LEGAL

Spendek Privacy Policy

Last updated: 7 September 2026Effective date: 7 September 2026Version: 1.0

1. Who we are

This Privacy Policy explains how FRP LIMITED (RC 8930511) ("Spendek", "we", "us", "our"), a company incorporated in the Federal Republic of Nigeria with its registered office at Primaltek Plaza, No. 62/64 Egbeda–Idimu Road, Egbeda, Lagos, Lagos State, Nigeria, collects, uses, stores, shares and protects your personal data when you use the Spendek mobile application, the website at spendek.com, and any related services (together, the "Services").

Spendek is the data controller in respect of the personal data described in this Policy.

We are registered with the Nigeria Data Protection Commission ("NDPC"). Our data protection registration number is NDPC/DPC/11694.

Data Protection Officer

Faith Umunnakwe

Email: dpo@spendek.com

Address: Primaltek Plaza, No. 62/64 Egbeda–Idimu Road, Egbeda, Lagos, Lagos State, Nigeria

This Policy is issued in compliance with the Nigeria Data Protection Act 2023 ("NDPA"), the Nigeria Data Protection Regulation 2019 ("NDPR"), and any subsidiary legislation, guidance or directives issued by the NDPC.

2. Scope

This Policy applies to all users of the Services, including account holders, dependants and sub-account users, prospective users, and visitors to our website.

It does not apply to the practices of third parties whose services you access through Spendek, including your bank, Mono Technologies Nigeria Limited, Flutterwave, or Apple and Google — who both distribute the app and, where you buy Linx tokens inside it, take the payment as merchant of record. Those parties handle your data under their own policies, and we encourage you to read them.

3. Personal data we collect

3.1 Data you give us directly

CategoryExamplesWhen collected
Identity dataFirst name, middle name, surname, date of birth, genderRegistration; identity verification
Contact dataEmail address, phone number, residential addressRegistration; profile updates
Profile dataProfile photograph, spending category preferences, budget and envelope configurationsRegistration; ongoing use
Government identifiersNational Identification Number (NIN)Identity verification
Authentication dataPassword (stored only as a salted cryptographic hash), transaction PIN, two-factor authentication settings, biometric preference flagRegistration; security settings
Manually entered financial dataTransactions you record yourself, receipts you upload, cash splits, budget limitsOngoing use
Uploaded bank statementsStatement files you upload in PDF or CSV form so we can read the transactions in them. A statement usually contains your full transaction history for the period, your account number and your account holder nameWhen you import a statement
Family and dependant dataNames, email addresses and relationship details of dependants or sub-account users you inviteWhen you create a sub-account
CommunicationsMessages you send to support, feedback, survey responsesWhen you contact us

3.2 Data we collect from your financial institutions

Where you choose to link a bank account, we receive the following through our licensed open banking partner:

  • Account identity: account holder name, account number (in whole or in part), account type, institution name and code.
  • Balance data: current and available balances, currency.
  • Transaction data: transaction narration, amount, debit or credit indicator, date, running balance and, where available, merchant or category signals.
  • Where you consent to it, identity and income attributes held by your bank.
Read-only access

We receive this data on a read-only basis. Spendek cannot move money out of, or initiate a transfer from, any account you link. We never receive or store your internet banking username, password, PIN, token or one-time passwords — those are entered directly with your bank or our open banking partner and are never accessible to us.

3.3 Data generated by your use of the Services

  • Usage and interaction data: features used, screens viewed, session timing, actions taken.
  • Device and technical data: device model, operating system and version, application version, language, time zone, IP address, unique device or installation identifiers, crash and diagnostic logs.
  • Transaction categorisation, budget performance, insights and analytics we derive from your financial data.
  • Records of AI interactions: prompts you submit to Linx, the responses returned, and metering records (request counts, tokens reserved, settled or released).
  • Payment records: amounts paid, payment references, payment status, token balances and purchase history. Where you buy inside the app, the payment itself is taken by Apple or Google and we receive only confirmation of the purchase — never your card details.

3.4 Data from third parties

  • Identity verification results from our verification partner, including verified name, date of birth, gender, phone number, state and local government of origin and residence, and residential address associated with your NIN.
  • Payment confirmations from our payment partner.
  • Fraud, sanctions and watchlist screening resultswhere such screening is carried out.

