Spendek Privacy Policy
1. Who we are
This Privacy Policy explains how FRP LIMITED (RC 8930511) ("Spendek", "we", "us", "our"), a company incorporated in the Federal Republic of Nigeria with its registered office at Primaltek Plaza, No. 62/64 Egbeda–Idimu Road, Egbeda, Lagos, Lagos State, Nigeria, collects, uses, stores, shares and protects your personal data when you use the Spendek mobile application, the website at spendek.com, and any related services (together, the "Services").
Spendek is the data controller in respect of the personal data described in this Policy.
We are registered with the Nigeria Data Protection Commission ("NDPC"). Our data protection registration number is NDPC/DPC/11694.
Data Protection Officer
Faith Umunnakwe
Email: dpo@spendek.com
Address: Primaltek Plaza, No. 62/64 Egbeda–Idimu Road, Egbeda, Lagos, Lagos State, Nigeria
This Policy is issued in compliance with the Nigeria Data Protection Act 2023 ("NDPA"), the Nigeria Data Protection Regulation 2019 ("NDPR"), and any subsidiary legislation, guidance or directives issued by the NDPC.
2. Scope
This Policy applies to all users of the Services, including account holders, dependants and sub-account users, prospective users, and visitors to our website.
It does not apply to the practices of third parties whose services you access through Spendek, including your bank, Mono Technologies Nigeria Limited, Flutterwave, or Apple and Google — who both distribute the app and, where you buy Linx tokens inside it, take the payment as merchant of record. Those parties handle your data under their own policies, and we encourage you to read them.
3. Personal data we collect
3.1 Data you give us directly
| Category | Examples | When collected |
|---|---|---|
| Identity data | First name, middle name, surname, date of birth, gender | Registration; identity verification |
| Contact data | Email address, phone number, residential address | Registration; profile updates |
| Profile data | Profile photograph, spending category preferences, budget and envelope configurations | Registration; ongoing use |
| Government identifiers | National Identification Number (NIN) | Identity verification |
| Authentication data | Password (stored only as a salted cryptographic hash), transaction PIN, two-factor authentication settings, biometric preference flag | Registration; security settings |
| Manually entered financial data | Transactions you record yourself, receipts you upload, cash splits, budget limits | Ongoing use |
| Uploaded bank statements | Statement files you upload in PDF or CSV form so we can read the transactions in them. A statement usually contains your full transaction history for the period, your account number and your account holder name | When you import a statement |
| Family and dependant data | Names, email addresses and relationship details of dependants or sub-account users you invite | When you create a sub-account |
| Communications | Messages you send to support, feedback, survey responses | When you contact us |
3.2 Data we collect from your financial institutions
Where you choose to link a bank account, we receive the following through our licensed open banking partner:
- Account identity: account holder name, account number (in whole or in part), account type, institution name and code.
- Balance data: current and available balances, currency.
- Transaction data: transaction narration, amount, debit or credit indicator, date, running balance and, where available, merchant or category signals.
- Where you consent to it, identity and income attributes held by your bank.
We receive this data on a read-only basis. Spendek cannot move money out of, or initiate a transfer from, any account you link. We never receive or store your internet banking username, password, PIN, token or one-time passwords — those are entered directly with your bank or our open banking partner and are never accessible to us.
3.3 Data generated by your use of the Services
- Usage and interaction data: features used, screens viewed, session timing, actions taken.
- Device and technical data: device model, operating system and version, application version, language, time zone, IP address, unique device or installation identifiers, crash and diagnostic logs.
- Transaction categorisation, budget performance, insights and analytics we derive from your financial data.
- Records of AI interactions: prompts you submit to Linx, the responses returned, and metering records (request counts, tokens reserved, settled or released).
- Payment records: amounts paid, payment references, payment status, token balances and purchase history. Where you buy inside the app, the payment itself is taken by Apple or Google and we receive only confirmation of the purchase — never your card details.
3.4 Data from third parties
- Identity verification results from our verification partner, including verified name, date of birth, gender, phone number, state and local government of origin and residence, and residential address associated with your NIN.
- Payment confirmations from our payment partner.
- Fraud, sanctions and watchlist screening resultswhere such screening is carried out.
