) are activated only after you consent via our cookie settings panel; strictly necessary and security cookies are on by default because the Platform cannot function or stay compliant without them.

11. Marketing Communications

We send marketing only with your prior, freely given consent, which you can give at registration or in your account preferences. You can withdraw it at any time via the unsubscribe link, your account settings, or compliance@usezolan.com, and we will action it without undue delay. Opting out does not stop essential service notifications (account status, transaction confirmations, security alerts, regulatory notices, and changes affecting services you use), which are not marketing.

12. International Data Transfers

Because we operate a cross-border payments platform, your data is necessarily transferred across borders to process international payments. When transferring personal data outside Nigeria, we will ensure to comply with applicable regulations. Where local storage is required, we keep a copy on servers in the relevant jurisdiction.

13. Children, Changes, and Contact

Children. The Platform is for business users and is not directed at anyone under 18. We do not knowingly collect children’s data and will delete it promptly if we become aware of it.

Changes to this Policy. We may update this Policy to reflect changes in our practices or the law. For material changes we will notify you by email or a prominent Platform notice at least 14 days before they take effect, and the current version will always be at usezolan.com/privacy. Where a material change introduces a new basis for processing data previously handled under your consent, we will seek fresh consent first; continued use of the Platform alone does not constitute consent to new or materially different processing.

Governing law. This Policy is governed by the laws of the Federal Republic of Nigeria, including the NDPA 2023.

Contact. Privacy and data protection: compliance@usezolan.com · General support: support@usezolan.com · usezolan.com/privacy · Subprocessor list: usezolan.com/subprocessors

Prepared by the Legal and Compliance team of Zolan Global Technologies Limited. Version 1.1 · June 2026 · usezolan.com/privacy