3.5 Sensitive personal data

Your National Identification Number (NIN) and your financial data are treated as sensitive personal data under the NDPA. We apply enhanced safeguards to this data as described in section 9.

We do not knowingly collect data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, health data or sexual orientation. Please do not submit such information to us, including in free-text fields or messages to Linx.

4. How and why we use your data

We process personal data only where we have a lawful basis to do so. Each purpose below is listed with its basis.

PurposePersonal data usedLawful basis (NDPA s.25)
Creating and administering your accountIdentity, contact, authenticationPerformance of a contract
Verifying your identity and meeting KYC/AML obligationsIdentity, government identifiers, verification resultsLegal obligation; performance of a contract
Linking bank accounts and importing transactionsBank account, balance and transaction dataConsent; performance of a contract
Categorising spending, producing budgets, envelopes and insightsFinancial data, usage dataPerformance of a contract
Providing Linx AI features (chat, forecasts, envelope suggestions)Bounded, aggregated financial summaries; your promptsConsent; performance of a contract
Processing payments for Linx tokensPayment records, identity, contactPerformance of a contract
Preventing fraud, abuse and unauthorised accessDevice, usage, authentication, transaction dataLegitimate interests; legal obligation
Securing the Services and investigating incidentsDevice, technical, log dataLegitimate interests; legal obligation
Support and responding to your enquiriesContact, communications, account dataPerformance of a contract; legitimate interests
Service emails and in-app notices (security, billing, service changes)Contact dataPerformance of a contract; legal obligation
Marketing communicationsContact data, usage dataConsent
Product improvement and analyticsAggregated or de-identified usage dataLegitimate interests
Establishing, exercising or defending legal claimsAs relevantLegal obligation; legitimate interests

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests are not overridden by your rights and freedoms. You may request a summary of that assessment from our DPO.

Where we rely on consent, you may withdraw it at any time as described in section 8. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may mean we can no longer provide certain features.

5. Artificial intelligence and automated processing

5.1 What Linx is

Linx is our AI-assisted feature set. It provides conversational explanations of information already in your Spendek account, cautious qualitative interpretations of forecasts that Spendek itself calculates, and suggested allocations of a budget across spending categories.

5.2 What is sent to our AI provider

To generate a response, we transmit to our AI model provider:

  • Instructions authored by Spendek.
  • A bounded, aggregated summary of your financial position — for example category totals, budget states, date ranges and counts.
  • The content of the message you submit.
Important

We do not transmit your full transaction ledger, your account numbers, your NIN, your password, PIN or authentication credentials. Where category identifiers are required, we use ephemeral codes rather than database identifiers.

Prompts and responses are transmitted with provider-side storage disabled, and our internal usage records retain aggregate counters only — not the content of prompts or responses.

5.3 Limits of AI output

Linx output is informational only. It is not financial, investment, tax, legal or accounting advice, and must not be relied upon as such. AI systems can produce inaccurate, incomplete or misleading output. All monetary amounts presented in Linx features are calculated by Spendek, not by the model. You are responsible for verifying any figure before acting on it.

5.4 Automated decision-making

We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. Linx makes suggestions; it does not create, modify or delete any budget, envelope or transaction without your explicit confirmation.

If this ever changes, we will update this Policy and provide you with information about the logic involved and your right to obtain human intervention, express your point of view and contest the decision.

6. Disclosure of your data

We do not sell your personal data. We do not share your data with third parties for their own independent marketing purposes.

We disclose personal data only as follows:

6.1 Service providers and processors

ProviderPurposeLocation
Mono Technologies Nigeria Limited
Open banking and identity verification
Account linking, transaction retrieval, NIN verificationNigeria
Flutterwave
Payment processing
Collecting payments for Linx tokens bought on spendek.comNigeria
Apple (App Store) and Google (Google Play Billing)Collecting payments for Linx tokens bought inside the app. Apple or Google is the merchant of record for those purchases and holds the payment details; we receive confirmation that a purchase completed, not your cardUnited States
OpenAI
AI model provider
Generating Linx responsesUnited States
Amazon Web Services
Cloud hosting and infrastructure
Operating the ServicesSweden (AWS eu-north-1)
Media storage providerStoring profile images and receiptsSweden (AWS eu-north-1)
PostHog
Product analytics
Recording which features and screens are used, so we can see where Spendek is confusing or broken. Linked to your account. Carries no amounts, balances, account numbers, NIN, names, emails, phone numbers or Linx messages.United States
Google (Firebase Crashlytics)
Crash reporting
Recording crashes and the device state around them, so faults can be diagnosed. Not linked to your account.United States
Communications providerSending emails and notificationsSweden (AWS eu-north-1)
Google (Firebase Cloud Messaging)
Push notification provider
Delivering push notifications to your deviceUnited States (Google, Firebase Cloud Messaging)

Each processor acts on our documented instructions under a written contract containing the protections required by the NDPA, including confidentiality, security, sub-processing controls, assistance with data subject rights, and deletion or return of data on termination.

6.2 Other disclosures

  • Within your family group: where you create or accept a sub-account, the account owner may see spending and budget information associated with that sub-account. We will make the scope of that visibility clear at the point you accept.
  • Legal and regulatory: to the NDPC, the Central Bank of Nigeria, the Nigerian Financial Intelligence Unit, law enforcement, courts, or other authorities where required by law or where necessary to establish, exercise or defend legal claims.
  • Corporate transactions: to a prospective buyer, investor or successor in the event of a merger, acquisition, restructuring or sale of assets, subject to confidentiality undertakings. We will notify you of any such transfer that materially affects how your data is handled.
  • Professional advisers: to our auditors, lawyers, insurers and accountants where they are bound by professional confidentiality.

7. International transfers

Some of our processors are located outside Nigeria. Our cloud hosting, media storage and communications infrastructure runs in Sweden (AWS eu-north-1). Our AI model provider, our push notification provider, our product analytics provider and our crash reporting provider are in the United States.

Product analytics are processed by PostHog in the United States and are linked to your account. Crash reports are processed by Google (Firebase Crashlytics) in the United States and are not linked to your account. Neither carries amounts, balances, account numbers, your NIN, names, email addresses, phone numbers or the contents of your Linx conversations — only which features were used, counts, and technical details of the device.

Push notifications are delivered through Google's Firebase Cloud Messaging. The data transferred is limited to a device registration token and the contents of the notification itself. We do not include account numbers, balances or transaction details in a notification payload.

Where we transfer personal data outside Nigeria, we do so only where one of the following applies, as required by Part VIII of the NDPA:

  1. The NDPC has determined the recipient jurisdiction provides an adequate level of protection
  2. The transfer is subject to appropriate safeguards, including standard contractual clauses or binding contractual commitments imposing protections equivalent to the NDPA
  3. You have given explicit consent, having been informed of the possible risks
  4. The transfer is necessary for the performance of a contract with you, or for the establishment, exercise or defence of legal claims

We limit transferred data to what is strictly necessary. In the case of AI processing, this means bounded aggregate summaries rather than raw records, as described in section 5.2.

You may request details of the safeguards applied to any transfer by writing to our DPO.

8. Your rights

Under the NDPA and NDPR you have the right to:

Access

Obtain confirmation of whether we process your data and receive a copy of it.

Rectification

Have inaccurate or incomplete data corrected.

Erasure

Request deletion where the data is no longer necessary, consent is withdrawn, or processing is unlawful.

Restriction

Require us to limit processing in defined circumstances.

Objection

Object to processing based on legitimate interests, and to direct marketing at any time.

Portability

Receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.

Withdraw consent

Withdraw consent at any time where processing is based on it.

Human review

Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

Lodge a complaint

Complain to the NDPC.

How to exercise your rights

Write to dpo@spendek.com or use the in-app account settings. We will respond within thirty (30) days. Where a request is complex or numerous, we may extend this by a further two months and will tell you why within the initial period.

We may ask you to verify your identity before acting on a request. We do not charge a fee, unless a request is manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable administrative fee or decline to act, giving reasons.

Limits on erasure

We may be unable to delete data we are required to retain by law — for example transaction and KYC records retained under anti-money-laundering legislation. Where we cannot erase, we will restrict processing to storage only and tell you why.