3.5 Sensitive personal data
Your National Identification Number (NIN) and your financial data are treated as sensitive personal data under the NDPA. We apply enhanced safeguards to this data as described in section 9.
We do not knowingly collect data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, health data or sexual orientation. Please do not submit such information to us, including in free-text fields or messages to Linx.
4. How and why we use your data
We process personal data only where we have a lawful basis to do so. Each purpose below is listed with its basis.
| Purpose | Personal data used | Lawful basis (NDPA s.25) |
|---|---|---|
| Creating and administering your account | Identity, contact, authentication | Performance of a contract |
| Verifying your identity and meeting KYC/AML obligations | Identity, government identifiers, verification results | Legal obligation; performance of a contract |
| Linking bank accounts and importing transactions | Bank account, balance and transaction data | Consent; performance of a contract |
| Categorising spending, producing budgets, envelopes and insights | Financial data, usage data | Performance of a contract |
| Providing Linx AI features (chat, forecasts, envelope suggestions) | Bounded, aggregated financial summaries; your prompts | Consent; performance of a contract |
| Processing payments for Linx tokens | Payment records, identity, contact | Performance of a contract |
| Preventing fraud, abuse and unauthorised access | Device, usage, authentication, transaction data | Legitimate interests; legal obligation |
| Securing the Services and investigating incidents | Device, technical, log data | Legitimate interests; legal obligation |
| Support and responding to your enquiries | Contact, communications, account data | Performance of a contract; legitimate interests |
| Service emails and in-app notices (security, billing, service changes) | Contact data | Performance of a contract; legal obligation |
| Marketing communications | Contact data, usage data | Consent |
| Product improvement and analytics | Aggregated or de-identified usage data | Legitimate interests |
| Establishing, exercising or defending legal claims | As relevant | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests are not overridden by your rights and freedoms. You may request a summary of that assessment from our DPO.
Where we rely on consent, you may withdraw it at any time as described in section 8. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may mean we can no longer provide certain features.
5. Artificial intelligence and automated processing
5.1 What Linx is
Linx is our AI-assisted feature set. It provides conversational explanations of information already in your Spendek account, cautious qualitative interpretations of forecasts that Spendek itself calculates, and suggested allocations of a budget across spending categories.
5.2 What is sent to our AI provider
To generate a response, we transmit to our AI model provider:
- Instructions authored by Spendek.
- A bounded, aggregated summary of your financial position — for example category totals, budget states, date ranges and counts.
- The content of the message you submit.
We do not transmit your full transaction ledger, your account numbers, your NIN, your password, PIN or authentication credentials. Where category identifiers are required, we use ephemeral codes rather than database identifiers.
Prompts and responses are transmitted with provider-side storage disabled, and our internal usage records retain aggregate counters only — not the content of prompts or responses.
5.3 Limits of AI output
Linx output is informational only. It is not financial, investment, tax, legal or accounting advice, and must not be relied upon as such. AI systems can produce inaccurate, incomplete or misleading output. All monetary amounts presented in Linx features are calculated by Spendek, not by the model. You are responsible for verifying any figure before acting on it.
5.4 Automated decision-making
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. Linx makes suggestions; it does not create, modify or delete any budget, envelope or transaction without your explicit confirmation.
If this ever changes, we will update this Policy and provide you with information about the logic involved and your right to obtain human intervention, express your point of view and contest the decision.
6. Disclosure of your data
We do not sell your personal data. We do not share your data with third parties for their own independent marketing purposes.
