1. Who this policy covers, and who controls what
Dafsolt BOS for Finance ("the Platform") is core banking software provided by Dafsolt Consult ("Dafsolt", "we", "us") to cooperative societies, daily-contribution (ajo/esusu) groups, and microfinance institutions ("Client Institutions" or "Tenants"). This policy applies differently depending on who you are:
- Visitors to our public website, before signing up for anything.
- Tenant staff — a Client Institution's administrators, branch managers, tellers, and route officers who hold a login on the Platform.
- End customers/members — the borrowers, savers, and guarantors whose records a Client Institution enters and manages on the Platform.
If you are a member or customer of a cooperative, ajo/esusu group, or microfinance institution that uses this Platform, and you have a question or request about your own data, please contact that institution directly first — they hold the relationship with you and are legally responsible for it. If they are unable to resolve your request, you may contact us at the address below and we will assist as the Platform provider.
2. What data we collect
2.1 Visitors to our website
- Anonymous page-visit analytics: the page path, an anonymous visitor identifier generated and stored in your browser (not tied to any account), and how long you spent on the page. This is first-party only — we do not use third-party advertising trackers, Google Analytics, or similar tools.
- Information you voluntarily submit through a contact or registration form.
2.2 Tenant staff (Platform account holders)
- Name, email address, phone number, and role.
- Login credentials (your password is stored as a one-way cryptographic hash — we cannot see or recover your actual password) and, where enabled, two-factor authentication details.
- Activity logs: actions you take on the Platform (e.g. recording a payment, reversing an entry), each with a timestamp, for audit and security purposes.
2.3 End-customer/member data (entered by a Client Institution, on their behalf)
- Identity and contact information: full name, phone number, address, date of birth, occupation, and other government-issued ID details.
- National Identification Number (NIN) and Bank Verification Number (BVN), where a Client Institution has collected these for its own KYC/AML compliance.
- Financial records: savings balances and transaction history, loan applications, disbursements, repayment history, guarantor relationships, and risk/standing indicators.
- Support messages, if a member communicates through a Client Institution's use of the Platform's in-app assistant (see §4.3).
3. Legal basis for processing
Under the NDPA, personal data may only be processed where a lawful basis exists. Depending on the data and the party involved, we (or the relevant Client Institution, as Controller) rely on:
- Performance of a contract — to provide the Platform to a Tenant, or a loan/savings product to their member.
- Legal obligation — Client Institutions are generally required by Nigerian financial regulation (including CBN guidelines applicable to microfinance and cooperative lending) to collect and retain KYC/AML records such as NIN and BVN.
- Legitimate interest — fraud prevention, platform security, and service improvement, balanced against your rights and never used to justify marketing without consent.
- Consent — for anything not covered above, such as optional communications.
4. How data is used
- To operate the Platform — processing loans, savings, repayments, and generating the statements and reports a Client Institution and its members rely on.
- Security and audit — every financial-record correction (reversal or deletion) is logged with who made it, when, and the stated reason, so a Client Institution can account for its own books.
- AI support assistant — the in-app help assistant, where used, sends the text of your question (not your account credentials) to Groq, a third-party AI processing service based in the United States, solely to generate a response. See §6 on cross-border transfers.
- Communications — service notices (e.g. password resets, security alerts) and, only with consent, product updates.
- Compliance — responding to a lawful request from a Nigerian regulator, law enforcement agency, or court order.
We do not sell personal data, and we do not use member or customer data for advertising.
5. Who we share data with
- Within a Client Institution — staff see the data their role permits (e.g. a route officer sees only their assigned members; an administrator sees their whole institution). This is enforced in the software itself, not just by policy.
- Sub-processors we use to run the Platform: our hosting/server infrastructure, our email delivery provider, and (where the in-app assistant is used) Groq for AI text processing. Each is bound to only use data as we instruct, to provide the specific service.
- Regulators and law enforcement, where legally required to disclose.
- A successor entity, in the event of a merger, acquisition, or sale of Dafsolt's business — you would be notified of any such change and any resulting change to this policy.
We never share Client Institution data with another, unrelated Client Institution.
6. International data transfers
Our servers are operated by us and may be located outside Nigeria. Where the in-app AI assistant is used, the text of a query is processed by Groq in the United States. The NDPA permits cross-border transfer where the recipient country or organization provides an adequate level of data protection, or where appropriate contractual safeguards are in place — we take reasonable steps to ensure either applies before data is transferred.
7. Data retention
We retain data for as long as a Client Institution's account is active, plus any further period required by Nigerian financial-record-keeping regulation (commonly several years from the end of a customer relationship, for AML/KYC purposes) or needed to resolve disputes and enforce our agreements. A Client Institution controls its own members' retention decisions within these legal limits; contact them directly to request deletion of your own record.
8. Security measures
- Passwords are never stored in plain text — only as salted, one-way cryptographic hashes.
- Role-based access control restricts every user to only the data their role requires.
- Two-factor authentication is available, and mandatory for platform administrators.
- Financial records are append-only at the ledger level — a posted entry is never silently edited; a correction always creates a new, attributed entry, and every deletion is logged with a reason.
- Regular encrypted database backups are maintained.
No system is 100% secure, and we cannot guarantee absolute security — but we design and operate the Platform to industry-standard practice and will notify affected Client Institutions and, where legally required, the Nigeria Data Protection Commission (NDPC), without undue delay in the event of a data breach affecting personal data.
9. Your rights under the NDPA
If you are the Data Subject and the request concerns data controlled by us directly (visitor data, or your own Tenant staff account), you may exercise the following rights by contacting us at the email below. If your data is controlled by a Client Institution (i.e., you are their member/customer), please direct these requests to that institution first, per §1.
| Right | What it means |
|---|---|
| Access | Ask what personal data we hold about you. |
| Rectification | Ask us to correct inaccurate or incomplete data. |
| Erasure | Ask us to delete your data, subject to legal retention requirements. |
| Restriction | Ask us to limit how your data is used while a concern is resolved. |
| Portability | Request a copy of your data in a common electronic format. |
| Objection | Object to processing based on legitimate interest. |
| Complaint | Lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your rights have been violated. |
10. Cookies and local storage
The Platform uses a session cookie strictly necessary to keep you signed in — no advertising cookies. Our public website stores a randomly generated, anonymous visitor identifier in your browser's local storage to understand page engagement; it identifies a browser, never a person, and is never linked to an account.
11. Children's privacy
The Platform is not directed at, and is not knowingly used to collect data from, individuals under 18. Loan and savings products offered through Client Institutions are intended for adult members only, consistent with standard lending eligibility requirements.
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by an updated effective date at the top of this page, and, where required by law, Client Institutions will be notified directly.
13. Contact us
For any question about this policy, or to exercise a right described in §9 where we are the Controller:
Dafsolt Consult
Email: support@dafsolt.cloud