Complaints

If you are dissatisfied with our handling of your data, contact our DPO first so we may resolve it. You also have the right to complain directly to:

Nigeria Data Protection Commission

Website: ndpc.gov.ng

Email: info@ndpc.gov.ng

9. Security

We implement technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit using TLS, and encryption of sensitive data at rest
  • Passwords stored only as salted cryptographic hashes; never in plain text or in a recoverable form.
  • Session tokens protected by device hardware security (iOS Keychain, Android Keystore) where biometric login is enabled.
  • Role-based access control and the principle of least privilege for staff access.
  • Read-only access to linked bank accounts; no capability to initiate transfers from them.
  • Logging and monitoring of access to production systems, with logs excluding credentials and financial data.
  • Vendor due diligence and written data processing agreements.
  • Staff confidentiality obligations and data protection training.
  • Regular reviews, testing and, where required, an annual data protection audit filed with the NDPC.

No system is completely secure. We cannot guarantee absolute security, and you play an essential part: keep your password and PIN confidential, do not share your device, enable two-factor authentication, and tell us immediately if you suspect unauthorised access.

Breach notification

Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the NDPC within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we will notify you without undue delay, describing the nature of the breach, its likely consequences, the measures taken, and contact details for further information.

10. Retention

We retain personal data only for as long as necessary for the purposes set out in this Policy.

DataRetention period
Account and profile dataFor the life of your account, then five (5) years after closure, aligned to the anti-money-laundering periods below
KYC and identity verification recordsNot less than five (5) years after the end of the relationship, as required by the Money Laundering (Prevention and Prohibition) Act 2022
Transaction and financial recordsNot less than five (5) years
Payment and billing recordsNot less than six (6) years, for tax and audit purposes
Linx usage and metering recordsTwo (2) years, in aggregate form
Support communicationsThree (3) years after resolution
Marketing consent recordsFor the duration of consent plus three (3) years as proof
Server and security logsTwelve (12) months

At the end of the applicable period we securely delete or irreversibly anonymise the data. Anonymised data that can no longer identify you may be retained indefinitely for analytics and product improvement.

11. Children

The Services are not intended for, and may not be used by, persons under eighteen (18) years of age. We do not knowingly collect personal data from children.

Where you create a dependant or sub-account for a person under 18, you confirm that you are their parent or legal guardian and that you consent to our processing of their data on their behalf. You are responsible for informing them, in a manner appropriate to their age, of how their data is used.

If we learn that we have collected data from a child without proper authorisation, we will delete it promptly. Contact dpo@spendek.com if you believe this has occurred.

12. Cookies and website tracking

The spendek.com website sets no analytics, advertising or tracking cookies. We run no analytics product, no advertising pixel and no third-party tracking script on the site. Nothing on spendek.com profiles you or follows you to other websites, and there is therefore no cookie banner to accept or dismiss.

The only data stored in your browser is what is strictly necessary to serve the page and to carry out an action you have asked for — for example, submitting the form at spendek.com/delete-account. Strictly necessary storage of this kind does not require consent under the NDPA.

If we introduce analytics or any other non-essential cookie, we will ask for your consent before setting it and update this section first.

The mobile application does not use cookies. It uses a device identifier issued by Firebase Cloud Messaging so we can send you notifications, and our own first-party event logging as described in section 3.3. We do not embed third-party advertising or attribution SDKs in the app.

13. Third-party links

The Services may contain links to third-party websites and services, including your bank's authentication pages and our payment partner's checkout. We are not responsible for the content or privacy practices of those third parties. This Policy does not apply to them.

14. Changes to this Policy

We may update this Policy from time to time. Where a change is material — for example a new purpose of processing, a new category of recipient, or a change in lawful basis — we will notify you by email or through the Services at least fourteen (14) days before it takes effect, and where required by law we will seek your fresh consent.

The "Last updated" date at the top of this Policy shows when it was last revised. Continued use of the Services after the effective date constitutes acceptance of the revised Policy, save where consent is required.

15. Contact

Data Protection Officer

dpo@spendek.com

General enquiries

support@spendek.com

Postal

FRP LIMITED, Primaltek Plaza, No. 62/64 Egbeda–Idimu Road, Egbeda, Lagos, Lagos State, Nigeria

This Policy is governed by the laws of the Federal Republic of Nigeria.