We disclose personal data only as follows:
6.1 Service providers and processors
| Provider | Purpose | Location |
|---|---|---|
| Mono Technologies Nigeria Limited Open banking and identity verification | Account linking, transaction retrieval, NIN verification | Nigeria |
| Flutterwave Payment processing | Collecting payments for Linx tokens bought on spendek.com | Nigeria |
| Apple (App Store) and Google (Google Play Billing) | Collecting payments for Linx tokens bought inside the app. Apple or Google is the merchant of record for those purchases and holds the payment details; we receive confirmation that a purchase completed, not your card | United States |
| OpenAI AI model provider | Generating Linx responses | United States |
| Amazon Web Services Cloud hosting and infrastructure | Operating the Services | Sweden (AWS eu-north-1) |
| Media storage provider | Storing profile images and receipts | Sweden (AWS eu-north-1) |
| PostHog Product analytics | Recording which features and screens are used, so we can see where Spendek is confusing or broken. Linked to your account. Carries no amounts, balances, account numbers, NIN, names, emails, phone numbers or Linx messages. | United States |
| Google (Firebase Crashlytics) Crash reporting | Recording crashes and the device state around them, so faults can be diagnosed. Not linked to your account. | United States |
| Communications provider | Sending emails and notifications | Sweden (AWS eu-north-1) |
| Google (Firebase Cloud Messaging) Push notification provider | Delivering push notifications to your device | United States (Google, Firebase Cloud Messaging) |
Each processor acts on our documented instructions under a written contract containing the protections required by the NDPA, including confidentiality, security, sub-processing controls, assistance with data subject rights, and deletion or return of data on termination.
6.2 Other disclosures
- Within your family group: where you create or accept a sub-account, the account owner may see spending and budget information associated with that sub-account. We will make the scope of that visibility clear at the point you accept.
- Legal and regulatory: to the NDPC, the Central Bank of Nigeria, the Nigerian Financial Intelligence Unit, law enforcement, courts, or other authorities where required by law or where necessary to establish, exercise or defend legal claims.
- Corporate transactions: to a prospective buyer, investor or successor in the event of a merger, acquisition, restructuring or sale of assets, subject to confidentiality undertakings. We will notify you of any such transfer that materially affects how your data is handled.
- Professional advisers: to our auditors, lawyers, insurers and accountants where they are bound by professional confidentiality.
7. International transfers
Some of our processors are located outside Nigeria. Our cloud hosting, media storage and communications infrastructure runs in Sweden (AWS eu-north-1). Our AI model provider, our push notification provider, our product analytics provider and our crash reporting provider are in the United States.
Product analytics are processed by PostHog in the United States and are linked to your account. Crash reports are processed by Google (Firebase Crashlytics) in the United States and are not linked to your account. Neither carries amounts, balances, account numbers, your NIN, names, email addresses, phone numbers or the contents of your Linx conversations — only which features were used, counts, and technical details of the device.
Push notifications are delivered through Google's Firebase Cloud Messaging. The data transferred is limited to a device registration token and the contents of the notification itself. We do not include account numbers, balances or transaction details in a notification payload.
Where we transfer personal data outside Nigeria, we do so only where one of the following applies, as required by Part VIII of the NDPA:
- The NDPC has determined the recipient jurisdiction provides an adequate level of protection
- The transfer is subject to appropriate safeguards, including standard contractual clauses or binding contractual commitments imposing protections equivalent to the NDPA
- You have given explicit consent, having been informed of the possible risks
- The transfer is necessary for the performance of a contract with you, or for the establishment, exercise or defence of legal claims
We limit transferred data to what is strictly necessary. In the case of AI processing, this means bounded aggregate summaries rather than raw records, as described in section 5.2.
You may request details of the safeguards applied to any transfer by writing to our DPO.
8. Your rights
Under the NDPA and NDPR you have the right to:
Access
Obtain confirmation of whether we process your data and receive a copy of it.
Rectification
Have inaccurate or incomplete data corrected.
Erasure
Request deletion where the data is no longer necessary, consent is withdrawn, or processing is unlawful.
Restriction
Require us to limit processing in defined circumstances.
Objection
Object to processing based on legitimate interests, and to direct marketing at any time.
Portability
Receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
Withdraw consent
Withdraw consent at any time where processing is based on it.
Human review
Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
Lodge a complaint
Complain to the NDPC.
How to exercise your rights
Write to dpo@spendek.com or use the in-app account settings. We will respond within thirty (30) days. Where a request is complex or numerous, we may extend this by a further two months and will tell you why within the initial period.
We may ask you to verify your identity before acting on a request. We do not charge a fee, unless a request is manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable administrative fee or decline to act, giving reasons.
Limits on erasure
We may be unable to delete data we are required to retain by law — for example transaction and KYC records retained under anti-money-laundering legislation. Where we cannot erase, we will restrict processing to storage only and tell you why.
Complaints
If you are dissatisfied with our handling of your data, contact our DPO first so we may resolve it. You also have the right to complain directly to:
9. Security
We implement technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit using TLS, and encryption of sensitive data at rest
- Passwords stored only as salted cryptographic hashes; never in plain text or in a recoverable form.
- Session tokens protected by device hardware security (iOS Keychain, Android Keystore) where biometric login is enabled.
- Role-based access control and the principle of least privilege for staff access.
- Read-only access to linked bank accounts; no capability to initiate transfers from them.
- Logging and monitoring of access to production systems, with logs excluding credentials and financial data.
- Vendor due diligence and written data processing agreements.
- Staff confidentiality obligations and data protection training.
- Regular reviews, testing and, where required, an annual data protection audit filed with the NDPC.
No system is completely secure. We cannot guarantee absolute security, and you play an essential part: keep your password and PIN confidential, do not share your device, enable two-factor authentication, and tell us immediately if you suspect unauthorised access.
Breach notification
Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the NDPC within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we will notify you without undue delay, describing the nature of the breach, its likely consequences, the measures taken, and contact details for further information.
10. Retention
We retain personal data only for as long as necessary for the purposes set out in this Policy.
| Data | Retention period |
|---|---|
| Account and profile data | For the life of your account, then five (5) years after closure, aligned to the anti-money-laundering periods below |
| KYC and identity verification records | Not less than five (5) years after the end of the relationship, as required by the Money Laundering (Prevention and Prohibition) Act 2022 |
| Transaction and financial records | Not less than five (5) years |
| Payment and billing records | Not less than six (6) years, for tax and audit purposes |
| Linx usage and metering records | Two (2) years, in aggregate form |
| Support communications | Three (3) years after resolution |
| Marketing consent records | For the duration of consent plus three (3) years as proof |
| Server and security logs | Twelve (12) months |
At the end of the applicable period we securely delete or irreversibly anonymise the data. Anonymised data that can no longer identify you may be retained indefinitely for analytics and product improvement.
11. Children
The Services are not intended for, and may not be used by, persons under eighteen (18) years of age. We do not knowingly collect personal data from children.
Where you create a dependant or sub-account for a person under 18, you confirm that you are their parent or legal guardian and that you consent to our processing of their data on their behalf. You are responsible for informing them, in a manner appropriate to their age, of how their data is used.
If we learn that we have collected data from a child without proper authorisation, we will delete it promptly. Contact dpo@spendek.com if you believe this has occurred.
12. Cookies and website tracking
The spendek.com website sets no analytics, advertising or tracking cookies. We run no analytics product, no advertising pixel and no third-party tracking script on the site. Nothing on spendek.com profiles you or follows you to other websites, and there is therefore no cookie banner to accept or dismiss.
The only data stored in your browser is what is strictly necessary to serve the page and to carry out an action you have asked for — for example, submitting the form at spendek.com/delete-account. Strictly necessary storage of this kind does not require consent under the NDPA.
If we introduce analytics or any other non-essential cookie, we will ask for your consent before setting it and update this section first.
The mobile application does not use cookies. It uses a device identifier issued by Firebase Cloud Messaging so we can send you notifications, and our own first-party event logging as described in section 3.3. We do not embed third-party advertising or attribution SDKs in the app.
13. Third-party links
The Services may contain links to third-party websites and services, including your bank's authentication pages and our payment partner's checkout. We are not responsible for the content or privacy practices of those third parties. This Policy does not apply to them.
14. Changes to this Policy
We may update this Policy from time to time. Where a change is material — for example a new purpose of processing, a new category of recipient, or a change in lawful basis — we will notify you by email or through the Services at least fourteen (14) days before it takes effect, and where required by law we will seek your fresh consent.
The "Last updated" date at the top of this Policy shows when it was last revised. Continued use of the Services after the effective date constitutes acceptance of the revised Policy, save where consent is required.
15. Contact
Data Protection Officer
General enquiries
Postal
FRP LIMITED, Primaltek Plaza, No. 62/64 Egbeda–Idimu Road, Egbeda, Lagos, Lagos State, Nigeria